# Using OIDC authenticated browser session to query Elasticsearch API

**URL:** <https://discuss.elastic.co/t/using-oidc-authenticated-browser-session-to-query-elasticsearch-api/221278>\
**Category:** Elasticsearch\
**Created:** [February 27, 2020, 4:16pm UTC](https://discuss.elastic.co/t/using-oidc-authenticated-browser-session-to-query-elasticsearch-api/221278 "2020-02-27T16:16:05Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dennis\_Rietvink](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dennis_rietvink/32/60342_2.png) [@Dennis\_Rietvink](https://discuss.elastic.co/u/Dennis_Rietvink)\
**Post date:** [February 27, 2020, 4:16pm UTC](https://discuss.elastic.co/t/using-oidc-authenticated-browser-session-to-query-elasticsearch-api/221278/1 "2020-02-27T16:16:05Z")

</div>

Hi There,

We are currently successfully using an OIDC setup with Keycloak to integrate Kibana dashboards into our customer portal. We use Elastic Cloud as backend and host the Kibana instances ourselves. Both running 7.5.1.

OIDC config:

```auto
xpack:
  security:
    authc:
      realms:
        oidc:
          customer: 
            order: 2
            rp.client_id: "kibana" 
            rp.response_type: "code"
            rp.redirect_uri: "https://kibana. ***********.com/api/security/v1/oidc" 
            rp.post_logout_redirect_uri: "https://kibana. ***********.com/logout"
            op.issuer: "https://keycloak. ***********.com/auth/realms/customer" 
            op.authorization_endpoint: "https://keycloak ***********.com/auth/realms/customer/protocol/openid-connect/auth" 
            op.token_endpoint: "https://keycloak. ***********.com/auth/realms/customer/protocol/openid-connect/token" 
            op.userinfo_endpoint: "https://keycloak. ***********.com/auth/realms/customer/protocol/openid-connect/userinfo" 
            op.jwkset_path: "https://keycloak. ***********.com/auth/realms/customer/protocol/openid-connect/certs" 
            claims.principal: sub
            claims.name: preferred_username
            claims.mail: email
            claims.groups: groups

```

Plans are to add some D3 graphs to our portal that need direct access to the elasticsearch API with the logged on credentials.

My dev guys are have not been able to create a successful setup. The article on your website ([https://www.elastic.co/guide/en/elasticsearch/reference/current/oidc-without-kibana.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/oidc-without-kibana.html)) didn't really help.

Questions:

- is what we are trying to achieve possible?
- do you have any working examples that we could use as a reference?

Thanks,  
Dennis

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 26, 2020, 4:16pm UTC](https://discuss.elastic.co/t/using-oidc-authenticated-browser-session-to-query-elasticsearch-api/221278/2 "2020-03-26T16:16:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
