# Watcher webhook gives error 401 Authorization after certificate update

**URL:** <https://discuss.elastic.co/t/watcher-webhook-gives-error-401-authorization-after-certificate-update/335457>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [June 7, 2023, 6:03pm UTC](https://discuss.elastic.co/t/watcher-webhook-gives-error-401-authorization-after-certificate-update/335457 "2023-06-07T18:03:58Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![ynassipov](https://avatars.discourse-cdn.com/v4/letter/y/c67d28/32.png) [@ynassipov](https://discuss.elastic.co/u/ynassipov)\
**Post date:** [June 7, 2023, 6:03pm UTC](https://discuss.elastic.co/t/watcher-webhook-gives-error-401-authorization-after-certificate-update/335457/1 "2023-06-07T18:03:58Z")

</div>

Recently upgraded Elasticsearch from 8.3.2 to 8.6.2  
we have watcher with webhook posting information to 3rd party application  
for one of the instances of that 3rd party application we had to update SSL certificate  
after updating the certificate we started getting 401 authorization error on the watcher.  
also noticed that Authorization token in the watcher code has been replaced by "::es\_redacted::"

"actions": {  
"webhook\_1": {  
"webhook": {  
"scheme": "https",  
"host": "[hostname.com](http://hostname.com)",  
"port": 443,  
"method": "post",  
"path": "/api/1.0/route",  
"params": {},  
"headers": {  
"Authorization": "::es\_redacted::",  
"Content-Type": "application/json"  
},  
"body": """[{ "source\_ip"

If I replace "::es\_redacted::" with actual token - watcher works fine but if I save it it gets back to "::es\_redacted::" and fails to work.  
Other webhooks, communicating with other instances also have "::es\_redacted::" but no error, however we haven't updated certificate there yet.  
please advice what is causing this issue and how to fix it.  
Thanks

---

<div class="post-metadata">

**Author:** ![\_brady.s](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/_brady.s/32/58454_2.png) [@\_brady.s](https://discuss.elastic.co/u/_brady.s)\
**Post date:** [June 13, 2023, 12:57am UTC](https://discuss.elastic.co/t/watcher-webhook-gives-error-401-authorization-after-certificate-update/335457/2 "2023-06-13T00:57:33Z")

</div>

i has same problem with 8.6.2  
in watcher http input "Authorization" will be redacted  
but watcher edit ui save action not replace redacted to original data,  
get that watcher source from .watcher index , that's saved "::es\_redacted::", it means you lost your token. ☹

original watcher save -\> (normal) .watcher -\> (redacted) load watcher ui -\> (bug, redacted string will save) save watcher again -\> 401

I've searched the forums and github issues, but haven't found a patch for this, and the current solution is to save the token anew each time.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 11, 2023, 12:58am UTC](https://discuss.elastic.co/t/watcher-webhook-gives-error-401-authorization-after-certificate-update/335457/3 "2023-07-11T00:58:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
