stack es security get-api-key cli command
Auth required
Idempotent
Scope: global
elastic stack es security get-api-key [options]
Get API key information.
Behaviour flags:
--dry-run — validate all inputs and exit without performing any action
--idstring- An API key id.
This parameter cannot be used with any of
name,realm_nameorusername. --namestring- An API key name.
This parameter cannot be used with any of
id,realm_nameorusername. It supports prefix search with wildcard. --owner- A boolean flag that can be used to query API keys owned by the currently authenticated user.
The
realm_nameorusernameparameters cannot be specified when this parameter is set totrueas they are assumed to be the currently authenticated ones. --realm-namestring- The name of an authentication realm.
This parameter cannot be used with either
idornameor whenownerflag is set totrue. --usernamestring- The username of a user.
This parameter cannot be used with either
idornameor whenownerflag is set totrue. --with-limited-by- Return the snapshot of the owner user's role descriptors associated with the API key. An API key's actual permission is the intersection of its assigned role descriptors and the owner user's role descriptors.
--active-only- A boolean flag that can be used to query API keys that are currently active. An API key is considered active if it is neither invalidated, nor expired at query time. You can specify this together with other parameters such as
ownerorname. Ifactive_onlyis false, the response will include both active and inactive (expired or invalidated) keys. --with-profile-uid- Determines whether to also retrieve the profile uid, for the API key owner principal, if it exists.
--error-trace- When set to
trueElasticsearch will include the full stack trace of errors when they occur. --filter-pathstring-
Comma-separated list of filters in dot notation which reduce the response returned by Elasticsearch.
Repeatable: pass
--filter-pathmultiple times to supply more than one value --human- When set to
truewill return statistics in a format suitable for humans. For example"exists_time": "1h"for humans and"exists_time_in_millis": 3600000for computers. When disabled the human readable values will be omitted. This makes sense for responses being consumed only by machines. --pretty- If set to
truethe returned JSON will be "pretty-formatted". Only use this option for debugging only. --input-filestring- path to a JSON file to use as command input
--dry-run- validate all inputs and exit without performing any action (preview changes without applying them)
--json-
output as JSON