Create a bearer token for access without requiring basic authentication.
The tokens are created by the Elasticsearch Token Service, which is automatically enabled when you configure TLS on the HTTP interface.
Alternatively, you can explicitly enable the xpack.security.authc.token.enabled setting.
When you are running in production mode, a bootstrap check prevents you from enabling the token service unless you also enable TLS on the HTTP interface.
The get token API takes the same parameters as a typical OAuth 2.0 token API except for the use of a JSON request body.
A successful get token API call returns a JSON structure that contains the access token, the amount of time (seconds) that the token expires in, the type, and the scope if available.
The tokens returned by the get token API have a finite period of time for which they are valid and after that time period, they can no longer be used.
That time period is defined by the xpack.security.authc.token.timeout setting.
If you want to invalidate a token immediately, you can do so by using the invalidate token API.
Required authorization
- Cluster privileges:
manage_token
Body
Required
-
The type of grant. Supported grant types are:
password,_kerberos,client_credentials,refresh_token, and_user_managed_service_account.Supported values include:
password: This grant type implements the Resource Owner Password Credentials Grant of OAuth2. In this grant, a trusted client exchanges the end user's credentials for an access token and (possibly) a refresh token. The request needs to be made by an authenticated user but happens on behalf of another authenticated user (the one whose credentials are passed as request parameters). This grant type is not suitable or designed for the self-service user creation of tokens.client_credentials: This grant type implements the Client Credentials Grant of OAuth2. It is geared for machine to machine communication and is not suitable or designed for the self-service user creation of tokens. It generates only access tokens that cannot be refreshed. The premise is that the entity that usesclient_credentialshas constant access to a set of (client, not end-user) credentials and can authenticate itself at will._kerberos: This grant type is supported internally and implements SPNEGO based Kerberos support. The_kerberosgrant type may change from version to version.refresh_token: This grant type implements the Refresh Token Grant of OAuth2. In this grant a user exchanges a previously issued refresh token for a new access token and a new refresh token._user_managed_service_account: This grant type is supported internally and exchanges a user-managed service account token for an access token that represents that service account. The request must be made by an authenticated caller with themanage_tokencluster privilege, on behalf of the service account whose token is passed in theservice_account_tokenparameter. The service account token is authenticated on every exchange, so a disabled account or an invalidated token is rejected. Tokens that belong to built-in (elastic/*) service accounts are rejected. It generates only access tokens that cannot be refreshed. The_user_managed_service_accountgrant type may change from version to version.
Values are
password,client_credentials,_kerberos,refresh_token, or_user_managed_service_account. -
The scope of the token. Currently tokens are only issued for a scope of FULL regardless of the value sent with the request.
-
The user's password. If you specify the
passwordgrant type, this parameter is required. This parameter is not valid with any other supported grant type. -
The base64 encoded kerberos ticket. If you specify the
_kerberosgrant type, this parameter is required. This parameter is not valid with any other supported grant type. -
The string that was returned when you created the token, which enables you to extend its life. If you specify the
refresh_tokengrant type, this parameter is required. This parameter is not valid with any other supported grant type. -
The service account token of a user-managed service account, as returned by the create service account token API. If you specify the
_user_managed_service_accountgrant type, this parameter is required. This parameter is not valid with any other supported grant type. -
The username that identifies the user. If you specify the
passwordgrant type, this parameter is required. This parameter is not valid with any other supported grant type.
POST /_security/oauth2/token
{
"grant_type" : "client_credentials"
}
resp = client.security.get_token(
grant_type="client_credentials",
)
const response = await client.security.getToken({
grant_type: "client_credentials",
});
response = client.security.get_token(
body: {
"grant_type": "client_credentials"
}
)
$resp = $client->security()->getToken([
"body" => [
"grant_type" => "client_credentials",
],
]);
curl -X POST -H "Authorization: ApiKey $ELASTIC_API_KEY" -H "Content-Type: application/json" -d '{"grant_type":"client_credentials"}' "$ELASTICSEARCH_URL/_security/oauth2/token"
var response = await client.Security
.GetTokenAsync(d1 => d1
.GrantType(AccessTokenGrantType.ClientCredentials)
);
client.security().getToken(g -> g
.grantType(AccessTokenGrantType.ClientCredentials)
);
{
"grant_type" : "client_credentials"
}
{
"grant_type" : "password",
"username" : "test_admin",
"password" : "x-pack-test-password"
}
{
"grant_type" : "_user_managed_service_account",
"service_account_token" : "AAEAAWFwcHMvb2F1dGgyX3dvcmtlci9leGNoYW5nZS10b2tlbjpyNVdhVjNiYUxTX2lPRXhRb0VOSDdR"
}
{
"access_token" : "dGhpcyBpcyBub3QgYSByZWFsIHRva2VuIGJ1dCBpdCBpcyBvbmx5IHRlc3QgZGF0YS4gZG8gbm90IHRyeSB0byByZWFkIHRva2VuIQ==",
"type" : "Bearer",
"expires_in" : 1200,
"authentication" : {
"username" : "test_admin",
"roles" : [
"superuser"
],
"full_name" : null,
"email" : null,
"metadata" : { },
"enabled" : true,
"authentication_realm" : {
"name" : "file",
"type" : "file"
},
"lookup_realm" : {
"name" : "file",
"type" : "file"
},
"authentication_type" : "realm"
}
}
{
"access_token" : "dGhpcyBpcyBub3QgYSByZWFsIHRva2VuIGJ1dCBpdCBpcyBvbmx5IHRlc3QgZGF0YS4gZG8gbm90IHRyeSB0byByZWFkIHRva2VuIQ==",
"type" : "Bearer",
"expires_in" : 1200,
"authentication" : {
"username" : "test_admin",
"roles" : [
"superuser"
],
"full_name" : null,
"email" : null,
"metadata" : { },
"enabled" : true,
"authentication_realm" : {
"name" : "file",
"type" : "file"
},
"lookup_realm" : {
"name" : "file",
"type" : "file"
},
"authentication_type" : "realm"
}
}
{
"access_token" : "dGhpcyBpcyBub3QgYSByZWFsIHRva2VuIGJ1dCBpdCBpcyBvbmx5IHRlc3QgZGF0YS4gZG8gbm90IHRyeSB0byByZWFkIHRva2VuIQ==",
"type" : "Bearer",
"expires_in" : 1200,
"authentication" : {
"username" : "apps/oauth2_worker",
"roles" : [
"umsa_oauth2_monitor"
],
"full_name" : "User-managed service account - apps/oauth2_worker",
"email" : null,
"metadata" : {
"_user_managed_service_account" : true
},
"enabled" : true,
"authentication_realm" : {
"name" : "_service_account",
"type" : "_service_account"
},
"lookup_realm" : {
"name" : "_service_account",
"type" : "_service_account"
},
"authentication_type" : "token"
}
}