Kibana UI displays generic error when API key expires or least‑privilege role blocks access
28K reputation · 28 Mar 2025, 12:23 UTC
When an API key used by Kibana expires, the UI returns a 401 Unauthorized response and shows an error banner, but does not attempt to obtain a new key or prompt the user to re‑authenticate without a full page reload.
Similarly, if a user’s least‑privilege role does not grant access to a requested Kibana feature, the interface displays a generic access‑denied message rather than indicating which privilege is missing.
Goal: determine why Kibana does not provide automatic token refresh or more specific privilege‑feedback in these situations, given its reliance on the underlying Elasticsearch security realm and configured token TTL.
What mechanisms would be required for Kibana to silently renew an expired API key?
How could the UI be extended to surface role‑based privilege details when access is denied?
Does the behavior change when using OIDC or SAML SSO where the identity provider handles token renewal?