elastic / elastic/docs-content

[Kibana][9.4, 9.5, & Serverless] Document connector authentication (personal credentials, OAuth v2 testing, and related gaps)

Open
#7,828 0 comments 0 reactions 0 assignees View on GitHub
documentation unplanned
Dominant language
No language data
Stars
47
Forks
261
Avg merge
3d 12h
Merged PRs (30d)
116

Description

### Description

**Summary:** This issue tracks all connector-authentication doc work stemming from the OAuth v2 / personal-credentials rollout in 9.4. It includes requests from https://github.com/elastic/docs-content/issues/6802 and https://github.com/elastic/docs-content/issues/6802.

**What:** We're introducing per-user authentication for Kibana connectors, enabling connectors to operate with user-specific permissions alongside the existing shared service account method.

**When:** This feature was shipped in v9.4.0.

**Why:** Currently, all Kibana connectors use a shared credentials for authentication, which lacks per-user access scope. Connector configuration with personal credentials improves security, auditability, and compliance by enabling fine-grained access control while maintaining compatibility with existing service account workflows.

### Doc plan

#### Create new page explaining personal vs. shared credentials
- [ ] Explain what personal credentials are vs. shared credentials, and when to use each
- [ ] Document how to configure per-user auth when creating/editing a connector
- [ ] Document permission/privilege requirements for personal credentials

#### Testing connectors
- [ ] Add a Connectors API testing example per connector (min. 1 working example — bar set by https://github.com/elastic/kibana/issues/273661)
- [ ] Confirm the "Test connector" UI ships correctly in 9.5 (https://github.com/elastic/search-team/issues/15316) - Verify existing docs match. No changes expected per @erikcurrin-elastic
- [ ] Review connector docs structure per https://github.com/elastic/kibana/issues/280455 - "Test connectors" section currently holds the action catalog, not testing content. Realign once testing content above is written

#### SharePoint Online: New Entra certificate auth (from https://github.com/elastic/docs-content/issues/6802)
- [ ] Add "OAuth Client Certificate (Microsoft Entra)" as a third auth type in Connector configuration
- [ ] Add a "Get API credentials" subsection: Entra app registration, Sites.Selected/Files.Read.All permissions, cert generation, upload, and field mapping (Token URL, Client ID, Certificate, Private Key, Passphrase)
- [ ] Scope with applies_to 9.5.0+, serverless

#### Agent Builder connector integration (blocked on product status)
- Page already marked not-applicable to 9.4 (https://github.com/elastic/docs-content/pull/7417) — No additional actions needed.
- Three product gaps from https://github.com/elastic/docs-content-internal/issues/1484 are unresolved and unlinked:
1. Experimental features must be enabled before connector creation (fix promised, no ticket linked)
2. SML shouldn't need to be referenced by name for discovery (fix promised, no ticket linked)
3. Minimum default-tools requirement (no response/commitment yet)

**Blocked on:** confirmation from @erikcurrin-elastic on (a) ticket links for items 1–2, (b) whether all three land in 9.5, before this can be scoped as a doc task.

### Resources

Product outcome: https://github.com/elastic/platform-product-outcomes/issues/159
Engineering epic: https://github.com/elastic/kibana-team/issues/1846 and https://github.com/elastic/search-team/issues/13423

### Which deployment methods does this change impact?
all deployments

### Feature differences

n/a
### What Elastic Stack release is this request related to?

v.9.4 , v.9.5

### Serverless release
v.9.4 , v.9.5

### Collaboration model

We expect to collaborate on the first draft

### Point of contact.

**Main contact:** @tiamliu @jcger

**Stakeholders:**@tiamliu

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reviewing docs-content issue 6802 and the existing connector documentation structure. Cover personal versus shared credentials, per-user configuration and privileges, one Connectors API testing example per connector, and the SharePoint Online Entra certificate-authentication section. Done means the checklist is documented for the stated 9.4/9.5 and Serverless scopes, after the blocked Agent Builder product questions are resolved.

Written by the indexing model from the issue text.

Assessment

Domain
api, authentication, documentation
Issue type
Documentation
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.