elastic / elastic/docs-content
[Kibana][9.4, 9.5, & Serverless] Document connector authentication (personal credentials, OAuth v2 testing, and related gaps)
- Dominant language
- No language data
- Stars
- 47
- Forks
- 261
- Avg merge
- 3d 12h
- Merged PRs (30d)
- 116
Description
### Description
**Summary:** This issue tracks all connector-authentication doc work stemming from the OAuth v2 / personal-credentials rollout in 9.4. It includes requests from https://github.com/elastic/docs-content/issues/6802 and https://github.com/elastic/docs-content/issues/6802.
**What:** We're introducing per-user authentication for Kibana connectors, enabling connectors to operate with user-specific permissions alongside the existing shared service account method.
**When:** This feature was shipped in v9.4.0.
**Why:** Currently, all Kibana connectors use a shared credentials for authentication, which lacks per-user access scope. Connector configuration with personal credentials improves security, auditability, and compliance by enabling fine-grained access control while maintaining compatibility with existing service account workflows.
### Doc plan
#### Create new page explaining personal vs. shared credentials
- [ ] Explain what personal credentials are vs. shared credentials, and when to use each
- [ ] Document how to configure per-user auth when creating/editing a connector
- [ ] Document permission/privilege requirements for personal credentials
#### Testing connectors
- [ ] Add a Connectors API testing example per connector (min. 1 working example — bar set by https://github.com/elastic/kibana/issues/273661)
- [ ] Confirm the "Test connector" UI ships correctly in 9.5 (https://github.com/elastic/search-team/issues/15316) - Verify existing docs match. No changes expected per @erikcurrin-elastic
- [ ] Review connector docs structure per https://github.com/elastic/kibana/issues/280455 - "Test connectors" section currently holds the action catalog, not testing content. Realign once testing content above is written
#### SharePoint Online: New Entra certificate auth (from https://github.com/elastic/docs-content/issues/6802)
- [ ] Add "OAuth Client Certificate (Microsoft Entra)" as a third auth type in Connector configuration
- [ ] Add a "Get API credentials" subsection: Entra app registration, Sites.Selected/Files.Read.All permissions, cert generation, upload, and field mapping (Token URL, Client ID, Certificate, Private Key, Passphrase)
- [ ] Scope with applies_to 9.5.0+, serverless
#### Agent Builder connector integration (blocked on product status)
- Page already marked not-applicable to 9.4 (https://github.com/elastic/docs-content/pull/7417) — No additional actions needed.
- Three product gaps from https://github.com/elastic/docs-content-internal/issues/1484 are unresolved and unlinked:
1. Experimental features must be enabled before connector creation (fix promised, no ticket linked)
2. SML shouldn't need to be referenced by name for discovery (fix promised, no ticket linked)
3. Minimum default-tools requirement (no response/commitment yet)
**Blocked on:** confirmation from @erikcurrin-elastic on (a) ticket links for items 1–2, (b) whether all three land in 9.5, before this can be scoped as a doc task.
### Resources
Product outcome: https://github.com/elastic/platform-product-outcomes/issues/159
Engineering epic: https://github.com/elastic/kibana-team/issues/1846 and https://github.com/elastic/search-team/issues/13423
### Which deployment methods does this change impact?
all deployments
### Feature differences
n/a
### What Elastic Stack release is this request related to?
v.9.4 , v.9.5
### Serverless release
v.9.4 , v.9.5
### Collaboration model
We expect to collaborate on the first draft
### Point of contact.
**Main contact:** @tiamliu @jcger
**Stakeholders:**@tiamliu
Contributor guide
No contributing guide indexed for this repository
Research direction
Start by reviewing docs-content issue 6802 and the existing connector documentation structure. Cover personal versus shared credentials, per-user configuration and privileges, one Connectors API testing example per connector, and the SharePoint Online Entra certificate-authentication section. Done means the checklist is documented for the stated 9.4/9.5 and Serverless scopes, after the blocked Agent Builder product questions are resolved.
Written by the indexing model from the issue text.
Assessment
- Domain
- api, authentication, documentation
- Issue type
- Documentation
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100