# API Keys access version 3.7.0

**URL:** <https://forum.opensearch.org/t/api-keys-access-version-3-7-0/28130>\
**Category:** Security\
**Created:** [June 11, 2026, 10:17pm UTC](https://forum.opensearch.org/t/api-keys-access-version-3-7-0/28130 "2026-06-11T22:17:02Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![hitesh303](https://avatars.discourse-cdn.com/v4/letter/h/bbe5ce/32.png) [@hitesh303](https://forum.opensearch.org/u/hitesh303)\
**Post date:** [June 11, 2026, 10:17pm UTC](https://forum.opensearch.org/t/api-keys-access-version-3-7-0/28130/1 "2026-06-11T22:17:03Z")

</div>

**Versions** (relevant - OpenSearch/Dashboard/Server OS/Browser):

**Describe the issue** : Upgraded to 3.7.0. When log-in as user can’t see API key option in UI. Is this only limited to Admin?

**Configuration** :

**Relevant Logs or Screenshots** :

---

<div class="post-metadata">

**Author:** ![Anthony](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/anthony/32/9939_2.png) [@Anthony](https://forum.opensearch.org/u/Anthony)\
**Post date:** [June 12, 2026, 9:38am UTC](https://forum.opensearch.org/t/api-keys-access-version-3-7-0/28130/2 "2026-06-12T09:38:18Z")

</div>

@hitesh303 Welcome to the forum!

According to the [documentation](https://docs.opensearch.org/latest/security/access-control/api-keys/#limitations): “Only security administrators can create, list, and revoke API keys”

Are you referring to option in “Security” → “API Keys”?

Is your user mapped to `all_access` role to access the “Security” section? Or is one of the roles its mapped to listed in `plugins.security.restapi.roles_enabled`?

---

<div class="post-metadata">

**Author:** ![hitesh303](https://avatars.discourse-cdn.com/v4/letter/h/bbe5ce/32.png) [@hitesh303](https://forum.opensearch.org/u/hitesh303)\
**Post date:** [June 12, 2026, 11:39am UTC](https://forum.opensearch.org/t/api-keys-access-version-3-7-0/28130/3 "2026-06-12T11:39:06Z")

</div>

Hi Anthony,

Thanks for quick response and doc. As Admin we can see the option but not as user.

---

<div class="post-metadata">

**Author:** ![Anthony](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/anthony/32/9939_2.png) [@Anthony](https://forum.opensearch.org/u/Anthony)\
**Post date:** [June 15, 2026, 9:11am UTC](https://forum.opensearch.org/t/api-keys-access-version-3-7-0/28130/4 "2026-06-15T09:11:03Z")

</div>

@hitesh303 yes, this is by design, as per the documentation.

---

<div class="post-metadata">

**Author:** ![hitesh303](https://avatars.discourse-cdn.com/v4/letter/h/bbe5ce/32.png) [@hitesh303](https://forum.opensearch.org/u/hitesh303)\
**Post date:** [June 22, 2026, 7:34pm UTC](https://forum.opensearch.org/t/api-keys-access-version-3-7-0/28130/5 "2026-06-22T19:34:25Z")

</div>

Hi Anthony,

I have created api key with below permissions:  
POST /\_plugins/\_security/api/apitokens  
{  
“name”: “hp-api-new6”,  
“cluster\_permissions”: [“cluster\_monitor”],  
“index\_permissions”: [  
{  
“index\_pattern”: [  
“logs-\*_“,”_”  
],  
“allowed\_actions”: [  
“\*”  
]  
}  
],  
“duration\_seconds”: 2592000  
}

But when I search the index I’m not getting any documents in postman get call:

{  
“took”: 3,  
“timed\_out”: false,  
“\_shards”: {  
“total”: 1,  
“successful”: 1,  
“skipped”: 0,  
“failed”: 0  
},  
“hits”: {  
“total”: {  
“value”: 0,  
“relation”: “eq”  
},  
“max\_score”: null,  
“hits”:   
}  
}
