# Embed OpenSearch Dashboards using iframe without providing user access to the cluster

**URL:** <https://forum.opensearch.org/t/embed-opensearch-dashboards-using-iframe-without-providing-user-access-to-the-cluster/21684>\
**Category:** OpenSearch\
**Tags:** discuss, troubleshoot, configure\
**Created:** [September 27, 2024, 6:26pm UTC](https://forum.opensearch.org/t/embed-opensearch-dashboards-using-iframe-without-providing-user-access-to-the-cluster/21684 "2024-09-27T18:26:35Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![zhan2819](https://avatars.discourse-cdn.com/v4/letter/z/48db29/32.png) [@zhan2819](https://forum.opensearch.org/u/zhan2819)\
**Post date:** [September 27, 2024, 6:26pm UTC](https://forum.opensearch.org/t/embed-opensearch-dashboards-using-iframe-without-providing-user-access-to-the-cluster/21684/1 "2024-09-27T18:26:35Z")

</div>

Hi guys!

We have a site with permission control for different clients. We are building an opensearch solution for all clients and would like to display each dashboard in an iframe on our site. How can we enable client permission to view dashboards in iframe without having to re-build the same access pattern in Opensearch, and without users from being able to login to the domain?

I.e A solution which access control is done through users being able to see what is displayed in the iframe, since user are only able to view our site pages which they have access to. Access to the opensearch domain itself is not provided.

---

<div class="post-metadata">

**Author:** ![Mantas](https://avatars.discourse-cdn.com/v4/letter/m/7bcc69/32.png) [@Mantas](https://forum.opensearch.org/u/Mantas)\
**Post date:** [September 30, 2024, 10:03am UTC](https://forum.opensearch.org/t/embed-opensearch-dashboards-using-iframe-without-providing-user-access-to-the-cluster/21684/2 "2024-09-30T10:03:20Z")

</div>

Hi @zhan2819,

Have you considered using JWT authentication for your iframe?

more here: [JSON Web Token - OpenSearch Documentation](https://opensearch.org/docs/latest/security/authentication-backends/jwt/)

a similar case has been discussed here: [Bypass sign-in to an embedded Opensearch dashboard iframe](https://forum.opensearch.org/t/bypass-sign-in-to-an-embedded-opensearch-dashboard-iframe/16195)

best,  
mj

---

<div class="post-metadata">

**Author:** ![zhan2819](https://avatars.discourse-cdn.com/v4/letter/z/48db29/32.png) [@zhan2819](https://forum.opensearch.org/u/zhan2819)\
**Post date:** [October 1, 2024, 3:21pm UTC](https://forum.opensearch.org/t/embed-opensearch-dashboards-using-iframe-without-providing-user-access-to-the-cluster/21684/3 "2024-10-01T15:21:20Z")

</div>

Thanks @Mantas! this is very helpful. We have two additional questions if you don’t mind:

1. Can we put the dataset discover page in an iframe for user to query on? Can they export from it?
2. If so, is there a way to prevent user from selecting another dataset in the discover dashboard, as dataset belonging to other clients will be there?

Thank you.
