﻿---
title: stack es security grant-api-key cli command
description: Grant an API key. Behaviour flags: --dry-run — validate all inputs and exit without performing any action 
url: https://www.elastic.co/elastic/docs-builder/docs/4118/reference/elastic-cli/cli/stack/es/security/grant-api-key
applies_to:
  - Elastic Cloud Serverless: Preview
  - Elastic Stack: Preview
---

# stack es security grant-api-key cli command
<cli-modifiers>
</cli-modifiers>

```bash
elastic stack es security grant-api-key \
  --api-key <api-key> \
  --grant-type <grant-type> \
  [options]
```

Grant an API key.
**Behaviour flags:**
`--dry-run` — validate all inputs and exit without performing any action

## Options

<definitions>
  <definition term="--api-key string required">
    The API key.
  </definition>
  <definition term="--grant-type enum required">
    The type of grant. Supported grant types are: `access_token`, `password`.
    **Values:** access_token, password
  </definition>
  <definition term="--refresh enum">
    If 'true', Elasticsearch refreshes the affected shards to make this operation
    visible to search.
    If 'wait_for', it waits for a refresh to make this operation visible to search.
    If 'false', nothing is done with refreshes.
    **Values:** true, false, wait_for
  </definition>
  <definition term="--access-token string">
    The user's access token.
    If you specify the `access_token` grant type, this parameter is required.
    It is not valid with other grant types.
  </definition>
  <definition term="--username string">
    The user name that identifies the user.
    If you specify the `password` grant type, this parameter is required.
    It is not valid with other grant types.
  </definition>
  <definition term="--password string">
    The user's password.
    If you specify the `password` grant type, this parameter is required.
    It is not valid with other grant types.
  </definition>
  <definition term="--run-as string">
    The name of the user to be impersonated.
  </definition>
  <definition term="--error-trace">
    When set to `true` Elasticsearch will include the full stack trace of errors
    when they occur.
  </definition>
  <definition term="--filter-path string">
    Comma-separated list of filters in dot notation which reduce the response
    returned by Elasticsearch.
    **Repeatable:** pass `--filter-path` multiple times to supply more than one value
  </definition>
  <definition term="--human">
    When set to `true` will return statistics in a format suitable for humans.
    For example `"exists_time": "1h"` for humans and
    `"exists_time_in_millis": 3600000` for computers. When disabled the human
    readable values will be omitted. This makes sense for responses being consumed
    only by machines.
  </definition>
  <definition term="--pretty">
    If set to `true` the returned JSON will be "pretty-formatted". Only use
    this option for debugging only.
  </definition>
  <definition term="--input-file string">
    path to a JSON file to use as command input
  </definition>
  <definition term="--dry-run">
    validate all inputs and exit without performing any action (preview changes without applying them)
  </definition>
</definitions>


## Global Options

<definitions>
  <definition term="--json">
    output as JSON
  </definition>
</definitions>