# Authenticate with CLI (or API) via username & password

**URL:** <https://forums.suse.com/t/authenticate-with-cli-or-api-via-username-password/9757>\
**Category:** Rancher 1.x\
**Created:** [March 9, 2018, 8:34pm UTC](https://forums.suse.com/t/authenticate-with-cli-or-api-via-username-password/9757 "2018-03-09T20:34:30Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![afgane](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/afgane/32/3796_2.png) [@afgane](https://forums.suse.com/u/afgane)\
**Post date:** [March 9, 2018, 8:34pm UTC](https://forums.suse.com/t/authenticate-with-cli-or-api-via-username-password/9757/1 "2018-03-09T20:34:30Z")

</div>

Is it possible to use the Rancher CLI (or API) knowing only the username and password (after access control has been enabled) vs. the access and secret keys?

The [docs](http://rancher.com/docs/rancher/v1.6/en/cli/#configuring-the-rancher-command-line-interface) seem to require possession of the keys, which can be obtained only prior to enabling access control or require going through the UI. Unfortunately, these don’t play well with creating an idempotent setup process.

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [March 9, 2018, 9:12pm UTC](https://forums.suse.com/t/authenticate-with-cli-or-api-via-username-password/9757/2 "2018-03-09T21:12:04Z")

</div>

No; You could make an argument for this for local auth, but for the others there either is no username/password in the first place (github, saml) or it’s probably an important password to other systems that shouldn’t be written to config files in plaintext (ldap, activedirectory).

The UI is 100% static html/js/css, anything it does can be by definition done through the API. We don’t really document the token auth for UI session because most people have no use for it, but if you really want to create an API key given a username/password you post them to `/v2-beta/token` endpoint and can then use that to authenticate creating an apikey.

---

<div class="post-metadata">

**Author:** ![afgane](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/afgane/32/3796_2.png) [@afgane](https://forums.suse.com/u/afgane)\
**Post date:** [March 9, 2018, 9:29pm UTC](https://forums.suse.com/t/authenticate-with-cli-or-api-via-username-password/9757/3 "2018-03-09T21:29:04Z")

</div>

Got the token path working. Thanks for the pointer!
