# AUTHENTICATION\_APIKEY\_ENABLED: 'true' throwing oidc auth not configured error

**URL:** <https://forum.weaviate.io/t/authentication-apikey-enabled-true-throwing-oidc-auth-not-configured-error/2175>\
**Category:** General\
**Created:** [May 3, 2024, 3:34am UTC](https://forum.weaviate.io/t/authentication-apikey-enabled-true-throwing-oidc-auth-not-configured-error/2175 "2024-05-03T03:34:05Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sukanta\_Nanda](https://yyz1.discourse-cdn.com/flex027/user_avatar/forum.weaviate.io/sukanta_nanda/32/602_2.png) [@Sukanta\_Nanda](https://forum.weaviate.io/u/Sukanta_Nanda)\
**Post date:** [May 3, 2024, 3:34am UTC](https://forum.weaviate.io/t/authentication-apikey-enabled-true-throwing-oidc-auth-not-configured-error/2175/1 "2024-05-03T03:34:05Z")

</div>

curl [http://adb83896cdc8d45df833bb48ee424179-1487540750.us-east-1.elb.amazonaws.com:80/v1/meta](http://adb83896cdc8d45df833bb48ee424179-1487540750.us-east-1.elb.amazonaws.com:80/v1/meta) -H “Authorization: Bearer secret1” | jq  
% Total % Received % Xferd Average Speed Time Time Time Current  
Dload Upload Total Spent Left Speed  
100 124 100 124 0 0 576 0 --:–:-- --:–:-- --:–:-- 579  
{  
“code”: 401,  
“message”: “oidc auth is not configured, please try another auth scheme or set up weaviate with OIDC configured”  
}

---

<div class="post-metadata">

**Author:** ![DudaNogueira](https://yyz1.discourse-cdn.com/flex027/user_avatar/forum.weaviate.io/dudanogueira/32/7846_2.png) [@DudaNogueira](https://forum.weaviate.io/u/DudaNogueira)\
**Post date:** [May 3, 2024, 1:26pm UTC](https://forum.weaviate.io/t/authentication-apikey-enabled-true-throwing-oidc-auth-not-configured-error/2175/2 "2024-05-03T13:26:40Z")

</div>

Hi!

Can you share the environment variables you have?

You probably have it misconfigured.

check here for references:

> **[Authentication | Weaviate - Vector Database](https://weaviate.io/developers/weaviate/configuration/authentication#oidc---configuring-weaviate-as-the-resource)**
>
> Weaviate offers an optional authentication scheme using API keys and OpenID Connect (OIDC), which can enable various authorizations levels.

Thanks!

---

<div class="post-metadata">

**Author:** ![Sukanta\_Nanda](https://yyz1.discourse-cdn.com/flex027/user_avatar/forum.weaviate.io/sukanta_nanda/32/602_2.png) [@Sukanta\_Nanda](https://forum.weaviate.io/u/Sukanta_Nanda)\
**Post date:** [May 3, 2024, 3:37pm UTC](https://forum.weaviate.io/t/authentication-apikey-enabled-true-throwing-oidc-auth-not-configured-error/2175/3 "2024-05-03T15:37:25Z")

</div>

authentication:  
anonymous\_access:  
enabled: false

# This configuration allows to add API keys to Weaviate. This configuration allows only

# plain text API Keys, if you want to store the API Keys in a Kubernetes secret you can

# configure the same configuration with ENV Vars. Read the `env` section below on what

# needs to be configured. If using ENV Vars over this make sure to comment out the whole

#`apikey` section (as it is by default). ENV Vars has priority over this config.  
apikey:  
enabled: true

# # Any number of allowed API Keys as plain text

```
allowed_keys:
   - readOnly-API-Key
   - admin-API-Key

```

# # You can either set a single user for all the listed Allowed API keys OR

# # one user per API Key, i.e. length(apikey.allowed\_keys) == length(apikey.users) OR

# # length(apikey.users) == 1

# # NOTE: Make sure the lister Users are added to the Authorization as well.

```
users:
   - suknanda
   - nkhaja

```

oidc:  
enabled: false  
# issuer: ‘’  
# username\_claim: ‘’  
# groups\_claim: ‘’  
# client\_id: ‘’

authorization:  
admin\_list:  
enabled: true  
users:  
- suknanda  
# - admin\_user2  
# - api-key-user-admin  
read\_only\_users:  
- nkhaja  
# - readonly\_user2  
# - api-key-user-readOnly

---

<div class="post-metadata">

**Author:** ![Sukanta\_Nanda](https://yyz1.discourse-cdn.com/flex027/user_avatar/forum.weaviate.io/sukanta_nanda/32/602_2.png) [@Sukanta\_Nanda](https://forum.weaviate.io/u/Sukanta_Nanda)\
**Post date:** [May 3, 2024, 3:43pm UTC](https://forum.weaviate.io/t/authentication-apikey-enabled-true-throwing-oidc-auth-not-configured-error/2175/4 "2024-05-03T15:43:10Z")

</div>

##########################

# API Keys with ENV Vars

##########################

# If using ENV Vars to set up API Keys make sure to have `authentication.apikey` block commented out

# to avoid any future changes. ENV Vars has priority over the config above `authentication.apikey`.

# If using `authentication.apikey `the below ENV Vars will be used because they have priority,

# so comment them out to avoid any future changes.

# Enables API key authentication. If it is set to ‘false’ the AUTHENTICATION\_APIKEY\_ALLOWED\_KEYS

# and AUTHENTICATION\_APIKEY\_USERS will not have any effect.

AUTHENTICATION\_APIKEY\_ENABLED: ‘true’

# List one or more keys, separated by commas. Each key corresponds to a specific user identity below.

# If you want to use a kubernetes secret for the API Keys comment out this Variable and use the one in `envSecrets` below

# AUTHENTICATION\_APIKEY\_ALLOWED\_KEYS: ‘jane-secret-key,ian-secret-key’ (plain text)

AUTHENTICATION\_APIKEY\_ALLOWED\_KEYS: ‘secret1,secret2’

# List one or more user identities, separated by commas. You can have only one User for all the keys or one user per key.

# The User/s can be a simple name or an email, no matter if it exists or not.

# NOTE: Make sure to add the users to the authorization above overwise they will not be allowed to interact with Weaviate.

# AUTHENTICATION\_APIKEY\_USERS: ‘jane@doe.com,ian-smith’

AUTHENTICATION\_APIKEY\_USERS: ‘suknanda,nkhaja’  
AUTHORIZATION\_ADMINLIST\_ENABLED: ‘true’  
AUTHORIZATION\_ADMINLIST\_USERS: ‘suknanda,nkhaja’  
AUTHORIZATION\_ADMINLIST\_READONLY\_USERS: ‘nkhaja1’  
AUTHENTICATION\_OIDC\_ISSUER: “[https://auth.wcs.api.weaviate.io/auth/realms/SeMI](https://auth.wcs.api.weaviate.io/auth/realms/SeMI)”  
AUTHENTICATION\_OIDC\_ENABLED: ‘true’  
AUTHENTICATION\_OIDC\_CLIENT\_ID: ‘wcs’  
AUTHENTICATION\_OIDC\_USERNAME\_CLAIM: ‘email’

---

<div class="post-metadata">

**Author:** ![DudaNogueira](https://yyz1.discourse-cdn.com/flex027/user_avatar/forum.weaviate.io/dudanogueira/32/7846_2.png) [@DudaNogueira](https://forum.weaviate.io/u/DudaNogueira)\
**Post date:** [May 7, 2024, 12:45pm UTC](https://forum.weaviate.io/t/authentication-apikey-enabled-true-throwing-oidc-auth-not-configured-error/2175/5 "2024-05-07T12:45:41Z")

</div>

hi, not sure I understood.

Are you using k8s or docker compose?

---

<div class="post-metadata">

**Author:** ![Sukanta\_Nanda](https://yyz1.discourse-cdn.com/flex027/user_avatar/forum.weaviate.io/sukanta_nanda/32/602_2.png) [@Sukanta\_Nanda](https://forum.weaviate.io/u/Sukanta_Nanda)\
**Post date:** [May 8, 2024, 3:08pm UTC](https://forum.weaviate.io/t/authentication-apikey-enabled-true-throwing-oidc-auth-not-configured-error/2175/6 "2024-05-08T15:08:37Z")

</div>

We have been using EKS on aws.

---

<div class="post-metadata">

**Author:** ![DudaNogueira](https://yyz1.discourse-cdn.com/flex027/user_avatar/forum.weaviate.io/dudanogueira/32/7846_2.png) [@DudaNogueira](https://forum.weaviate.io/u/DudaNogueira)\
**Post date:** [May 8, 2024, 7:42pm UTC](https://forum.weaviate.io/t/authentication-apikey-enabled-true-throwing-oidc-auth-not-configured-error/2175/7 "2024-05-08T19:42:28Z")

</div>

Do you want to use OIDC?

Have you tried commenting out those:

AUTHENTICATION\_OIDC\_ISSUER: “[https://auth.wcs.api.weaviate.io/auth/realms/SeMI”](https://auth.wcs.api.weaviate.io/auth/realms/SeMI%E2%80%9D)  
AUTHENTICATION\_OIDC\_ENABLED: ‘true’  
AUTHENTICATION\_OIDC\_CLIENT\_ID: ‘wcs’  
AUTHENTICATION\_OIDC\_USERNAME\_CLAIM: ‘email’

?

---

<div class="post-metadata">

**Author:** ![Sukanta\_Nanda](https://yyz1.discourse-cdn.com/flex027/user_avatar/forum.weaviate.io/sukanta_nanda/32/602_2.png) [@Sukanta\_Nanda](https://forum.weaviate.io/u/Sukanta_Nanda)\
**Post date:** [May 9, 2024, 5:16am UTC](https://forum.weaviate.io/t/authentication-apikey-enabled-true-throwing-oidc-auth-not-configured-error/2175/8 "2024-05-09T05:16:43Z")

</div>

Latest values.yaml :  
##########################

# API Keys with ENV Vars

##########################

# If using ENV Vars to set up API Keys make sure to have `authentication.apikey` block commented out

# to avoid any future changes. ENV Vars has priority over the config above `authentication.apikey`.

# If using `authentication.apikey `the below ENV Vars will be used because they have priority,

# so comment them out to avoid any future changes.

# Enables API key authentication. If it is set to ‘false’ the AUTHENTICATION\_APIKEY\_ALLOWED\_KEYS

# and AUTHENTICATION\_APIKEY\_USERS will not have any effect.

AUTHENTICATION\_APIKEY\_ENABLED: ‘true’

# List one or more keys, separated by commas. Each key corresponds to a specific user identity below.

# If you want to use a kubernetes secret for the API Keys comment out this Variable and use the one in `envSecrets` below

# AUTHENTICATION\_APIKEY\_ALLOWED\_KEYS: ‘jane-secret-key,ian-secret-key’ (plain text)

AUTHENTICATION\_APIKEY\_ALLOWED\_KEYS: ‘secret1,secret2’

# List one or more user identities, separated by commas. You can have only one User for all the keys or one user per key.

# The User/s can be a simple name or an email, no matter if it exists or not.

# NOTE: Make sure to add the users to the authorization above overwise they will not be allowed to interact with Weaviate.

# AUTHENTICATION\_APIKEY\_USERS: ‘jane@doe.com,ian-smith’

AUTHENTICATION\_APIKEY\_USERS: ‘suknanda,nkhaja’  
AUTHORIZATION\_ADMINLIST\_ENABLED: ‘true’  
AUTHORIZATION\_ADMINLIST\_USERS: ‘suknanda,nkhaja’  
AUTHORIZATION\_ADMINLIST\_READONLY\_USERS: ‘nkhaja1’

authentication:  
anonymous\_access:  
enabled: false  
apikey:  
enabled: true

# # Any number of allowed API Keys as plain text

```
  allowed_keys:
   - adminkey

```

# # You can either set a single user for all the listed Allowed API keys OR

# # one user per API Key, i.e. length(apikey.allowed\_keys) == length(apikey.users) OR

# # length(apikey.users) == 1

# # NOTE: Make sure the lister Users are added to the Authorization as well.

```
  users:
   - suknanda
   - nkhaja

```

oidc:  
enabled: false  
#issuer: ‘’  
#username\_claim: ‘’  
#groups\_claim: ‘’  
#client\_id: ‘’

authorization:  
admin\_list:  
enabled: true  
users:  
- suknanda  
# - admin\_user2  
# - api-key-user-admin  
read\_only\_users:  
- nkhaja  
# - readonly\_user2  
# - api-key-user-readOnly

# Validation script

$ cat auth2.py  
import weaviate

# The URL to your Weaviate instance

weaviate\_url = “[http://adb83896cdc8d45df833bb48ee424179-1487540750.us-east-1.elb.amazonaws.com:80](http://adb83896cdc8d45df833bb48ee424179-1487540750.us-east-1.elb.amazonaws.com:80)”

# API keys

#admin\_api\_key = “adminkey” # Make sure this matches an allowed key from your config  
admin\_api\_key = “secret1” # Make sure this matches an allowed key from your config

# Create admin client

admin\_client = weaviate.Client(url=weaviate\_url,auth\_api\_key=(admin\_api\_key,“”)) # Use the correct parameter for the API key

# Get and print the status of the cluster nodes

try:  
nodes\_status = admin\_client.cluster.get\_nodes\_status()  
print(nodes\_status)  
except weaviate.exceptions.UnexpectedStatusCodeError as e:  
print(f"Authorization failed: {e}")

$ python auth2.py  
Traceback (most recent call last):  
File “C:\Users\suknanda\terraform\eks\weaviate\auth2.py”, line 11, in   
admin\_client = weaviate.Client(url=weaviate\_url,auth\_api\_key=(admin\_api\_key,“”)) # Use the correct parameter for the API key  
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^  
TypeError: Client. **init** () got an unexpected keyword argument ‘auth\_api\_key’

---

<div class="post-metadata">

**Author:** ![DudaNogueira](https://yyz1.discourse-cdn.com/flex027/user_avatar/forum.weaviate.io/dudanogueira/32/7846_2.png) [@DudaNogueira](https://forum.weaviate.io/u/DudaNogueira)\
**Post date:** [May 10, 2024, 1:29pm UTC](https://forum.weaviate.io/t/authentication-apikey-enabled-true-throwing-oidc-auth-not-configured-error/2175/9 "2024-05-10T13:29:17Z")

</div>

Hi! can you try using the new python version? This is how you can do it with it:

> **[Python | Weaviate - Vector Database](https://weaviate.io/developers/weaviate/client-libraries/python#instantiate-a-client)**
>
> Overview

You are using the python v3, and this is how you should initialize it:

> **[Python (Client v3) | Weaviate - Vector Database](https://weaviate.io/developers/weaviate/client-libraries/python/python_v3#api-key-authentication)**
>
> The current Python client version is v||site.pythonclientversion||

for instance:

```auto
import weaviate

auth_config = weaviate.auth.AuthApiKey(api_key="YOUR-WEAVIATE-API-KEY") # Replace with your Weaviate instance API key

# Instantiate the client with the auth config
client = weaviate.Client(
    url="https://WEAVIATE_INSTANCE_URL", # Replace with your Weaviate endpoint
    auth_client_secret=auth_config
)

```
