Confluent Authorization API
For components to find service nodes and call Authorize. KSQL, Schema Registry, Connect would use these methods to enforce role permissions on their specfic resources.
For components to find service nodes and call Authorize. KSQL, Schema Registry, Connect would use these methods to enforce role permissions on their specfic resources.
Every API here is available over the APIs.io API and to AI agents over MCP.
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
find_apisBrowse and filter every API in the catalog.get_api_artifactsOne API's artifacts, grouped by type.get_openapiThe primary OpenAPI for this API.find_similar_apisAPIs that look like this one.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.curl "https://apis.io/api/v1/apis/confluent-authorization-api"
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.
openapi: 3.2.0
info:
description: '## Confluent Metadata API - Swagger UI
---
This tool (SwaggerUI) and the Open API spec file are provided _for development / test
purposes only_:
- **Do _not_ enable in Production.**
- **This tool only works with HTTP.**
### Authenticating
Authentication is performed by HTTP Basic Auth or by presenting a bearer token.'
title: MDS Authorization API
version: '1.0'
x-api-id: 9a0c4222-9190-4816-b872-1a9cf002afab
x-audience: external-public
servers:
- url: /
security:
- basicAuth: []
- bearerAuth: []
tags:
- description: 'For components to find service nodes and call Authorize.
KSQL, Schema Registry, Connect would use these methods to enforce role permissions on their specfic resources.'
name: Authorization
paths:
/security/1.0/authorize:
put:
description: Callable by Admins+User.
operationId: authorize
requestBody:
content:
application/json:
example:
userPrincipal: User:bob
actions:
- scope:
clusters:
kafka-cluster: K_GUID
resourceName: clicksTopic1
resourceType: Topic
operation: Read
schema:
$ref: '#/components/schemas/AuthorizeRequest'
required: true
responses:
'200':
content:
application/json:
example:
- ALLOWED
- DENIED
schema:
items:
type: string
type: array
description: Authorization proccessed
default:
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
description: Error Response
summary: Authorize operations against resourceType for a given user
tags:
- Authorization
components:
schemas:
AuthorizeRequest:
example:
userPrincipal: User:bob
actions:
- scope:
clusters:
kafka-cluster: kafkaClusterId
schema-registry-cluster: schemaRegistryClusterId
flink-environment: flinkEnvironmentId
ksql-cluster: ksqlClusterId
cmf: cmfId
connect-cluster: connectClusterId
resourceName: clicksTopic1
operation: Read
resourceType: Topic
- scope:
clusters:
kafka-cluster: kafkaClusterId
schema-registry-cluster: schemaRegistryClusterId
flink-environment: flinkEnvironmentId
ksql-cluster: ksqlClusterId
cmf: cmfId
connect-cluster: connectClusterId
resourceName: clicksTopic1
operation: Read
resourceType: Topic
properties:
userPrincipal:
description: The 'target' user principal.
example: User:bob
pattern: ^User:.+$
type: string
actions:
description: Actions to authorize.
items:
$ref: '#/components/schemas/Action'
type: array
required:
- actions
- userPrincipal
type: object
Scope:
example:
clusters:
kafka-cluster: kafkaClusterId
schema-registry-cluster: schemaRegistryClusterId
flink-environment: flinkEnvironmentId
ksql-cluster: ksqlClusterId
cmf: cmfId
connect-cluster: connectClusterId
properties:
clusters:
$ref: '#/components/schemas/Scope_clusters'
required:
- clusters
type: object
Action:
example:
scope:
clusters:
kafka-cluster: kafkaClusterId
schema-registry-cluster: schemaRegistryClusterId
flink-environment: flinkEnvironmentId
ksql-cluster: ksqlClusterId
cmf: cmfId
connect-cluster: connectClusterId
resourceName: clicksTopic1
operation: Read
resourceType: Topic
properties:
scope:
$ref: '#/components/schemas/Scope'
operation:
example: Read
type: string
resourceType:
example: Topic
type: string
resourceName:
example: clicksTopic1
type: string
required:
- operation
- resourceName
- resourceType
- scope
type: object
ErrorResponse:
properties:
status_code:
description: Optional - http status code
example: 400
type: integer
error_code:
description: Optional - Kafka error code (typically 5 digits)
type: integer
type:
description: Optional - Type of error
example: INVALID REQUEST DATA
type: string
message:
description: Required - Top level error message
example: Bad request
type: string
errors:
description: Optional - List of errors
items:
$ref: '#/components/schemas/ErrorDetail'
type: array
required:
- message
type: object
ErrorDetail:
properties:
error_type:
type: string
message:
type: string
required:
- error_type
- type
type: object
Scope_clusters:
example:
kafka-cluster: kafkaClusterId
schema-registry-cluster: schemaRegistryClusterId
flink-environment: flinkEnvironmentId
ksql-cluster: ksqlClusterId
cmf: cmfId
connect-cluster: connectClusterId
properties:
kafka-cluster:
example: kafkaClusterId
type: string
connect-cluster:
example: connectClusterId
type: string
ksql-cluster:
example: ksqlClusterId
type: string
schema-registry-cluster:
example: schemaRegistryClusterId
type: string
cmf:
example: cmfId
type: string
flink-environment:
example: flinkEnvironmentId
type: string
type: object
securitySchemes:
basicAuth:
scheme: basic
type: http
bearerAuth:
bearerFormat: JWT
scheme: bearer
type: http