Confluent OAuth Tokens (sts/v1) API

[![General Availability](https://img.shields.io/badge/Lifecycle%20Stage-General%20Availability-%2345c6e8)](#section/Versioning/API-Lifecycle-Policy) OAuth Token is a [JSON Web Token (JWT)](https://www.rfc-editor.org/rfc/rfc7519) that enables the use of external identities to access Confluent Cloud APIs

Operations 1

POST /sts/v1/oauth2/token Exchange an OAuth Token #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/confluent-oauth-tokens-sts-v1-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

confluent-oauth-tokens-sts-v1-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Confluent Cloud OAuth Tokens (sts/v1) API
  version: ''
  x-api-id: 46234552-5833-42eb-ba0f-883ad3f70d2b
  x-audience: external-public
  x-logo:
    url: https://assets.confluent.io/m/1661ef5e4ff82d3d/
  description: '# Introduction


    Note


    This documents the collection of Confluent Cloud APIs.'
servers:
- url: https://api.confluent.cloud
  description: Confluent Cloud API
tags:
- name: OAuth Tokens (sts/v1)
  description: '![General Availability](#section/Versioning/API-Lifecycle-Policy)


    OAuth Token is a JSON Web Token (JWT) that enables the use of

    external identities to access Confluent Cloud APIs'
paths:
  /sts/v1/oauth2/token:
    x-lifecycle-stage: General Availability
    x-self-access: true
    post:
      description: '![General Availability](#section/Versioning/API-Lifecycle-Policy)


        Use this operation to exchange an access token (JWT) issued by an external identity provider for

        an access token (JWT) issued by Confluent.This enables the use of external identities

        to access Confluent Cloud APIs.'
      requestBody:
        content:
          application/x-www-form-urlencoded:
            schema:
              allOf:
              - $ref: '#/components/schemas/sts.v1.TokenExchangeRequest'
              - type: object
                required:
                - subject_token
                - grant_type
                - identity_pool_id
                - subject_token_type
                - requested_token_type
      x-lifecycle-stage: General Availability
      x-self-access: true
      x-name: sts.v1.OauthToken
      operationId: exchangeStsV1OauthToken
      summary: Exchange an OAuth Token
      tags:
      - OAuth Tokens (sts/v1)
      responses:
        '200':
          description: 'access token used to access public control plane api

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/sts.v1.TokenExchangeReply'
        '400':
          $ref: '#/components/responses/BadRequestError'
        '429':
          $ref: '#/components/responses/RateLimitError'
        '500':
          $ref: '#/components/responses/DefaultSystemError'
components:
  responses:
    RateLimitError:
      description: Rate Limit Exceeded
      headers:
        X-Request-Id:
          schema:
            type: string
          description: The unique identifier for the API request.
        X-RateLimit-Limit:
          schema:
            type: integer
          description: The maximum number of requests you're permitted to make per time period.
        X-RateLimit-Remaining:
          schema:
            type: integer
          description: The number of requests remaining in the current rate limit window.
        X-RateLimit-Reset:
          schema:
            type: integer
          description: "The relative time in seconds until the current rate-limit window resets.  \n  \n**Important:** This differs from Github and Twitter's same-named header which uses UTC epoch seconds. We use relative time to avoid client/server time synchronization issues."
        Retry-After:
          schema:
            type: integer
          description: The number of seconds to wait until the rate limit window resets. Only sent when the rate limit is reached.
    BadRequestError:
      description: Bad Request
      headers:
        X-Request-Id:
          schema:
            type: string
          description: The unique identifier for the API request.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Failure'
          example:
            errors:
            - id: ed42afdc-f0d5-4c0d-b428-9fc6ed6e279d
              status: '400'
              code: invalid_filter
              title: Invalid Filter
              detail: The 'delorean' resource can't be filtered by 'num_doors'
              source:
                parameter: num_doors
    DefaultSystemError:
      description: Oops, something went wrong!
      headers:
        X-Request-Id:
          schema:
            type: string
          description: The unique identifier for the API request.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Failure'
          example:
            errors:
            - id: ed42afdc-f0d5-4c0d-b428-9fc6ed6e279d
              status: '500'
              code: out_of_gas
              title: DeLorean Out Of Gas
              detail: The DeLorean has run out of gas, but Doc Brown will fill 'er up for you asap
  schemas:
    sts.v1.TokenExchangeRequest:
      type: object
      description: token exchange request parameters
      properties:
        api_version:
          type: string
          enum:
          - sts/v1
          description: APIVersion defines the schema version of this representation of a resource.
          readOnly: true
        kind:
          type: string
          description: Kind defines the object this REST resource represents.
          readOnly: true
          enum:
          - TokenExchangeRequest
        id:
          description: ID is the "natural identifier" for an object within its scope/namespace; it is normally unique across time but not space. That is, you can assume that the ID will not be reclaimed and reused after an object is deleted ("time"); however, it may collide with IDs for other object `kinds` or objects of the same `kind` within a different scope/namespace ("space").
          type: string
          maxLength: 255
          readOnly: true
          example: dlz-f3a90de
        metadata:
          allOf:
          - $ref: '#/components/schemas/ObjectMeta'
          - properties:
              self:
                example: https://api.confluent.cloud/sts/v1/token-exchange-requests/ter-12345
              resource_name:
                example: crn://confluent.cloud/organization=9bb441c4-edef-46ac-8a41-c49e44a3fd9a/token-exchange-request=ter-12345
        grant_type:
          type: string
          x-extensible-enum:
          - urn:ietf:params:oauth:grant-type:token-exchange
          description: 'The grant type. Must be urn:ietf:params:oauth:grant-type:token-exchange, which indicates a token exchange.

            '
          example: urn:ietf:params:oauth:grant-type:token-exchange
        subject_token:
          type: string
          description: Confluent Cloud only accepts JSON Web Token (JWT) access tokens from customer identity provider
          example: test_jwt_token
        identity_pool_id:
          type: string
          description: 'Identity pool is a group of external identities that are assigned a certain level of access based on policy

            '
          example: pool_1
        subject_token_type:
          type: string
          x-extensible-enum:
          - urn:ietf:params:oauth:token-type:jwt
          description: 'An identifier for the type of requested security token. Supported values

            is urn:ietf:params:oauth:token-type:jwt.

            '
          example: urn:ietf:params:oauth:token-type:jwt
        requested_token_type:
          type: string
          x-extensible-enum:
          - urn:ietf:params:oauth:token-type:access_token
          description: 'An identifier for the type of requested security token.

            Supported values is urn:ietf:params:oauth:token-type:access_token.

            '
          example: urn:ietf:params:oauth:token-type:access_token
        expires_in:
          type: integer
          format: int32
          description: 'The amount of time, in seconds, between the time when the access token was issued

            and the time when the access token will expire

            '
          default: 900
          maximum: 900
    Failure:
      type: object
      description: Provides information about problems encountered while performing an operation.
      required:
      - errors
      properties:
        errors:
          description: List of errors which caused this operation to fail
          type: array
          items:
            $ref: '#/components/schemas/Error'
          uniqueItems: true
    sts.v1.TokenExchangeReply:
      type: object
      description: token exchange response
      required:
      - access_token
      - issued_token_type
      - token_type
      - expires_in
      properties:
        access_token:
          type: string
          description: 'An JWT access token, issued by Confluent, in response to the token exchange request.

            Client application could use the access token to access confluent public api

            '
        issued_token_type:
          type: string
          x-extensible-enum:
          - urn:ietf:params:oauth:token-type:access_token
          description: The token type. Always matches the value of requested_token_type from the request.
          example: urn:ietf:params:oauth:token-type:access_token
        token_type:
          type: string
          x-extensible-enum:
          - Bearer
          description: Indicates the token type value. The only type that Confluent supports is Bearer
          example: Bearer
        expires_in:
          type: integer
          format: int32
          description: The length of time, in seconds, that the access token is valid.
          example: 3600
    ObjectMeta:
      description: ObjectMeta is metadata that all persisted resources must have, which includes all objects users must create.
      required:
      - self
      properties:
        self:
          description: Self is a Uniform Resource Locator (URL) at which an object can be addressed. This URL encodes the service location, API version, and other particulars necessary to locate the resource at a point in time
          type: string
          format: uri
          readOnly: true
          example: https://api.confluent.cloud/v2/kafka-clusters/lkc-f3a90de
        resource_name:
          description: Resource Name is a Uniform Resource Identifier (URI) that is globally unique across space and time. It is represented as a Confluent Resource Name
          type: string
          format: uri
          readOnly: true
          example: crn://confluent.cloud/kafka=lkc-f3a90de
        created_at:
          type: string
          format: date-time
          example: '2006-01-02T15:04:05-07:00'
          readOnly: true
          description: The date and time at which this object was created. It is represented in RFC3339 format and is in UTC.
        updated_at:
          type: string
          format: date-time
          example: '2006-01-02T15:04:05-07:00'
          readOnly: true
          description: The date and time at which this object was last updated. It is represented in RFC3339 format and is in UTC.
        deleted_at:
          type: string
          format: date-time
          example: '2006-01-02T15:04:05-07:00'
          readOnly: true
          description: The date and time at which this object was (or will be) deleted. It is represented in RFC3339 format and is in UTC.
      readOnly: true
    Error:
      type: object
      description: Describes a particular error encountered while performing an operation.
      properties:
        id:
          description: A unique identifier for this particular occurrence of the problem.
          type: string
          maxLength: 255
        status:
          description: The HTTP status code applicable to this problem, expressed as a string value.
          type: string
        code:
          description: An application-specific error code, expressed as a string value.
          type: string
        title:
          description: A short, human-readable summary of the problem. It **SHOULD NOT** change from occurrence to occurrence of the problem, except for purposes of localization.
          type: string
        detail:
          description: A human-readable explanation specific to this occurrence of the problem.
          type: string
        source:
          type: object
          description: If this error was caused by a particular part of the API request, the source will point to the query string parameter or request body property that caused it.
          properties:
            pointer:
              description: A JSON Pointer [RFC6901] to the associated entity in the request document [e.g. "/spec" for a spec object, or "/spec/title" for a specific field].
              type: string
            parameter:
              description: A string indicating which query parameter caused the error.
              type: string
        error_code:
          type: integer
          format: int32
        message:
          type:
          - string
          - 'null'
      additionalProperties: false
  securitySchemes:
    cloud-api-key:
      type: http
      scheme: basic
      description: Authenticate with Cloud API Keys using HTTP Basic Auth. Treat the Cloud API Key ID as the username and Cloud API Key Secret as the password.
    confluent-sts-access-token:
      type: oauth2
      description: Authenticate with Confluent API using this credentials (JSON Web Tokens) following OAuth 2.0.
      flows:
        clientCredentials:
          tokenUrl: https://api.confluent.cloud/sts/v1/oauth2/token
          scopes: {}
    global-api-key:
      type: http
      scheme: basic
      description: Authenticate with Global API Keys using HTTP Basic Auth. Treat the Global API Key ID as the username and Global API Key Secret as the password.
    resource-api-key:
      type: http
      scheme: basic
      description: Authenticate with resource-specific API Keys using HTTP Basic Auth. Treat the resource-specific API Key ID as the username and resource-specific API Key Secret as the password.
    external-access-token:
      type: oauth2
      description: Authenticate with Confluent API using this credentials (JSON Web Tokens) following OAuth 2.0.
      flows:
        clientCredentials:
          tokenUrl: https://api.confluent.cloud/sts/v1/oauth2/token
          scopes: {}
    oauth:
      type: oauth2
      description: Authenticate with OAuth 2.0. Currently this is only supported for partner APIs.
      flows:
        clientCredentials:
          tokenUrl: /oauth2/token
          scopes:
            partner:alter: enables partners to alter entitlements
            partner:create: enables partners to create entitlements and signup on behalf of customers
            partner:delete: enables partners to delete entitlements and organizations
            partner:describe: enables partners to read and list entitlements and organizations
x-tagGroups:
- name: Identity Access Management (v2)
  tags:
  - API Keys (iam/v2)
  - Users (iam/v2)
  - Service Accounts (iam/v2)
  - Invitations (iam/v2)
  - IP Groups (iam/v2)
  - IP Filters (iam/v2)
  - IP Filter Summaries (iam/v2)
  - Role Bindings (iam/v2)
  - Identity Providers (iam/v2)
  - Jwks (iam/v2)
  - Identity Pools (iam/v2)
  - Group Mappings (iam/v2/sso)
  - Certificate Authorities (iam/v2)
  - Certificate Identity Pools (iam/v2)
- name: Org API (v2)
  tags:
  - Environments (org/v2)
  - Organizations (org/v2)
- name: Notifications API (v1)
  tags:
  - Subscriptions (notifications/v1)
  - Integrations (notifications/v1)
  - Notification Types (notifications/v1)
  - Resource Preferences (notifications/v1)
  - Resource Subscriptions (notifications/v1)
  - User Notifications (notifications/v1)
- name: Cluster Mgmt for Kafka (v2)
  tags:
  - Clusters (cmk/v2)
- name: Cluster Mgmt for ksqlDB (v2)
  tags:
  - Clusters (ksqldbcm/v2)
- name: Connect API (v1)
  tags:
  - Connectors (connect/v1)
  - Lifecycle (connect/v1)
  - Status (connect/v1)
  - Managed Connector Plugins (connect/v1)
  - Offsets (connect/v1)
  - Custom Connector Plugins (connect/v1)
  - Presigned Urls (connect/v1)
  - Custom Connector Runtimes (connect/v1)
- name: Connect Artifact Management (v1)
  tags:
  - Connect Artifacts (cam/v1)
  - Presigned Urls (cam/v1)
- name: Kafka API (v3)
  tags:
  - Cluster (v3)
  - Configs (v3)
  - ACL (v3)
  - Consumer Group (v3)
  - Partition (v3)
  - Topic (v3)
  - Records (v3)
  - Cluster Linking (v3)
  - Share Group (v3)
  - Streams Group (v3)
- name: Service Quota API (v1)
  tags:
  - Applied Quotas (service-quota/v1)
  - Scopes (service-quota/v1)
- name: Partner API (v2)
  tags:
  - Entitlements (partner/v2)
  - Organizations (partner/v2)
  - Signup (partner/v2)
- name: Cluster Mgmt for Schema Registry (v2)
  tags:
  - Regions (srcm/v2)
  - Clusters (srcm/v2)
- name: Cluster Mgmt for Schema Registry (v3)
  tags:
  - Clusters (srcm/v3)
- name: Schema Registry API (v1)
  tags:
  - Compatibility (v1)
  - Config (v1)
  - Contexts (v1)
  - Exporters (v1)
  - Modes (v1)
  - Schemas (v1)
  - Subjects (v1)
  - Key Encryption Keys (v1)
  - Data Encryption Keys (v1)
- name: Catalog API (v1)
  tags:
  - Entity (v1)
  - Search (v1)
  - Types (v1)
- name: Stream Sharing API (v1)
  tags:
  - Provider Shared Resources (cdx/v1)
  - Provider Shares (cdx/v1)
  - Consumer Shared Resources (cdx/v1)
  - Consumer Shares (cdx/v1)
  - Shared Tokens (cdx/v1)
  - Opt Ins (cdx/v1)
- name: Networking (v1)
  tags:
  - Networks (networking/v1)
  - Peerings (networking/v1)
  - Transit Gateway Attachments (networking/v1)
  - Private Link Accesses (networking/v1)
  - Network Link Services (networking/v1)
  - Network Link Endpoints (networking/v1)
  - Network Link Service Associations (networking/v1)
  - IP Addresses (networking/v1)
  - Private Link Attachments (networking/v1)
  - Private Link Attachment Connections (networking/v1)
  - DNS Forwarders (networking/v1)
  - Access Points (networking/v1)
  - DNS Records (networking/v1)
  - Gateways (networking/v1)
- name: Security Token Service (v1)
  tags:
  - OAuth Tokens (sts/v1)
- name: Kafka Quota (v1)
  tags:
  - Client Quotas (kafka-quotas/v1)
- name: Bring Your Own Key (BYOK) Management (v1)
  tags:
  - Keys (byok/v1)
- name: Billing API (v1)
  tags:
  - Costs (billing/v1)
- name: Compute Pool Mgmt for Flink (v2)
  tags:
  - Compute Pools (fcpm/v2)
  - Regions (fcpm/v2)
  - Org Compute Pool Configs (fcpm/v2)
- name: SQL API (v1)
  tags:
  - Statements (sql/v1)
  - Statement Results (sql/v1)
  - Statement Exceptions (sql/v1)
  - Connections (sql/v1)
  - Agents (sql/v1)
  - Tools (sql/v1)
  - Materialized Tables (sql/v1)
  - Materialized Table Versions (sql/v1)
- name: Provider Integration Management (v1)
  tags:
  - Integrations (pim/v1)
- name: Provider Integration Management (v2)
  tags:
  - Integrations (pim/v2)
- name: Artifact API (v1)
  tags:
  - Flink Artifacts (artifact/v1)
  - Presigned Urls (artifact/v1)
  - Flink Artifact Versions (artifact/v1)
- name: Custom Code Logging API (v1)
  tags:
  - Custom Code Loggings (ccl/v1)
- name: Tableflow (v1)
  tags:
  - Regions (tableflow/v1)
  - Tableflow Topics (tableflow/v1)
  - Catalog Integrations (tableflow/v1)
- name: Custom Connect Plugin Management (v1)
  tags:
  - Custom Connect Plugins (ccpm/v1)
  - Presigned Urls (ccpm/v1)
  - Custom Connect Plugin Versions (ccpm/v1)
- name: Unified Stream Manager (v1)
  tags:
  - Kafka Clusters (usm/v1)
  - Connect Clusters (usm/v1)
- name: Endpoint (v1)
  tags:
  - Endpoints (endpoint/v1)
- name: Real Time Context Engine (v1)
  tags:
  - Rtce Topics (rtce/v1)
  - Regions (rtce/v1)
- name: Analytics (v1alpha1)
  tags:
  - Statements (query/v1alpha1)