Confluent The Data Streaming Platform Authentication
Authentication
Confluent
the Data Streaming Platform secures its APIs with http and oauth2 across 3 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the clientCredentials flow(s).
generated: '2026-09-05'
method: searched
source: openapi/confluent-the-data-streaming-platform-api-keys-api-openapi.yml, openapi/confluent-the-data-streaming-platform-cloud-apis-openapi.yml,
openapi/confluent-the-data-streaming-platform-clusters-api-openapi.yml, openapi/confluent-the-data-streaming-platform-environments-api-openapi.yml,
openapi/confluent-the-data-streaming-platform-organizations-api-openapi.yml, openapi/confluent-the-data-streaming-platform-service-accounts-api-openapi.yml
summary:
types:
- http
- oauth2
oauth2_flows:
- clientCredentials
schemes:
- name: basicAuth
type: http
scheme: basic
description: Cloud API Key (key) and Secret (password)
sources:
- openapi/confluent-the-data-streaming-platform-api-keys-api-openapi.yml
- openapi/confluent-the-data-streaming-platform-cloud-apis-openapi.yml
- openapi/confluent-the-data-streaming-platform-clusters-api-openapi.yml
- openapi/confluent-the-data-streaming-platform-environments-api-openapi.yml
- openapi/confluent-the-data-streaming-platform-organizations-api-openapi.yml
- openapi/confluent-the-data-streaming-platform-service-accounts-api-openapi.yml
- name: bearerAuth
type: http
scheme: bearer
bearerFormat: JWT
description: Confluent STS or external OAuth access token
sources:
- openapi/confluent-the-data-streaming-platform-api-keys-api-openapi.yml
- openapi/confluent-the-data-streaming-platform-clusters-api-openapi.yml
- openapi/confluent-the-data-streaming-platform-environments-api-openapi.yml
- openapi/confluent-the-data-streaming-platform-organizations-api-openapi.yml
- openapi/confluent-the-data-streaming-platform-service-accounts-api-openapi.yml
- name: confluent-sts-access-token
type: oauth2
flows:
- flow: clientCredentials
tokenUrl: https://api.confluent.cloud/sts/v1/oauth2/token
scopes: 0
description: Authenticate with Confluent API using this credentials (JSON Web Tokens) following OAuth
2.0.
sources:
- openapi/confluent-the-data-streaming-platform-cloud-apis-openapi.yml
docs: https://docs.confluent.io/cloud/current/api.html#authentication
docs_notes:
api_key_categories:
- name: Cloud API key
grants: The Confluent Cloud Management APIs — provisioning and metrics integrations.
- name: Resource-specific API key
grants: One Confluent Kafka cluster, Schema Registry cluster, ksqlDB cluster or Flink region.
transport: HTTP Basic — API key ID as username, secret as password.
oauth: OAuth 2.0 client credentials against https://api.confluent.cloud/sts/v1/oauth2/token (Confluent
STS), or a token from an external IdP registered as an identity provider.
workload_identity: iam/v2 identity-providers and identity-pools support OIDC federation, so a workload
can exchange an external IdP token rather than holding a long-lived key.
key_management: Keys are created and rotated with createIamV2ApiKey / deleteIamV2ApiKey or the confluent
CLI. The secret is returned once at creation and cannot be retrieved again.
mcp: 'The managed MCP servers reuse the same credentials, base64-encoded into an Authorization: Basic
header. Global API keys work on both managed servers; Cloud API keys on the global server only; Flink
API keys on the regional server only.'
scopes: Only the partner OAuth scheme declares scopes (partner:describe / create / alter / delete).
Everything else is authorized by RBAC role bindings, not by token scope.
source:
- https://docs.confluent.io/cloud/current/api.html
- https://docs.confluent.io/cloud/current/security/authenticate/workload-identities/service-accounts/api-keys/overview.html
- https://docs.confluent.io/cloud/current/ai/ai-tools/managed-mcp-server.html
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we
store it to create your key and to recognise you if you sign in with another
provider. See our Privacy Policy and
Terms.