Confluent Cloud

by confluentinc

164 2.5k downloads Not rated yet MIT

About

# Confluent MCP Server [![npm version](https://img.shields.io/npm/v/@confluentinc/mcp-confluent.svg)](https://www.npmjs.com/package/@confluentinc/mcp-confluent) [![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](LICENSE) An open-source [MCP server](https://modelcontextprotocol.io/) that enables AI…

Details

License
MIT

Explore

- 50+ tools across Kafka, Flink SQL, Schema Registry, Connectors, Tableflow, and more.
- Always-available tools for documentation and diagnostics.
- Tools for Confluent Cloud with OAuth authentication support.
- Tools for local deployments (Confluent Platform / self-managed Kafka).
- Tools auto-enabled based on configuration service blocks.
- Works with Claude Desktop, Claude Code, Cursor, VS Code, Goose, Gemini CLI.

Setting up with Highlight

This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:

  1. Download and install Highlight from highlightai.com/download
  2. Navigate to the plugins tab and select "Add Custom Plugin"
  3. Configure the plugin with the settings below
    Plugin Name Confluent Cloud
    Command (node, npx, python, etc.)

    Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.

  4. Enable "Start Automatically" if you want the plugin to start when Highlight launches

From the repository

> Prerequisites: Node.js 22.19.0+.
> If you want to interact with Confluent Cloud, you need to create an account first.

1. Generate a quick config.yaml file in your project root:

npx @confluentinc/mcp-confluent --init-config

2. Edit the config.yaml file with your connection details, then:

npx @confluentinc/mcp-confluent --config ./config.yaml

See Getting Started for full setup instructions and Configuring MCP Clients for integration with your preferred AI tool.

connections:
local:
type: direct
kafka:
bootstrap_servers: "localhost:9092"
schema_registry:
endpoint: "http://localhost:8081"


Ready-to-use variants live in sample_configs/.

| Category | Tools | Description |
| ------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------- |
| Kafka | list-topics, create-topics, delete-topics, produce-message, consume-messages, list-consumer-groups, describe-consumer-group, get-consumer-group-lag | Manage topics, produce/consume messages, inspect consumer groups |
| Schema Registry | list-schemas, create-schema, delete-schema | List, inspect, create, and delete data schemas |

sample_configs/confluent-platform.yaml is a copy-pasteable starter.
It assumes PLAIN over SASL_SSL for Kafka and HTTP Basic Auth for Schema Registry.
Customize the broker and Schema Registry URLs, and inject credentials via the ${KAFKA_API_KEY} / ${KAFKA_API_SECRET} / ${SCHEMA_REGISTRY_API_KEY} / ${SCHEMA_REGISTRY_API_SECRET} environment variables.
If your cluster uses SCRAM or another SASL mechanism, override security.protocol and sasl.mechanisms through the kafka.extra_properties map in that file.

This MCP server is designed to be used with various MCP clients, such as Claude Desktop, Copilot, or Goose CLI/Desktop.
The specific configuration and interaction will depend on the client you are using.

The MCP server can authenticate to Confluent Cloud via OAuth (PKCE) in addition to static API keys defined in the YAML config.
See OAuth Authentication For Confluent Cloud for more details.

The general steps to configure (if not using OAuth) and run this MCP are:

1. Create a configuration file: Copy the provided config.yaml example file to the root of your project.
You can use the CLI to bootstrap one in your current directory — no git checkout required:

bash
npx @confluentinc/mcp-confluent --init-config

2. Populate the file: Fill in the necessary values for your Confluent Cloud environment.
See CONFIGURATION.md for the full reference; only fill in the service blocks you need (each one enables a group of tools).

3. Start the Server: You can run the MCP server in one of two ways:
- From source: Follow the instructions in the Contributing Guide to build and run the server from source.
This typically involves:
- Installing dependencies (pnpm install)
- Building the project (pnpm run build or pnpm run dev)
- With npx: You can start the server directly using npx, no build required:

bash
npx @confluentinc/mcp-confluent --config /path/to/myconfig.yaml

4. Configure your MCP Client: Each client (e.g., Claude, Goose) will have its own way of specifying the MCP server's address and any required credentials.
You'll need to configure your client to connect to the address where this server is running (likely localhost with a specific port).
The port the server runs on is set via server.http.port in config.yaml.

5. Start your MCP Client: Once your client is configured to connect to the MCP server, you can start your MCP client and on startup it will stand up an instance of this MCP server locally.
This instance will be responsible for managing data schemas and interacting with resources on your behalf.

6. Interact with your resources through the Client: Once the client is connected and configured, you can use the client's interface to interact with Confluent Cloud or local resources.
The client will send requests to this MCP server, which will then interact with the available connections on your behalf.

Tableflow tools interact with cloud storage (e.g. AWS S3) and a metadata catalog (e.g. AWS Glue) on your behalf via the Flink runtime in Confluent Cloud.
The Flink runtime needs IAM permissions on your cloud account, and those have to be granted and linked into Confluent Cloud before any Tableflow tool will succeed.

Follow the Tableflow quick start with custom storage & Glue to set up the roles, policies, and provider integrations.
Skipping this step leads to authorization errors when mcp-confluent tries to provision or manage Tableflow-enabled tables.

The MCP server can authenticate to Confluent Cloud via OAuth (PKCE) instead of static API keys.
On the first tool call that needs Confluent access, the server opens your browser to the Confluent Cloud sign-in page; subsequent tool calls reuse the resulting session.
No API keys to provision.

npx @confluentinc/mcp-confluent --config ./config.yaml

--init-oauth-config drops a starter config.oauth.example.yaml into ./config.yaml.
The whole file is essentially:

connections:
  ccloud-oauth:
    type: oauth

See CONFIGURATION.md → Authentication modes for the full schema and ergonomics.

The ¹-marked categories in Available Tools for Confluent Cloud work under OAuth today; everything else still needs a direct connection with static API keys.

The MCP server provides a flexible command line interface (CLI) for advanced control.
The CLI lets you pick the config file, transports, and fine-tune which tools are enabled or blocked.

You can view all CLI options and help with:

npx @confluentinc/mcp-confluent --help

<details>
<summary>Show output</summary>

Usage: mcp-confluent [options]

Confluent MCP Server - Model Context Protocol implementation for Confluent Cloud

Options:
-V, --version output the version number
-e, --env-file <path> Load environment variables from file
-k, --kafka-config-file <file> Path to a properties file for configuring kafka clients
-t, --transport <types> Transport types (comma-separated list) (choices: "http", "sse", "stdio", default: "stdio")
--allow-tools <tools> Comma-separated list of tool names to allow. If provided, takes precedence over --allow-tools-file. Allow-list is applied before block-list.
--block-tools <tools> Comma-separated list of tool names to block. If provided, takes precedence over --block-tools-file. Block-list is applied after allow-list.
--allow-tools-file <file> File with tool names to allow (one per line). Used only if --allow-tools is not provided. Allow-list is applied before block-list.
--block-tools-file <file> File with tool names to block (one per line). Used only if --block-tools is not provided. Block-list is applied after allow-list.
--list-tools Print the final set of enabled tool names (with descriptions) after allow/block filtering and exit. Does not start the server.
--disable-auth Disable authentication for HTTP/SSE transports. WARNING: Only use in development environments.
--allowed-hosts <hosts> Comma-separated list of allowed Host header values for DNS rebinding protection.
--generate-key Generate a secure API key for MCP_API_KEY and print it to stdout, then exit.
-h, --help display help for command

</details>

npx @confluentinc/mcp-confluent -c config.yaml --transport http,sse,stdio

<details>
<summary>Show output</summary>

...
{"level":"info","time":"2025-05-14T17:03:02.883Z","pid":47959,"hostname":"G9PW1FJH64","name":"mcp-confluent","msg":"Starting transports: http, sse, stdio"}
{"level":"info","time":"2025-05-14T17:03:02.971Z","pid":47959,"hostname":"G9PW1FJH64","name":"mcp-confluent","msg":"HTTP transport routes registered"}
{"level":"info","time":"2025-05-14T17:03:02.972Z","pid":47959,"hostname":"G9PW1FJH64","name":"mcp-confluent","msg":"SSE transport routes registered"}
{"level":"info","time":"2025-05-14T17:03:02.972Z","pid":47959,"hostname":"G9PW1FJH64","name":"mcp-confluent","msg":"STDIO transport connected"}
{"level":"info","time":"2025-05-14T17:03:03.012Z","pid":47959,"hostname":"G9PW1FJH64","name":"mcp-confluent","msg":"Server listening at http://[::1]:3000"}
{"level":"info","time":"2025-05-14T17:03:03.013Z","pid":47959,"hostname":"G9PW1FJH64","name":"mcp-confluent","msg":"Server listening at http://127.0.0.1:3000"}
{"level":"info","time":"2025-05-14T17:03:03.013Z","pid":47959,"hostname":"G9PW1FJH64","name":"mcp-confluent","msg":"All transports started successfully"}

</details>

Tools are auto-enabled based on which service blocks are present in your resolved configuration; see CONFIGURATION.md for the full block-to-tool mapping.

You can list all available tools via the CLI:

npx -y @confluentinc/mcp-confluent --list-tools

Claude Desktop / Cursor

Paste into your MCP client config file to install this server.

{
    "mcpServers": {
        "confluent cloud": {
            "mcp-confluent": {
                "command": "npx",
                "args": [
                    "@confluentinc/mcp-confluent",
                    "--init-config"
                ]
            }
        }
    }
}

McpServers

{
    "mcp-confluent": {
        "command": "npx",
        "args": [
            "@confluentinc/mcp-confluent",
            "--init-config"
        ]
    }
}

OAuth Authentication for Confluent Cloud

The MCP server can authenticate to Confluent Cloud via OAuth (PKCE) instead of static API keys.
On the first tool call that needs Confluent access, the server opens your browser to the Confluent Cloud sign-in page; subsequent tool calls reuse the resulting session.
No API keys to provision.

Setup

```bash
npx @confluentinc/mcp-confluent --init-oauth-config

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.

Videos about Confluent Cloud

Relevant YouTube tutorials, setups, and demos