Kafka ACL Permission Matrix Viewer

Turn a list of Kafka ACL bindings into a principal-by-resource matrix, with denials kept separate because a DENY beats every ALLOW. Catches the consumer with no GROUP grant and the IDEMPOTENT_WRITE requirement that changed in 3.0.

Only used for the IDEMPOTENT_WRITE rule, which WRITE implies from 3.0 onward and did not before. The rest of the analysis is version independent.

Paste below, or drop a file anywhere on this panel

Or drop a file anywhere on this panel. Nothing is uploaded: the analysis runs in this tab.

The answer appears here

Paste on the left and press Build matrix. Nothing leaves this tab.

Examples

Real input you can load into the tool above. Each one shows a different thing going wrong, because that is what the tool is for.

A consumer with no group ACL

READ on the topic but nothing on the group, so the consumer fails to join

Current ACLs for resource `ResourcePattern(resourceType=TOPIC, name=orders, patternType=LITERAL)`:
	(principal=User:app, host=*, operation=READ, permissionType=ALLOW)

No host restriction

An ACL allowing any host, which is the default and rarely reconsidered

Current ACLs for resource `ResourcePattern(resourceType=TOPIC, name=events, patternType=PREFIXED)`:
	(principal=User:svc, host=*, operation=WRITE, permissionType=ALLOW)

Common mistakes

These are the ones that fail silently. The config is accepted, nothing raises an error, and the consequence arrives later.

  1. Granting topic READ without group READ

    A consumer needs READ on the topic AND READ on its consumer group. With only the first it fails to join, with an error about the group.

    Instead:Grant both.

  2. Leaving host as *

    The default allows the principal from anywhere. It is rarely reconsidered and is the easiest ACL tightening available.

    Instead:Restrict host where the client network is known.

  3. Expecting DENY to be a filter

    In Kafka a DENY always wins over an ALLOW for the same resource, exactly like IAM. It is not a precedence hint.

    Instead:Use DENY for guardrails, and scope ALLOW properly.

What the authorizer would actually allow

A list of bindings is not a permission model. The matrix is, and two Kafka rules make reading the list directly misleading.

A DENY beats every ALLOW, however specific

Kafka's authorizer checks denials first and returns on the first match. There is no specificity ordering, so a broad DENY plus a narrow ALLOW does not carve out an exception, it just denies. That makes a DENY binding much blunter than it looks, and it is why this page lists denials separately from grants rather than merging them into one cell. Superusers named in super.users bypass the authorizer entirely, so they will not appear here at all: an empty matrix does not mean nobody has access.

A consumer needs the group as well as the topic

READ on the topic gets you fetches. Joining a group, committing offsets and reading committed offsets are all authorized against the GROUP resource, so a consumer without a GROUP READ binding authenticates successfully and then fails at the first poll with GroupAuthorizationException. It reads as a topic permission problem and is not one. This is the most common incomplete ACL set and the page reports it directly.

IDEMPOTENT_WRITE changed in 3.0

Before Kafka 3.0, enable.idempotence=true needed a separate IDEMPOTENT_WRITE grant on the CLUSTER resource, and without it the producer failed with ClusterAuthorizationException. From 3.0 onward, WRITE on any topic implies it. Both directions matter: on an older cluster the grant is missing and nothing in current documentation tells you to add it, and on a newer one the grant is a cluster-scoped permission that no longer does anything. Set the version above and the advice follows it.

Transactions need a resource nobody grants in advance

A transactional producer needs WRITE and DESCRIBE on the TRANSACTIONAL_ID resource on top of its topic grants. Nothing fails until transactional.id is set, at which point initTransactions() throws TransactionalIdAuthorizationException, so this is almost always discovered during the change that enables exactly-once rather than before it.

PREFIXED is the pattern worth using

A literal resource name of * covers every resource of that type, including ones that do not exist yet, and combined with CREATE it means a client can invent a topic and then read and write it. A PREFIXED pattern over a namespace you own keeps future topics in scope without covering somebody else's, which is almost always what the wildcard was reaching for.

What this reads, and what it cannot see

Paste kafka-acls --list output unmodified, or one binding per line as User:app ALLOW READ TOPIC:orders with an optional PREFIXED. A line it cannot parse is reported and skipped rather than guessed at, because a binding read wrongly would put a grant in the matrix that does not exist. It does not know your super.users, your allow.everyone.if.no.acl.found setting, or your principal builder, all three of which change the real answer.

More kafka tools

Kafka Confluent Wire Format Decoder The five junk bytes in front of your payload Kafka Key to Partition Mapper Which partition does this key land on? Kafka Topic Name Validator Legal, risky, or 249 characters too long? Kafka Replication Safety Checker How many brokers can you lose Kafka Producer Config Linter Will it start, and will it lose a record? Kafka Message Payload Decoder The first five bytes are usually not data Kafka Connect Source Connector Generator tasks.max is a ceiling, not a count Kafka Connect Sink Connector Generator A dead letter queue with no context headers is a pile of records Kafka Connect SMT Chain Builder The order is the transforms list Kafka MirrorMaker 2 Config Generator It renames every topic by default Kafka Partition Reassignment Generator The throttle is not optional Strimzi Kafka Resource Generator Without the cluster label, nothing happens Kafka mTLS Config Generator The certificate is the identity Kafka Schema Registry Config Generator The compatibility direction is your deployment order Kafka Exactly-Once Config Generator Half of it is worse than none Kafka Broker and KRaft Config Generator The internal topics that break a one-broker cluster Kafka Quota Generator Byte rates are per broker, not per cluster Kafka Streams Config Generator application.id is four things at once Kafka Connect Worker Config Generator Security three times, or the tasks fail Kafka Retention and Unit Converter log.retention.hours does not take milliseconds Kafka Timestamp Converter Two sentinels and two meanings Kafka .properties to YAML Converter Dotted keys stay flat Kafka Streams Internal Topic Predictor Create them before Streams does Kafka ACL Generator The grant you forgot is on another resource type Kafka Topic Config Generator min.insync.replicas is the one that matters Kafka client.properties Generator The file every CLI tool asks for Kafka Producer Config Generator No password field, on purpose Kafka Consumer Config Generator The commit mode decides the semantics Kafka Disk and Retention Calculator retention.bytes is per partition Kafka Partition Count Calculator The number you can never reduce Kafka Cluster Sizing Calculator The traffic no client metric shows Kafka Consumer Lag Catch-Up Calculator Whether it ever clears, not just when Kafka Producer Batching Calculator linger.ms=0 still batches Kafka Segment and Index Sizing Why retention.ms is a lower bound Kafka Rebalance Duration Estimator What a rolling restart really costs Kafka Cost Estimator Your rates, so nothing goes stale Kafka Config Explorer by Version The answer depends on the release Kafka Default Config Reference What moved under a config you never edited Kafka OAuth Bearer Token Decoder Will Kafka accept it, and can it refresh Kafka Record Header Viewer Headers are a list, not a map Kafka Topic Regex Subscription Tester Kafka matches the whole name Kafka Connect Config Validator The mistakes that raise no error Kafka Consumer Group Id Validator Which broker coordinates the group Kafka Partition Assignment Visualizer Leadership is the load, not replicas Kafka Consumer Assignment Visualizer The three assignors disagree Kafka ZooKeeper to KRaft Config Converter The authorizer class nobody changes Kafka Config to Strimzi Half of it belongs elsewhere Kafka Docker Compose Generator (KRaft) Reachable from inside and outside Kafka JAAS Config Decoder The line that stops SASL working Kafka CRC32C Calculator Which CRC, over which bytes Kafka Config Upgrade Checker What breaks when you upgrade Kafka Kafka Config Diff Which change actually changed something Kafka Consumer Config Linter Why the group rebalances, and where the records went Kafka Avro Schema Validator The defaults Avro accepts and rejects Kafka Schema Compatibility Checker What the registry will say, before you ask it Kafka Avro Schema Diff Which direction each change breaks Kafka Compression Comparison Measured on your bytes Kafka Delivery Semantics Exactly-once has a consumer half Kafka ksqlDB Query Builder It looks like SQL and the rules are not Kafka Connect SMT Predicate Tester negate reads backwards Kafka Streams Topology Viewer Count the repartitions Kafka Connect Pipeline Visualizer The order things really run in Kafka Protobuf Binary Decoder Works without the .proto Kafka Protobuf JSON Converter Why your JSON does not round-trip Kafka Protobuf to Avro Schema What does not survive the conversion Kafka Avro Binary Decoder Wrong schema, no error Kafka Avro JSON Converter Why the console producer rejects your line Kafka Avro Sample Data Generator Records that actually serialize Kafka JSON to Avro Schema What JSON cannot tell you Kafka JSON Schema to Avro What does not survive the conversion Kafka SASL JAAS Generator One login module, four syntaxes Kafka CLI Command Builder kcat is librdkafka, not Kafka

Elsewhere on the site