Kafka JAAS Config Decoder

Decode and check a sasl.jaas.config value, or the whole properties file around it. The password is never printed back to you, which is what makes this safe to paste.

Paste below, or drop a file anywhere on this panel

Or drop a file anywhere on this panel. Nothing is uploaded: the analysis runs in this tab.

The answer appears here

Paste on the left and press Decode & check. Nothing leaves this tab.

Examples

Real input you can load into the tool above. Each one shows a different thing going wrong, because that is what the tool is for.

A password in the JAAS string

The credential that ends up in every config file and process listing

org.apache.kafka.common.security.plain.PlainLoginModule required username="admin" password="admin-secret";

A module with no password

A JAAS line that will fail to authenticate, and why the error is unhelpful

org.apache.kafka.common.security.scram.ScramLoginModule required username="app";

Common mistakes

These are the ones that fail silently. The config is accepted, nothing raises an error, and the consequence arrives later.

  1. Putting the password inline in sasl.jaas.config

    It lands in the properties file, in process listings, in container inspect output and in any log that dumps configuration.

    Instead:Use a KafkaClient section in a separate JAAS file with restricted permissions, or a config provider that resolves the value at startup.

  2. Forgetting the trailing semicolon

    A JAAS entry must end with a semicolon. Without it the parse fails with a message about the login module rather than about punctuation.

    Instead:End every entry with a semicolon, inside the quoted value.

  3. Using PlainLoginModule over a plaintext listener

    SASL/PLAIN sends the password essentially in the clear. It is only safe wrapped in TLS, which means SASL_SSL rather than SASL_PLAINTEXT.

    Instead:Use SASL_SSL, or SCRAM which does not transmit the password itself.

Why sasl.jaas.config is where SASL setups get stuck

It is one line, it has its own grammar borrowed from Java, and every way it fails produces an error message about something else.

The grammar is not a Kafka property, it is a JAAS entry

The value is `<LoginModule> <controlFlag> [option=value ...];` and each part has rules. The control flag is one of required, requisite, sufficient or optional, and with a single module anything other than required either behaves identically or lets login succeed without this module doing anything. The terminating semicolon is required. Option values are quoted, which is what lets a password contain a space or an equals sign, and it is also why a parser that splits on whitespace reports a working config as broken.

Three settings have to agree and they are in three places

The JAAS entry names a login module. `sasl.mechanism` names a mechanism, and defaults to GSSAPI, which is Kerberos, so leaving it out of a PLAIN setup means the client attempts the wrong thing entirely. `security.protocol` decides whether SASL is attempted at all, and defaults to PLAINTEXT. Any one of the three being wrong produces a symptom that points at the other two, which is why this page wants the whole file.

An unescaped quote eats the rest of the line

A password containing a double quote has to escape it. Without that, the value ends early and every option after it becomes part of the password or is dropped, so a config that looks complete is missing settings with no error to say which. The same applies to a backslash. A semicolon inside a quoted value is fine and does not terminate the entry, which is worth knowing because it looks like it should.

SASL_PLAINTEXT sends PLAIN credentials in the clear

SASL_PLAINTEXT authenticates and does not encrypt. With the PLAIN mechanism that means the password itself crosses the network readable by anything on the path, which is a different risk from SCRAM, where a challenge is exchanged and the password is not sent. Neither is a reason to skip TLS, and the page flags the combination rather than the protocol on its own.

What this cannot see

It reads one line of configuration. It does not contact a broker, verify that credentials work, check that a keytab exists at the path given, or know what your broker's sasl.enabled.mechanisms allows. It also cannot check the options of a vendor login module, and says so rather than guessing. For whether a config will start at all, the producer and consumer linters on this site cover the rest of the file.

More kafka tools

Kafka Confluent Wire Format Decoder The five junk bytes in front of your payload Kafka Key to Partition Mapper Which partition does this key land on? Kafka Topic Name Validator Legal, risky, or 249 characters too long? Kafka Replication Safety Checker How many brokers can you lose Kafka Producer Config Linter Will it start, and will it lose a record? Kafka Message Payload Decoder The first five bytes are usually not data Kafka Connect Source Connector Generator tasks.max is a ceiling, not a count Kafka Connect Sink Connector Generator A dead letter queue with no context headers is a pile of records Kafka Connect SMT Chain Builder The order is the transforms list Kafka MirrorMaker 2 Config Generator It renames every topic by default Kafka Partition Reassignment Generator The throttle is not optional Strimzi Kafka Resource Generator Without the cluster label, nothing happens Kafka mTLS Config Generator The certificate is the identity Kafka Schema Registry Config Generator The compatibility direction is your deployment order Kafka Exactly-Once Config Generator Half of it is worse than none Kafka Broker and KRaft Config Generator The internal topics that break a one-broker cluster Kafka Quota Generator Byte rates are per broker, not per cluster Kafka Streams Config Generator application.id is four things at once Kafka Connect Worker Config Generator Security three times, or the tasks fail Kafka Retention and Unit Converter log.retention.hours does not take milliseconds Kafka Timestamp Converter Two sentinels and two meanings Kafka .properties to YAML Converter Dotted keys stay flat Kafka Streams Internal Topic Predictor Create them before Streams does Kafka ACL Generator The grant you forgot is on another resource type Kafka Topic Config Generator min.insync.replicas is the one that matters Kafka client.properties Generator The file every CLI tool asks for Kafka Producer Config Generator No password field, on purpose Kafka Consumer Config Generator The commit mode decides the semantics Kafka Disk and Retention Calculator retention.bytes is per partition Kafka Partition Count Calculator The number you can never reduce Kafka Cluster Sizing Calculator The traffic no client metric shows Kafka Consumer Lag Catch-Up Calculator Whether it ever clears, not just when Kafka Producer Batching Calculator linger.ms=0 still batches Kafka Segment and Index Sizing Why retention.ms is a lower bound Kafka Rebalance Duration Estimator What a rolling restart really costs Kafka Cost Estimator Your rates, so nothing goes stale Kafka Config Explorer by Version The answer depends on the release Kafka Default Config Reference What moved under a config you never edited Kafka OAuth Bearer Token Decoder Will Kafka accept it, and can it refresh Kafka Record Header Viewer Headers are a list, not a map Kafka Topic Regex Subscription Tester Kafka matches the whole name Kafka ACL Permission Matrix Viewer DENY beats every ALLOW Kafka Connect Config Validator The mistakes that raise no error Kafka Consumer Group Id Validator Which broker coordinates the group Kafka Partition Assignment Visualizer Leadership is the load, not replicas Kafka Consumer Assignment Visualizer The three assignors disagree Kafka ZooKeeper to KRaft Config Converter The authorizer class nobody changes Kafka Config to Strimzi Half of it belongs elsewhere Kafka Docker Compose Generator (KRaft) Reachable from inside and outside Kafka CRC32C Calculator Which CRC, over which bytes Kafka Config Upgrade Checker What breaks when you upgrade Kafka Kafka Config Diff Which change actually changed something Kafka Consumer Config Linter Why the group rebalances, and where the records went Kafka Avro Schema Validator The defaults Avro accepts and rejects Kafka Schema Compatibility Checker What the registry will say, before you ask it Kafka Avro Schema Diff Which direction each change breaks Kafka Compression Comparison Measured on your bytes Kafka Delivery Semantics Exactly-once has a consumer half Kafka ksqlDB Query Builder It looks like SQL and the rules are not Kafka Connect SMT Predicate Tester negate reads backwards Kafka Streams Topology Viewer Count the repartitions Kafka Connect Pipeline Visualizer The order things really run in Kafka Protobuf Binary Decoder Works without the .proto Kafka Protobuf JSON Converter Why your JSON does not round-trip Kafka Protobuf to Avro Schema What does not survive the conversion Kafka Avro Binary Decoder Wrong schema, no error Kafka Avro JSON Converter Why the console producer rejects your line Kafka Avro Sample Data Generator Records that actually serialize Kafka JSON to Avro Schema What JSON cannot tell you Kafka JSON Schema to Avro What does not survive the conversion Kafka SASL JAAS Generator One login module, four syntaxes Kafka CLI Command Builder kcat is librdkafka, not Kafka

Elsewhere on the site