A password in the JAAS string
The credential that ends up in every config file and process listing
org.apache.kafka.common.security.plain.PlainLoginModule required username="admin" password="admin-secret";
Decode and check a sasl.jaas.config value, or
the whole properties file around it. The password is never printed back to
you, which is what makes this safe to paste.
Or drop a file anywhere on this panel. Nothing is uploaded: the analysis runs in this tab.
The answer appears here
Paste on the left and press Decode & check. Nothing leaves this tab.
Nothing else to flag.
No formatting problems, and nothing the rules object to. Worth remembering what that covers: this reads the file you pasted, not the account or cluster it will be applied to.
No finding matches that filter.
Real input you can load into the tool above. Each one shows a different thing going wrong, because that is what the tool is for.
The credential that ends up in every config file and process listing
org.apache.kafka.common.security.plain.PlainLoginModule required username="admin" password="admin-secret";
A JAAS line that will fail to authenticate, and why the error is unhelpful
org.apache.kafka.common.security.scram.ScramLoginModule required username="app";
These are the ones that fail silently. The config is accepted, nothing raises an error, and the consequence arrives later.
It lands in the properties file, in process listings, in container inspect output and in any log that dumps configuration.
Instead:Use a KafkaClient section in a separate JAAS file with restricted permissions, or a config provider that resolves the value at startup.
A JAAS entry must end with a semicolon. Without it the parse fails with a message about the login module rather than about punctuation.
Instead:End every entry with a semicolon, inside the quoted value.
SASL/PLAIN sends the password essentially in the clear. It is only safe wrapped in TLS, which means SASL_SSL rather than SASL_PLAINTEXT.
Instead:Use SASL_SSL, or SCRAM which does not transmit the password itself.
It is one line, it has its own grammar borrowed from Java, and every way it fails produces an error message about something else.
The value is `<LoginModule> <controlFlag> [option=value ...];` and each part has rules. The control flag is one of required, requisite, sufficient or optional, and with a single module anything other than required either behaves identically or lets login succeed without this module doing anything. The terminating semicolon is required. Option values are quoted, which is what lets a password contain a space or an equals sign, and it is also why a parser that splits on whitespace reports a working config as broken.
The JAAS entry names a login module. `sasl.mechanism` names a mechanism, and defaults to GSSAPI, which is Kerberos, so leaving it out of a PLAIN setup means the client attempts the wrong thing entirely. `security.protocol` decides whether SASL is attempted at all, and defaults to PLAINTEXT. Any one of the three being wrong produces a symptom that points at the other two, which is why this page wants the whole file.
A password containing a double quote has to escape it. Without that, the value ends early and every option after it becomes part of the password or is dropped, so a config that looks complete is missing settings with no error to say which. The same applies to a backslash. A semicolon inside a quoted value is fine and does not terminate the entry, which is worth knowing because it looks like it should.
SASL_PLAINTEXT authenticates and does not encrypt. With the PLAIN mechanism that means the password itself crosses the network readable by anything on the path, which is a different risk from SCRAM, where a challenge is exchanged and the password is not sent. Neither is a reason to skip TLS, and the page flags the combination rather than the protocol on its own.
It reads one line of configuration. It does not contact a broker, verify that credentials work, check that a keytab exists at the path given, or know what your broker's sasl.enabled.mechanisms allows. It also cannot check the options of a vendor login module, and says so rather than guessing. For whether a config will start at all, the producer and consumer linters on this site cover the rest of the file.