ConfluentCAUTION
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/@confluentinc/mcp-confluent) [](LICENSE)
An open-source MCP server that enables AI assistants to interact with Confluent Cloud, Confluent Platform, and standalone Apache Kafka deployments through natural language. It provides 50+ tools across Kafka, Flink SQL, Schema Registry, Connectors, Tableflow, and more -- usable from any MCP-compatible client including Claude Desktop, Claude Code, Cursor, VS Code, Goose, and Gemini CLI.
[!TIP] Already a Confluent Cloud customer? Confluent offers a fully managed MCP server with no local server to run and no dependencies to install. It provides access to your Confluent Cloud resources with AI-powered connector diagnostics, governed by your existing RBAC permissions. Use this open-source server if you need Confluent Platform / self-managed Kafka support, or want to customize and extend the toolset. NOTE: The open-source MCP server is a community-supported project. Confluent doesn’t provide dedicated support for it, and support is best-effort only, with no service level commitments. If you run into an issue or want to contribute, open an issue or pull request directly in this repository.
Quick Start
Prerequisites: Node.js 22.19.0+. If you want to interact with Confluent Cloud, you need to create an account first.
- Generate a quick
config.yamlfile in your project root:
npx @confluentinc/mcp-confluent --init-config
- Edit the
config.yamlfile with your connection details, then:
npx @confluentinc/mcp-confluent --config ./config.yaml
See Getting Started for full setup instructions
82b223578decOBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-confluent --env CONFLUENT_CLOUD_PASSWORD=${CONFLUENT_CLOUD_PASSWORD} --env TELEMETRY_WRITE_KEY=${TELEMETRY_WRITE_KEY} -- npx -y @confluentinc/[email protected]{
"mcpServers": {
"mcp-confluent": {
"command": "npx",
"args": [
"-y",
"@confluentinc/[email protected]"
],
"env": {
"CONFLUENT_CLOUD_PASSWORD": "${CONFLUENT_CLOUD_PASSWORD}",
"TELEMETRY_WRITE_KEY": "${TELEMETRY_WRITE_KEY}"
}
}
}
}Exposed tools (1)
1 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
mcp | read | Model Context Protocol endpoints |
Trust audit
CAUTIONgrade B · trust 81/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
console.log(apiKey);
console.log(`MCP_API_KEY=${apiKey}\n`);api_key: "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
.cursorignore
.env.integration.example
.prettierignore
new URL("../../test-fixtures/yaml_configs", import.meta.url),new URL("../../config.example.yaml", import.meta.url),new URL("../../sample_configs", import.meta.url),import pkg from "../../package.json" with { type: "json" };"../../../assets/oauth-templates/",
describe("install hint beacon + stream", () => {it("should track AGENT_SKILLS_HINT_COPIED on POST to the beacon path", async () => {it("should reject non-POST methods on the beacon path with 405", async () => {This starts the server on `http://127.0.0.1:8080/mcp` (the defaults for `HTTP_HOST`, `HTTP_PORT`, and `HTTP_MCP_ENDPOINT_PATH`) with authentication disabled for local development.
"url": "http://127.0.0.1:8080/mcp"
Press **F5** in VS Code to build and start the server in HTTP mode with auth disabled. The launch config (`.vscode/launch.json`) automatically runs `pnpm run build`, enables pretty logging (`LOG_PRETT
{"level":"info","time":"2025-05-14T17:03:03.013Z","pid":47959,"hostname":"G9PW1FJH64","name":"mcp-confluent","msg":"Server listening at http://127.0.0.1:3000"}"http://127.0.0.1:26640/gateway/v1/callback-local-mcp-docs",
@bufbuild/protobuf, @commander-js/extra-typings, @confluentinc/kafka-javascript, @confluentinc/schemaregistry, @fastify/swagger, @fastify/swagger-ui, @modelcontextprotocol/sdk, @segment/analytics-node
assets/claude-desktop-demo.gif
assets/goose-cli-demo.gif
openapi.json
src/confluent/openapi-schema.d.ts
- **OAuth (PKCE) authentication for Confluent Cloud.** A `connections.<id>.type: oauth` connection signs the user in via the Confluent Cloud login page on the first tool call that needs Cloud access,
Gates applied: no_behavioural_pass.
82b223578decfull audit observations/trust-audit/mcp-server/confluentinc__confluent.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 82b223578dec | CAUTION | B | 81 | first audit |
Questions
What tools does Confluent expose?
1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Confluent safe to connect to an agent?
With care. The audit graded it B (81/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Confluent need?
It reads CONFLUENT_CLOUD_PASSWORD and TELEMETRY_WRITE_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Confluent run?
It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @confluentinc/mcp-confluent at 1.7.0.
How current is this page?
The grade is for one exact copy of the source (82b223578dec), read on 2026-10-06. The repository is watched and re-audited when it changes.