Best Kafka CLI Tools in 2026: kcat vs kafkactl vs kaf
kcat, formerly kafkacat, is still a widely used Kafka command-line tool. Its last GitHub release, 1.7.0, shipped in August 2021, and its default branch has had no commits since November 2022. Yet Homebrew recorded 11,094 kcat installs in the year ending 28 September 2026.
So in 2026, should you keep using kcat, and if not, which Kafka CLI should replace it?
This guide compares kcat with kafkactl, kaf, kcl, rpk, Confluent CLI, and Kafka's built-in scripts across authentication (including MSK IAM), consumer group administration, Schema Registry formats, JSON output, and maintenance activity. It also covers declarative topic tools and terminal UIs.
Quick decision
| If you need to... | Start with | Why |
|---|---|---|
| Replace kcat with one maintained CLI for records and administration | kafkactl | Named contexts, group and ACL commands, and regular releases; see Moving from kcat |
Keep existing kcat pipelines and -f format strings | kcat | Still handles produce and consume, but has had no GitHub release since 2021; check the linked librdkafka version |
| Connect to AWS MSK with IAM without a plugin | kcl or kaf | Built-in MSK IAM support; kafkactl needs a separate plugin |
| Decode Avro, Protobuf, and JSON Schema from Schema Registry on Apache Kafka | kcl | All three registry formats, plus newer APIs such as share groups |
| Use short commands for everyday topic and group work | kaf | Resource-oriented commands; recent repository activity has slowed |
| Operate Redpanda | rpk | Redpanda's documented CLI for records and cluster operations |
| Operate Confluent Cloud or Confluent Platform | Confluent CLI | Platform resources and schema-aware produce and consume |
| Run a command on a Kafka host with nothing else to install | Kafka's built-in scripts | Ship with Kafka; require Java |
| Browse records in an SSH terminal | kaskade or ktea | Keyboard-driven terminal interfaces |
| Manage topic definitions in Git | topicctl or Jikkou | Declarative resource configuration |
Tip: To search and decode many records, or copy them across clusters, see Kafma's desktop workflow.
Built-in scripts or a standalone CLI?
Apache Kafka ships its own command-line tools in bin/ (with .bat versions in bin\windows\): kafka-topics.sh, kafka-console-producer.sh, kafka-console-consumer.sh, kafka-consumer-groups.sh, kafka-configs.sh, and more. They match the Kafka release they ship with, and the distribution includes dedicated tools for cluster operations such as partition reassignment (kafka-reassign-partitions.sh) and KRaft storage and quorum management (kafka-storage.sh, kafka-metadata-quorum.sh).
The costs show up in daily use. The scripts require Java and a Kafka distribution, different operations use separate scripts and flags, and SASL or TLS settings usually go into client properties files. The Apache distribution cannot decode Schema Registry records; Confluent Platform adds kafka-avro-console-consumer and similar tools for that. Older tutorials may run kafka-topics.sh and kafka-reassign-partitions.sh with --zookeeper; Kafka removed that option from these commands, so use --bootstrap-server instead.
A standalone CLI such as kafkactl is a single binary with named contexts, record formatting, and JSON output, which makes it easier to use on a laptop or in a container. Many teams use both: a standalone CLI for daily work, and the bundled scripts for cluster operations on a Kafka host.
Kafka CLI tools compared
| Tool | Contexts or profiles | SASL/TLS | MSK IAM | Consumer group lag / offset reset | JVM required |
|---|---|---|---|---|---|
| Kafka scripts | — (properties file per command) | Yes | External AWS Java library | Both | Yes |
| kcat | Single config file (-F) | Yes | — | — / — | No |
| kafkactl | Named contexts | Yes | AWS plugin | Both | No |
| kaf | Named clusters | Yes | Yes | Both | No |
| rpk | Profiles | Yes | — | Both | No |
| kcl | Profiles | Yes | Yes | Both | No |
| Confluent CLI | Contexts | Yes | — | Cloud Dedicated or Platform / — | No |
Confluent CLI reads group lag on Confluent Cloud Dedicated clusters and, through REST Proxy, on Confluent Platform; it has no group offset reset command.
| Tool | Registry Avro decode | Registry Protobuf decode | Registry JSON Schema decode | JSON output |
|---|---|---|---|---|
| Kafka scripts | — | — | — | — |
| kcat | Yes, with libserdes | — | — | Records (-J) |
| kafkactl | Yes | Local .proto or protoset only | Yes | Commands and records |
| kaf | Yes | Local .proto only | — | Records |
| rpk | Yes | Yes | Yes | Records |
| kcl | Yes | Yes | Yes | Commands and records |
| Confluent CLI | Yes | Yes | Yes | Commands |
kcat
kcat is a single C binary built on librdkafka for producing, consuming, and listing metadata. It is at its best in pipelines: records come from stdin and go to stdout, -e stops at the current end, -c stops after a record count, -o s@<ms> starts at a timestamp, and -f formats each record. With a build that includes libserdes, it decodes Avro through Schema Registry.
kcat -b localhost:9092 -C -t orders -o s@1759017600000 -e -f '%p %o %k %s\n'
Its last GitHub release was 1.7.0 in August 2021, and kcat itself has received no commits since November 2022. Homebrew links kcat against its packaged librdkafka and libserdes, so client-library fixes can still arrive through those packages (check with kcat -V). Keep it for pipelines that already work; for new scripts, see Moving from kcat.
kafkactl
kafkactl uses kubectl-style commands such as kafkactl get topics, kafkactl describe consumer-group, and kafkactl config use-context. One binary covers topics, consumer groups and offset resets, ACLs, produce, and consume, and it installs through Homebrew, winget, Docker, or a release binary.
Two features stand out. If your brokers are reachable only from inside Kubernetes, Kubernetes mode runs each command in a pod through kubectl. Credentials can come from an interactive prompt or the OS keyring instead of a plaintext config file. The trade-offs are in the matrix: Protobuf uses local .proto files, and MSK IAM needs a separate plugin.
kaf
kaf keeps commands short: kaf topics, kaf groups, kaf consume orders. Two commands have no direct equivalent in kcat: kaf group peek shows records before and after a group's committed offset, and kaf query scans a topic for a key (--key) or a value substring (--grep). kaf config select-cluster switches clusters from an interactive list, and kaf can import a Confluent Cloud configuration or add an Azure Event Hubs namespace.
Activity has slowed. The latest release is v0.2.14 from February 2026, there were no commits in the 90 days before 28 September 2026, and open issues have a median age of 5.9 years. Choose it when kaf group peek and kaf query fit your day-to-day inspection work.
rpk
rpk is Redpanda's CLI. Its record commands will feel familiar to kcat users: rpk topic consume takes -f format strings and timestamp offsets, --regex reads every topic matching a pattern, and --use-schema-registry decodes Avro, Protobuf, and JSON Schema. rpk profile stores named clusters, and rpk container start starts a local Redpanda cluster in Docker for testing.
Common topic, group, and record commands speak the Kafka protocol and work with Apache Kafka. Commands for cluster configuration, health, tuning, and Redpanda Cloud need Redpanda's Admin API or Redpanda Cloud. If you run Redpanda, make it your main CLI; on Apache Kafka, it is a capable record tool rather than a full admin CLI.
kcl
kcl is a pure-Go CLI from the author of franz-go that aims to cover the whole Kafka API: produce and consume with kcat-style format verbs, administration, transactions, ACLs, and share groups (KIP-932, Kafka 4.0+). It encodes and decodes Avro, Protobuf, and JSON Schema through Schema Registry. For protocol debugging, kcl misc api-versions shows what a broker supports and kcl misc raw-req sends a raw request.
kcl fake starts an in-process fake cluster for CI and demos without Docker; it is not a production broker. Administrative commands offer stable --format json output; produce and consume use per-record format strings. Choose kcl when you need share groups, raw protocol access, or scriptable JSON from the same binary you use for records.
Confluent CLI
Confluent CLI (confluent) manages Confluent Cloud and Confluent Platform resources, including environments, clusters, API keys, RBAC, connectors, and Schema Registry, alongside topics. Its kafka topic produce and kafka topic consume commands handle Avro, Protobuf, and JSON Schema through Schema Registry, and with --bootstrap they connect directly to brokers. confluent local kafka start runs a local Apache Kafka instance in Docker for testing.
Most other commands need a Confluent Cloud login or, for self-managed clusters, Confluent REST Proxy. Choose it if you run on Confluent. For an existing Apache Kafka cluster without REST Proxy, its direct broker access is limited to produce and consume.
Kafka topics as code: topicctl and Jikkou
topicctl, from Segment, keeps each topic's settings in a YAML file in Git. topicctl apply creates the topic or brings it in line with the file, and topicctl check validates configs and compares them with cluster state before you apply them. It also manages replica placement across racks (cross-rack, in-rack, balanced-leaders), and topicctl rebalance can rebalance eligible topics under a config path. For ad hoc inspection, topicctl repl opens a shell with get and tail.
Jikkou covers more resource types: topics, ACLs, quotas, Schema Registry schemas, and Kafka Connect connectors. jikkou diff compares the files in Git with the live cluster, without a state file, and jikkou apply makes only the necessary changes. Jinja templates and provider groups let one definition target several environments or clusters. Its August 2026 release added CI drift detection and Kafka 4.x share-group support.
Choose topicctl if you focus on topics and replica placement; choose Jikkou if schemas or connectors belong in the same repository.
Terminal UIs: kaskade and ktea
A terminal UI gives you navigable screens when you're working inside an SSH session.
kaskade has two modes. kaskade admin browses topics, partitions, consumer groups, and lag, and can create, edit, or delete topics. kaskade consumer -t orders reads records, filters them by key, value, header, or partition, and decodes Avro and Protobuf through Confluent Schema Registry or Apicurio Registry. It supports SASL, TLS, and MSK IAM, and installs with Homebrew or pipx.
ktea will feel familiar to k9s users. It switches between several clusters, lists and modifies topics, searches consumed records, shows consumer group lag, and browses and registers Schema Registry schemas. It can also browse Kafka Connect clusters. Record decoding covers text, JSON, and Avro; Protobuf is on its to-do list.
Both suit interactive browsing. For repeatable scripts and pipeline output, use a line-oriented CLI.
Moving from kcat
These examples assume a local broker or an already selected CLI profile and a topic named orders.
| Task | kcat | kafkactl | kaf |
|---|---|---|---|
| Read from the beginning and follow new records | kcat -b localhost:9092 -t orders -C -o beginning | kafkactl consume orders --from-beginning | kaf consume orders -f |
| Read historical records and exit at the current end | kcat -b localhost:9092 -t orders -C -o beginning -e | kafkactl consume orders --from-beginning --exit | kaf consume orders |
| Start at a timestamp | kcat -b localhost:9092 -t orders -C -o s@1759017600000 | kafkactl consume orders --from-timestamp 2025-09-28T00:00:00Z | — |
| Stop after 10 records | kcat -b localhost:9092 -t orders -C -o beginning -c 10 | kafkactl consume orders --from-beginning --max-messages 10 | kaf consume orders -l 10 (up to 10 per partition) |
| Print records as JSON | kcat -b localhost:9092 -t orders -C -J | kafkactl consume orders -o json | kaf consume orders --output json |
| List topics | kcat -b localhost:9092 -L | kafkactl get topics | kaf topics |
| Send one keyed record with a header | printf 'hello\n' | kcat -b localhost:9092 -t orders -P -k order-1 -H source=manual | kafkactl produce orders --key=order-1 --value=hello --header source:manual | printf 'hello\n' | kaf produce orders --key order-1 --header source:manual |
kcl and rpk offer similar format strings, making them closer fits for scripts built around -f, but their verbs differ: kcat's %s becomes %v. JSON output also differs: kafkactl -o json and kaf --output json do not follow kcat's -J field layout. When a script parses kcat output, check how the new tool prints null values, binary payloads, and headers.
GitHub repository metrics
The tables below compare the GitHub activity, maintenance, and public interest of the five CLIs that have their own repositories. Snapshot: 28 Sep 2026. Kafka's scripts ship in apache/kafka and rpk in the Redpanda monorepo; those repositories measure the broker rather than the CLI, so they are not included.
Project overview
| kcat | kafkactl | kaf | kcl | Confluent CLI | |
|---|---|---|---|---|---|
| Repository created | 30 Mar 2014 | 10 Dec 2018 | 11 Sep 2018 | 11 Apr 2019 | 3 Apr 2018 |
| License | BSD-2-Clause | Apache-2.0 | Apache-2.0 | BSD-3-Clause | Confluent Community License 1.0 |
| Repository status | Not archived · original | Not archived · original | Not archived · original | Not archived · original | Not archived · original |
GitHub does not detect kcat's license automatically because its LICENSE file keeps the librdkafka heading; the text is the BSD 2-clause license. Confluent CLI is source-available under the Confluent Community License, not an OSI-approved open source license.
Activity
| Metric | kcat | kafkactl | kaf | kcl | Confluent CLI |
|---|---|---|---|---|---|
| Latest default-branch commit | 17 Nov 2022 | 30 Jul 2026 | 19 Apr 2026 | 27 Sep 2026 | 25 Sep 2026 |
| Latest GitHub Release | 1.7.0 (23 Aug 2021) | v5.20.0 (30 Jul 2026) | v0.2.14 (27 Feb 2026) | v0.20.0 (18 Sep 2026) | v4.77.0 (22 Sep 2026) |
| GitHub Releases (12 mo) | 0 | 8 | 1 | 4 | 43 |
| Commits | 0 (90 d) · 0 (12 mo) | 8 (90 d) · 87 (12 mo) | 0 (90 d) · 12 (12 mo) | 254 (90 d) · 350 (12 mo) | 78 (90 d) · 222 (12 mo) |
| Issue flow (90 d) | 0 opened · 0 closed | 2 opened · 0 closed | 0 opened · 0 closed | 1 opened · 3 closed | 1 opened · 1 closed |
| PR flow (90 d) | 0 opened · 0 merged | 12 opened · 3 merged | 0 opened · 0 merged | 31 opened · 31 merged | 130 opened · 80 merged |
| Activity assessment | 🔴 No commit on the default branch in 1,410 days. | 🟢 8 commits and 3 merged PRs in the last 90 days. | 🔴 No commits and no merged PRs in the last 90 days. | 🟢 254 commits and 31 merged PRs in the last 90 days. | 🟢 78 commits and 80 merged PRs in the last 90 days. |
Maintenance
| Metric | kcat | kafkactl | kaf | kcl | Confluent CLI |
|---|---|---|---|---|---|
| Active commit authors (12 mo) | 0 | 8 | 4 | 3 | 48 |
| PR merge distribution (12 mo) | 0 people · no recorded non-bot merges | 1 person · 100% of merges | 1 person · 100% of merges | 1 person · 100% of merges | 40 people · Top 1: 25% · Top 2: 42% |
| Issue backlog | 138 open · median age 5.3 y | 12 open · median age 2.4 y | 66 open · median age 5.9 y | 0 open issues | 14 open · median age 2.5 y |
| PR backlog | 23 open · median age 4 y | 5 open · median age 19 d | 15 open · median age 1.1 y | 0 open PRs | 71 open · median age 73 d |
| Median PR merge time (90 d) | N/A — no merged PRs in window | 1.4 h (n=3 — small sample) | N/A — no merged PRs in window | <1 h (n=31) | 1 d (n=80) |
| Published GitHub security advisories | 0 | 0 | 0 | 0 | 0 |
| Responsiveness assessment | 🔴 No PRs merged in 90 d, while 23 open PRs have a median age of 4 y. | 🟢 The median open PR age is 19 d. | 🔴 No PRs merged in 90 d, while 15 open PRs have a median age of 1.1 y. | 🟢 New PRs merge in a median of <1 h (n=31). | 🟡 Median open PR age 73 d exceeds 60 d. |
| PR merge concentration assessment | N/A — no recorded merges in 12 mo. | 🔴 1 person merged PRs in 12 mo and handled 100% of merges. | 🔴 1 person merged PRs in 12 mo and handled 100% of merges. | 🔴 1 person merged PRs in 12 mo and handled 100% of merges. | 🟢 40 people merged PRs in 12 mo; the most active account handled 25% of merges. |
PR merge distribution counts non-bot mergedBy accounts, so automated merges may undercount human reviewers.
Public usage and interest
| Metric | kcat | kafkactl | kaf | kcl | Confluent CLI |
|---|---|---|---|---|---|
| Stars | 5,782 | 1,071 | 2,442 | 232 | 80 |
| Forks | 498 | 110 | 163 | 25 | 37 |
| Homebrew installs (365 d) | 11,094 | 2,394 | 226 | Not in Homebrew core | Not in Homebrew core |
Homebrew figures count installs through the main formula catalog in the 365 days ending 28 September 2026, not unique users. They are the closest public usage signal for a CLI; GitHub dependents are left out because people install these tools as binaries rather than import them as libraries. Stars measure interest, not use: kaf has more than twice kafkactl's stars but about a tenth of its Homebrew installs.
Among the other tools in this guide, kaskade had 1,028 Homebrew installs, ktea 330, and topicctl 63 over the same period. rpk installs through Redpanda's own tap, which does not publish comparable figures.
Overall repository signals
- kcat has no default-branch commit since November 2022 and no release since August 2021, with 138 open issues and 23 open PRs waiting; it still leads Homebrew installs by a wide margin.
- kafkactl ships releases steadily (8 in 12 months) and has the second-highest Homebrew installs; one account handled all recorded PR merges in the past year.
- kaf has more stars than kafkactl but no commits or merged PRs in the last 90 days, and its open issues have a median age of 5.9 years.
- kcl has the most commits of the five, 254 in 90 days, and no open issues or PRs; it has the fewest GitHub stars among the four standalone Apache Kafka CLIs, and one account handled all merges.
- Confluent CLI releases most often and spreads PR merges across the most accounts; its GitHub stars say little about its use, which follows Confluent Cloud and Platform adoption.
These are maintenance and adoption signals, not evidence of runtime quality or feature fit.
When a desktop UI is faster than a CLI
A Kafka CLI is the right tool for scripts, CI jobs, and SSH sessions. It slows down when an investigation means reading many records, moving between topics, schemas, and consumer groups, and re-running commands with different flags to compare results.
Kafma is a desktop Kafka UI that connects to the same clusters as your CLI, including over SASL, TLS, and AWS MSK IAM.
Search and inspect records
With kcat, finding one record means piping a bounded read through grep and reformatting the match. In Kafma's Kafka console, load a range from the beginning, an offset, or a timestamp, then filter by key or value. Expand a match to see its headers, partition, offset, timestamp, and decoded value in one place. Search covers the records already loaded; it does not scan the whole topic.

Decode Avro, Protobuf, and JSON Schema
kcat's Schema Registry decoding is limited to Avro, and kafkactl and kaf need local .proto files for Protobuf. Kafma reads the schema ID from Confluent-framed records and decodes Avro, Protobuf, and JSON Schema through Schema Registry, while Raw always shows the original bytes. The Schema Registry UI lists subjects, versions, and schema IDs, so you can match a record to the schema that wrote it.
Watch consumer lag over time
kafka-consumer-groups.sh --describe prints one snapshot; to see a trend, you run it again and compare. Kafma's consumer group UI shows total and max lag, a recent lag trend, and lag per partition, with unassigned partitions flagged. Watch Group opens records around each partition's committed offset without joining the group or changing its offsets.

Copy records between clusters
A kcat -C | kcat -P pipe can carry keys with -K, but -H only adds fixed headers, so each record's own headers are lost. Kafma Data Clone copies a selected range of records to a topic on another cluster with keys, values, timestamps, headers, and tombstones, and can mask selected value fields on the way. With Structure + Data, it also registers the schemas those records use and rewrites their schema IDs for the target registry. See the Data Clone guide for copy behavior.

Download Kafma and connect to the cluster you already use with your CLI.
Frequently asked questions
Is kcat still maintained?
Not actively. Its last GitHub release was 1.7.0 in August 2021, and its default branch has had no commits since November 2022. Homebrew links it against a separately updated librdkafka, so client-library fixes can still reach packaged builds.
What is the best kcat alternative?
For a general Apache Kafka CLI, start with kafkactl: it covers records and administration and ships regular releases. If your scripts depend on kcat's -f format strings, kcl and rpk are closer fits. See Moving from kcat for command equivalents.
Can kcat decode Protobuf from Schema Registry?
No. kcat's Schema Registry support covers Avro only. kcl, rpk, and Confluent CLI decode Avro, Protobuf, and JSON Schema through Schema Registry; see the feature matrix.
How do I check consumer group lag from the command line?
Run bin/kafka-consumer-groups.sh --bootstrap-server localhost:9092 --describe --group my-group from an Apache Kafka installation. Its CURRENT-OFFSET, LOG-END-OFFSET, and LAG columns show the backlog for each partition. kafkactl describe consumer-group my-group, kaf group describe my-group, and kcl group describe my-group offer the same kind of snapshot. To see whether lag rises or falls while group details refresh, use Kafma's recent lag trend.
How do I install kcat on Windows?
The project does not publish an official prebuilt Windows executable with its GitHub releases. Follow the source build instructions, which use NuGet and MSBuild, or run a Linux build through WSL. For a Windows install through a package manager, kafkactl documents winget install kafkactl.
What is the difference between kcat and kafkacat?
They are the same project. It was renamed in August 2021, so older packages and examples may still say kafkacat.
Is there an official Kafka CLI?
Yes. Apache Kafka ships command-line scripts with every distribution; they require Java. Confluent CLI and rpk are the official CLIs for Confluent and Redpanda.
Can Confluent CLI connect directly to an Apache Kafka broker?
Yes. Its produce and consume commands connect through --bootstrap; see Confluent CLI for the REST Proxy requirement on other cluster operations.
Which CLI should I use for AWS MSK IAM?
kcl and kaf support AWS MSK IAM out of the box. kafkactl needs its AWS plugin, and the bundled Kafka scripts need AWS's Java IAM library on the classpath. kcat and rpk have no built-in MSK IAM support.
Does rpk work with Apache Kafka?
Yes. Common topic, group, and record commands use the Kafka protocol; see rpk for the Redpanda-specific limits.
How do I manage Kafka Connect from the command line?
Use the Kafka Connect REST API with curl, or your platform's tooling. To manage connectors declaratively from Git, Jikkou covers them too. kcctl is a Connect-specific CLI; its latest candidate release is v1.0.0.CR4 from November 2024, and the project also publishes early-access builds.
Conclusion
Keep kcat for existing pipelines that already work, especially those built around -f format strings. For new work on Apache Kafka, start with kafkactl, which covers records and administration and ships regular releases. Choose kcl when you need share groups, MSK IAM without a plugin, or all three Schema Registry formats, and use rpk or Confluent CLI when you run Redpanda or Confluent. For browsing over SSH, try kaskade or ktea.
When an investigation spans many records, schemas, and consumer groups, use Kafma alongside your CLI.
This guide is maintained by the team behind Kafma.