[{"data":1,"prerenderedAt":1607},["ShallowReactive",2],{"blog-post-\u002Fblog\u002Fkafka-rest-proxy":3},{"id":4,"title":5,"body":6,"date":1593,"description":1594,"extension":1595,"meta":1596,"navigation":1597,"ogImage":1598,"path":1599,"pinned":1600,"seo":1601,"sitemap":1602,"stem":1603,"tags":1604,"__hash__":1606},"blog\u002Fblog\u002Fkafka-rest-proxy.md","Kafka REST Proxy: Confluent vs Karapace vs Strimzi",{"type":7,"value":8,"toc":1556},"minimark",[9,18,41,46,165,169,178,181,198,207,211,363,366,370,382,387,478,483,486,489,495,499,537,542,545,548,564,568,626,631,634,638,666,670,723,728,731,734,748,752,807,812,815,819,822,840,847,851,854,869,875,881,885,888,896,900,964,968,1092,1107,1111,1260,1263,1267,1320,1323,1327,1344,1347,1351,1355,1361,1378,1388,1397,1401,1409,1417,1420,1427,1435,1439,1442,1467,1474,1478,1481,1487,1491,1496,1500,1507,1511,1517,1521,1530,1534,1543,1547,1550,1553],[10,11,12,13,17],"p",{},"Apache Kafka has no built-in HTTP API for records: clients speak Kafka's binary protocol over TCP. A Kafka REST proxy translates between the two, so applications can produce and consume Kafka records over HTTP. Common use cases include browser apps, serverless functions that prefer an HTTP API, and services on networks that only allow HTTPS. Producing is the simpler part: every REST proxy compared here accepts a ",[14,15,16],"code",{},"POST"," with a batch of records and returns offsets. Consuming through a consumer-instance API is harder. Requests for that consumer must reach the proxy process that owns it. A proxy restart loses the instance; idle cleanup depends on the proxy and its configuration.",[10,19,20,21,28,29,34,35,40],{},"This guide compares three self-managed Kafka REST proxies you can run against an Apache Kafka cluster: ",[22,23,27],"a",{"href":24,"rel":25},"https:\u002F\u002Fgithub.com\u002Fconfluentinc\u002Fkafka-rest",[26],"nofollow","Confluent REST Proxy",", the reference implementation of the v2 and v3 APIs, under the Confluent Community License; ",[22,30,33],{"href":31,"rel":32},"https:\u002F\u002Fgithub.com\u002FAiven-Open\u002Fkarapace",[26],"Karapace",", an Apache 2.0 implementation of the Confluent v2 API; and ",[22,36,39],{"href":37,"rel":38},"https:\u002F\u002Fgithub.com\u002Fstrimzi\u002Fstrimzi-kafka-bridge",[26],"Strimzi Kafka Bridge",", an Apache 2.0 bridge with its own v2-style API and no built-in Schema Registry serialization. It covers API compatibility, serialization formats, consumer recovery, authentication, license, and maintenance activity, then looks at the built-in options on Redpanda and Confluent Cloud and at declarative HTTP gateways.",[42,43,45],"h2",{"id":44},"quick-decision","Quick decision",[47,48,49,65],"table",{},[50,51,52],"thead",{},[53,54,55,59,62],"tr",{},[56,57,58],"th",{},"If you need to...",[56,60,61],{},"Start with",[56,63,64],{},"Why",[66,67,68,82,95,112,126,140,154],"tbody",{},[53,69,70,74,79],{},[71,72,73],"td",{},"Run Confluent Platform, use the v3 API, or authenticate HTTP clients with Confluent's security plugins",[71,75,76],{},[22,77,27],{"href":78},"#confluent-rest-proxy",[71,80,81],{},"v2 and v3 APIs; Avro, Protobuf, and JSON Schema serialization; Confluent Community License, Enterprise license for the security plugins",[53,83,84,87,92],{},[71,85,86],{},"Use the Confluent v2 API, with Schema Registry serialization, under Apache 2.0",[71,88,89],{},[22,90,33],{"href":91},"#karapace",[71,93,94],{},"Aims to be a drop-in replacement for v2 clients; test the endpoints you use",[53,96,97,100,105],{},[71,98,99],{},"Run on Kubernetes with the Strimzi Operator, with JSON, text, or binary payloads",[71,101,102],{},[22,103,39],{"href":104},"#strimzi-kafka-bridge",[71,106,107,108,111],{},"Managed through the ",[14,109,110],{},"KafkaBridge"," resource; no built-in Schema Registry serialization and no built-in HTTP client authentication",[53,113,114,117,123],{},[71,115,116],{},"Run self-managed Redpanda or a Redpanda Cloud BYOC or Dedicated cluster",[71,118,119],{},[22,120,122],{"href":121},"#redpanda-http-proxy-pandaproxy","Redpanda HTTP Proxy",[71,124,125],{},"Built into the brokers, with no separate proxy to deploy; also reads a partition at an offset without creating a consumer instance",[53,127,128,131,137],{},[71,129,130],{},"Produce to Confluent Cloud over HTTPS",[71,132,133],{},[22,134,136],{"href":135},"#confluent-cloud-rest-api","Confluent Cloud REST API",[71,138,139],{},"Hosted v3 produce endpoint; no built-in Schema Registry serialization; see the consume caveat",[53,141,142,145,151],{},[71,143,144],{},"Expose an application-specific HTTP or SSE API instead of a generic proxy",[71,146,147],{},[22,148,150],{"href":149},"#declarative-http-gateways-zilla-and-gravitee","Zilla or Gravitee",[71,152,153],{},"You define the routes and their mapping to topics",[53,155,156,159,162],{},[71,157,158],{},"Consume continuously when native Kafka access is available",[71,160,161],{},"A native Kafka client",[71,163,164],{},"Your application controls polling and commits directly, without an HTTP proxy session to maintain",[42,166,168],{"id":167},"does-kafka-have-a-rest-api","Does Kafka have a REST API?",[10,170,171,172,177],{},"Not for producing or consuming records. ",[22,173,176],{"href":174,"rel":175},"https:\u002F\u002Fkafka.apache.org\u002F43\u002Fkafka-connect\u002Fuser-guide\u002F#rest-api",[26],"Kafka Connect"," has a REST API for managing connectors and tasks, but it does not expose record-level produce or consume endpoints.",[10,179,180],{},"To reach Kafka over HTTP, you run a proxy that translates HTTP requests into Kafka client calls, or use one built into your platform. Two kinds of work go through these proxies:",[182,183,184,192],"ul",{},[185,186,187,191],"li",{},[188,189,190],"strong",{},"Data plane",": producing and reading records. Consumer-instance APIs support group subscriptions or manual partition assignment. Redpanda's HTTP Proxy also lets clients read a partition at an explicit offset without creating a consumer instance.",[185,193,194,197],{},[188,195,196],{},"Admin plane",": listing and creating topics, reading and changing configs, and inspecting consumer groups.",[10,199,200,201,206],{},"Confluent REST Proxy covers both, with a ",[22,202,205],{"href":203,"rel":204},"https:\u002F\u002Fdocs.confluent.io\u002Fplatform\u002F8.3\u002Fkafka-rest\u002Fapi.html",[26],"v2 API for produce and consume and a v3 API for produce and administration",". Karapace and Strimzi Kafka Bridge focus on the data plane and expose a smaller set of metadata and admin endpoints.",[42,208,210],{"id":209},"kafka-rest-proxies-compared","Kafka REST proxies compared",[47,212,213,241],{},[50,214,215],{},[53,216,217,220,227,234],{},[56,218,219],{},"Capability",[56,221,222],{},[22,223,226],{"href":224,"rel":225},"https:\u002F\u002Fdocs.confluent.io\u002Fplatform\u002F8.3\u002Fkafka-rest\u002Findex.html",[26],"Confluent REST Proxy 8.3.0",[56,228,229],{},[22,230,233],{"href":231,"rel":232},"https:\u002F\u002Fgithub.com\u002FAiven-Open\u002Fkarapace\u002Freleases\u002Ftag\u002F6.2.3",[26],"Karapace 6.2.3",[56,235,236],{},[22,237,240],{"href":238,"rel":239},"https:\u002F\u002Fgithub.com\u002Fstrimzi\u002Fstrimzi-kafka-bridge\u002Freleases\u002Ftag\u002F1.2.0",[26],"Strimzi Kafka Bridge 1.2.0",[66,242,243,259,274,289,305,325,344],{},[53,244,245,250,253,256],{},[71,246,247],{},[188,248,249],{},"API",[71,251,252],{},"Confluent v2 and v3",[71,254,255],{},"Confluent v2",[71,257,258],{},"Own API, modeled on Confluent v2",[53,260,261,266,269,271],{},[71,262,263],{},[188,264,265],{},"Formats",[71,267,268],{},"JSON, binary; Avro, Protobuf, JSON Schema through Schema Registry",[71,270,268],{},[71,272,273],{},"JSON, binary, text; no built-in Schema Registry serialization",[53,275,276,281,284,287],{},[71,277,278],{},[188,279,280],{},"Idle consumer cleanup",[71,282,283],{},"5 minutes by default (configurable)",[71,285,286],{},"Off by default (configurable)",[71,288,286],{},[53,290,291,296,299,302],{},[71,292,293],{},[188,294,295],{},"Admin endpoints",[71,297,298],{},"v3: topics, configs, ACLs, consumer groups, and more",[71,300,301],{},"v2 metadata: topics (including configs), partitions, offset bounds, brokers",[71,303,304],{},"List topics, partitions, and offset bounds; create topics",[53,306,307,312,315,322],{},[71,308,309],{},[188,310,311],{},"HTTP client authentication",[71,313,314],{},"Basic or mutual TLS; OAuth\u002FOIDC with the Enterprise security plugins",[71,316,317,318,321],{},"Basic or Bearer with ",[14,319,320],{},"rest_authorization","; credentials validated by Kafka",[71,323,324],{},"None built in; use a reverse proxy or API gateway",[53,326,327,332,335,341],{},[71,328,329],{},[188,330,331],{},"Caller identity in Kafka ACLs",[71,333,334],{},"With the Enterprise security plugins",[71,336,337,338,340],{},"Yes, with ",[14,339,320],{}," (Basic → configured SASL mechanism, including PLAIN or SCRAM; Bearer → OAUTHBEARER)",[71,342,343],{},"No; one configured Kafka identity",[53,345,346,351,354,357],{},[71,347,348],{},[188,349,350],{},"Deployment",[71,352,353],{},"Confluent Platform package, container image, Confluent for Kubernetes",[71,355,356],{},"Container image (ghcr.io) or install from source",[71,358,359,360,362],{},"Archive on a host, container image, or ",[14,361,110],{}," resource",[10,364,365],{},"This table is based on each version's documentation, source code, and upstream test definitions.",[367,368,27],"h3",{"id":369},"confluent-rest-proxy",[10,371,372,375,376,381],{},[22,373,27],{"href":24,"rel":374},[26]," defines the v2 API that Karapace and Redpanda implement and that Strimzi's API is modeled on. It is source-available under the ",[22,377,380],{"href":378,"rel":379},"https:\u002F\u002Fgithub.com\u002Fconfluentinc\u002Fkafka-rest\u002Fblob\u002Fv8.3.0\u002FLICENSE",[26],"Confluent Community License",", which allows production use but not offering it as a competing hosted service; it is not an OSI-approved open source license.",[10,383,384],{},[188,385,386],{},"Capabilities and limitations",[182,388,389,413,436,460],{},[185,390,391,394,395,398,399,398,402,398,405,408,409,412],{},[188,392,393],{},"v2 API:"," Produces to topics and partitions and runs consumer instances with subscription, manual assignment, seek, commit, and fetch endpoints. The embedded formats are ",[14,396,397],{},"json",", ",[14,400,401],{},"binary",[14,403,404],{},"avro",[14,406,407],{},"protobuf",", and ",[14,410,411],{},"jsonschema","; with the last three, the proxy registers or looks up the schema in Schema Registry and writes records in the Confluent wire format.",[185,414,415,418,419,422,423,427,428,431,432,435],{},[188,416,417],{},"v3 API:"," Adds cluster administration (topics, configs, ACLs, consumer groups) and a produce endpoint, ",[14,420,421],{},"POST \u002Fv3\u002Fclusters\u002F{cluster_id}\u002Ftopics\u002F{topic_name}\u002Frecords",", which can stream records over one connection. It has no consume endpoints, so HTTP consumers still use v2. ",[22,424,426],{"href":203,"rel":425},[26],"Confluent's reference"," warns that \"the v3 Produce API returns HTTP 200 even when individual records fail validation.\" Check the HTTP status for request-level errors, then the ",[14,429,430],{},"error_code"," in each delivery report: ",[14,433,434],{},"200"," means that record was written.",[185,437,438,441,442,447,448,453,454,459],{},[188,439,440],{},"Authentication:"," ",[22,443,446],{"href":444,"rel":445},"https:\u002F\u002Fdocs.confluent.io\u002Fplatform\u002F8.3\u002Fkafka-rest\u002Fproduction-deployment\u002Frest-proxy\u002Fsecurity.html",[26],"HTTP clients can authenticate"," with Basic, mutual TLS, or ",[22,449,452],{"href":450,"rel":451},"https:\u002F\u002Fdocs.confluent.io\u002Fplatform\u002F8.3\u002Fsecurity\u002Fauthentication\u002Foauth-oidc\u002Fconfigure-rest-proxy.html",[26],"OAuth\u002FOIDC",". OAuth\u002FOIDC uses Confluent's ",[22,455,458],{"href":456,"rel":457},"https:\u002F\u002Fdocs.confluent.io\u002Fplatform\u002F8.3\u002Fconfluent-security-plugins\u002Fkafka-rest.html",[26],"security plugins",", which require an Enterprise license (a trial is available). Authenticating the HTTP caller and authenticating the proxy's Kafka connections are separate settings. Basic authentication alone does not propagate the caller's identity to Kafka ACLs; principal propagation requires the Enterprise security plugin.",[185,461,462,465,466,469,470,473,474,477],{},[188,463,464],{},"Upgrading from before 8.0:"," Check HTTPS host name handling after the move to Jetty 12 (the check can be turned off with ",[14,467,468],{},"sni.host.check.enabled=false","), and update the HTTP Basic JAAS module to ",[14,471,472],{},"org.eclipse.jetty.security.jaas.spi.PropertyFileLoginModule",". For schema-based formats, null key or value data is now validated against the supplied schema; set ",[14,475,476],{},"null.request.body.always.publishes.empty.record=true"," to restore the previous behavior.",[10,479,480],{},[188,481,482],{},"When to choose Confluent REST Proxy",[10,484,485],{},"Choose Confluent REST Proxy if you run Confluent Platform, need the v3 API, or want the reference implementation of the v2 API with Avro, Protobuf, and JSON Schema serialization. Choose another proxy if you need an OSI-approved license, or per-caller Kafka identity without an Enterprise license.",[367,487,33],{"id":488},"karapace",[10,490,491,494],{},[22,492,33],{"href":31,"rel":493},[26]," is Aiven's implementation of both Schema Registry and REST Proxy, written in Python and licensed under Apache 2.0. It describes itself as a \"drop-in replacement both on pre-existing Schema Registry \u002F Kafka Rest Proxy client and server-sides\", and Aiven runs it for its own managed Kafka service.",[10,496,497],{},[188,498,386],{},[182,500,501,507,513,525],{},[185,502,503,506],{},[188,504,505],{},"API:"," Implements the Confluent v2 API for producing, consumer instances, and metadata.",[185,508,509,512],{},[188,510,511],{},"Schema Registry:"," Avro, Protobuf, and JSON Schema formats serialize through a configured Schema Registry endpoint. The REST proxy and Schema Registry can be enabled independently.",[185,514,515,517,518,520,521,524],{},[188,516,440],{}," With ",[14,519,320],{}," enabled, Karapace uses each caller's ",[14,522,523],{},"Authorization"," header for that caller's Kafka connection. Basic credentials use the configured SASL mechanism, such as PLAIN or SCRAM; Bearer tokens use SASL OAUTHBEARER. Kafka validates the JWT and enforces ACLs; Karapace reads the token's expiry to manage its client connections.",[185,526,527,530,531,536],{},[188,528,529],{},"OAuth sessions:"," Karapace ",[22,532,535],{"href":533,"rel":534},"https:\u002F\u002Fgithub.com\u002FAiven-Open\u002Fkarapace\u002Fblob\u002F6.2.3\u002FREADME.rst#token-expiry",[26],"removes the clients tied to a token before it expires",". Before that cleanup, commit processed offsets and delete the existing consumer using the current token, then refresh the token and recreate the consumer.",[10,538,539],{},[188,540,541],{},"When to choose Karapace",[10,543,544],{},"Choose Karapace if you want the Confluent v2 API with Schema Registry serialization under the Apache 2.0 license, or per-caller Kafka ACLs without an Enterprise license. Choose Confluent REST Proxy if you need the v3 API.",[367,546,39],{"id":547},"strimzi-kafka-bridge",[10,549,550,553,554,559,560,563],{},[22,551,39],{"href":37,"rel":552},[26]," is the Strimzi project's HTTP bridge for Kafka, written in Java and licensed under Apache 2.0. Its HTTP API is published as an ",[22,555,558],{"href":556,"rel":557},"https:\u002F\u002Fstrimzi.io\u002Fdocs\u002Fbridge\u002Flatest\u002F",[26],"OpenAPI specification"," that the bridge also serves at ",[14,561,562],{},"GET \u002Fopenapi",".",[10,565,566],{},[188,567,386],{},[182,569,570,585,594,610,616],{},[185,571,572,574,575,398,578,398,581,584],{},[188,573,505],{}," The paths and media types resemble Confluent v2 (",[14,576,577],{},"POST \u002Ftopics\u002F{topic}",[14,579,580],{},"POST \u002Fconsumers\u002F{group}",[14,582,583],{},"application\u002Fvnd.kafka.json.v2+json","), but the APIs are not interchangeable: Strimzi does not expose Confluent's endpoint for reading a consumer's committed offsets. CORS can be enabled for browser clients.",[185,586,587,590,591,593],{},[188,588,589],{},"Deployment:"," Many people meet it as the ",[14,592,110],{}," custom resource that the Strimzi Operator deploys on Kubernetes, but the bridge is a standalone Java application. You can also download the archive and run it on a host, or run its container image yourself.",[185,595,596,441,599,398,601,408,603,606,607,609],{},[188,597,598],{},"Formats:",[14,600,397],{},[14,602,401],{},[14,604,605],{},"text",", with no built-in Schema Registry serialization. A client can serialize a record with a Schema Registry serializer, Base64-encode the resulting bytes, and send them using the ",[14,608,401],{}," format; the bridge forwards those bytes to Kafka. That is a workaround, not Schema Registry support: the client needs a serializer and registry access, which is often what you were trying to avoid by using HTTP.",[185,611,612,615],{},[188,613,614],{},"Security:"," The bridge can serve HTTPS, but it does not authenticate HTTP clients. Add authentication through a reverse proxy or API gateway; network policies and firewalls can restrict network access. Connections from the bridge to Kafka support TLS and SASL.",[185,617,618,621,622,625],{},[188,619,620],{},"Observability:"," Supports OpenTelemetry tracing and Prometheus metrics at ",[14,623,624],{},"\u002Fmetrics",", both enabled through configuration.",[10,627,628],{},[188,629,630],{},"When to choose Strimzi Kafka Bridge",[10,632,633],{},"Choose Strimzi Kafka Bridge if you already use the Strimzi Operator and need HTTP produce and consume with JSON, text, or binary payloads. Choose Karapace or Confluent REST Proxy if you need built-in Schema Registry serialization or per-caller Kafka identities.",[367,635,637],{"id":636},"redpanda-http-proxy-pandaproxy","Redpanda HTTP Proxy (Pandaproxy)",[10,639,640,645,646,649,650,653,654,659,660,665],{},[22,641,644],{"href":642,"rel":643},"https:\u002F\u002Fgithub.com\u002Fredpanda-data\u002Fredpanda",[26],"Redpanda"," builds an HTTP proxy into its brokers, configured in the ",[14,647,648],{},"pandaproxy"," section of ",[14,651,652],{},"redpanda.yaml",". On self-managed Redpanda, ",[22,655,658],{"href":656,"rel":657},"https:\u002F\u002Fdocs.redpanda.com\u002Fstreaming\u002Fcurrent\u002Fdevelop\u002Fhttp-proxy\u002F",[26],"it listens on port 8082 by default",". On ",[22,661,664],{"href":662,"rel":663},"https:\u002F\u002Fdocs.redpanda.com\u002Fcloud-data-platform\u002Fdevelop\u002Fhttp-proxy\u002F",[26],"Redpanda Cloud",", it is available on BYOC and Dedicated clusters, not Serverless, and its address comes from the cluster's connection details.",[10,667,668],{},[188,669,386],{},[182,671,672,691,704,709,714],{},[185,673,674,676,677,682,683,686,687,690],{},[188,675,505],{}," Uses Confluent v2 paths and media types to list topics and brokers, produce, and run consumer groups with subscribe, fetch, and commit. The consumer API is a subset of v2: ",[22,678,681],{"href":679,"rel":680},"https:\u002F\u002Fdocs.redpanda.com\u002Fapi\u002Fdoc\u002Fhttp-proxy\u002Foperation\u002Foperation-create_consumer",[26],"creating a consumer"," accepts only ",[14,684,685],{},"\"auto.offset.reset\": \"earliest\""," and ",[14,688,689],{},"\"auto.commit.enable\": \"false\"",", so clients must commit offsets explicitly.",[185,692,693,441,696,703],{},[188,694,695],{},"Direct partition reads:",[22,697,700],{"href":698,"rel":699},"https:\u002F\u002Fdocs.redpanda.com\u002Fstreaming\u002Fcurrent\u002Fdevelop\u002Fhttp-proxy\u002F#get-events-from-a-topic",[26],[14,701,702],{},"GET \u002Ftopics\u002F{topic}\u002Fpartitions\u002F{partition}\u002Frecords?offset=0&timeout=1000&max_bytes=100000"," reads from an explicit offset without creating a consumer instance. The caller tracks its own progress; this is separate from the consumer-group subscribe and commit APIs.",[185,705,706,708],{},[188,707,598],{}," JSON and binary, with no built-in Schema Registry serialization. Schema-encoded records must be serialized by the client and sent as Base64-encoded binary data.",[185,710,711,713],{},[188,712,440],{}," HTTP Basic with SCRAM credentials, or OIDC Bearer tokens; OIDC requires an Enterprise license on self-managed Redpanda. Authenticated callers are subject to their Kafka ACLs.",[185,715,716,719,720,563],{},[188,717,718],{},"Consumer timeout:"," Consumer instances expire after five minutes of inactivity by default, configurable through ",[14,721,722],{},"pandaproxy.consumer_instance_timeout_ms",[10,724,725],{},[188,726,727],{},"When to choose Redpanda HTTP Proxy",[10,729,730],{},"If you already run self-managed Redpanda or a Redpanda Cloud BYOC or Dedicated cluster, start with its built-in HTTP Proxy before deploying a separate proxy.",[367,732,136],{"id":733},"confluent-cloud-rest-api",[10,735,736,741,742,747],{},[22,737,740],{"href":738,"rel":739},"https:\u002F\u002Fwww.confluent.io\u002Fconfluent-cloud\u002F",[26],"Confluent Cloud"," hosts a ",[22,743,746],{"href":744,"rel":745},"https:\u002F\u002Fdocs.confluent.io\u002Fcloud\u002Fcurrent\u002Fkafka-rest\u002Fkafka-rest-cc.html",[26],"Kafka REST API v3"," on its clusters, so you can produce over HTTPS without running a proxy. Authenticate with a cluster API key over HTTP Basic, preferably one owned by a service account, or with OAuth 2.0.",[10,749,750],{},[188,751,386],{},[182,753,754,772,789,801],{},[185,755,756,441,759,398,764,767,768,431,770,435],{},[188,757,758],{},"Produce:",[22,760,763],{"href":761,"rel":762},"https:\u002F\u002Fdocs.confluent.io\u002Fcloud\u002Fcurrent\u002Fccloud\u002Fproduce-record\u002F",[26],"Produce Records",[14,765,766],{},"POST \u002Fkafka\u002Fv3\u002Fclusters\u002F{cluster_id}\u002Ftopics\u002F{topic_name}\u002Frecords",", is generally available and supports a streaming mode over one connection. Check the HTTP status for request-level errors, then the ",[14,769,430],{},[14,771,434],{},[185,773,774,441,776,398,779,408,782,785,786,788],{},[188,775,598],{},[14,777,778],{},"BINARY",[14,780,781],{},"JSON",[14,783,784],{},"STRING",", with no built-in Schema Registry serialization. Schema-encoded records must be serialized by the client and sent as Base64-encoded ",[14,787,778],{}," data.",[185,790,791,794,795,800],{},[188,792,793],{},"Consume:"," As of 3 Oct 2026, the published API reference documents record production but no record-consumption endpoint. Consumer-group and lag endpoints return metadata, not topic records. ",[22,796,799],{"href":797,"rel":798},"https:\u002F\u002Fdocs.confluent.io\u002Fcloud\u002Fcurrent\u002Fsecurity\u002Fauthenticate\u002Fworkload-identities\u002Fservice-accounts\u002Fmanage-service-accounts.html",[26],"Some guides"," show consume examples, but those routes are absent from the API reference.",[185,802,803,806],{},[188,804,805],{},"Admin:"," Topics, configs, ACLs, Cluster Linking, and consumer-group metadata; the lag endpoints are documented as Dedicated-only.",[10,808,809],{},[188,810,811],{},"When to choose Confluent Cloud REST API",[10,813,814],{},"Use the hosted API when you need to produce to Confluent Cloud over HTTPS without operating a proxy. For HTTP consumption or built-in Schema Registry serialization, use a self-managed REST proxy connected to the cluster. If HTTP is not required, use a native Kafka client for consumption.",[42,816,818],{"id":817},"declarative-http-gateways-zilla-and-gravitee","Declarative HTTP gateways: Zilla and Gravitee",[10,820,821],{},"The proxies above expose Kafka's own concepts: topics, partitions, consumer instances, offsets. A gateway lets you design the HTTP API your application needs and maps it onto Kafka.",[182,823,824,832],{},[185,825,826,831],{},[22,827,830],{"href":828,"rel":829},"https:\u002F\u002Fgithub.com\u002Faklivity\u002Fzilla",[26],"Zilla"," from Aklivity is configured in YAML. You declare HTTP routes and how each maps to topics, keys, and headers, and it can serve topics as Server-Sent Events streams. Zilla mixes Apache 2.0 components with modules under the Aklivity Community License 1.0, including its HTTP–Kafka and SSE–Kafka bindings. The community license permits production use but excludes providing hosted services that compete with Aklivity's offerings.",[185,833,834,839],{},[22,835,838],{"href":836,"rel":837},"https:\u002F\u002Fdocumentation.gravitee.io\u002Fapim\u002Fcreate-and-configure-apis\u002Fconfigure-v4-apis\u002Fendpoints\u002Fkafka",[26],"Gravitee"," API Management can put HTTP POST, HTTP GET, WebSocket, SSE, and webhook entrypoints in front of a Kafka endpoint. These message APIs are an Enterprise Edition feature.",[10,841,842,843,846],{},"Choose a gateway when clients need an application-specific API, such as ",[14,844,845],{},"POST \u002Forders",", with routes mapped to Kafka topics. Choose a REST proxy when clients need a general-purpose API that exposes Kafka topics, partitions, records, and consumer operations.",[42,848,850],{"id":849},"consumer-instances-routing-timeouts-and-recovery","Consumer instances: routing, timeouts, and recovery",[10,852,853],{},"Suppose your service creates a consumer through proxy A and then fetches records from it over HTTP. That consumer lives in proxy A's process. If a load balancer sends the next request to proxy B, B has no such consumer and returns 404. If proxy A restarts, the consumer is gone and must be created again. A native Kafka client keeps this state in your own process; a REST proxy keeps it on the instance that created it. Three things follow.",[10,855,856,859,860,863,864,868],{},[188,857,858],{},"Send every request for a consumer to the same instance."," Producer requests can go to any instance. Use the returned ",[14,861,862],{},"base_uri"," for subsequent consumer requests. If that URI points to a load balancer, configure session affinity so requests reach the instance that created the consumer. ",[22,865,867],{"href":556,"rel":866},[26],"Strimzi"," leaves this affinity to the client application.",[10,870,871,874],{},[188,872,873],{},"Detect a lost consumer and recreate it."," Idle cleanup and proxy restarts both destroy consumer instances. Confluent and Redpanda remove idle consumers after five minutes by default; Karapace and Strimzi disable idle cleanup by default. Fetch more often than the idle timeout. On a consumer-not-found response, first check routing and session affinity. If the consumer has expired or its proxy has restarted, recreate it in the same group and restore its subscription. Delete consumers explicitly when your service shuts down.",[10,876,877,880],{},[188,878,879],{},"Commit after processing, and expect redelivery."," Session affinity cannot bring back a destroyed consumer. What survives is the group's committed offsets in Kafka: a recreated consumer in the same group resumes from those offsets, provided they have not expired and remain within each partition's valid offset range. Disable auto-commit and commit after processing; records that were processed but not committed before the loss may be delivered again, so make processing idempotent. (With Redpanda's direct partition reads, there is no consumer instance to lose, but your application must store the next offset for each partition.)",[42,882,884],{"id":883},"github-repository-metrics","GitHub repository metrics",[10,886,887],{},"The tables below compare the GitHub activity, maintenance, and public interest of the three proxies. Snapshot: 2 Oct 2026.",[10,889,890,891,895],{},"Redpanda's HTTP Proxy lives in the ",[22,892,894],{"href":642,"rel":893},[26],"Redpanda monorepo",", which measures the broker rather than the proxy, so it is not included. The Karapace repository also contains its Schema Registry, so its figures cover both components.",[367,897,899],{"id":898},"project-overview","Project overview",[47,901,902,923],{},[50,903,904],{},[53,905,906,908,913,918],{},[56,907],{},[56,909,910],{},[22,911,27],{"href":24,"rel":912},[26],[56,914,915],{},[22,916,33],{"href":31,"rel":917},[26],[56,919,920],{},[22,921,39],{"href":37,"rel":922},[26],[66,924,925,939,952],{},[53,926,927,930,933,936],{},[71,928,929],{},"Repository created",[71,931,932],{},"19 Nov 2014",[71,934,935],{},"7 Jan 2019",[71,937,938],{},"21 Mar 2016",[53,940,941,944,947,950],{},[71,942,943],{},"License",[71,945,946],{},"Confluent Community License 1.0",[71,948,949],{},"Apache-2.0",[71,951,949],{},[53,953,954,957,960,962],{},[71,955,956],{},"Repository status",[71,958,959],{},"Not archived · original",[71,961,959],{},[71,963,959],{},[367,965,967],{"id":966},"activity","Activity",[47,969,970,992],{},[50,971,972],{},[53,973,974,977,982,987],{},[56,975,976],{},"Metric",[56,978,979],{},[22,980,27],{"href":24,"rel":981},[26],[56,983,984],{},[22,985,33],{"href":31,"rel":986},[26],[56,988,989],{},[22,990,39],{"href":37,"rel":991},[26],[66,993,994,1008,1022,1036,1050,1064,1078],{},[53,995,996,999,1002,1005],{},[71,997,998],{},"Latest default-branch commit",[71,1000,1001],{},"26 Sep 2026",[71,1003,1004],{},"2 Oct 2026",[71,1006,1007],{},"1 Oct 2026",[53,1009,1010,1013,1016,1019],{},[71,1011,1012],{},"Latest GitHub Release",[71,1014,1015],{},"—",[71,1017,1018],{},"6.2.3 (15 Sep 2026)",[71,1020,1021],{},"1.2.0 (1 Oct 2026)",[53,1023,1024,1027,1030,1033],{},[71,1025,1026],{},"GitHub Releases (12 mo)",[71,1028,1029],{},"0",[71,1031,1032],{},"15",[71,1034,1035],{},"6",[53,1037,1038,1041,1044,1047],{},[71,1039,1040],{},"Commits",[71,1042,1043],{},"1,194 (90 d) · 3,934 (12 mo)",[71,1045,1046],{},"50 (90 d) · 210 (12 mo)",[71,1048,1049],{},"44 (90 d) · 127 (12 mo)",[53,1051,1052,1055,1058,1061],{},[71,1053,1054],{},"Issue flow (90 d)",[71,1056,1057],{},"0 opened · 0 closed",[71,1059,1060],{},"6 opened · 2 closed",[71,1062,1063],{},"3 opened · 4 closed",[53,1065,1066,1069,1072,1075],{},[71,1067,1068],{},"PR flow (90 d)",[71,1070,1071],{},"24 opened · 18 merged",[71,1073,1074],{},"51 opened · 22 merged",[71,1076,1077],{},"45 opened · 44 merged",[53,1079,1080,1083,1086,1089],{},[71,1081,1082],{},"Activity assessment",[71,1084,1085],{},"🟢 18 merged PRs in the last 90 days.",[71,1087,1088],{},"🟢 50 commits and 22 merged PRs in the last 90 days.",[71,1090,1091],{},"🟢 44 commits and 44 merged PRs in the last 90 days.",[10,1093,1094,1095,1098,1099,1102,1103,1106],{},"Confluent ships REST Proxy as part of Confluent Platform rather than through GitHub Releases. Its commit count is inflated by automated merges that carry each change forward through every maintained release branch (",[14,1096,1097],{},"7.6.x"," into ",[14,1100,1101],{},"7.7.x",", and so on up to ",[14,1104,1105],{},"master","); merged PRs are the better activity signal.",[367,1108,1110],{"id":1109},"maintenance","Maintenance",[47,1112,1113,1134],{},[50,1114,1115],{},[53,1116,1117,1119,1124,1129],{},[56,1118,976],{},[56,1120,1121],{},[22,1122,27],{"href":24,"rel":1123},[26],[56,1125,1126],{},[22,1127,33],{"href":31,"rel":1128},[26],[56,1130,1131],{},[22,1132,39],{"href":37,"rel":1133},[26],[66,1135,1136,1150,1164,1178,1192,1206,1220,1232,1246],{},[53,1137,1138,1141,1144,1147],{},[71,1139,1140],{},"Active commit authors (12 mo)",[71,1142,1143],{},"17",[71,1145,1146],{},"21",[71,1148,1149],{},"18",[53,1151,1152,1155,1158,1161],{},[71,1153,1154],{},"PR merge distribution (12 mo)",[71,1156,1157],{},"17 accounts · Top 1: 21% · Top 2: 40%",[71,1159,1160],{},"10 accounts · Top 1: 26% · Top 2: 43%",[71,1162,1163],{},"6 accounts · Top 1: 88% · Top 2: 92%",[53,1165,1166,1169,1172,1175],{},[71,1167,1168],{},"Issue backlog",[71,1170,1171],{},"238 open · median age 7.7 y",[71,1173,1174],{},"70 open · median age 2.3 y",[71,1176,1177],{},"14 open · median age 6 y",[53,1179,1180,1183,1186,1189],{},[71,1181,1182],{},"Issue closure rate",[71,1184,1185],{},"N\u002FA — no issues in the measured cohort",[71,1187,1188],{},"1\u002F7 closed within 30 d · 1\u002F7 within 90 d",[71,1190,1191],{},"1\u002F6 closed within 30 d · 2\u002F6 within 90 d",[53,1193,1194,1197,1200,1203],{},[71,1195,1196],{},"PR backlog",[71,1198,1199],{},"38 open · median age 3.6 y",[71,1201,1202],{},"24 open · median age 172 d",[71,1204,1205],{},"0 open PRs",[53,1207,1208,1211,1214,1217],{},[71,1209,1210],{},"Median PR merge time (90 d)",[71,1212,1213],{},"17.6 h (n=18)",[71,1215,1216],{},"1.8 d (n=22)",[71,1218,1219],{},"3.4 h (n=44)",[53,1221,1222,1225,1227,1230],{},[71,1223,1224],{},"Published GitHub security advisories",[71,1226,1029],{},[71,1228,1229],{},"2 (fixed in 5.0.2 and 6.0.0)",[71,1231,1029],{},[53,1233,1234,1237,1240,1243],{},[71,1235,1236],{},"Backlog and closure assessment",[71,1238,1239],{},"🟡 For the 18 PRs merged in the last 90 d, the median creation-to-merge time was 17.6 h; 38 open PRs have a median age of 3.6 y.",[71,1241,1242],{},"🔴 1 of 7 issues in the cohort (14%) closed within 90 d; small sample.",[71,1244,1245],{},"🟡 2 of 6 issues in the cohort (33%) closed within 90 d; small sample.",[53,1247,1248,1251,1254,1257],{},[71,1249,1250],{},"PR merge concentration assessment",[71,1252,1253],{},"🟢 17 accounts merged PRs in 12 mo; the most active account handled 21% of attributed merges.",[71,1255,1256],{},"🟢 10 accounts merged PRs in 12 mo; the most active account handled 26% of attributed merges.",[71,1258,1259],{},"🟡 6 accounts merged PRs in 12 mo; the most active account handled 88% of attributed merges.",[10,1261,1262],{},"PR merge distribution counts non-bot merge accounts, with percentages calculated over merges attributed to those accounts. It does not measure reviewer or maintainer headcount. Median PR merge time measures creation to merge for PRs merged in the last 90 days; unmerged PRs are excluded. Issue closure rates use issues opened 90–180 days before the snapshot, giving each issue a full 90-day window. These figures cover public GitHub issues and exclude commercial support channels.",[367,1264,1266],{"id":1265},"public-interest","Public interest",[47,1268,1269,1290],{},[50,1270,1271],{},[53,1272,1273,1275,1280,1285],{},[56,1274,976],{},[56,1276,1277],{},[22,1278,27],{"href":24,"rel":1279},[26],[56,1281,1282],{},[22,1283,33],{"href":31,"rel":1284},[26],[56,1286,1287],{},[22,1288,39],{"href":37,"rel":1289},[26],[66,1291,1292,1306],{},[53,1293,1294,1297,1300,1303],{},[71,1295,1296],{},"Stars",[71,1298,1299],{},"165",[71,1301,1302],{},"637",[71,1304,1305],{},"342",[53,1307,1308,1311,1314,1317],{},[71,1309,1310],{},"Forks",[71,1312,1313],{},"658",[71,1315,1316],{},"112",[71,1318,1319],{},"141",[10,1321,1322],{},"Stars and forks measure interest, not use.",[367,1324,1326],{"id":1325},"overall-repository-signals","Overall repository signals",[182,1328,1329,1334,1339],{},[185,1330,1331,1333],{},[188,1332,27],{}," has the most accounts merging PRs, 17 in 12 months. For the 18 PRs merged in the last 90 days, the median creation-to-merge time was 17.6 hours. Its open backlog is old: 238 issues with a median age of 7.7 years and 38 PRs with a median age of 3.6 years.",[185,1335,1336,1338],{},[188,1337,33],{}," releases most often, 15 GitHub releases in 12 months, but those releases also cover its Schema Registry. Only 1 of 7 issues in the measured cohort was closed within 90 days.",[185,1340,1341,1343],{},[188,1342,39],{}," has no open PRs and the fastest median merge time, 3.4 hours, but one account handled 88% of attributed merges in the past year.",[10,1345,1346],{},"These are repository activity, maintenance, and public-interest signals, not evidence of runtime quality or feature fit.",[42,1348,1350],{"id":1349},"test-kafka-rest-proxies-with-kafma","Test Kafka REST proxies with Kafma",[367,1352,1354],{"id":1353},"check-what-the-proxy-stored","Check what the proxy stored",[10,1356,1357,1358,1360],{},"Even a successfully produced record may contain bytes that differ from the consumer's expected format: a payload Base64-encoded twice is stored as Base64 text, and Avro bytes sent through ",[14,1359,401],{}," without the Confluent prefix fail in consumers that expect it.",[10,1362,1363,1364,1368,1369,1372,1373,1377],{},"Kafma's ",[22,1365,1367],{"href":1366},"\u002Ffeatures\u002Fkafka-console","Kafka console"," shows the record as Kafka stores it. ",[188,1370,1371],{},"Raw"," shows the exact bytes in hexadecimal, and with a Confluent-compatible Schema Registry connection, ",[22,1374,1376],{"href":1375},"\u002Fdocs\u002Fconsole\u002Fdecoding-messages","automatic decoding"," reads the schema ID from the record and shows the decoded value.",[10,1379,1380,1381,1384,1385,1387],{},"This matters most with Strimzi, Redpanda, and Confluent Cloud, which have no built-in Schema Registry serialization. The client serializes the value with a Confluent-compatible Schema Registry serializer (which adds the prefix), Base64-encodes the bytes once, and sends them as binary. A value written this way shows magic byte ",[14,1382,1383],{},"0x00"," and the 4-byte schema ID at the start of ",[188,1386,1371],{},", and decoding shows the expected value.",[10,1389,1390],{},[1391,1392],"img",{"alt":1393,"height":1394,"src":1395,"width":1396},"A decoded Avro record with its schema ID and metadata in Kafma",1204,"https:\u002F\u002Fmedia.kafma.app\u002Fchangelog\u002Fv1.0.0\u002Fhomepage-console-decode.png",2428,[367,1398,1400],{"id":1399},"see-where-an-http-consumer-will-resume","See where an HTTP consumer will resume",[10,1402,1403,1404,1408],{},"A consumer recreated in the same group starts from the group's committed offsets, if they are still valid. The proxy may not show them: Strimzi has no endpoint for them, and Confluent's requires a live consumer instance. Kafma's ",[22,1405,1407],{"href":1406},"\u002Ffeatures\u002Fkafka-consumer-groups","consumer group UI"," shows each partition's committed offset, lag, and assignment.",[10,1410,1411],{},[1391,1412],{"alt":1413,"height":1414,"src":1415,"width":1416},"Kafka consumer group details showing state, members, topic assignments, committed offsets, and lag",1312,"https:\u002F\u002Fmedia.kafma.app\u002Fdocs\u002Fconsumer-groups\u002Foverview\u002Fconsumer-group-details.png",1560,[10,1418,1419],{},"Auto-commit can commit offsets for records your application has not processed yet, so a lost consumer may skip them. Disable it when you create the consumer. In a test group with a single consumer, the committed offsets in Kafma should then move only after your application commits.",[10,1421,1422,1426],{},[22,1423,1425],{"href":1424},"\u002Fdocs\u002Fconsole\u002Fconsuming-messages#live-and-watch-group-modes","Watch Group"," marks the records around those positions as consumed or pending. Kafma reads this without joining the group, so it does not disturb the HTTP consumers. These labels reflect committed offsets, not whether application processing succeeded.",[10,1428,1429],{},[1391,1430],{"alt":1431,"height":1432,"src":1433,"width":1434},"Kafma Watch Group marking consumed and pending records around a consumer group's committed offsets",1056,"https:\u002F\u002Fmedia.kafma.app\u002Fblog\u002Fkafka-rest-proxy\u002Fwatch-group.png",1722,[367,1436,1438],{"id":1437},"move-offsets-before-recreating-consumers","Move offsets before recreating consumers",[10,1440,1441],{},"Sometimes you need a different starting position: to skip a record that keeps failing, or to process a range again. Recreating the consumer does not help, because it resumes from the same committed offsets.",[1443,1444,1445,1461,1464],"ol",{},[185,1446,1447,1448,1451,1452,1455,1456,1460],{},"Stop all applications using the group, delete their HTTP consumer instances, and wait for the group to become ",[188,1449,1450],{},"Empty"," or ",[188,1453,1454],{},"Dead",". Kafma enables ",[22,1457,1459],{"href":1458},"\u002Fdocs\u002Fconsumer-groups\u002Freset-offsets","Reset Offsets"," only then, so no running member can commit over the change.",[185,1462,1463],{},"Reset the offsets to the earliest or latest offset, a timestamp, a specific offset, or by a relative amount.",[185,1465,1466],{},"Recreate the HTTP consumers in the same group and restore their subscriptions. They start from the new offsets.",[10,1468,1469,1473],{},[22,1470,1472],{"href":1471},"\u002Fdownload","Download Kafma"," and connect it to the cluster behind your proxy.",[42,1475,1477],{"id":1476},"frequently-asked-questions","Frequently asked questions",[367,1479,168],{"id":1480},"does-kafka-have-a-rest-api-1",[10,1482,1483,1484,563],{},"Not for producing or consuming records. Kafka Connect has a REST API, but it manages connectors and tasks. Producing and consuming over HTTP needs a proxy; see ",[22,1485,168],{"href":1486},"#does-kafka-have-a-rest-api",[367,1488,1490],{"id":1489},"what-is-the-difference-between-the-v2-and-v3-rest-proxy-apis","What is the difference between the v2 and v3 REST Proxy APIs?",[10,1492,1493,1494,563],{},"v2 produces and consumes, with Schema Registry formats. v3 produces and administers the cluster but has no consume endpoints. See ",[22,1495,27],{"href":78},[367,1497,1499],{"id":1498},"can-a-rest-proxy-consume-messages","Can a REST proxy consume messages?",[10,1501,1502,1503,1506],{},"Yes. Consumer-instance APIs keep state in one proxy process, so plan for session affinity, idle timeouts, and restarts; see ",[22,1504,850],{"href":1505},"#consumer-instances-routing-timeouts-and-recovery",". Redpanda's HTTP Proxy also provides direct partition reads, where the caller supplies the offset without first creating a consumer instance.",[367,1508,1510],{"id":1509},"is-karapace-a-drop-in-replacement-for-confluent-rest-proxy","Is Karapace a drop-in replacement for Confluent REST Proxy?",[10,1512,1513,1514,1516],{},"For the Confluent v2 API, that is its stated goal. Test the endpoints and formats you use. It does not implement Confluent's commercial security plugins; with ",[14,1515,320],{}," enabled, it forwards each caller's credentials to Kafka instead.",[367,1518,1520],{"id":1519},"is-kafka-pixy-still-maintained","Is Kafka-Pixy still maintained?",[10,1522,1523,1524,1529],{},"The repository appears inactive. ",[22,1525,1528],{"href":1526,"rel":1527},"https:\u002F\u002Fgithub.com\u002Fmailgun\u002Fkafka-pixy",[26],"Kafka-Pixy",", Mailgun's gRPC and REST proxy, tagged its last release, v0.18.0, in July 2021, and its default branch has had no commits since July 2022. It manages consumer-group membership through ZooKeeper, so it is not suitable for KRaft-only clusters, including Kafka 4.0 and later.",[367,1531,1533],{"id":1532},"what-happened-to-upstash-kafkas-rest-api","What happened to Upstash Kafka's REST API?",[10,1535,1536,1537,1542],{},"Upstash ",[22,1538,1541],{"href":1539,"rel":1540},"https:\u002F\u002Fupstash.com\u002Fblog\u002Fworkflow-kafka",[26],"announced the deprecation of Upstash Kafka on 6 September 2024",". The announcement said it was no longer accepting new users and would discontinue support in six months. It did not specify an exact shutdown date. Upstash Kafka is therefore not an option for a new deployment; existing integrations should follow the provider's migration guidance.",[42,1544,1546],{"id":1545},"conclusion","Conclusion",[10,1548,1549],{},"If you run Confluent Platform or need the v3 API, start with Confluent REST Proxy and accept its source-available license. If you need the v2 API with Avro, Protobuf, or JSON Schema serialization under Apache 2.0, choose Karapace; test the endpoints you depend on. If you already use the Strimzi Operator and need JSON, text, or binary payloads, choose Strimzi Kafka Bridge, with a reverse proxy or API gateway for HTTP client authentication.",[10,1551,1552],{},"When you use a consumer-instance API, commit after processing and be ready to recreate the consumer. With direct partition reads, persist the next offset for each partition in your own application. To check what your proxy wrote and where its consumers will resume, use Kafma alongside it.",[10,1554,1555],{},"This guide is maintained by the team behind Kafma.",{"title":1557,"searchDepth":1558,"depth":1558,"links":1559},"",3,[1560,1562,1563,1570,1571,1572,1579,1584,1592],{"id":44,"depth":1561,"text":45},2,{"id":167,"depth":1561,"text":168},{"id":209,"depth":1561,"text":210,"children":1564},[1565,1566,1567,1568,1569],{"id":369,"depth":1558,"text":27},{"id":488,"depth":1558,"text":33},{"id":547,"depth":1558,"text":39},{"id":636,"depth":1558,"text":637},{"id":733,"depth":1558,"text":136},{"id":817,"depth":1561,"text":818},{"id":849,"depth":1561,"text":850},{"id":883,"depth":1561,"text":884,"children":1573},[1574,1575,1576,1577,1578],{"id":898,"depth":1558,"text":899},{"id":966,"depth":1558,"text":967},{"id":1109,"depth":1558,"text":1110},{"id":1265,"depth":1558,"text":1266},{"id":1325,"depth":1558,"text":1326},{"id":1349,"depth":1561,"text":1350,"children":1580},[1581,1582,1583],{"id":1353,"depth":1558,"text":1354},{"id":1399,"depth":1558,"text":1400},{"id":1437,"depth":1558,"text":1438},{"id":1476,"depth":1561,"text":1477,"children":1585},[1586,1587,1588,1589,1590,1591],{"id":1480,"depth":1558,"text":168},{"id":1489,"depth":1558,"text":1490},{"id":1498,"depth":1558,"text":1499},{"id":1509,"depth":1558,"text":1510},{"id":1519,"depth":1558,"text":1520},{"id":1532,"depth":1558,"text":1533},{"id":1545,"depth":1561,"text":1546},"2026-10-03","Kafka has no REST API for records. Compare Confluent REST Proxy, Karapace, and Strimzi Kafka Bridge: auth, license, consumer recovery.","md",{},true,null,"\u002Fblog\u002Fkafka-rest-proxy",false,{"title":5,"description":1594},{"loc":1599},"blog\u002Fkafka-rest-proxy",[1605],"Kafka REST Proxy","RnLSf2HnUqK1KArb_NHRCx0fpcyiFv2P11DUq1cbWrM",1791030260160]