Skip to main content

Conduktor API overview

You can automate some of your tasks using our REST API. Conduktor offers the Console API and Gateway API, each used for managing different resources.
From our blog: Kafka automation platform: self-serve by policy Why manual provisioning turns platform teams into a ticket queue, and how policy-based automation gives them their time back.
The Conduktor HTTP API can be used to manage your organizations users, groups and their associated permissions. You can also use it to interact with Kafka resources such as clusters and certificates.Go to the API portal or /docs in your deployment host (e.g., http://localhost:8080/docs).Use the API portal to download the OpenAPI specification. You can then import it to tools such as Postman .

Manage API keys

In Console, go to Settings > API Keys to manage and create new keys. Click New Token and enter a unique name. When both token types are available, pick one:
  • API Key: always has admin access. Use it for automation, such as the Conduktor CLI. Only members of the admin group can generate API keys.
  • Personal Access Token: inherits your own permissions. Use it for personal integrations, such as a Model Context Protocol (MCP) client. It’s only available when the Conduktor MCP server is enabled.
Click Generate. You can then copy the token and use it as required.Save API keyMake sure to copy the key as it won’t be accessible when this window is closed.

Revoke API keys

To revoke a key, select it from the list and click the trash can icon. You’ll be prompted to confirm as this can’t be undone.

API key lifetime

  • Admin and application API keys don’t expire. They stay valid until you revoke them.
  • Keys don’t depend on the user who created them. An Admin API key keeps full permissions, even if its creator loses access to Console or is deleted.
  • An application instance can have several API keys. Deleting the application instance deletes its keys.
To rotate a key, generate a new one, update your clients, then revoke the old key.

Example

Here’s a sample request listing the permissions associated with group ‘project-a’: