Changelog

OAuth 2.0/OIDC authentication for Karapace Schema Registry

    New
    Aiven for Apache Kafka®

You can now use OAuth 2.0/OpenID Connect (OIDC) bearer tokens to authenticate requests to Karapace Schema Registry on Aiven for Apache Kafka®. Schema Registry validates JSON Web Tokens (JWTs) using the same OIDC provider settings as Apache Kafka.

You can also enable role-based authorization to control Schema Registry operations based on roles in the JWT. Enabling JWT authentication does not disable basic authentication, so you can migrate clients gradually and disable basic authentication after the migration is complete.

Requires Karapace 6.2.1 or later. Configure authentication and authorization in the Aiven Console or with the Aiven CLI.

For more information, see Enable OAuth 2.0/OIDC authentication for Aiven for Apache Kafka® Schema Registry.