Skip to content
Last updated

Confluent Cloud integration

Confluent Cloud is a fully managed data streaming platform built on Apache Kafka, with Schema Registry and Apache Flink for stream processing.

Agen.co connects to Confluent Cloud through Confluent's own hosted regional MCP server as an Official connector. The server authenticates with a Confluent Cloud API key, not OAuth, so there is no sign-in screen or callback URL. You build a Base64 credential from the key and paste it into Agen.co. What agents can see and do is limited by the permissions of that key.


Prerequisites

  • A Confluent Cloud account and its Organization ID.
  • A cluster in a region where Confluent Cloud for Apache Flink is available. Confluent only runs the regional MCP server in those regions. Confluent requires a payment method on the account before you can create a cluster.
  • A Global or Flink API key and secret, created in the same organization. Cloud API keys, Kafka cluster keys, and other resource-scoped keys are not accepted by the regional server.
  • A cluster reachable from the public internet. A public regional MCP server cannot reach private clusters.

Prepare the credentials

If you do not have a Confluent Cloud account, sign up at confluent.cloud and complete the registration form first.

Create an API key

Create one of these key types in Confluent Cloud, following Confluent's API key documentation:

  • Global API key — Confluent's recommended choice. One global key also works with Confluent's global MCP server.
  • Flink API key — scoped to a single cloud provider and region, so it works only with the regional server and only for that region. Create it under Flink → API keys → Add API Key, and select the same cloud provider and region you enter in Agen.co.

For production, create the key for a service account rather than a person, so the connector keeps working if that person leaves.

The secret is shown only once

Copy the API key and secret when Confluent shows them. The secret cannot be retrieved later. If you lose it, create a new key.

A key grants no access by itself. Confluent authorizes every call with the role bindings and ACLs of the account that owns the key, so grant that account access to the topics, Schema Registry subjects, and Flink resources your agents need, and nothing more.

Build the Base64 credential

Agen.co sends the key as HTTP Basic authentication, so the API key field takes the Base64 encoding of <key>:<secret>, not the bare key. In a terminal, run:

echo -n '<api_key>:<api_secret>' | base64

Use -n so no newline is encoded. Copy the output.

Find your Organization ID

In the Confluent Cloud Console, open the organization name above your user name in the sidebar. The Details page shows the Organization name and Organization ID. It must be the organization the API key belongs to.

Connect Confluent Cloud in Agen.co

  1. In the Agen.co portal, go to Connectors → My connectors and click Add connector.

  2. In the Select connector drawer, search for Confluent and select Confluent Cloud. The Add Confluent Cloud panel opens.

  3. Fill in the fields:

    FieldRequiredDescription
    Instance SlugYesNamespaces this instance — it prefixes each imported tool as slug__tool, so several instances of the same MCP can coexist. Prefilled with confluent. Use lowercase kebab-case. You can change it later from the connector's settings.
    RegionYesThe region code of the cloud region hosting your cluster, for example us-east-2. Must be a region where Confluent Cloud Flink is available.
    Cloud providerYesOne of aws (Amazon Web Services), gcp (Google Cloud Platform), or azure (Microsoft Azure). Defaults to aws.
    Organization IDYesYour Confluent Cloud organization ID. Must be the organization the API key belongs to.
    API keyYesThe Base64 of <key>:<secret> from the previous section. Agen.co sends it as HTTP Basic authentication.
  4. Click Connect. Agen.co connects to Confluent's MCP server with the key, and the panel switches to Select the tools to import from Confluent Cloud. Every tool is toggled on; turn off any you don't want to import, then click Add.

The connector is created and its tools imported only when you click Add. If you close the panel before that, nothing is saved.

One instance connects to one region, cloud provider, and organization. To connect another region or cloud, add Confluent Cloud again with a different Instance Slug and that region's values.

What it covers

This connector uses Confluent's regional MCP server. The server needs a key, so its tool list could not be queried unauthenticated; the areas below come from Confluent's MCP documentation (checked 2026-10-08), and the tool selection screen after Connect shows exactly what your key serves. Confluent states that most tools are read-only.

AreaWhat it covers
Topics and schemasList and describe Kafka topics, read sample messages, and read Schema Registry subjects
Flink SQLValidate SQL, create, list, read, and delete Flink statements, and check statement health and errors

Creating and deleting Flink statements change your environment, and a deleted statement cannot be restored. Agents cannot create or delete connectors or clusters. Environment, cluster, connector, and metrics tools belong to Confluent's separate global MCP server, which this connector does not use.

Enabling the Confluent Cloud connector isn't enough on its own. Tool calls remain denied until you create a policy that grants access to the specific tools you want to expose.

Additional resources