Confluent Cloud is a fully managed data streaming platform built on Apache Kafka, with Schema Registry and Apache Flink for stream processing.
Agen.co connects to Confluent Cloud through Confluent's own hosted regional MCP server as an Official connector. The server authenticates with a Confluent Cloud API key, not OAuth, so there is no sign-in screen or callback URL. You build a Base64 credential from the key and paste it into Agen.co. What agents can see and do is limited by the permissions of that key.
Prerequisites
Prerequisites
- A Confluent Cloud account and its Organization ID.
- A cluster in a region where Confluent Cloud for Apache Flink is available. Confluent only runs the regional MCP server in those regions. Confluent requires a payment method on the account before you can create a cluster.
- A Global or Flink API key and secret, created in the same organization. Cloud API keys, Kafka cluster keys, and other resource-scoped keys are not accepted by the regional server.
- A cluster reachable from the public internet. A public regional MCP server cannot reach private clusters.
If you do not have a Confluent Cloud account, sign up at confluent.cloud and complete the registration form first.
Create one of these key types in Confluent Cloud, following Confluent's API key documentation:
- Global API key — Confluent's recommended choice. One global key also works with Confluent's global MCP server.
- Flink API key — scoped to a single cloud provider and region, so it works only with the regional server and only for that region. Create it under Flink → API keys → Add API Key, and select the same cloud provider and region you enter in Agen.co.
For production, create the key for a service account rather than a person, so the connector keeps working if that person leaves.
The secret is shown only once
The secret is shown only once
Copy the API key and secret when Confluent shows them. The secret cannot be retrieved later. If you lose it, create a new key.
A key grants no access by itself. Confluent authorizes every call with the role bindings and ACLs of the account that owns the key, so grant that account access to the topics, Schema Registry subjects, and Flink resources your agents need, and nothing more.
Agen.co sends the key as HTTP Basic authentication, so the API key field takes the Base64 encoding of <key>:<secret>, not the bare key. In a terminal, run:
echo -n '<api_key>:<api_secret>' | base64Use -n so no newline is encoded. Copy the output.
In the Confluent Cloud Console, open the organization name above your user name in the sidebar. The Details page shows the Organization name and Organization ID. It must be the organization the API key belongs to.
In the Agen.co portal, go to Connectors → My connectors and click Add connector.
In the Select connector drawer, search for
Confluentand select Confluent Cloud. The Add Confluent Cloud panel opens.Fill in the fields:
Field Required Description Instance Slug Yes Namespaces this instance — it prefixes each imported tool as slug__tool, so several instances of the same MCP can coexist. Prefilled withconfluent. Use lowercase kebab-case. You can change it later from the connector's settings.Region Yes The region code of the cloud region hosting your cluster, for example us-east-2. Must be a region where Confluent Cloud Flink is available.Cloud provider Yes One of aws(Amazon Web Services),gcp(Google Cloud Platform), orazure(Microsoft Azure). Defaults toaws.Organization ID Yes Your Confluent Cloud organization ID. Must be the organization the API key belongs to. API key Yes The Base64 of <key>:<secret>from the previous section. Agen.co sends it as HTTP Basic authentication.Click Connect. Agen.co connects to Confluent's MCP server with the key, and the panel switches to Select the tools to import from Confluent Cloud. Every tool is toggled on; turn off any you don't want to import, then click Add.
The connector is created and its tools imported only when you click Add. If you close the panel before that, nothing is saved.
One instance connects to one region, cloud provider, and organization. To connect another region or cloud, add Confluent Cloud again with a different Instance Slug and that region's values.
This connector uses Confluent's regional MCP server. The server needs a key, so its tool list could not be queried unauthenticated; the areas below come from Confluent's MCP documentation (checked 2026-10-08), and the tool selection screen after Connect shows exactly what your key serves. Confluent states that most tools are read-only.
| Area | What it covers |
|---|---|
| Topics and schemas | List and describe Kafka topics, read sample messages, and read Schema Registry subjects |
| Flink SQL | Validate SQL, create, list, read, and delete Flink statements, and check statement health and errors |
Creating and deleting Flink statements change your environment, and a deleted statement cannot be restored. Agents cannot create or delete connectors or clusters. Environment, cluster, connector, and metrics tools belong to Confluent's separate global MCP server, which this connector does not use.
Enabling the Confluent Cloud connector isn't enough on its own. Tool calls remain denied until you create a policy that grants access to the specific tools you want to expose.