## Confluent Cloud integration Confluent Cloud is a fully managed data streaming platform built on Apache Kafka, with Schema Registry and Apache Flink for stream processing. Agen.co connects to Confluent Cloud through Confluent's own hosted regional MCP server as an **Official** connector. The server authenticates with a Confluent Cloud API key, not OAuth, so there is no sign-in screen or callback URL. You build a Base64 credential from the key and paste it into Agen.co. What agents can see and do is limited by the permissions of that key. Prerequisites - A Confluent Cloud account and its **Organization ID**. - A cluster in a region where Confluent Cloud for Apache Flink is available. Confluent only runs the regional MCP server in those regions. Confluent requires a payment method on the account before you can create a cluster. - A **Global** or **Flink** API key and secret, created in the same organization. Cloud API keys, Kafka cluster keys, and other resource-scoped keys are not accepted by the regional server. - A cluster reachable from the public internet. A public regional MCP server cannot reach private clusters. ### Prepare the credentials If you do not have a Confluent Cloud account, sign up at [confluent.cloud](https://confluent.cloud/signup) and complete the registration form first. #### Create an API key Create one of these key types in Confluent Cloud, following Confluent's [API key documentation](https://docs.confluent.io/cloud/current/security/authenticate/workload-identities/service-accounts/api-keys/overview.html): - **Global API key** — Confluent's recommended choice. One global key also works with Confluent's global MCP server. - **Flink API key** — scoped to a single cloud provider and region, so it works only with the regional server and only for that region. Create it under **Flink** → **API keys** → **Add API Key**, and select the same cloud provider and region you enter in Agen.co. For production, create the key for a service account rather than a person, so the connector keeps working if that person leaves. The secret is shown only once Copy the API key and secret when Confluent shows them. The secret cannot be retrieved later. If you lose it, create a new key. A key grants no access by itself. Confluent authorizes every call with the role bindings and ACLs of the account that owns the key, so grant that account access to the topics, Schema Registry subjects, and Flink resources your agents need, and nothing more. #### Build the Base64 credential Agen.co sends the key as HTTP Basic authentication, so the **API key** field takes the Base64 encoding of `:`, not the bare key. In a terminal, run: ``` echo -n ':' | base64 ``` Use `-n` so no newline is encoded. Copy the output. #### Find your Organization ID In the Confluent Cloud Console, open the organization name above your user name in the sidebar. The **Details** page shows the **Organization name** and **Organization ID**. It must be the organization the API key belongs to. ### Connect Confluent Cloud in Agen.co 1. In the Agen.co portal, go to **Connectors** → **My connectors** and click **Add connector**. 2. In the **Select connector** drawer, search for `Confluent` and select **Confluent Cloud**. The **Add Confluent Cloud** panel opens. 3. Fill in the fields: | Field | Required | Description | | --- | --- | --- | | **Instance Slug** | Yes | Namespaces this instance — it prefixes each imported tool as `slug__tool`, so several instances of the same MCP can coexist. Prefilled with `confluent`. Use lowercase kebab-case. You can change it later from the connector's settings. | | **Region** | Yes | The region code of the cloud region hosting your cluster, for example `us-east-2`. Must be a region where Confluent Cloud Flink is available. | | **Cloud provider** | Yes | One of `aws` (Amazon Web Services), `gcp` (Google Cloud Platform), or `azure` (Microsoft Azure). Defaults to `aws`. | | **Organization ID** | Yes | Your Confluent Cloud organization ID. Must be the organization the API key belongs to. | | **API key** | Yes | The Base64 of `:` from the previous section. Agen.co sends it as HTTP Basic authentication. | 4. Click **Connect**. Agen.co connects to Confluent's MCP server with the key, and the panel switches to **Select the tools to import from Confluent Cloud.** Every tool is toggled on; turn off any you don't want to import, then click **Add**. The connector is created and its tools imported only when you click **Add**. If you close the panel before that, nothing is saved. One instance connects to one region, cloud provider, and organization. To connect another region or cloud, add Confluent Cloud again with a different **Instance Slug** and that region's values. ### What it covers This connector uses Confluent's regional MCP server. The server needs a key, so its tool list could not be queried unauthenticated; the areas below come from Confluent's MCP documentation (checked 2026-10-08), and the tool selection screen after **Connect** shows exactly what your key serves. Confluent states that most tools are read-only. | Area | What it covers | | --- | --- | | Topics and schemas | List and describe Kafka topics, read sample messages, and read Schema Registry subjects | | Flink SQL | Validate SQL, create, list, read, and delete Flink statements, and check statement health and errors | Creating and deleting Flink statements change your environment, and a deleted statement cannot be restored. Agents cannot create or delete connectors or clusters. Environment, cluster, connector, and metrics tools belong to Confluent's separate global MCP server, which this connector does not use. Enabling the Confluent Cloud connector isn't enough on its own. Tool calls remain denied until you create a [policy](/agen-for-work/policies/overview) that grants access to the specific tools you want to expose. ### Additional resources - [Access Confluent Cloud with the managed MCP servers](https://docs.confluent.io/cloud/current/ai/ai-tools/managed-mcp-server.html) - [Confluent Cloud API keys](https://docs.confluent.io/cloud/current/security/authenticate/workload-identities/service-accounts/api-keys/overview.html) - [Generate an API key for Confluent Cloud for Apache Flink](https://docs.confluent.io/cloud/current/flink/operate-and-deploy/generate-api-key-for-flink.html)