Skip to content
m manifester.io
All Kafka APIs

CreateDelegationToken

This page encodes the smallest legal instance of the request and the response: numeric fields are zero, strings and byte arrays are empty, every array carries exactly one sample element, and any records field holds one empty 61-byte RecordBatch v2. Version 3 is a flexible version, so every struct is terminated by a uvarint tagged-field count and strings and arrays carry compact length-plus-one prefixes. Sizes below include the leading int32 size prefix.

API key
38
Encoded at
v3
Flexible versions
2+
Headers
req v2, resp v1
Request versions
1-3
Response versions
1-3
Request size
30 bytes
Response size
46 bytes
framerpc headerrequest bodyRecordBatchRecordresponse bodytagged_fields

Request

CreateDelegationTokenRequest v3, request header v2, 30 bytes on the wire

byte layout (30 bytes, 16 bytes per row)

0
1
2
3
4
5
6
7
8
9
A
B
C
D
E
F
0000
0010

object tree

CreateDelegationTokenRequest      message v3                                         [0x0000, 30B]
+-- Frame                                                                            [0x0000, 4B]   length-delimited framing
|   +-- size                      int32                = 26                          [0x0000, 4B]   number of bytes that follow, patched after encoding
+-- RequestHeader                 v2                                                 [0x0004, 11B]  common request header
|   +-- request_api_key           int16                = 38 (CreateDelegationToken)  [0x0004, 2B]   numeric id of the API being invoked
|   +-- request_api_version       int16                = 3                           [0x0006, 2B]   version of the API being invoked
|   +-- correlation_id            int32                = 0                           [0x0008, 4B]   echoed back by the broker in the response
|   +-- client_id                 nullable_string      = "" (int16 len=0)            [0x000c, 2B]   always a non-flexible int16-prefixed string
|   +-- tagged_fields             uvarint              = 0                           [0x000e, 1B]   number of tagged fields in the header
+-- CreateDelegationTokenRequest  struct                                             [0x000f, 15B]  message body, version 3
    +-- OwnerPrincipalType        string               = "" (compact, len+1=1)       [0x000f, 1B]   The principal type of the owner of the token. If it's null it defaults to t...
    +-- OwnerPrincipalName        string               = "" (compact, len+1=1)       [0x0010, 1B]   The principal name of the owner of the token. If it's null it defaults to t...
    +-- Renewers                  []CreatableRenewers  = 1 element                   [0x0011, 4B]   A list of those who are allowed to renew this token before it expires.
    |   +-- length                uvarint              = 2 (compact, n+1)            [0x0011, 1B]   one sample element follows
    |   +-- CreatableRenewers[0]  CreatableRenewers    = struct                      [0x0012, 3B]
    |       +-- PrincipalType     string               = "" (compact, len+1=1)       [0x0012, 1B]   The type of the Kafka principal.
    |       +-- PrincipalName     string               = "" (compact, len+1=1)       [0x0013, 1B]   The name of the Kafka principal.
    |       +-- tagged_fields     uvarint              = 0                           [0x0014, 1B]   number of tagged fields in this struct
    +-- MaxLifetimeMs             int64                = 0                           [0x0015, 8B]   The maximum lifetime of the token in milliseconds, or -1 to use the server ...
    +-- tagged_fields             uvarint              = 0                           [0x001d, 1B]   number of tagged fields in this struct

kafka message schema (.json)

{
  "apiKey": 38,
  "type": "request",
  "listeners": ["broker", "controller"],
  "name": "CreateDelegationTokenRequest",
  // Version 0 was removed in Apache Kafka 4.0, Version 1 is the new baseline.
  //
  // Version 1 is the same as version 0.
  //
  // Version 2 is the first flexible version.
  //
  // Version 3 adds owner principal
  "validVersions": "1-3",
  "flexibleVersions": "2+",
  "fields": [
    { "name": "OwnerPrincipalType", "type": "string", "versions": "3+", "nullableVersions": "3+",
      "about": "The principal type of the owner of the token. If it's null it defaults to the token request principal." },
    { "name": "OwnerPrincipalName", "type": "string", "versions": "3+", "nullableVersions": "3+",
      "about": "The principal name of the owner of the token. If it's null it defaults to the token request principal." },
    { "name": "Renewers", "type": "[]CreatableRenewers", "versions": "0+",
      "about": "A list of those who are allowed to renew this token before it expires.", "fields": [
      { "name": "PrincipalType", "type": "string", "versions": "0+",
        "about": "The type of the Kafka principal." },
      { "name": "PrincipalName", "type": "string", "versions": "0+",
        "about": "The name of the Kafka principal." }
    ]},
    { "name": "MaxLifetimeMs", "type": "int64", "versions": "0+",
      "about": "The maximum lifetime of the token in milliseconds, or -1 to use the server side default." }
  ]
}

Response

CreateDelegationTokenResponse v3, response header v1, 46 bytes on the wire

byte layout (46 bytes, 16 bytes per row)

0
1
2
3
4
5
6
7
8
9
A
B
C
D
E
F
0000
0010
0020

object tree

CreateDelegationTokenResponse        message v3                              [0x0000, 46B]
+-- Frame                                                                    [0x0000, 4B]   length-delimited framing
|   +-- size                         int32       = 42                        [0x0000, 4B]   number of bytes that follow, patched after encoding
+-- ResponseHeader                   v1                                      [0x0004, 5B]   common response header
|   +-- correlation_id               int32       = 0                         [0x0004, 4B]   matches the correlation_id of the request
|   +-- tagged_fields                uvarint     = 0                         [0x0008, 1B]   number of tagged fields in the header
+-- CreateDelegationTokenResponse    struct                                  [0x0009, 37B]  message body, version 3
    +-- ErrorCode                    int16       = 0                         [0x0009, 2B]   The top-level error, or zero if there was no error.
    +-- PrincipalType                string      = "" (compact, len+1=1)     [0x000b, 1B]   The principal type of the token owner.
    +-- PrincipalName                string      = "" (compact, len+1=1)     [0x000c, 1B]   The name of the token owner.
    +-- TokenRequesterPrincipalType  string      = "" (compact, len+1=1)     [0x000d, 1B]   The principal type of the requester of the token.
    +-- TokenRequesterPrincipalName  string      = "" (compact, len+1=1)     [0x000e, 1B]   The principal type of the requester of the token.
    +-- IssueTimestampMs             int64       = 0                         [0x000f, 8B]   When this token was generated.
    +-- ExpiryTimestampMs            int64       = 0                         [0x0017, 8B]   When this token expires.
    +-- MaxTimestampMs               int64       = 0                         [0x001f, 8B]   The maximum lifetime of this token.
    +-- TokenId                      string      = "" (compact, len+1=1)     [0x0027, 1B]   The token UUID.
    +-- Hmac                         bytes       = empty (compact, len+1=1)  [0x0028, 1B]   HMAC of the delegation token.
    +-- ThrottleTimeMs               int32       = 0                         [0x0029, 4B]   The duration in milliseconds for which the request was throttled due to a q...
    +-- tagged_fields                uvarint     = 0                         [0x002d, 1B]   number of tagged fields in this struct

kafka message schema (.json)

{
  "apiKey": 38,
  "type": "response",
  "name": "CreateDelegationTokenResponse",
  // Version 0 was removed in Apache Kafka 4.0, Version 1 is the new baseline.
  //
  // Starting in version 1, on quota violation, brokers send out responses before throttling.
  //
  // Version 2 is the first flexible version.
  //
  // Version 3 adds token requester details
  "validVersions": "1-3",
  "flexibleVersions": "2+",
  "fields": [
    { "name": "ErrorCode", "type": "int16", "versions": "0+",
      "about": "The top-level error, or zero if there was no error."},
    { "name": "PrincipalType", "type": "string", "versions": "0+",
      "about": "The principal type of the token owner." },
    { "name": "PrincipalName", "type": "string", "versions": "0+",
      "about": "The name of the token owner." },
    { "name": "TokenRequesterPrincipalType", "type": "string", "versions": "3+",
      "about": "The principal type of the requester of the token." },
    { "name": "TokenRequesterPrincipalName", "type": "string", "versions": "3+",
      "about": "The principal type of the requester of the token." },
    { "name": "IssueTimestampMs", "type": "int64", "versions": "0+",
      "about": "When this token was generated." },
    { "name": "ExpiryTimestampMs", "type": "int64", "versions": "0+",
      "about": "When this token expires." },
    { "name": "MaxTimestampMs", "type": "int64", "versions": "0+",
      "about": "The maximum lifetime of this token." },
    { "name": "TokenId", "type": "string", "versions": "0+",
      "about": "The token UUID." },
    { "name": "Hmac", "type": "bytes", "versions": "0+",
      "about": "HMAC of the delegation token." },
    { "name": "ThrottleTimeMs", "type": "int32", "versions": "0+",
      "about": "The duration in milliseconds for which the request was throttled due to a quota violation, or zero if the request did not violate any quota." }
  ]
}