CreateDelegationToken
This page encodes the smallest legal instance of the request and the response: numeric fields are zero, strings and byte arrays are empty, every array carries exactly one sample element, and any records field holds one empty 61-byte RecordBatch v2. Version 3 is a flexible version, so every struct is terminated by a uvarint tagged-field count and strings and arrays carry compact length-plus-one prefixes. Sizes below include the leading int32 size prefix.
- API key
- 38
- Encoded at
- v3
- Flexible versions
- 2+
- Headers
- req v2, resp v1
- Request versions
- 1-3
- Response versions
- 1-3
- Request size
- 30 bytes
- Response size
- 46 bytes
framerpc headerrequest bodyRecordBatchRecordresponse bodytagged_fields
Request
CreateDelegationTokenRequest v3, request header v2, 30 bytes on the wire
byte layout (30 bytes, 16 bytes per row)
0
1
2
3
4
5
6
7
8
9
A
B
C
D
E
F
0000
0010
object tree
CreateDelegationTokenRequest message v3 [0x0000, 30B] +-- Frame [0x0000, 4B] length-delimited framing | +-- size int32 = 26 [0x0000, 4B] number of bytes that follow, patched after encoding +-- RequestHeader v2 [0x0004, 11B] common request header | +-- request_api_key int16 = 38 (CreateDelegationToken) [0x0004, 2B] numeric id of the API being invoked | +-- request_api_version int16 = 3 [0x0006, 2B] version of the API being invoked | +-- correlation_id int32 = 0 [0x0008, 4B] echoed back by the broker in the response | +-- client_id nullable_string = "" (int16 len=0) [0x000c, 2B] always a non-flexible int16-prefixed string | +-- tagged_fields uvarint = 0 [0x000e, 1B] number of tagged fields in the header +-- CreateDelegationTokenRequest struct [0x000f, 15B] message body, version 3 +-- OwnerPrincipalType string = "" (compact, len+1=1) [0x000f, 1B] The principal type of the owner of the token. If it's null it defaults to t... +-- OwnerPrincipalName string = "" (compact, len+1=1) [0x0010, 1B] The principal name of the owner of the token. If it's null it defaults to t... +-- Renewers []CreatableRenewers = 1 element [0x0011, 4B] A list of those who are allowed to renew this token before it expires. | +-- length uvarint = 2 (compact, n+1) [0x0011, 1B] one sample element follows | +-- CreatableRenewers[0] CreatableRenewers = struct [0x0012, 3B] | +-- PrincipalType string = "" (compact, len+1=1) [0x0012, 1B] The type of the Kafka principal. | +-- PrincipalName string = "" (compact, len+1=1) [0x0013, 1B] The name of the Kafka principal. | +-- tagged_fields uvarint = 0 [0x0014, 1B] number of tagged fields in this struct +-- MaxLifetimeMs int64 = 0 [0x0015, 8B] The maximum lifetime of the token in milliseconds, or -1 to use the server ... +-- tagged_fields uvarint = 0 [0x001d, 1B] number of tagged fields in this struct
kafka message schema (.json)
{ "apiKey": 38, "type": "request", "listeners": ["broker", "controller"], "name": "CreateDelegationTokenRequest", // Version 0 was removed in Apache Kafka 4.0, Version 1 is the new baseline. // // Version 1 is the same as version 0. // // Version 2 is the first flexible version. // // Version 3 adds owner principal "validVersions": "1-3", "flexibleVersions": "2+", "fields": [ { "name": "OwnerPrincipalType", "type": "string", "versions": "3+", "nullableVersions": "3+", "about": "The principal type of the owner of the token. If it's null it defaults to the token request principal." }, { "name": "OwnerPrincipalName", "type": "string", "versions": "3+", "nullableVersions": "3+", "about": "The principal name of the owner of the token. If it's null it defaults to the token request principal." }, { "name": "Renewers", "type": "[]CreatableRenewers", "versions": "0+", "about": "A list of those who are allowed to renew this token before it expires.", "fields": [ { "name": "PrincipalType", "type": "string", "versions": "0+", "about": "The type of the Kafka principal." }, { "name": "PrincipalName", "type": "string", "versions": "0+", "about": "The name of the Kafka principal." } ]}, { "name": "MaxLifetimeMs", "type": "int64", "versions": "0+", "about": "The maximum lifetime of the token in milliseconds, or -1 to use the server side default." } ] }
Response
CreateDelegationTokenResponse v3, response header v1, 46 bytes on the wire
byte layout (46 bytes, 16 bytes per row)
0
1
2
3
4
5
6
7
8
9
A
B
C
D
E
F
0000
0010
0020
object tree
CreateDelegationTokenResponse message v3 [0x0000, 46B] +-- Frame [0x0000, 4B] length-delimited framing | +-- size int32 = 42 [0x0000, 4B] number of bytes that follow, patched after encoding +-- ResponseHeader v1 [0x0004, 5B] common response header | +-- correlation_id int32 = 0 [0x0004, 4B] matches the correlation_id of the request | +-- tagged_fields uvarint = 0 [0x0008, 1B] number of tagged fields in the header +-- CreateDelegationTokenResponse struct [0x0009, 37B] message body, version 3 +-- ErrorCode int16 = 0 [0x0009, 2B] The top-level error, or zero if there was no error. +-- PrincipalType string = "" (compact, len+1=1) [0x000b, 1B] The principal type of the token owner. +-- PrincipalName string = "" (compact, len+1=1) [0x000c, 1B] The name of the token owner. +-- TokenRequesterPrincipalType string = "" (compact, len+1=1) [0x000d, 1B] The principal type of the requester of the token. +-- TokenRequesterPrincipalName string = "" (compact, len+1=1) [0x000e, 1B] The principal type of the requester of the token. +-- IssueTimestampMs int64 = 0 [0x000f, 8B] When this token was generated. +-- ExpiryTimestampMs int64 = 0 [0x0017, 8B] When this token expires. +-- MaxTimestampMs int64 = 0 [0x001f, 8B] The maximum lifetime of this token. +-- TokenId string = "" (compact, len+1=1) [0x0027, 1B] The token UUID. +-- Hmac bytes = empty (compact, len+1=1) [0x0028, 1B] HMAC of the delegation token. +-- ThrottleTimeMs int32 = 0 [0x0029, 4B] The duration in milliseconds for which the request was throttled due to a q... +-- tagged_fields uvarint = 0 [0x002d, 1B] number of tagged fields in this struct
kafka message schema (.json)
{ "apiKey": 38, "type": "response", "name": "CreateDelegationTokenResponse", // Version 0 was removed in Apache Kafka 4.0, Version 1 is the new baseline. // // Starting in version 1, on quota violation, brokers send out responses before throttling. // // Version 2 is the first flexible version. // // Version 3 adds token requester details "validVersions": "1-3", "flexibleVersions": "2+", "fields": [ { "name": "ErrorCode", "type": "int16", "versions": "0+", "about": "The top-level error, or zero if there was no error."}, { "name": "PrincipalType", "type": "string", "versions": "0+", "about": "The principal type of the token owner." }, { "name": "PrincipalName", "type": "string", "versions": "0+", "about": "The name of the token owner." }, { "name": "TokenRequesterPrincipalType", "type": "string", "versions": "3+", "about": "The principal type of the requester of the token." }, { "name": "TokenRequesterPrincipalName", "type": "string", "versions": "3+", "about": "The principal type of the requester of the token." }, { "name": "IssueTimestampMs", "type": "int64", "versions": "0+", "about": "When this token was generated." }, { "name": "ExpiryTimestampMs", "type": "int64", "versions": "0+", "about": "When this token expires." }, { "name": "MaxTimestampMs", "type": "int64", "versions": "0+", "about": "The maximum lifetime of this token." }, { "name": "TokenId", "type": "string", "versions": "0+", "about": "The token UUID." }, { "name": "Hmac", "type": "bytes", "versions": "0+", "about": "HMAC of the delegation token." }, { "name": "ThrottleTimeMs", "type": "int32", "versions": "0+", "about": "The duration in milliseconds for which the request was throttled due to a quota violation, or zero if the request did not violate any quota." } ] }