DescribeDelegationToken
This page encodes the smallest legal instance of the request and the response: numeric fields are zero, strings and byte arrays are empty, every array carries exactly one sample element, and any records field holds one empty 61-byte RecordBatch v2. Version 3 is a flexible version, so every struct is terminated by a uvarint tagged-field count and strings and arrays carry compact length-plus-one prefixes. Sizes below include the leading int32 size prefix.
- API key
- 41
- Encoded at
- v3
- Flexible versions
- 2+
- Headers
- req v2, resp v1
- Request versions
- 1-3
- Response versions
- 1-3
- Request size
- 20 bytes
- Response size
- 52 bytes
framerpc headerrequest bodyRecordBatchRecordresponse bodytagged_fields
Request
DescribeDelegationTokenRequest v3, request header v2, 20 bytes on the wire
byte layout (20 bytes, 16 bytes per row)
0
1
2
3
4
5
6
7
8
9
A
B
C
D
E
F
0000
0010
object tree
DescribeDelegationTokenRequest message v3 [0x0000, 20B] +-- Frame [0x0000, 4B] length-delimited framing | +-- size int32 = 16 [0x0000, 4B] number of bytes that follow, patched after encoding +-- RequestHeader v2 [0x0004, 11B] common request header | +-- request_api_key int16 = 41 (DescribeDelegationToken) [0x0004, 2B] numeric id of the API being invoked | +-- request_api_version int16 = 3 [0x0006, 2B] version of the API being invoked | +-- correlation_id int32 = 0 [0x0008, 4B] echoed back by the broker in the response | +-- client_id nullable_string = "" (int16 len=0) [0x000c, 2B] always a non-flexible int16-prefixed string | +-- tagged_fields uvarint = 0 [0x000e, 1B] number of tagged fields in the header +-- DescribeDelegationTokenRequest struct [0x000f, 5B] message body, version 3 +-- Owners []DescribeDelegationTokenOwner = 1 element [0x000f, 4B] Each owner that we want to describe delegation tokens for, or null to descr... | +-- length uvarint = 2 (compact, n+1) [0x000f, 1B] one sample element follows | +-- DescribeDelegationTokenOwner[0] DescribeDelegationTokenOwner = struct [0x0010, 3B] | +-- PrincipalType string = "" (compact, len+1=1) [0x0010, 1B] The owner principal type. | +-- PrincipalName string = "" (compact, len+1=1) [0x0011, 1B] The owner principal name. | +-- tagged_fields uvarint = 0 [0x0012, 1B] number of tagged fields in this struct +-- tagged_fields uvarint = 0 [0x0013, 1B] number of tagged fields in this struct
kafka message schema (.json)
{ "apiKey": 41, "type": "request", "listeners": ["broker", "controller"], "name": "DescribeDelegationTokenRequest", // Version 0 was removed in Apache Kafka 4.0, Version 1 is the new baseline. // Version 1 is the same as version 0. // Version 2 adds flexible version support // Version 3 adds token requester into the response "validVersions": "1-3", "flexibleVersions": "2+", "fields": [ { "name": "Owners", "type": "[]DescribeDelegationTokenOwner", "versions": "0+", "nullableVersions": "0+", "about": "Each owner that we want to describe delegation tokens for, or null to describe all tokens.", "fields": [ { "name": "PrincipalType", "type": "string", "versions": "0+", "about": "The owner principal type." }, { "name": "PrincipalName", "type": "string", "versions": "0+", "about": "The owner principal name." } ]} ] }
Response
DescribeDelegationTokenResponse v3, response header v1, 52 bytes on the wire
byte layout (52 bytes, 16 bytes per row)
0
1
2
3
4
5
6
7
8
9
A
B
C
D
E
F
0000
0010
0020
0030
object tree
DescribeDelegationTokenResponse message v3 [0x0000, 52B] +-- Frame [0x0000, 4B] length-delimited framing | +-- size int32 = 48 [0x0000, 4B] number of bytes that follow, patched after encoding +-- ResponseHeader v1 [0x0004, 5B] common response header | +-- correlation_id int32 = 0 [0x0004, 4B] matches the correlation_id of the request | +-- tagged_fields uvarint = 0 [0x0008, 1B] number of tagged fields in the header +-- DescribeDelegationTokenResponse struct [0x0009, 43B] message body, version 3 +-- ErrorCode int16 = 0 [0x0009, 2B] The error code, or 0 if there was no error. +-- Tokens []DescribedDelegationToken = 1 element [0x000b, 36B] The tokens. | +-- length uvarint = 2 (compact, n+1) [0x000b, 1B] one sample element follows | +-- DescribedDelegationToken[0] DescribedDelegationToken = struct [0x000c, 35B] | +-- PrincipalType string = "" (compact, len+1=1) [0x000c, 1B] The token principal type. | +-- PrincipalName string = "" (compact, len+1=1) [0x000d, 1B] The token principal name. | +-- TokenRequesterPrincipalType string = "" (compact, len+1=1) [0x000e, 1B] The principal type of the requester of the token. | +-- TokenRequesterPrincipalName string = "" (compact, len+1=1) [0x000f, 1B] The principal type of the requester of the token. | +-- IssueTimestamp int64 = 0 [0x0010, 8B] The token issue timestamp in milliseconds. | +-- ExpiryTimestamp int64 = 0 [0x0018, 8B] The token expiry timestamp in milliseconds. | +-- MaxTimestamp int64 = 0 [0x0020, 8B] The token maximum timestamp length in milliseconds. | +-- TokenId string = "" (compact, len+1=1) [0x0028, 1B] The token ID. | +-- Hmac bytes = empty (compact, len+1=1) [0x0029, 1B] The token HMAC. | +-- Renewers []DescribedDelegationTokenRenewer = 1 element [0x002a, 4B] Those who are able to renew this token before it expires. | | +-- length uvarint = 2 (compact, n+1) [0x002a, 1B] one sample element follows | | +-- DescribedDelegationTokenRenewer[0] DescribedDelegationTokenRenewer = struct [0x002b, 3B] | | +-- PrincipalType string = "" (compact, len+1=1) [0x002b, 1B] The renewer principal type. | | +-- PrincipalName string = "" (compact, len+1=1) [0x002c, 1B] The renewer principal name. | | +-- tagged_fields uvarint = 0 [0x002d, 1B] number of tagged fields in this struct | +-- tagged_fields uvarint = 0 [0x002e, 1B] number of tagged fields in this struct +-- ThrottleTimeMs int32 = 0 [0x002f, 4B] The duration in milliseconds for which the request was throttled due to a q... +-- tagged_fields uvarint = 0 [0x0033, 1B] number of tagged fields in this struct
kafka message schema (.json)
{ "apiKey": 41, "type": "response", "name": "DescribeDelegationTokenResponse", // Version 0 was removed in Apache Kafka 4.0, Version 1 is the new baseline. // Starting in version 1, on quota violation, brokers send out responses before throttling. // Version 2 adds flexible version support // Version 3 adds token requester details "validVersions": "1-3", "flexibleVersions": "2+", "fields": [ { "name": "ErrorCode", "type": "int16", "versions": "0+", "about": "The error code, or 0 if there was no error." }, { "name": "Tokens", "type": "[]DescribedDelegationToken", "versions": "0+", "about": "The tokens.", "fields": [ { "name": "PrincipalType", "type": "string", "versions": "0+", "about": "The token principal type." }, { "name": "PrincipalName", "type": "string", "versions": "0+", "about": "The token principal name." }, { "name": "TokenRequesterPrincipalType", "type": "string", "versions": "3+", "about": "The principal type of the requester of the token." }, { "name": "TokenRequesterPrincipalName", "type": "string", "versions": "3+", "about": "The principal type of the requester of the token." }, { "name": "IssueTimestamp", "type": "int64", "versions": "0+", "about": "The token issue timestamp in milliseconds." }, { "name": "ExpiryTimestamp", "type": "int64", "versions": "0+", "about": "The token expiry timestamp in milliseconds." }, { "name": "MaxTimestamp", "type": "int64", "versions": "0+", "about": "The token maximum timestamp length in milliseconds." }, { "name": "TokenId", "type": "string", "versions": "0+", "about": "The token ID." }, { "name": "Hmac", "type": "bytes", "versions": "0+", "about": "The token HMAC." }, { "name": "Renewers", "type": "[]DescribedDelegationTokenRenewer", "versions": "0+", "about": "Those who are able to renew this token before it expires.", "fields": [ { "name": "PrincipalType", "type": "string", "versions": "0+", "about": "The renewer principal type." }, { "name": "PrincipalName", "type": "string", "versions": "0+", "about": "The renewer principal name." } ]} ]}, { "name": "ThrottleTimeMs", "type": "int32", "versions": "0+", "about": "The duration in milliseconds for which the request was throttled due to a quota violation, or zero if the request did not violate any quota." } ] }