Skip to content
m manifester.io
All Kafka APIs

DescribeDelegationToken

This page encodes the smallest legal instance of the request and the response: numeric fields are zero, strings and byte arrays are empty, every array carries exactly one sample element, and any records field holds one empty 61-byte RecordBatch v2. Version 3 is a flexible version, so every struct is terminated by a uvarint tagged-field count and strings and arrays carry compact length-plus-one prefixes. Sizes below include the leading int32 size prefix.

API key
41
Encoded at
v3
Flexible versions
2+
Headers
req v2, resp v1
Request versions
1-3
Response versions
1-3
Request size
20 bytes
Response size
52 bytes
framerpc headerrequest bodyRecordBatchRecordresponse bodytagged_fields

Request

DescribeDelegationTokenRequest v3, request header v2, 20 bytes on the wire

byte layout (20 bytes, 16 bytes per row)

0
1
2
3
4
5
6
7
8
9
A
B
C
D
E
F
0000
0010

object tree

DescribeDelegationTokenRequest               message v3                                                      [0x0000, 20B]
+-- Frame                                                                                                    [0x0000, 4B]   length-delimited framing
|   +-- size                                 int32                           = 16                            [0x0000, 4B]   number of bytes that follow, patched after encoding
+-- RequestHeader                            v2                                                              [0x0004, 11B]  common request header
|   +-- request_api_key                      int16                           = 41 (DescribeDelegationToken)  [0x0004, 2B]   numeric id of the API being invoked
|   +-- request_api_version                  int16                           = 3                             [0x0006, 2B]   version of the API being invoked
|   +-- correlation_id                       int32                           = 0                             [0x0008, 4B]   echoed back by the broker in the response
|   +-- client_id                            nullable_string                 = "" (int16 len=0)              [0x000c, 2B]   always a non-flexible int16-prefixed string
|   +-- tagged_fields                        uvarint                         = 0                             [0x000e, 1B]   number of tagged fields in the header
+-- DescribeDelegationTokenRequest           struct                                                          [0x000f, 5B]   message body, version 3
    +-- Owners                               []DescribeDelegationTokenOwner  = 1 element                     [0x000f, 4B]   Each owner that we want to describe delegation tokens for, or null to descr...
    |   +-- length                           uvarint                         = 2 (compact, n+1)              [0x000f, 1B]   one sample element follows
    |   +-- DescribeDelegationTokenOwner[0]  DescribeDelegationTokenOwner    = struct                        [0x0010, 3B]
    |       +-- PrincipalType                string                          = "" (compact, len+1=1)         [0x0010, 1B]   The owner principal type.
    |       +-- PrincipalName                string                          = "" (compact, len+1=1)         [0x0011, 1B]   The owner principal name.
    |       +-- tagged_fields                uvarint                         = 0                             [0x0012, 1B]   number of tagged fields in this struct
    +-- tagged_fields                        uvarint                         = 0                             [0x0013, 1B]   number of tagged fields in this struct

kafka message schema (.json)

{
  "apiKey": 41,
  "type": "request",
  "listeners": ["broker", "controller"],
  "name": "DescribeDelegationTokenRequest",
  // Version 0 was removed in Apache Kafka 4.0, Version 1 is the new baseline.
  // Version 1 is the same as version 0.
  // Version 2 adds flexible version support
  // Version 3 adds token requester into the response
  "validVersions": "1-3",
  "flexibleVersions": "2+",
  "fields": [
    { "name": "Owners", "type": "[]DescribeDelegationTokenOwner", "versions": "0+", "nullableVersions": "0+",
      "about": "Each owner that we want to describe delegation tokens for, or null to describe all tokens.", "fields": [
      { "name": "PrincipalType", "type": "string", "versions": "0+",
        "about": "The owner principal type." },
      { "name": "PrincipalName", "type": "string", "versions": "0+",
        "about": "The owner principal name." }
    ]}
  ]
}

Response

DescribeDelegationTokenResponse v3, response header v1, 52 bytes on the wire

byte layout (52 bytes, 16 bytes per row)

0
1
2
3
4
5
6
7
8
9
A
B
C
D
E
F
0000
0010
0020
0030

object tree

DescribeDelegationTokenResponse                         message v3                                                     [0x0000, 52B]
+-- Frame                                                                                                              [0x0000, 4B]   length-delimited framing
|   +-- size                                            int32                              = 48                        [0x0000, 4B]   number of bytes that follow, patched after encoding
+-- ResponseHeader                                      v1                                                             [0x0004, 5B]   common response header
|   +-- correlation_id                                  int32                              = 0                         [0x0004, 4B]   matches the correlation_id of the request
|   +-- tagged_fields                                   uvarint                            = 0                         [0x0008, 1B]   number of tagged fields in the header
+-- DescribeDelegationTokenResponse                     struct                                                         [0x0009, 43B]  message body, version 3
    +-- ErrorCode                                       int16                              = 0                         [0x0009, 2B]   The error code, or 0 if there was no error.
    +-- Tokens                                          []DescribedDelegationToken         = 1 element                 [0x000b, 36B]  The tokens.
    |   +-- length                                      uvarint                            = 2 (compact, n+1)          [0x000b, 1B]   one sample element follows
    |   +-- DescribedDelegationToken[0]                 DescribedDelegationToken           = struct                    [0x000c, 35B]
    |       +-- PrincipalType                           string                             = "" (compact, len+1=1)     [0x000c, 1B]   The token principal type.
    |       +-- PrincipalName                           string                             = "" (compact, len+1=1)     [0x000d, 1B]   The token principal name.
    |       +-- TokenRequesterPrincipalType             string                             = "" (compact, len+1=1)     [0x000e, 1B]   The principal type of the requester of the token.
    |       +-- TokenRequesterPrincipalName             string                             = "" (compact, len+1=1)     [0x000f, 1B]   The principal type of the requester of the token.
    |       +-- IssueTimestamp                          int64                              = 0                         [0x0010, 8B]   The token issue timestamp in milliseconds.
    |       +-- ExpiryTimestamp                         int64                              = 0                         [0x0018, 8B]   The token expiry timestamp in milliseconds.
    |       +-- MaxTimestamp                            int64                              = 0                         [0x0020, 8B]   The token maximum timestamp length in milliseconds.
    |       +-- TokenId                                 string                             = "" (compact, len+1=1)     [0x0028, 1B]   The token ID.
    |       +-- Hmac                                    bytes                              = empty (compact, len+1=1)  [0x0029, 1B]   The token HMAC.
    |       +-- Renewers                                []DescribedDelegationTokenRenewer  = 1 element                 [0x002a, 4B]   Those who are able to renew this token before it expires.
    |       |   +-- length                              uvarint                            = 2 (compact, n+1)          [0x002a, 1B]   one sample element follows
    |       |   +-- DescribedDelegationTokenRenewer[0]  DescribedDelegationTokenRenewer    = struct                    [0x002b, 3B]
    |       |       +-- PrincipalType                   string                             = "" (compact, len+1=1)     [0x002b, 1B]   The renewer principal type.
    |       |       +-- PrincipalName                   string                             = "" (compact, len+1=1)     [0x002c, 1B]   The renewer principal name.
    |       |       +-- tagged_fields                   uvarint                            = 0                         [0x002d, 1B]   number of tagged fields in this struct
    |       +-- tagged_fields                           uvarint                            = 0                         [0x002e, 1B]   number of tagged fields in this struct
    +-- ThrottleTimeMs                                  int32                              = 0                         [0x002f, 4B]   The duration in milliseconds for which the request was throttled due to a q...
    +-- tagged_fields                                   uvarint                            = 0                         [0x0033, 1B]   number of tagged fields in this struct

kafka message schema (.json)

{
  "apiKey": 41,
  "type": "response",
  "name": "DescribeDelegationTokenResponse",
  // Version 0 was removed in Apache Kafka 4.0, Version 1 is the new baseline.
  // Starting in version 1, on quota violation, brokers send out responses before throttling.
  // Version 2 adds flexible version support
  // Version 3 adds token requester details
  "validVersions": "1-3",
  "flexibleVersions": "2+",
  "fields": [
    { "name": "ErrorCode", "type": "int16", "versions": "0+",
      "about": "The error code, or 0 if there was no error." },
    { "name": "Tokens", "type": "[]DescribedDelegationToken", "versions": "0+",
      "about": "The tokens.", "fields": [
      { "name": "PrincipalType", "type": "string", "versions": "0+",
        "about": "The token principal type." },
      { "name": "PrincipalName", "type": "string", "versions": "0+",
        "about": "The token principal name." },
      { "name": "TokenRequesterPrincipalType", "type": "string", "versions": "3+",
        "about": "The principal type of the requester of the token." },
      { "name": "TokenRequesterPrincipalName", "type": "string", "versions": "3+",
        "about": "The principal type of the requester of the token." },
      { "name": "IssueTimestamp", "type": "int64", "versions": "0+",
        "about": "The token issue timestamp in milliseconds." },
      { "name": "ExpiryTimestamp", "type": "int64", "versions": "0+",
        "about": "The token expiry timestamp in milliseconds." },
      { "name": "MaxTimestamp", "type": "int64", "versions": "0+",
        "about": "The token maximum timestamp length in milliseconds." },
      { "name": "TokenId", "type": "string", "versions": "0+",
        "about": "The token ID." },
      { "name": "Hmac", "type": "bytes", "versions": "0+",
        "about": "The token HMAC." },
      { "name": "Renewers", "type": "[]DescribedDelegationTokenRenewer", "versions": "0+",
        "about": "Those who are able to renew this token before it expires.", "fields": [
        { "name": "PrincipalType", "type": "string", "versions": "0+",
          "about": "The renewer principal type." },
        { "name": "PrincipalName", "type": "string", "versions": "0+",
          "about": "The renewer principal name." }
      ]}
    ]},
    { "name": "ThrottleTimeMs", "type": "int32", "versions": "0+",
      "about": "The duration in milliseconds for which the request was throttled due to a quota violation, or zero if the request did not violate any quota." }
  ]
}