If you already think in kubectl get and kubectl config use-context, kafkactl will feel familiar. It is a single binary that covers producing, consuming, topics, consumer groups and offset resets, and ACLs, with the same verb-first command style.
TL;DR: Choose kafkactl if you want one maintained binary for records and administration, especially if your team already works in Kubernetes. Look at kcl, a pure-Go CLI from the author of franz-go, instead if AWS MSK IAM without a plugin or Protobuf decoding through Schema Registry is a daily requirement.
For how kafkactl compares with kcat, kaf, kcl, rpk, and Confluent CLI across authentication, Schema Registry formats, and dated GitHub activity, see Best Kafka CLI Tools in 2026: kcat vs kafkactl vs kaf.
Install
kafkactl installs through Homebrew, winget, Docker, or a release binary:
brew install kafkactl # Homebrew
winget install kafkactl # Windows
Configure contexts
kafkactl keeps each cluster as a named context, but there is no command to add one. Contexts live in a YAML file, by default ~/.config/kafkactl/config.yml, which kafkactl generates on first run if it finds no config file:
contexts:
local:
brokers:
- localhost:9092
prod:
brokers:
- prod-kafka-1:9092
- prod-kafka-2:9092
Then list and switch contexts:
kafkactl config get-contexts
kafkactl config use-context prod
If no current context is set, kafkactl uses the first context in the file.
Everyday commands
kafkactl get topics
kafkactl describe consumer-group my-group
describe consumer-group shows a snapshot of the group, including its lag. Reading and writing records looks like this, using a topic named orders:
# Read history and exit at the current end
kafkactl consume orders --from-beginning --exit
# Start at a timestamp
kafkactl consume orders --from-timestamp 2026-09-28T00:00:00Z
# Stop after 10 records, printed as JSON
kafkactl consume orders --from-beginning --max-messages 10 -o json
# Send one keyed record with a header
kafkactl produce orders --key=order-1 --value=hello --header source:manual
Coming from kcat
| Task | kcat | kafkactl |
|---|---|---|
| Follow a topic from the beginning | kcat -b localhost:9092 -t orders -C -o beginning |
kafkactl consume orders --from-beginning |
| Read history and exit | kcat -b localhost:9092 -t orders -C -o beginning -e |
kafkactl consume orders --from-beginning --exit |
| Print records as JSON | kcat -b localhost:9092 -t orders -C -J |
kafkactl consume orders -o json |
| List topics | kcat -b localhost:9092 -L |
kafkactl get topics |
kafkactl reads brokers from the current context, so there is no -b. Also, kafkactl -o json does not follow kcat's -J field layout. Before you switch a script that parses kcat output, check how kafkactl prints null values, binary payloads, and headers.
Two features worth knowing
Kubernetes mode. If your brokers are reachable only from inside a Kubernetes cluster, kafkactl can run each command in a pod through kubectl. You keep typing the same commands on your laptop.
Passwords in the OS keyring. If a required credential is missing from the config file and environment, kafkactl prompts for it in the terminal. By default, after the command succeeds, it stores the credential in Keychain on macOS, GNOME Keyring on Linux, or Credential Manager on Windows, so it does not end up in plaintext in the config file. After a password rotation, run the command with --clear-keyring to clear the stored credential and be prompted again.
Check these two gaps first
-
Protobuf decoding needs local files. kafkactl decodes Avro and JSON Schema through Schema Registry, but Protobuf needs local
.protofiles or a protoset. - AWS MSK IAM needs a plugin. It works through the separate AWS plugin rather than out of the box.
If either one is central to your work, kcl supports both natively.
Is the project active?
As of 28 September 2026, kafkactl had shipped 8 releases in the previous 12 months, the latest being v5.20.0 on 30 July 2026, with 87 commits from 8 authors over the same period. It had 2,394 Homebrew installs in the year to that date and is licensed under Apache-2.0.
One caveat: a single account merged all of its pull requests in those 12 months, so review capacity rests on one maintainer. For the same metrics across kcat, kaf, kcl, and Confluent CLI, see the GitHub repository metrics in the full comparison.
When a terminal is not enough
kafkactl is the right tool for scripts, CI jobs, and quick checks. When an investigation means reading many records and moving between topics, schemas, and consumer groups, a Kafka GUI client such as Kafma connects to the same clusters, including over SASL, TLS, and AWS MSK IAM, and decodes Avro, Protobuf, and JSON Schema through Schema Registry without local .proto files.
Written by the team behind Kafma.
Top comments (0)