Saturday, October 10, 2026 Newsletter Advertise
Latest
Products news

AWS Lambda Adds OAuth Support for Apache Kafka Event Sources

Amazon Web Services now allows developers to authenticate Lambda Kafka consumers via enterprise identity providers.

AWS Lambda Adds OAuth Support for Apache Kafka Event Sources. Source: Amazon Web Services

Amazon Web Services announced on October 9, 2026, that AWS Lambda now supports OAuth authentication for self-managed Apache Kafka event source mappings. The update allows customers to connect their Kafka consumers using enterprise identity providers.

OAuth Authentication for Kafka ESM

AWS stated that Lambda now supports OAuth authentication for self-managed Apache Kafka event source mappings (ESM). This includes Kafka clusters that customers run themselves as well as managed offerings such as Confluent Cloud, Aiven, and Redpanda.

According to AWS, previously supported authentication methods were limited to SASL/PLAIN, SASL/SCRAM, and mutual TLS (mTLS). With the new integration, customers can use enterprise identity providers like Amazon Cognito or Okta to authenticate their Kafka ESM.

Availability and Setup

AWS reported that the capability is available in all AWS commercial Regions where self-managed Kafka ESM is supported. Users can apply identity governance and access policies across their Kafka clusters and Lambda consumers.

To use the feature, customers can create a new Kafka ESM with their authentication configuration through the AWS Management Console, Lambda API, AWS CLI, AWS CloudFormation, or AWS SAM.

What to do

  • Create a new Kafka ESM with your authentication configuration through the AWS Management Console, Lambda API, AWS CLI, AWS CloudFormation, or AWS SAM.
Key facts and where they come from
  • AWS Lambda now supports OAuth authentication for self-managed Apache Kafka event source mappings.
    AWS Lambda now supports OAuth authentication for self-managed Apache Kafka event source mappings (ESM)
  • Managed offerings supported include Confluent Cloud, Aiven, and Redpanda.
    managed offerings such as Confluent Cloud, Aiven, and Redpanda.
  • Previously supported authentication methods were limited to SASL/PLAIN, SASL/SCRAM, and mutual TLS.
    Previously, Kafka ESM supported only SASL/PLAIN, SASL/SCRAM, and mutual TLS (mTLS) as authentication methods
  • Enterprise identity providers can include Amazon Cognito or Okta.
    enterprise identity provider, such as Amazon Cognito or Okta

Read the original from Amazon Web Services →

The TechUpscale Brief

The day's cyber, AI and tech news in one short email, every weekday morning. Free. Unsubscribe anytime.

I'm most interested in

More Products