Skip to content

AKHQ vs CMAK

Comparisons
Karel Sague·August 29, 2026·6 min read·Updated

At a glance

AKHQ and CMAK are scored here on the same five criteria, 50 points in all: AKHQ 37 out of 50, CMAK 20 out of 50. AKHQ takes its best score on Cost as teams grow (10 out of 10) and its lowest on Support and maintenance (5 out of 10). Cost a year, modelled: 8,640 US dollars, no licence fee. CMAK takes its best score on Cost as teams grow (10 out of 10) and its lowest on Support and maintenance (1 out of 10). Cost a year, modelled: 11,520 US dollars, no licence fee.

AKHQ vs CMAK, compared

F1 Kpow, AKHQ and CMAK, side by side
Kpow AKHQ CMAK
Newest published releaseIs the tool still being released?Yes. Version 96.4 in August 2026, after 96.3 and 96.2 in July, on a dated public changelog. Yes. 0.28.0 in August 2026, after 0.27.1 in May and 0.27.0 in March. No. 3.0.0.6 in April 2022. Last commit December 2022.
What it connects toDoes it connect with ordinary Kafka client properties rather than ZooKeeper?Yes. Ordinary Kafka client properties against self-managed Kafka, Amazon MSK, Confluent Platform and Cloud, Redpanda, Aiven, NetApp Instaclustr, Google Cloud MSK and Bufstream. Yes. bootstrap.servers and the ordinary Kafka client properties. No ZooKeeper property appears in the connection reference. No. A direct ZooKeeper connection. Kafka 4.0 runs no ensemble.
DeploymentDoes it ship as a maintained container image?Yes. A single stateless container, by Docker, a Kubernetes Helm chart, ECS, Fargate or a JAR, with no external database and no persistent volume. Yes. A JVM service, configured as YAML under Helm. No. Distributed as source, with an sbt and Scala build. Images are community-maintained and the only Kubernetes chart was archived in March 2026.
Cluster operationsCan it change broker and topic configuration, not only add partitions?Yes. Create, copy, delete and reconfigure topics, edit broker configuration, manage ACLs and manage or reset consumer offsets, with staged approval workflows gating mutations on Enterprise. No. Partition increase. No replica change, no reassignment and no JMX metrics. Yes. Partition reassignment, preferred-replica election, dynamic topic configuration and optional JMX polling.
Access controlDoes it offer SSO and per-resource access control?Yes. LDAP, SAML, OpenID and OAuth2, with Okta, Microsoft Entra ID, Keycloak and AWS SSO named, plus role based access control at the global and the resource level. Enterprise. Yes. LDAP, OIDC, HTTP basic, and external role and attribute claim mapping. No. LDAP basic auth and coarse global feature flags. No SAML, no OIDC and no per-topic granularity.
Audit logIs every user action recorded?Yes. Every user action on every cluster, recording who asked, what the request held and whether RBAC allowed it, readable in the UI or piped out as a webhook or a Kafka topic. Enterprise. No. Opt-in, written to a Kafka topic the operator nominates. Covers modifications. No. None in the product.
Issue trackerIs there a support channel under contract?Yes. Email support and an Enterprise support SLA, with priority support on Enterprise, and a community Slack channel and GitHub issues on both editions. No. Triaged, with three releases in the eight months to August 2026. No. 522 issues open, with no triage since 2022.
Licence and priceIs the software free to use at any team size?No. No. Community Edition is free at up to 3 clusters and 10 users, and Enterprise is a commercial licence starting at 4,500 US dollars per cluster per year. Yes. Apache 2.0, free, no paid tier, no hosted option and no commercial support. Yes. Apache 2.0, free, no paid tier, no hosted option and no commercial support.

Kpow meets 7 of 8 requirements on this page.

Both projects as published in August 2026. Kpow is Factor House's product and is listed first. Its marks answer the same requirement as the other two columns.

Key takeaway

AKHQ and CMAK are both free under Apache 2.0, self-hosted, with no paid tier on either side, so this is not a price comparison. AKHQ is live, shipping 0.28.0 in August 2026; CMAK last released 3.0.0.6 in April 2022 and needs a direct ZooKeeper connection Kafka 4.0 does not have, so a KRaft cutover ends it the day it lands. AKHQ also drops partition reassignment and JMX metrics, both of which CMAK keeps. Kpow by Factor House is licensed per cluster from 4,500 US dollars a year, with 100 users included.

Kpow live demo

Test the trade-offs in a live Kafka UI

You have compared AKHQ vs CMAK. Open a live Kpow environment to test the everyday workflows a shared Kafka platform needs.

Built for platform and data teams managing shared Kafka clusters.

Try the Kpow demo

What is AKHQ?

AKHQ is an open-source Kafka management console under Apache 2.0, formerly KafkaHQ, self-hosted, JVM-based and built on Micronaut. One deployment reaches one cluster or many. It reaches a cluster through bootstrap.servers and the ordinary Kafka client properties, with security.protocol, the SASL settings and the SSL stores alongside them. No ZooKeeper property appears anywhere in its cluster connection reference.

  • topic browsing, live tailing and producing records
  • consumer groups, Schema Registry and Kafka Connect
  • ACL management, and role-based access with LDAP and OIDC
  • 0.28.0 in August 2026, after 0.27.1 in May and 0.27.0 in March

The commit record is concentrated: the lead maintainer has 441 commits and the next human contributor has 82. The README opens with a block promoting Kestra, the maintainer’s orchestration platform. There is no commercial edition and no feature held back from the open release.

AKHQ

What is CMAK?

CMAK is the Cluster Manager for Apache Kafka, originally Kafka Manager, built at Yahoo and released under Apache 2.0. It is written in Scala on the Play framework, and it requires a direct connection to a ZooKeeper ensemble to function at all. Its scope is administrative rather than data-plane, and multi-cluster registration from a single view is what it was built to do.

  • partition reassignment and preferred-replica election
  • dynamic topic configuration, partition creation and replica change
  • optional JMX polling at broker and topic level
  • 3.0.0.6 in April 2022, last commit December 2022, 522 issues open

The repository is public and it is not archived.

CMAK

What is the official 2026 pricing of AKHQ and CMAK?

Neither project charges anything, so the whole comparison is carry cost, and carry is not the same on both sides. AKHQ is a JVM service somebody sizes, deploys and reads an issue tracker for before upgrading, and its configuration is YAML under Helm, so the cluster list, the users, the groups and the registry links sit in source control. CMAK is distributed as source and expects an sbt and Scala build, its container images are community-maintained, and the only Kubernetes chart was archived by its owner in March 2026.

At five engineers who all hold cluster credentials anyway, free is genuinely free on either side. At fifty, most of whom should never touch a broker, the carry becomes a job: an upgrade path, an access model, and an answer for the morning the console is the thing that is down. Neither has an SLA. The difference is that a report against AKHQ lands in a tracker that gets triaged, and a report against CMAK joins 522 others.

Where does each one run out?

Both tools are marked out of 10 on the same five criteria, for a total out of 50, and every criterion counts once. Nothing sits behind a multiplier, so a total is the sum of its five marks and a reader can recompute it. The five are cost as teams grow, deployment footprint, support and maintenance, access control and audit, and multi-cluster reach, because those are the questions a Kafka interface is actually measured against after the first month: a second cluster, an access review with a date on it, an upgrade nobody owns, and a bill that moves when the team does. The widest gap between the two marks is on deployment footprint, where AKHQ marks 8 and CMAK marks 3. The marks come from the same matrix used on every comparison on this site, so a tool scores the same here as it does anywhere else, and the reason behind each mark is in the card below, under Why these scores.

The dependency figures in the cards below were read on 24 September 2026 from each project’s published release artefact and matched against the NVD and GitHub advisory databases, so they move whenever a release or an advisory lands. Every jar AKHQ ships resolves to a Maven coordinate, while 109 of CMAK’s 112 do, so CMAK’s figure is a floor rather than a total and the two counts do not rank each other. Kpow is self-hosted as well. What a licence buys here is not a different deployment model, it is a company under contract to ship the patched build.

Rank 1

AKHQ

akhq.io

37 out of 50 Total

Cost a year, modelled
8,640 US dollars, no licence fee
Newest release
0.28.0, August 2026
Cluster operations
Partition increase only
Cost as teams grow
10 out of 10
Deployment footprint
8 out of 10
Support and maintenance
5 out of 10
Access control and audit
5 out of 10
Multi-cluster reach
9 out of 10
Why these scores for AKHQ
Cost as teams grow 10 out of 10
The compare figure gives Apache 2.0, free, no paid tier and no hosted option, the same 10 as CMAK on this page. This page’s modelled cost of ownership is about 8,640 US dollars a year at 6 engineer-hours a month and 120 US dollars an hour; the 10 is for the bill not moving as the team grows, not for total cost.
Deployment footprint 8 out of 10
The compare figure gives a JVM service configured as YAML under Helm, against CMAK’s sbt and Scala source build.
Support and maintenance 5 out of 10
The compare figure gives a triaged tracker and three releases in the eight months to August 2026, but no SLA and no commercial tier.
Access control and audit 5 out of 10
The compare figure gives LDAP, OIDC, HTTP basic and claim mapping, with an opt-in audit topic and masking that does not vary by who is looking.
Multi-cluster reach 9 out of 10
On this page, one deployment reaches one cluster or many, through bootstrap.servers and the ordinary client properties.

This page's cost estimate: no licence fee, and about 6 engineer-hours a month to size the JVM, keep the Helm YAML current and read a tracker that gets triaged, at 120 US dollars an hour, is about 8,640 US dollars a year.

AKHQ’s governance is present but shallow. Data masking takes four modes, configured globally in the application YAML and keyed on topic and field path, so what is hidden does not vary by who is looking, and only one filter per topic is supported. Audit logging is opt-in and writes to a Kafka topic the operator nominates, with no audit view inside the product.

Audit scope: modifications only, including record produce, delete and empty topic since 0.28.0. Reads are not covered.

Memory: a constantly-increasing-memory report open since July 2022, and a second since May 2025.

OIDC: the most active failure surface in the tracker, with new defects still arriving in August 2026.

Metrics: no JMX visualisation and no alerting, so a Kafka dashboard comes from elsewhere.

Staying patched: release 0.28.0, cut on 6 August 2026, bundles 270 libraries and 18 of them carry a high or critical advisory. Sixteen of the eighteen were already public, with fixed versions already on Maven Central, on the day it shipped, and five of those are netty CVEs Kpow had already remediated in release 96.2 three weeks earlier: CVE-2026-44249, CVE-2026-45416, CVE-2026-45674, CVE-2026-47691 and CVE-2026-50010. The oldest has been open 108 days. Every jar AKHQ ships resolves to a coordinate, so this is a complete count rather than a floor, and each identifier can be checked at nvd.nist.gov. A shipped vulnerable library is exposure and remediation latency, not a working attack.

Rank 2

20 out of 50 Total

Cost a year, modelled
11,520 US dollars, no licence fee
Newest release
3.0.0.6, April 2022
Needs to run
A direct ZooKeeper connection
Cost as teams grow
10 out of 10
Deployment footprint
3 out of 10
Support and maintenance
1 out of 10
Access control and audit
2 out of 10
Multi-cluster reach
4 out of 10
Why these scores for CMAK
Cost as teams grow 10 out of 10
The compare figure gives Apache 2.0, free, no paid tier. The bill is the same as AKHQ’s; the carry is not. This page’s modelled cost of ownership is about 11,520 US dollars a year at 8 engineer-hours a month and 120 US dollars an hour; the 10 is for the bill not moving as the team grows, not for total cost.
Deployment footprint 3 out of 10
The compare figure has it distributed as source with an sbt and Scala build, community-maintained images, and the only Kubernetes chart archived in March 2026.
Support and maintenance 1 out of 10
The compare figure gives the last release in April 2022, the last commit in December 2022, and 522 issues open with no triage since 2022.
Access control and audit 2 out of 10
The compare figure gives LDAP basic auth and coarse global feature flags, no SAML, no OIDC, no per-topic granularity and no audit log.
Multi-cluster reach 4 out of 10
On this page, multi-cluster registration from one view is what it was built to do, but it reaches only clusters still exposing a ZooKeeper endpoint.

This page's cost estimate: no licence fee, and about 8 engineer-hours a month to own the sbt and Scala build, the community-maintained images and a tracker holding 522 issues with no triage since 2022, at 120 US dollars an hour, is about 11,520 US dollars a year, and the KRaft cutover ends it.

CMAK’s ZooKeeper dependency is the whole clock. KIP-500 replaced the ensemble with a self-managed metadata quorum and KIP-833 set its removal for Kafka 4.0, which shipped in March 2025. CMAK talks to the ensemble directly, so on a KRaft cluster there is nothing for it to connect to. Managed services have already closed or stopped exposing ZooKeeper endpoints.

Message browsing: absent, so there is no way to query a Kafka topic from the interface.

Freshness: reads come from an internal cache rather than live broker APIs, so a change does not appear immediately.

Access control: LDAP basic auth and coarse global feature flags, with no SAML, no OIDC and no per-topic granularity.

Transport: LDAP is unencrypted unless SSL is configured, which the README states.

CMAK has no audit log, and enabling ZooKeeper ACLs breaks its connection entirely. Both are limits on any Kafka security architecture that assumes the console sits inside the perimeter.

Staying patched: the last release is from April 2022 and nothing has been committed since August 2023. It bundles ZooKeeper 3.5.7, carrying an authorization bypass that scores 9.1 and has been public since October 2023, 1,079 days. No release is coming to carry a fix. 109 of its 112 bundled jars resolve to a Maven coordinate, so its counts are floors rather than totals.

Which should you pick?

AKHQ is the pick of these two for any cluster with a KRaft cutover ahead, because CMAK reads Kafka through ZooKeeper and Kafka 4.0 has none. CMAK is worth keeping only while partition reassignment on a ZooKeeper cluster is the job in front of you. Both are volunteer-maintained with nobody under contract, so a team that needs a vendor to ship the patched build should shortlist Kpow by Factor House.

Pick AKHQ if:

  • the cluster is on KRaft, or heading there
  • the daily work is message browsing, live tailing and consumer group inspection
  • the tool is for engineers who already hold cluster access
  • RBAC for Kafka has to line up with an identity provider that already exists

Keep CMAK, with a date on it, if:

  • the cluster is still on ZooKeeper
  • the daily work is partition reassignment and preferred-replica election
  • the KRaft cutover is already in a migration plan somebody owns

Whichever way it goes, the reassignment console does not come across. AKHQ can increase a topic’s partition count, but it has no reassignment, no replica change and no JMX metrics, which are the operations CMAK is best at. Moving means reassignment goes back to kafka-reassign-partitions.sh or to something like Cruise Control, which is ranked against the rest of the field in Kafka partition rebalancing tools, and Kafka broker monitoring goes to whatever already scrapes JMX. Both tools sit on every list of best free Kafka UI tools, and free is a statement about the invoice rather than about the cost.

Kpow: no rota to run

Neither AKHQ nor CMAK has anybody behind it, so the cost of running either one is a rota rather than an invoice, and that rota only gets longer as the cluster count grows: someone sizes and reads the tracker for the JVM before an upgrade, someone owns the Scala build, and someone is the answer for the morning the console itself is down. Kpow by Factor House is licensed per cluster instead, from 4,500 US dollars a year with 100 users included: one stateless JVM container, with no external database and no persistent volume, running against a cluster you already operate. One instance manages up to 12 clusters, so the person on call does not multiply the way the rota does on either of these.

The rota doesn’t have to be the plan. Starting Kpow against one of your clusters is the way to find out how much shorter it gets.

Kpow

How these tools were scored

Every option is scored from 0 to 10 on each criterion, from the evidence and sources this page cites, and the reason for each score is on its card. Each criterion counts once, for a total out of 50. The options are listed by total.

Sources

Related reading