At a glance
AKHQ and CMAK are scored here on the same five criteria, 50 points in all: AKHQ 37 out of 50, CMAK 20 out of 50. AKHQ takes its best score on Cost as teams grow (10 out of 10) and its lowest on Support and maintenance (5 out of 10). Cost a year, modelled: 8,640 US dollars, no licence fee. CMAK takes its best score on Cost as teams grow (10 out of 10) and its lowest on Support and maintenance (1 out of 10). Cost a year, modelled: 11,520 US dollars, no licence fee.
AKHQ vs CMAK, compared
Kpow meets 7 of 8 requirements on this page.
Key takeaway
AKHQ and CMAK are both free under Apache 2.0, self-hosted, with no paid tier on either side, so this is not a price comparison. AKHQ is live, shipping 0.28.0 in August 2026; CMAK last released 3.0.0.6 in April 2022 and needs a direct ZooKeeper connection Kafka 4.0 does not have, so a KRaft cutover ends it the day it lands. AKHQ also drops partition reassignment and JMX metrics, both of which CMAK keeps. Kpow by Factor House is licensed per cluster from 4,500 US dollars a year, with 100 users included.
Kpow live demo
Test the trade-offs in a live Kafka UI
You have compared AKHQ vs CMAK. Open a live Kpow environment to test the everyday workflows a shared Kafka platform needs.
Built for platform and data teams managing shared Kafka clusters.
Try the Kpow demoWhat is AKHQ?
AKHQ is an open-source Kafka management console under Apache 2.0, formerly KafkaHQ, self-hosted, JVM-based and built on Micronaut. One deployment reaches one cluster or many. It reaches a cluster through bootstrap.servers and the ordinary Kafka client properties, with security.protocol, the SASL settings and the SSL stores alongside them. No ZooKeeper property appears anywhere in its cluster connection reference.
- topic browsing, live tailing and producing records
- consumer groups, Schema Registry and Kafka Connect
- ACL management, and role-based access with LDAP and OIDC
- 0.28.0 in August 2026, after 0.27.1 in May and 0.27.0 in March
The commit record is concentrated: the lead maintainer has 441 commits and the next human contributor has 82. The README opens with a block promoting Kestra, the maintainer’s orchestration platform. There is no commercial edition and no feature held back from the open release.

What is CMAK?
CMAK is the Cluster Manager for Apache Kafka, originally Kafka Manager, built at Yahoo and released under Apache 2.0. It is written in Scala on the Play framework, and it requires a direct connection to a ZooKeeper ensemble to function at all. Its scope is administrative rather than data-plane, and multi-cluster registration from a single view is what it was built to do.
- partition reassignment and preferred-replica election
- dynamic topic configuration, partition creation and replica change
- optional JMX polling at broker and topic level
- 3.0.0.6 in April 2022, last commit December 2022, 522 issues open
The repository is public and it is not archived.

What is the official 2026 pricing of AKHQ and CMAK?
Neither project charges anything, so the whole comparison is carry cost, and carry is not the same on both sides. AKHQ is a JVM service somebody sizes, deploys and reads an issue tracker for before upgrading, and its configuration is YAML under Helm, so the cluster list, the users, the groups and the registry links sit in source control. CMAK is distributed as source and expects an sbt and Scala build, its container images are community-maintained, and the only Kubernetes chart was archived by its owner in March 2026.
At five engineers who all hold cluster credentials anyway, free is genuinely free on either side. At fifty, most of whom should never touch a broker, the carry becomes a job: an upgrade path, an access model, and an answer for the morning the console is the thing that is down. Neither has an SLA. The difference is that a report against AKHQ lands in a tracker that gets triaged, and a report against CMAK joins 522 others.
Where does each one run out?
Both tools are marked out of 10 on the same five criteria, for a total out of 50, and every criterion counts once. Nothing sits behind a multiplier, so a total is the sum of its five marks and a reader can recompute it. The five are cost as teams grow, deployment footprint, support and maintenance, access control and audit, and multi-cluster reach, because those are the questions a Kafka interface is actually measured against after the first month: a second cluster, an access review with a date on it, an upgrade nobody owns, and a bill that moves when the team does. The widest gap between the two marks is on deployment footprint, where AKHQ marks 8 and CMAK marks 3. The marks come from the same matrix used on every comparison on this site, so a tool scores the same here as it does anywhere else, and the reason behind each mark is in the card below, under Why these scores.
The dependency figures in the cards below were read on 24 September 2026 from each project’s published release artefact and matched against the NVD and GitHub advisory databases, so they move whenever a release or an advisory lands. Every jar AKHQ ships resolves to a Maven coordinate, while 109 of CMAK’s 112 do, so CMAK’s figure is a floor rather than a total and the two counts do not rank each other. Kpow is self-hosted as well. What a licence buys here is not a different deployment model, it is a company under contract to ship the patched build.
Rank 1 AKHQ
37 out of 50 Total
- Cost a year, modelled
- 8,640 US dollars, no licence fee
- Newest release
- 0.28.0, August 2026
- Cluster operations
- Partition increase only
- Cost as teams grow
- 10 out of 10
- Deployment footprint
- 8 out of 10
- Support and maintenance
- 5 out of 10
- Access control and audit
- 5 out of 10
- Multi-cluster reach
- 9 out of 10
Why these scores for AKHQ
- Cost as teams grow 10 out of 10
- The compare figure gives Apache 2.0, free, no paid tier and no hosted option, the same 10 as CMAK on this page. This page’s modelled cost of ownership is about 8,640 US dollars a year at 6 engineer-hours a month and 120 US dollars an hour; the 10 is for the bill not moving as the team grows, not for total cost.
- Deployment footprint 8 out of 10
- The compare figure gives a JVM service configured as YAML under Helm, against CMAK’s sbt and Scala source build.
- Support and maintenance 5 out of 10
- The compare figure gives a triaged tracker and three releases in the eight months to August 2026, but no SLA and no commercial tier.
- Access control and audit 5 out of 10
- The compare figure gives LDAP, OIDC, HTTP basic and claim mapping, with an opt-in audit topic and masking that does not vary by who is looking.
- Multi-cluster reach 9 out of 10
- On this page, one deployment reaches one cluster or many, through bootstrap.servers and the ordinary client properties.
This page's cost estimate: no licence fee, and about 6 engineer-hours a month to size the JVM, keep the Helm YAML current and read a tracker that gets triaged, at 120 US dollars an hour, is about 8,640 US dollars a year.
AKHQ’s governance is present but shallow. Data masking takes four modes, configured globally in the application YAML and keyed on topic and field path, so what is hidden does not vary by who is looking, and only one filter per topic is supported. Audit logging is opt-in and writes to a Kafka topic the operator nominates, with no audit view inside the product.
Audit scope: modifications only, including record produce, delete and empty topic since 0.28.0. Reads are not covered.
Memory: a constantly-increasing-memory report open since July 2022, and a second since May 2025.
OIDC: the most active failure surface in the tracker, with new defects still arriving in August 2026.
Metrics: no JMX visualisation and no alerting, so a Kafka dashboard comes from elsewhere.
Staying patched: release 0.28.0, cut on 6 August 2026, bundles 270 libraries and 18 of them carry a high or critical advisory. Sixteen of the eighteen were already public, with fixed versions already on Maven Central, on the day it shipped, and five of those are netty CVEs Kpow had already remediated in release 96.2 three weeks earlier: CVE-2026-44249, CVE-2026-45416, CVE-2026-45674, CVE-2026-47691 and CVE-2026-50010. The oldest has been open 108 days. Every jar AKHQ ships resolves to a coordinate, so this is a complete count rather than a floor, and each identifier can be checked at nvd.nist.gov. A shipped vulnerable library is exposure and remediation latency, not a working attack.
20 out of 50 Total
- Cost a year, modelled
- 11,520 US dollars, no licence fee
- Newest release
- 3.0.0.6, April 2022
- Needs to run
- A direct ZooKeeper connection
- Cost as teams grow
- 10 out of 10
- Deployment footprint
- 3 out of 10
- Support and maintenance
- 1 out of 10
- Access control and audit
- 2 out of 10
- Multi-cluster reach
- 4 out of 10
Why these scores for CMAK
- Cost as teams grow 10 out of 10
- The compare figure gives Apache 2.0, free, no paid tier. The bill is the same as AKHQ’s; the carry is not. This page’s modelled cost of ownership is about 11,520 US dollars a year at 8 engineer-hours a month and 120 US dollars an hour; the 10 is for the bill not moving as the team grows, not for total cost.
- Deployment footprint 3 out of 10
- The compare figure has it distributed as source with an sbt and Scala build, community-maintained images, and the only Kubernetes chart archived in March 2026.
- Support and maintenance 1 out of 10
- The compare figure gives the last release in April 2022, the last commit in December 2022, and 522 issues open with no triage since 2022.
- Access control and audit 2 out of 10
- The compare figure gives LDAP basic auth and coarse global feature flags, no SAML, no OIDC, no per-topic granularity and no audit log.
- Multi-cluster reach 4 out of 10
- On this page, multi-cluster registration from one view is what it was built to do, but it reaches only clusters still exposing a ZooKeeper endpoint.
This page's cost estimate: no licence fee, and about 8 engineer-hours a month to own the sbt and Scala build, the community-maintained images and a tracker holding 522 issues with no triage since 2022, at 120 US dollars an hour, is about 11,520 US dollars a year, and the KRaft cutover ends it.
CMAK’s ZooKeeper dependency is the whole clock. KIP-500 replaced the ensemble with a self-managed metadata quorum and KIP-833 set its removal for Kafka 4.0, which shipped in March 2025. CMAK talks to the ensemble directly, so on a KRaft cluster there is nothing for it to connect to. Managed services have already closed or stopped exposing ZooKeeper endpoints.
Message browsing: absent, so there is no way to query a Kafka topic from the interface.
Freshness: reads come from an internal cache rather than live broker APIs, so a change does not appear immediately.
Access control: LDAP basic auth and coarse global feature flags, with no SAML, no OIDC and no per-topic granularity.
Transport: LDAP is unencrypted unless SSL is configured, which the README states.
CMAK has no audit log, and enabling ZooKeeper ACLs breaks its connection entirely. Both are limits on any Kafka security architecture that assumes the console sits inside the perimeter.
Staying patched: the last release is from April 2022 and nothing has been committed since August 2023. It bundles ZooKeeper 3.5.7, carrying an authorization bypass that scores 9.1 and has been public since October 2023, 1,079 days. No release is coming to carry a fix. 109 of its 112 bundled jars resolve to a Maven coordinate, so its counts are floors rather than totals.
Which should you pick?
AKHQ is the pick of these two for any cluster with a KRaft cutover ahead, because CMAK reads Kafka through ZooKeeper and Kafka 4.0 has none. CMAK is worth keeping only while partition reassignment on a ZooKeeper cluster is the job in front of you. Both are volunteer-maintained with nobody under contract, so a team that needs a vendor to ship the patched build should shortlist Kpow by Factor House.
Pick AKHQ if:
- the cluster is on KRaft, or heading there
- the daily work is message browsing, live tailing and consumer group inspection
- the tool is for engineers who already hold cluster access
- RBAC for Kafka has to line up with an identity provider that already exists
Keep CMAK, with a date on it, if:
- the cluster is still on ZooKeeper
- the daily work is partition reassignment and preferred-replica election
- the KRaft cutover is already in a migration plan somebody owns
Whichever way it goes, the reassignment console does not come across. AKHQ can increase a topic’s partition count, but it has no reassignment, no replica change and no JMX metrics, which are the operations CMAK is best at. Moving means reassignment goes back to kafka-reassign-partitions.sh or to something like Cruise Control, which is ranked against the rest of the field in Kafka partition rebalancing tools, and Kafka broker monitoring goes to whatever already scrapes JMX. Both tools sit on every list of best free Kafka UI tools, and free is a statement about the invoice rather than about the cost.
Kpow: no rota to run
Neither AKHQ nor CMAK has anybody behind it, so the cost of running either one is a rota rather than an invoice, and that rota only gets longer as the cluster count grows: someone sizes and reads the tracker for the JVM before an upgrade, someone owns the Scala build, and someone is the answer for the morning the console itself is down. Kpow by Factor House is licensed per cluster instead, from 4,500 US dollars a year with 100 users included: one stateless JVM container, with no external database and no persistent volume, running against a cluster you already operate. One instance manages up to 12 clusters, so the person on call does not multiply the way the rota does on either of these.
The rota doesn’t have to be the plan. Starting Kpow against one of your clusters is the way to find out how much shorter it gets.

How these tools were scored
Every option is scored from 0 to 10 on each criterion, from the evidence and sources this page cites, and the reason for each score is on its card. Each criterion counts once, for a total out of 50. The options are listed by total.
Sources
- KIP-500: Replace ZooKeeper with a Self-Managed Metadata Quorum
- KIP-833: Mark KRaft as Production Ready