At a glance
Offset Explorer and CMAK are scored here on the same five criteria, 50 points in all: Offset Explorer 26 out of 50, CMAK 20 out of 50. Offset Explorer takes its best score on Deployment footprint (7 out of 10) and its lowest on Access control and audit (1 out of 10). Cost a year, 50 users: $5,950 licences, $24,670 this page's estimate. CMAK takes its best score on Cost as teams grow (10 out of 10) and its lowest on Support and maintenance (1 out of 10). Cost a year, modelled: $0 licence, $18,720 to run.
CMAK vs Offset Explorer, compared
Kpow meets 6 of 7 requirements on this page. One row is not a yes or no question.
Key takeaway
CMAK is a server-side console deployed once for a team, while Offset Explorer installs on each engineer’s own machine, and that is the real difference, not the feature lists. CMAK requires a ZooKeeper connection Kafka 4.0 does not have, and its last release was tagged in April 2022. Offset Explorer is licensed per named user from 139 US dollars, plus 46 a year after the first, and neither tool authenticates a person at all. Kpow by Factor House is licensed per cluster at a published price.
Kpow live demo
Test the trade-offs in a live Kafka UI
You have compared CMAK vs Offset Explorer. Open a live Kpow environment to test the everyday workflows a shared Kafka platform needs.
Built for platform and data teams managing shared Kafka clusters.
Try the Kpow demoWhat is CMAK?
CMAK is the Cluster Manager for Apache Kafka, originally Kafka Manager, built at Yahoo and released under Apache 2.0. It is a Scala and Play web application, deployed on a server or in a container, holding a direct connection to a ZooKeeper ensemble. Its scope is that of a Kafka management console rather than a data browser, and there is no commercial distribution, no hosted offering and no paid support tier.
- registering and monitoring several clusters from one view
- creating and modifying topics, and managing partitions
- preferred-replica election and partition reassignment
- optional JMX polling at broker and topic level
The last stable release, 3.0.0.6, was tagged on 29 April 2022, and 3.0.0.5 before it in June 2020, so the silence since continues a cadence that had already stopped. The last commit on master is December 2022 and the last push of any kind is August 2023. There are 522 open issues with nobody triaging them. The repository is public and it is not archived.

What is Offset Explorer?
Offset Explorer is a GUI application for managing and using Apache Kafka clusters, installed on an engineer’s own machine rather than deployed as a service, on Windows, macOS or Linux. It was renamed from Kafka Tool, and the two names are one product. It is built by DB Solo, LLC, licensed per named user, and reaches Apache Kafka 0.11 and above.
- Payloads: rendered as hex or UTF-8, with text pretty-printed as JSON or XML.
- Search: string, binary, Avro, Protobuf, JSON Schema, regular expressions and JsonPath.
- Integrations: Schema Registry, Kafka Connect and ksqlDB, alongside import and export tools.
- Recent versions: 4.0 added Protobuf and OAuth, 4.0.3 added KRaft quorum support, and 4.0.4 added Compare Clusters.
The vendor publishes a change history, and that history carries no date against any version.

What is the official 2026 pricing of CMAK and Offset Explorer?
Offset Explorer is licensed per named user. Personal use is free with no time limit; commercial, educational and non-profit use gets a 30-day evaluation, and after that the published ladder steps the per-seat price down as the count goes up. A machine several people share needs a licence for each person on it. Five engineers is five licences at 139 US dollars each. Fifty is fifty, in the 119 band, plus fifty renewals a year later, and the fifty-first engineer is a purchase order rather than a download.
CMAK charges nothing, and what a team carries instead is the absence of a vendor. Both community deployment paths are now archived and read-only: the Helm chart that was the only Kubernetes route, and the community Docker image. A Kubernetes install therefore runs an unmaintained chart pointing at an unmaintained application, and there is nobody to escalate to when either stops working. The cap on the free side is not money at all. It is which clusters CMAK can address.
Where does each one run out?
The scoring is the same on both sides: five criteria, 10 points each, 50 in all, with every criterion counting once. Nothing sits behind a multiplier, so a total is the sum of its five marks and a reader can recompute it. The five are cost as teams grow, deployment footprint, support and maintenance, access control and audit, and multi-cluster reach, because those are the questions a Kafka interface is actually measured against after the first month: a second cluster, an access review with a date on it, an upgrade nobody owns, and a bill that moves when the team does. The widest gap between the two marks is on cost as teams grow, where CMAK marks 10 and Offset Explorer marks 5. The marks come from the same matrix used on every comparison on this site, so a tool scores the same here as it does anywhere else, and the reason behind each mark is in the card below, under Why these scores.
The dependency figures in the cards below were read on 24 September 2026 from each project’s published release artefact and matched against the NVD and GitHub advisory databases, so they move whenever a release or an advisory lands. Running it yourself is common to both. What differs is whether somebody is contracted to produce the fix.
Rank 1 Offset Explorer
kafkatool.com
26 out of 50 Total
- Cost a year, 50 users
- $5,950 licences, $24,670 this page's estimate
- Free use
- Personal only; 30 days otherwise
- Runs on
- Each engineer's own desktop
- Cost as teams grow
- 5 out of 10
- Deployment footprint
- 7 out of 10
- Support and maintenance
- 6 out of 10
- Access control and audit
- 1 out of 10
- Multi-cluster reach
- 7 out of 10
Why these scores for Offset Explorer
- Cost as teams grow 5 out of 10
- This page’s table prices it per named user, $139 each at 1 to 10, $128 at 11 to 20 and $119 at 21 to 50, so fifty licences is $5,950 in year one and $2,300 in renewals; with this page’s estimated $18,720 of workstation and audit work that is $24,670, against $18,000 for Kpow Enterprise on four clusters.
- Deployment footprint 7 out of 10
- This page gives nothing server-side, an installed desktop application on each machine, but the Linux build ships no JRE, so Java 21 or later has to be installed first.
- Support and maintenance 6 out of 10
- This page’s table gives DB Solo, LLC by email and phone, 365 days included at purchase, then $46 per licence a year.
- Access control and audit 1 out of 10
- On this page, the documented authentication is client to broker, so the application holds no user identity, and there is no shared deployment, no server-side audit log and no masking.
- Multi-cluster reach 7 out of 10
- This page’s table gives Apache Kafka 0.11 and above with documented paths for Azure Event Hubs, Amazon MSK and Confluent Cloud, but each workstation holds its own connection list.
Cost a year, modelled: fifty named users sit in the 21-to-50 band at $119 each, so the vendor’s published licence cost is $5,950 in the first year and $2,300 in renewals after it. This page’s estimate adds $18,720: eight engineer-hours a month at $120 an hour keeping fifty workstations and their exported connection files in step, which is $11,520, plus a one-off sixty hours at $120 to get a server-side record of who did what, which is $7,200. That is $24,670 in year one, and the hours are this page’s estimate rather than the vendor’s. Kpow Enterprise is $4,500 per cluster a year for up to 100 users, so the same four clusters are $18,000.
Offset Explorer is a desktop application, and the structural consequence is the one a platform team meets first. Nothing authenticates a person to the application: the documented authentication covers plaintext, SASL, SSL with a truststore and OAUTHBEARER, all of it client to broker, so the application holds no user identity for a role model or an audit entry to key on.
Shared record: no shared deployment, no server-side audit log, and no single place to see what an engineer did.
Configuration: connections are per workstation and travel as exported files, so nothing keeps two engineers in step.
ACLs: managed in the command line tool rather than the interface.
Runtime: the Linux build ships no JRE, so Java 21 or later has to be installed first.
Compare Kpow vs Offset ExplorerConduktor vs Offset ExplorerAKHQ vs Offset Explorer
CMAK
github.com/yahoo/CMAK
20 out of 50 Total
- Cost a year, modelled
- $0 licence, $18,720 to run
- Needs
- A ZooKeeper ensemble, so not Kafka 4.0
- Last release
- 3.0.0.6, 29 April 2022
- Cost as teams grow
- 10 out of 10
- Deployment footprint
- 3 out of 10
- Support and maintenance
- 1 out of 10
- Access control and audit
- 2 out of 10
- Multi-cluster reach
- 4 out of 10
Why these scores for CMAK
- Cost as teams grow 10 out of 10
- This page’s table gives it free under Apache 2.0, with no paid tier and no hosted offering, so adding an engineer changes nothing; this page’s estimate of running it at fifty engineers on four clusters is $18,720 a year, against $18,000 for Kpow Enterprise on the same four.
- Deployment footprint 3 out of 10
- This page gives a Scala and Play application holding a direct ZooKeeper connection, and both community deployment paths, the Helm chart and the Docker image, are archived and read-only.
- Support and maintenance 1 out of 10
- This page gives no vendor at all, 522 issues open with nobody triaging them, the last release in April 2022 and the last push of any kind in August 2023.
- Access control and audit 2 out of 10
- This page gives LDAP basic auth and coarse global feature flags, with no per-user, per-cluster or per-topic granularity and no audit log.
- Multi-cluster reach 4 out of 10
- This page’s table gives many clusters registered in one view, but ZooKeeper-era clusters only, and most managed services no longer expose the endpoint it needs.
Cost a year, modelled: the licence is $0 under Apache 2.0, and at fifty engineers on four clusters this page’s estimate of running it is $18,720 a year: eight engineer-hours a month at $120 an hour to build it from source and keep an unmaintained application alive, which is $11,520, plus a one-off sixty hours at $120 to put an audit trail and per-topic access control somewhere else, which is $7,200. Those rates and hours are this page’s estimate rather than a published price, and they assume all four clusters still run ZooKeeper, because CMAK cannot reach a KRaft one. Kpow Enterprise is $4,500 per cluster a year for up to 100 users, so the same four clusters are $18,000.
CMAK requires a direct ZooKeeper connection. Kafka 4.0, released on 18 March 2025, is the first major release to operate entirely without ZooKeeper, running in KRaft mode by default, so on a KRaft cluster CMAK does not degrade: it cannot connect. MSK, Confluent Cloud, Aiven and Redpanda Cloud either lock down or no longer expose ZooKeeper endpoints, so it is incompatible with most managed Kafka as well.
Data plane: no message browser, no Schema Registry integration, no Kafka Connect management and no ksqlDB.
Freshness: reads come from an internal cache rather than live broker APIs, so a reassignment may appear not to have landed.
Access control: LDAP basic auth and coarse global feature flags, with no per-user, per-cluster or per-topic granularity and no audit log.
Hardening: enabling ZooKeeper ACLs breaks its connection entirely, so the hardening step and the tool are mutually exclusive.
Staying patched: the last release is from April 2022 and nothing has been committed since August 2023. It bundles ZooKeeper 3.5.7, carrying an authorization bypass that scores 9.1 and has been public since October 2023, 1,079 days. No release is coming to carry a fix. 109 of its 112 bundled jars resolve to a Maven coordinate, so its counts are floors rather than totals.
Which should you pick?
Offset Explorer scores 26 against CMAK’s 20 and is the pick for an individual engineer who needs a working client today, because CMAK cannot reach a Kafka 4.0 cluster. Neither authenticates a person, so neither leaves an audit trail anybody can read. A team that has to answer who did what, from a shared deployment, should shortlist Kpow by Factor House, priced per cluster with audit in the product.
Pick Offset Explorer if:
- the user is one engineer reading messages on a cluster somebody else runs
- the payload formats are awkward and the search has to cover Protobuf and JsonPath
- an operation configured once in a GUI should be repeatable from a shell
Keep CMAK, with a date on it, if:
- the cluster is ZooKeeper-era
- the daily work is partition reassignment and preferred-replica election
- the migration date is already in a plan somebody owns
Two cases come back neither. A platform team of five to fifty that needs one shared view gets a shared deployment nobody maintains, or fifty copies of a personal tool each with its own connection list. A regulated environment that needs per-topic access control and an audit trail gets global feature flags behind LDAP basic auth with no audit log, or a tool with no user identity to attach a control to. On a KRaft cluster the two capabilities that actually have to be replaced are partition reassignment and preferred-replica election, and neither product covers them there. Both sit against the rest of the field in the best Kafka management tools, and the audit gap they share is the subject of Kafka audit logging tools.
Kpow: one shared view with an audit trail
Neither of these gives a regulated environment what it actually needs: per-topic access control and an audit trail. CMAK’s LDAP integration is basic auth behind coarse global feature flags, with no per-topic granularity and no audit log, and Offset Explorer has no user identity at all to attach a control to: its documented authentication is client to broker, and a shared workstation has no server-side record of who did what. Kpow by Factor House sits on top of the cluster rather than running it, deployed as a single stateless container with no external database, sidecar or persistent volume, against self-managed Kafka, MSK, Confluent Cloud, Redpanda, Aiven or Instaclustr. It is licensed per cluster at a published price, so adding another engineer never changes what the team pays.
One shared view an auditor can actually query beats fifty personal connection lists. Kpow’s product page lays out the published price next to both of these.

Product demo · 3 min
Apache Kafka audit logging: Kpow demo
Chad Harris walks through audit logging in Kpow: how every meaningful action is recorded on a Kafka topic you can inspect directly, tracing an entry back to the exact query and data it exposed, and forwarding audit events to Slack, Teams, or a SIEM via webhook.
How these tools were scored
Every option is scored from 0 to 10 on each criterion, from the evidence and sources this page cites, and the reason for each score is on its card. Each criterion counts once, for a total out of 50. The options are listed by total.
Sources
- Apache Kafka 4.0.0 release announcement
- Apache Kafka documentation on authorization and ACLs
- Apache Kafka documentation on basic cluster operations