Skip to content

Kafbat UI vs Kafdrop

Comparisons
Karel Sague·August 30, 2026·6 min read·Updated

At a glance

Kafbat UI and Kafdrop are scored here on the same five criteria, 50 points in all: Kafbat UI 38 out of 50, Kafdrop 23 out of 50. Kafbat UI takes its best score on Cost as teams grow (10 out of 10) and its lowest on Support and maintenance (5 out of 10). Cost a year: $0 licence, about $8,640 in operator time (this page's estimate). Kafdrop takes its best score on Cost as teams grow (10 out of 10) and its lowest on Access control and audit (0 out of 10). Cost a year: $0 licence, about $11,520 in operator time (this page's estimate).

Kafbat UI vs Kafdrop, compared

F1 Kpow, Kafbat UI and Kafdrop, side by side
Kpow Kafbat UI Kafdrop
Newest published releaseIs the tool still being released?Yes. Version 96.4 in August 2026, after 96.3 and 96.2 in July, on a dated public changelog. Yes. v1.5.0, published 20 April 2026, after five releases across 2025. No. 4.2.0, published 31 July 2025. Feature work merged in August 2026 is in no tagged image.
Kafka without ZooKeeperDoes it work against a KRaft cluster?Yes. A KRaft view for cluster information and for unregistering brokers, with KRaft metrics on the Prometheus endpoint. Yes. A cluster is addressed by bootstrap servers and standard Kafka client properties. The configuration reference carries no ZooKeeper setting. No. KRaft is unsupported. Three failure reports were closed as not planned, the last in April 2025.
AuthenticationIs authentication part of the product?Yes. LDAP, SAML, OpenID and OAuth2, with Okta, Microsoft Entra ID, Keycloak and AWS SSO named, plus role based access control at the global and the resource level. Enterprise. Yes. Role-based access control across eight resource types, with OAuth, Google, GitHub, Cognito, LDAP and Active Directory as identity providers. No. None in the product. The feature request was closed as not planned in February 2026, and the documented answer is an NGINX proxy in front.
Audit logIs every user action recorded?Yes. Every user action on every cluster, recording who asked, what the request held and whether RBAC allowed it, readable in the UI or piped out as a webhook or a Kafka topic. Enterprise. No. Built in, written to a Kafka topic, to the console, or to both. The default level records changes and not reads. No. None in the product.
Clusters per deploymentCan one deployment manage more than one cluster?Yes. Up to 12 per instance, each with its own connection, Kafka Connect, schema registry and ksqlDB. Community Edition covers 3, and Enterprise sets no licensed cap. Yes. Many, from a single deployment. No. One.
SupportIs there a support channel under contract?Yes. Email support and an Enterprise support SLA, with priority support on Enterprise, and a community Slack channel and GitHub issues on both editions. Yes. GitHub issues, or a paid professional services engagement. No. GitHub issues. No support tier and no forum.
Reported scale limitA known ceiling, not a pass or a fail.Not a yes or no. Up to 12 clusters per instance, a published ceiling rather than a performance failure. Past 12 you run a second instance. Not a yes or no. No published sizing guidance. The resource documentation is example Helm values, tied to no cluster, topic or partition count. Not a yes or no. Around 5,566 consumer groups took the UI past 30 minutes to load. The report was closed by a stale bot.
Licence and priceIs the software free to use at any team size?No. No. Community Edition is free at up to 3 clusters and 10 users, and Enterprise is a commercial licence starting at 4,500 US dollars per cluster per year. Yes. Apache 2.0, free, no paid tier and no cap. The company sells professional services around it and publishes no price for them. Yes. Apache 2.0, free, a single tier. No commercial edition and no paid support.

Kpow meets 6 of 7 requirements on this page. One row is not a yes or no question.

Both projects as published in August 2026. Kpow is Factor House's product and is listed first. Its marks answer the same requirement as the other two columns.

Key takeaway

Kafbat UI and Kafdrop both put a web interface over a Kafka cluster you already run, are Apache 2.0 and free on a single tier, and ship as one container against a broker list, so the split is not the feature list. Kafbat UI is the maintained continuation of the Provectus kafka-ui project, which last released in April 2024. Kafdrop does not support KRaft, which Apache Kafka 4.0 runs by default, and three failure reports against it closed as not planned; it also has no authentication. Kpow by Factor House is licensed per cluster at a published price.

Kpow live demo

Test the trade-offs in a live Kafka UI

You have compared Kafbat UI vs Kafdrop. Open a live Kpow environment to test the everyday workflows a shared Kafka platform needs.

Built for platform and data teams managing shared Kafka clusters.

Try the Kpow demo

What is Kafdrop?

Kafdrop is an open-source Kafka web UI built on Spring Boot, published under Apache 2.0 as obsidiandynamics/kafdrop. It runs as a stateless Java process against the standard broker protocols with no separate datastore, which is what keeps a deployment to one container and a broker list. It needs Java 17 or newer and Kafka 0.11.0 or newer, or Azure Event Hubs, and serves the UI on port 9000.

  • view brokers, topics and partition state
  • browse messages in JSON, plain text, Avro and Protobuf
  • view consumer groups with combined and per-partition lag
  • create topics, and view ACLs
  • Azure Event Hubs as a first-class target

The newest published release is 4.2.0, of 31 July 2025, while the codebase keeps moving: Java 25 merged in December 2025, Spring Boot 4.1 in August 2026, and community feature work in August 2026 that is in no tagged image. What has stalled is the tagging rather than the project.

Kafdrop

What is Kafbat UI?

Kafbat UI is the maintained continuation of the Provectus kafka-ui project, forked by contributors who had been on that project since its inception. Provectus last released v0.7.2 on 10 April 2024 and last took a commit that July, so the original image is abandoned software. Kafbat is free, Apache 2.0, deployed as a container, and one deployment reaches many clusters. There is no paid edition and no source-available restriction on production use.

  • Access control: roles across eight resource types, with subjects matched by regular expression.
  • Identity providers: OAuth, Google, GitHub, Cognito, LDAP and Active Directory.
  • Masking: server-side REMOVE, REPLACE and MASK policies applied to keys, values or named JSON fields.
  • Audit: a built-in log written to a Kafka topic, to the console, or to both.
  • Releases: v1.0.0 in March 2024 through v1.5.0 on 20 April 2026, five of them in 2025.

Kafbat UI

What is the official 2026 pricing of Kafbat UI and Kafdrop?

Neither product has a price, and both take payment somewhere else. Kafdrop takes nothing and offers nothing: no licence fee, no supported edition, no commercial entity behind it, and no channel beyond GitHub issues. Kafbat UI is free on the same terms, with no seat cap and no cluster cap, and the money sits in named professional services: architecture review, custom UI work, performance and scaling, security and compliance, and 24/7 support. No price is published for any of them.

For five engineers who all already hold cluster credentials, the difference is close to academic, and the cost is one container and one configuration block either way. For fifty it is not. The bill is still zero, and the cost has moved: Kafbat UI asks you to follow a release line, and Kafdrop asks you to own an authentication proxy, because the product has none.

Where does each one run out?

The scoring is the same on both sides: five criteria, 10 points each, 50 in all, with every criterion counting once. Nothing sits behind a multiplier, so a total is the sum of its five marks and a reader can recompute it. The five are cost as teams grow, deployment footprint, support and maintenance, access control and audit, and multi-cluster reach, because those are the questions a Kafka interface is actually measured against after the first month: a second cluster, an access review with a date on it, an upgrade nobody owns, and a bill that moves when the team does. The widest gap between the two marks is on multi-cluster reach, where Kafbat UI marks 9 and Kafdrop marks 1. The marks come from the same matrix used on every comparison on this site, so a tool scores the same here as it does anywhere else, and the reason behind each mark is in the card below, under Why these scores.

The dependency figures in the cards below were read on 24 September 2026 from each project’s published release artefact and matched against the NVD and GitHub advisory databases, so they move whenever a release or an advisory lands. Neither count is complete: 150 of Kafbat UI’s 266 bundled jars resolve to a Maven coordinate and 66 of Kafdrop’s 118 do, so both figures are floors rather than totals and neither ranks the other. Self-hosting is not the risk on this page. Both run in your own infrastructure. The question is who rebuilds the image when a dependency advisory lands.

Rank 1

38 out of 50 Total

Cost a year
$0 licence, about $8,640 in operator time (this page's estimate)
Newest published release
v1.5.0, 20 April 2026
Authentication
Eight resource types, six identity providers
Cost as teams grow
10 out of 10
Deployment footprint
8 out of 10
Support and maintenance
5 out of 10
Access control and audit
6 out of 10
Multi-cluster reach
9 out of 10
Why these scores for Kafbat UI
Cost as teams grow 10 out of 10
Apache 2.0 with no seat cap and no cluster cap and nothing held back. On this page, it is free on the same terms as Kafdrop, with the money in unpriced professional services rather than the licence.
Deployment footprint 8 out of 10
A stateless container with a published Helm chart, docked because anything set through the configuration wizard is written inside the container and lost on restart without a mounted volume.
Support and maintenance 5 out of 10
It shipped v1.5.0 on 20 April 2026 after five releases across 2025, against GitHub issues or an unpriced professional services engagement with no SLA. CVE-2025-49127 was remedied by an upgrade the operator performs.
Access control and audit 6 out of 10
Role-based access control across eight resource types with OAuth, Google, GitHub, Cognito, LDAP and Active Directory, server-side masking and a built-in audit log, docked because the default audit level records changes and not reads and masking is pattern-driven per cluster.
Multi-cluster reach 9 out of 10
A single deployment covers many clusters, against Kafdrop’s one.

Kafbat UI’s limits are the standing cost of the model it chose. CVE-2025-49127, an unsafe deserialisation flaw in v1.0.0, allowed an unauthenticated user to run arbitrary code on the server. It scored 8.9 HIGH on CVSS v4.0, was published in June 2025, and was fixed in v1.1.0. The remedy is an upgrade somebody on your side performs, and that obligation recurs. Sizing starts as a guess too, because the published resource guidance is example Helm values tied to no cluster, topic or partition count.

Audit defaults: the default level records changes and not reads, and the audit topic defaults to one partition and must never be compacted.

Masking: per cluster and pattern-driven, so coverage depends on patterns that match every topic carrying a sensitive field.

Dynamic config: anything set through the configuration wizard is written inside the container and lost on restart without a mounted volume.

Metrics: no time-series graphs for consumer lag or throughput. The feature request predates the fork.

Staying patched: v1.5.0 shipped in April 2026 and nothing has shipped since. In the 157 days after it, at least 20 high or critical advisories were published against libraries that release bundles, including a critical in netty. Only 150 of its 266 bundled jars resolve to a Maven coordinate, so that is a floor rather than a total, and the state of the release itself is unmeasured. Kafbat does publish a security policy, which AKHQ and Kafdrop do not.

What it costs a year: nothing to licence, and unlike the tool beside it nothing to build around it either, because the authentication is in the product. This page’s estimate rather than a vendor price: on twenty engineers and three clusters, six engineer-hours a month covering the container, the release line this page says you inherit, upgrades of the CVE-2025-49127 kind and the audit topic is 8,640 US dollars a year at 120 US dollars an hour. A Kpow licence on the same three clusters is 13,500 US dollars a year at its published 4,500 per cluster.

Rank 2

23 out of 50 Total

Cost a year
$0 licence, about $11,520 in operator time (this page's estimate)
Newest published release
4.2.0, 31 July 2025
Authentication
None in the product, an NGINX proxy in front
Cost as teams grow
10 out of 10
Deployment footprint
10 out of 10
Support and maintenance
2 out of 10
Access control and audit
0 out of 10
Multi-cluster reach
1 out of 10
Why these scores for Kafdrop
Cost as teams grow 10 out of 10
Apache 2.0, the whole product, no seat or cluster cap. This page gives no licence fee, no supported edition and no commercial entity behind it.
Deployment footprint 10 out of 10
One stateless Java process with no separate datastore, which is what keeps a deployment to one container and a broker list. Java 17 or newer, serving the UI on port 9000.
Support and maintenance 2 out of 10
Newest published release 4.2.0 of 31 July 2025, KRaft unsupported with three failure reports closed as not planned, and GitHub issues with no support tier and no forum.
Access control and audit 0 out of 10
No authentication in the product, the feature request closed as not planned in February 2026, and no read-only mode, so anyone who can reach an instance can delete a topic.
Multi-cluster reach 1 out of 10
One cluster per deployment. Azure Event Hubs as a first-class target is the only reach past that one cluster.

Kafdrop’s first limit decides whether it is viable at all. Apache Kafka 4.0, announced in March 2025, is the first major release to run without ZooKeeper, in KRaft mode by default. Kafdrop does not support KRaft: the topic view becomes unresponsive against a KRaft cluster, and three failure reports were closed as not planned, the last in April 2025. That is a settled position rather than a backlog item. Beneath it sit one cluster per deployment, no message search or filtering by key or value, and message encoding set per topic by hand.

Authentication: none in the product. The feature request was closed as not planned in February 2026, and the documented answer is an NGINX proxy in front.

Read-only mode: absent, so anyone who can reach an instance can delete a topic. The pull request adding one has sat since November 2020.

Scale: around 5,566 consumer groups took the UI past 30 minutes to load.

MSK IAM: never merged, so a cluster authenticating through IAM is reachable only through a community workaround.

Staying patched: 4.3.0 shipped on 31 August 2026 bundling Tomcat 11.0.22, which had carried three critical advisories since 25 August, six days earlier. One of them, CVE-2026-65905, scores 9.8 and is an authentication bypass, and all three are still in the current release. Three releases have shipped in two years. Only 66 of its 118 bundled jars resolve to a Maven coordinate, so those counts are floors rather than totals.

What it costs a year: nothing to licence, and the bill moves to the proxy. This page’s estimate rather than a vendor price: on twenty engineers and three clusters, eight engineer-hours a month covering three deployments plus the NGINX authentication proxy this product does not ship is 11,520 US dollars a year at 120 US dollars an hour, two hours a month more than the tool beside it purely because authentication is somebody else’s job here, and before anything is spent on the KRaft migration it cannot follow. A Kpow licence on the same three clusters is 13,500 US dollars a year at its published 4,500 per cluster, and it runs on KRaft.

Which should you pick?

Kafbat UI scores 38 against Kafdrop’s 23 and is the pick for anything past a development cluster, because Kafdrop does not support KRaft, which Apache Kafka 4.0 runs by default, and it has no authentication. Kafdrop remains the lightest free viewer. Both are volunteer-maintained with nobody under contract, so a team that needs a vendor to ship the patched build should shortlist Kpow by Factor House.

Pick Kafdrop if:

  • the cluster still runs ZooKeeper, and no KRaft migration has a date on it
  • the tool is for a handful of engineers who already hold cluster credentials
  • the job is local development, or a quick look at what is flowing through a topic
  • consumer group count has never been a number anybody had to think about

Pick Kafbat UI if:

  • the cluster is on KRaft, or is going there
  • more than one cluster has to be reachable from one place
  • somebody who must not delete a topic still needs to see one
  • an auditor is going to ask who did what

Underneath the four requirements is a question about staffing rather than features. Kafdrop’s scope is settled, so its limits are known in advance and the work of protecting it stays yours permanently. Kafbat UI’s scope moves, so you inherit a release cadence, and in exchange the governance sits inside the product rather than in a proxy in front of it.

Kafka RBAC tools ranks what can put roles in front of a cluster without a proxy in the way, and the best free Kafka UI tools sets out what the rest of the free field holds back.

Kpow: a published price, not a proxy to build or an upgrade cadence to own

Kafdrop has no authentication of any kind, and the documented answer is an NGINX proxy you build and run yourself; Kafbat UI ships real access control, but staying safe on it means tracking its release line closely enough to have already moved past CVE-2025-49127 before it mattered. Both are free, and both hand the cost to whoever on your side maintains that proxy or watches the release notes. Kpow by Factor House charges the cluster once and stops: licensed per cluster at a published price, unmoved whether five engineers become fifty, running as one stateless container through environment variables, with no external database, and reaching up to 12 clusters from a single instance.

A published price is one less thing to build a proxy for or watch a release feed for. Kpow publishes that per-cluster number in full, so the five-to-fifty math above checks against something real instead of a guess.

For teams in regulated industries that outgrow both tools, Factor House documents the governance controls on the Kpow product page. These include role-based access control at the global and resource level with multi-tenancy isolation, data masking for PII that is enforced server-side so the unmasked value never reaches the browser, a complete audit log of every action across every cluster, and SSO through Okta, Azure AD, KeyCloak and any LDAP, SAML or OAuth2 provider. Kpow runs self-hosted in your own environment and Kpow Enterprise can run fully offline in an air-gapped network.

Kpow

How these tools were scored

Every option is scored from 0 to 10 on each criterion, from the evidence and sources this page cites, and the reason for each score is on its card. Each criterion counts once, for a total out of 50. The options are listed by total.

Sources

Related reading