Skip to content

Best Kafka UI tools for AWS Glue Schema Registry

Comparisons
Chad Harris·October 1, 2026·19 min read·Updated

The best Kafka UI tool for AWS Glue Schema Registry is one that decodes records written with Glue’s own serializers, lets a permitted engineer create, evolve and delete Glue schemas, reaches a registry in another AWS account by assuming a role, and adds per-person roles, time-boxed production access, masking and an audit trail on top of IAM, from one container in your own AWS account that stays out of the data path. Kpow, Lenses, Kafbat UI, AKHQ, the AWS Glue console, Redpanda Console and Conduktor each cover part of that. Scored on the six weighted criteria explained below the rankings, Kpow ranks first with 86 out of 100, ahead of Lenses at 70 and Kafbat UI at 65; Conduktor, listed last, totals 73.

Tools compared

Kafka UI tools for AWS Glue Schema Registry scored against this page’s rubric (read 1 October 2026). Total is the weighted score out of 100, with the criteria in order of weight; the weights are explained under how these tools were scored. Conduktor is listed last whatever its total; on its total of 73 it would place second.
Rank Tool Total (out of 100) Governance beyond IAM Reading Glue-encoded records Out of the data path Managing Glue schemas Credentials and cross-account Inspecting topic data Cost a year, one cluster (modelled)
1 Kpow 86 RBAC, staged approvals, temporary access, masking, tenants, audit Avro and Protobuf in data inspect One container, no external database, not a proxy Create, edit, compatibility, delete Credentials chain, static keys, STS role kJQ search, data inspect, replay $7,380
2 Lenses 70 SSO and RBAC from Team tier, audit Avro and Protobuf, SQL over Glue topics HQ on PostgreSQL plus an agent per cluster Documented in 2023; one registry connection Access key, credentials chain, assumed role SQL over topics $20,882
3 Kafbat UI 65 RBAC, global masking, opt-in audit Separate serde plugin One container Not for Glue Credentials chain, static keys, profile Message browsing $8,640
4 AKHQ 62 Group roles, no masking Built in for Avro, Protobuf and JSON, reading only One container Not for Glue Default credentials provider only Message browsing $8,640
5 AWS Glue console and APIs 46 IAM policies per principal No records Nothing to deploy The native control plane Your AWS identity, one account at a time No records $11,520
6 Redpanda Console 44 Behind a paid Enterprise licence None documented One container None documented None documented Message browsing $8,640 plus an unpublished licence for RBAC
7 Conduktor 73 Strong; data-level controls through Gateway A supported registry type Console on PostgreSQL; Gateway, a proxy, for data-level controls Create, update, compatibility, compare, delete Credentials, profile or IAM role Message browsing $32,880; $122,880 with Gateway Core and Protect

The tools, ranked for AWS Glue Schema Registry

Rank 1

86 out of 100 Total

Try Kpow in the live demo No signup needed.

Cost a year
$4,500 per cluster with 100 users included, plus about $2,880 in operator time, so $7,380 on one cluster (modelled)
Glue support
Built in, Avro and Protobuf, cross-account through an STS role, in Community and Enterprise
Deployment
One container on ECS, Fargate or EKS, no external database
Governance beyond IAM ×3 weight, this criterion counts 3 times toward the total
9 out of 10
Reading Glue-encoded records ×2 weight, this criterion counts 2 times toward the total
8 out of 10
Out of the data path ×2 weight, this criterion counts 2 times toward the total
9 out of 10
Managing Glue schemas
8 out of 10
Credentials and cross-account
8 out of 10
Inspecting topic data
9 out of 10
Why these scores for Kpow
Governance beyond IAM 9 out of 10
RBAC per action and resource, staged approvals, time-boxed temporary policies, masking in data inspect, tenants for shared clusters, sign-in through SAML, OIDC or LDAP including AWS IAM Identity Center, and an audit log that names the person are all documented as Enterprise features.
Reading Glue-encoded records 8 out of 10
Data inspect decodes Glue-encoded Avro records, supported since release 84, and Protobuf since release 88.6; JSON Schema on Glue is not stated in its release notes, so this is a clean pass rather than the top mark.
Out of the data path 9 out of 10
It runs as one container or JAR and keeps its snapshots, metrics and audit log in topics on your own cluster, with no dependency beyond Kafka, and connects like any Kafka client, so it sits beside the cluster rather than in front of it; only the AWS Glue console, with nothing to deploy, scores higher.
Managing Glue schemas 8 out of 10
Kpow’s features page lists creating, editing and deleting subjects and updating compatibility in both editions, its fh command line has one schema command tree for Confluent and AWS Glue registries, and the public demo shows a Glue registry with each subject’s version, compatibility mode and status; the Glue console itself, as AWS’s own control plane, scores higher.
Credentials and cross-account 8 out of 10
Its Glue documentation covers the default AWS credentials chain, static keys and cross-account access by assuming an STS role, and links an AWS walkthrough of the cross-account setup, a clean pass that Lenses and Conduktor match.
Inspecting topic data 9 out of 10
Belong’s engineers name kJQ querying, message visualisation, replay and PII masking as the reasons they use Kpow on MSK with Glue.

On Glue Schema Registry. Kpow connects to a registry by its ARN and Region, set with SCHEMA_REGISTRY_ARN and SCHEMA_REGISTRY_REGION, per its Glue Schema Registry documentation. It authenticates with the default AWS credentials chain, with static keys, or by assuming a role in another account through SCHEMA_REGISTRY_STS_ROLE_ARN. Glue support arrived in release 84 in September 2021 and Protobuf on Glue in release 88.6. The Kpow features page lists the AWS Glue Schema Registry in both Community and Enterprise editions.

Next to other registries. A Glue registry can sit beside Confluent, Apicurio, Karapace, Google, Redpanda or Buf registries, and several registries can be attached to one Kafka cluster with SCHEMA_REGISTRY_RESOURCE_IDS (Kpow schema registry configuration).

Where it falls short. Kpow governs people working through Kpow. Producers and consumers still call Glue with their own IAM roles, and IAM policies remain the control for them. Kpow’s features page lists Avro, Protobuf and JSON Schema for schema registries, but its release notes name only Avro and Protobuf on Glue, so a team on JSON Schema should test it with its own records. RBAC, masking, staged mutations and the audit log need Kpow Enterprise; Community Edition is free for 3 clusters and 10 users and includes the AWS Glue Schema Registry.

Rank 2

Lenses

lenses.io

70 out of 100 Total

Cost a year
$18,002 software on the smallest AWS Marketplace EC2 listing plus $2,880 operator time, so $20,882 before EC2 charges (modelled)
Glue support
Avro and Protobuf; one registry connection
Deployment
HQ on PostgreSQL plus an agent and database per cluster
Governance beyond IAM ×3 weight, this criterion counts 3 times toward the total
7 out of 10
Reading Glue-encoded records ×2 weight, this criterion counts 2 times toward the total
8 out of 10
Out of the data path ×2 weight, this criterion counts 2 times toward the total
4 out of 10
Managing Glue schemas
7 out of 10
Credentials and cross-account
8 out of 10
Inspecting topic data
10 out of 10
Why these scores for Lenses
Governance beyond IAM 7 out of 10
SSO, SAML and RBAC come from the Team tier and audit logs are in the product, one grade below the tools with approvals and time-boxed access.
Reading Glue-encoded records 8 out of 10
Lenses extended its schema registry support to AWS Glue for Avro and Protobuf, including its SQL engine over Glue-backed topics, a clean pass.
Out of the data path 4 out of 10
It is self-hosted, but a central HQ on PostgreSQL plus an agent and an agent database for every cluster is the heaviest footprint here apart from Conduktor with Gateway.
Managing Glue schemas 7 out of 10
Its 2023 Glue announcement says Glue schemas can be created, browsed, edited and evolved like any other registry, but the current agent documentation allows only one schema registry connection.
Credentials and cross-account 8 out of 10
Its AWS connection takes an access key, the credentials chain or an assumed role with a session name, a clean pass.
Inspecting topic data 10 out of 10
SQL over topics is the centre of the product and the strongest query model on this page, ahead of Kpow’s kJQ.

On Glue Schema Registry. Lenses’ AWS Glue configuration connects its agent to a registry by ARN through a separate AWS connection, which authenticates with an access key, the credentials chain or an assumed role. Its April 2023 announcement extended its schema registry support to Glue for Avro and Protobuf, covering schema management, its SQL snapshot engine and SQL processors. It is sold on AWS Marketplace as Lenses EC2 - MSK, billed hourly from $2.055 an hour on a t2.large, which is $18,002 for an instance left on all year, before the EC2 instance charge.

Where it falls short. Only one schema registry connection is allowed, so a team with a Glue registry per account or a Confluent registry beside Glue picks one. The Team licence stops at 15 users on one cluster, and the Lenses review covers its pricing tiers.

Rank 3

65 out of 100 Total

Cost a year
$0 licence, about $8,640 in operator time (modelled)
Glue support
Separate serde plugin, serialise and deserialise
Schema view
Not for Glue
Governance beyond IAM ×3 weight, this criterion counts 3 times toward the total
6 out of 10
Reading Glue-encoded records ×2 weight, this criterion counts 2 times toward the total
7 out of 10
Out of the data path ×2 weight, this criterion counts 2 times toward the total
9 out of 10
Managing Glue schemas
1 out of 10
Credentials and cross-account
6 out of 10
Inspecting topic data
8 out of 10
Why these scores for Kafbat UI
Governance beyond IAM 6 out of 10
It offers LDAP and OIDC sign-in, resource-level RBAC, global masking and an opt-in audit topic, which is one grade below the commercial tools.
Reading Glue-encoded records 7 out of 10
The ui-serde-glue plugin serialises and deserialises Glue records, but it is a separate jar to download, version and configure per cluster, with topics mapped to schema names by template.
Out of the data path 9 out of 10
It is a self-hosted container with no database, the same pass as Kpow and the other open-source UIs.
Managing Glue schemas 1 out of 10
Glue appears only as a serde for reading and writing messages; its schema registry view manages one Confluent-compatible registry per cluster, so Glue schemas themselves are not browsed or changed.
Credentials and cross-account 6 out of 10
The plugin takes the default credentials chain, static keys on the serde, or a named profile from a credentials file, and documents no role to assume for another account.
Inspecting topic data 8 out of 10
Message browsing and inspection are core features of the open-source UI.

On Glue Schema Registry. Kafbat UI decodes Glue through the ui-serde-glue plugin, loaded from a jar file path and configured per cluster with a Region, a registry name and templates that map topics to key and value schema names. Its README lists the glue:GetSchema and glue:GetSchemaVersion permissions the serde needs. The Kafbat UI review covers its release history and RBAC.

Where it falls short. No vendor stands behind it, Glue decoding is an extra plugin to version alongside the UI, and Glue schemas are not managed from its schema view. Its modelled running cost on one cluster is 6 engineer-hours a month, $8,640 a year at $120 an hour.

Rank 4

AKHQ

akhq.io

62 out of 100 Total

Cost a year
$0 licence, about $8,640 in operator time (modelled)
Glue support
Built in, read only, Avro, Protobuf and JSON
AWS credentials
Default credentials provider only
Governance beyond IAM ×3 weight, this criterion counts 3 times toward the total
5 out of 10
Reading Glue-encoded records ×2 weight, this criterion counts 2 times toward the total
8 out of 10
Out of the data path ×2 weight, this criterion counts 2 times toward the total
9 out of 10
Managing Glue schemas
1 out of 10
Credentials and cross-account
4 out of 10
Inspecting topic data
8 out of 10
Why these scores for AKHQ
Governance beyond IAM 5 out of 10
It has LDAP, OIDC and basic sign-in with group-based roles, and no masking or audit comparable to the commercial tools.
Reading Glue-encoded records 8 out of 10
Its documentation states built-in Glue support for deserialising Avro, Protobuf and JSON serialised messages, a clean pass for reading.
Out of the data path 9 out of 10
It is a self-hosted container with no database.
Managing Glue schemas 1 out of 10
Glue support is limited to deserialisation, so Glue schemas are not browsed or changed from AKHQ.
Credentials and cross-account 4 out of 10
Authentication uses the AWS default credentials provider, with no documented static keys or role to assume for a registry in another account.
Inspecting topic data 8 out of 10
Topic data browsing is a core AKHQ feature.

On Glue Schema Registry. AKHQ’s Glue schema registry documentation sets the registry type to glue with a registry name and Region, and says Glue support is limited to deserialising Avro, Protobuf and JSON serialised messages, authenticated with the AWS default credentials provider. The AKHQ review covers the rest.

Where it falls short. There is no way to browse or change Glue schemas, no Glue serialiser for producing test records, and no documented route to a registry in another AWS account.

Rank 5

AWS Glue console and APIs

docs.aws.amazon.com/glue

46 out of 100 Total

Cost a year
Registry free to use; reading records falls to the Kafka CLI, modelled at 8 hours a month, $11,520 (modelled)
Sign-in
Your AWS console identity and IAM
Deployment
Nothing to deploy
Governance beyond IAM ×3 weight, this criterion counts 3 times toward the total
3 out of 10
Reading Glue-encoded records ×2 weight, this criterion counts 2 times toward the total
0 out of 10
Out of the data path ×2 weight, this criterion counts 2 times toward the total
10 out of 10
Managing Glue schemas
10 out of 10
Credentials and cross-account
6 out of 10
Inspecting topic data
1 out of 10
Why these scores for AWS Glue console and APIs
Governance beyond IAM 3 out of 10
IAM policies decide what each principal may do and CloudTrail records each Glue API call under the caller’s identity, but the console adds no masking, no approval step before a schema version is deleted and no per-person view of topic data.
Reading Glue-encoded records 0 out of 10
The Glue console manages registries and schemas and never reads Kafka records, so decoding falls to the Glue serializers inside your own applications.
Out of the data path 10 out of 10
There is nothing to deploy and nothing between clients and brokers, since this is AWS’s own control plane, which makes it the best on this criterion.
Managing Glue schemas 10 out of 10
Registries, schemas, versions, compatibility modes and metadata are created and changed here first, and the GetSchemaVersionsDiff API returns a diff between versions, so it leads this criterion.
Credentials and cross-account 6 out of 10
It uses your AWS identity directly, and a registry in another account is reached by signing in to or switching roles into that account, one account at a time.
Inspecting topic data 1 out of 10
There is no view of Kafka records at all.

What it covers. AWS describes the registry as serverless and free to use, with up to 100 registries per Region in an account. Registries and schemas are created and updated in the AWS Glue console or the Glue APIs, and the schema registry API includes a version diff. Producers and consumers use the Glue serializers and deserializers in their own code.

Where it falls short. There is no way to read or search the records a schema describes, so inspecting a message means the Kafka CLI with the Glue deserializer on its classpath, or a separate tool. Schemas sit in the Glue console and topics in the MSK console or elsewhere, two places that are not joined to each other.

Rank 6

Redpanda Console

redpanda.com

44 out of 100 Total

Cost a year
$0 for the free build, about $8,640 in operator time (modelled); RBAC and SSO need an unpublished Enterprise licence
Glue support
None documented
Schema view
Redpanda Schema Registry
Governance beyond IAM ×3 weight, this criterion counts 3 times toward the total
6 out of 10
Reading Glue-encoded records ×2 weight, this criterion counts 2 times toward the total
0 out of 10
Out of the data path ×2 weight, this criterion counts 2 times toward the total
9 out of 10
Managing Glue schemas
0 out of 10
Credentials and cross-account
0 out of 10
Inspecting topic data
8 out of 10
Why these scores for Redpanda Console
Governance beyond IAM 6 out of 10
RBAC, OIDC sign-in and masking exist but need a paid Redpanda Enterprise licence, and Console shuts down if that licence expires.
Reading Glue-encoded records 0 out of 10
Redpanda’s documentation describes no Glue Schema Registry support, so Glue-encoded records are not decoded.
Out of the data path 9 out of 10
It is a self-hosted container with no database.
Managing Glue schemas 0 out of 10
Its documented schema view manages Redpanda’s own Schema Registry, not Glue.
Credentials and cross-account 0 out of 10
With no Glue integration there are no AWS credentials or roles to configure for a registry.
Inspecting topic data 8 out of 10
Message browsing is the core of the product.

On Glue Schema Registry. Redpanda’s schema registry documentation for Console covers managing Redpanda’s own Schema Registry, and Redpanda’s documentation describes no AWS Glue Schema Registry support. The Redpanda Console review covers the rest.

Where it falls short. A team on Glue sees Glue-encoded records undecoded and manages its schemas elsewhere, and RBAC, SSO or masking need a Redpanda licence whose price is not published.

Rank 7

Conduktor

conduktor.io

73 out of 100 Total

Cost a year
25 Console seats at $1,200 is $30,000 plus $2,880 operator time, so $32,880; Gateway Core adds $60,000 and Gateway Protect, which carries encryption and masking, a further $30,000 (modelled)
Glue support
A supported registry type, with three AWS sign-in methods
Deployment
Console on PostgreSQL 13+; data-level controls through Gateway, a proxy
Governance beyond IAM ×3 weight, this criterion counts 3 times toward the total
9 out of 10
Reading Glue-encoded records ×2 weight, this criterion counts 2 times toward the total
8 out of 10
Out of the data path ×2 weight, this criterion counts 2 times toward the total
3 out of 10
Managing Glue schemas
8 out of 10
Credentials and cross-account
8 out of 10
Inspecting topic data
8 out of 10
Why these scores for Conduktor
Governance beyond IAM 9 out of 10
RBAC, SSO by OIDC or LDAP, an audit log and masking are strong, but encryption, field-level masking of the data itself and multi-tenancy run through Gateway.
Reading Glue-encoded records 8 out of 10
AWS Glue is one of the three schema registry types Console supports, configured per cluster, a clean pass on the documented registry type.
Out of the data path 3 out of 10
Console needs PostgreSQL 13 or later, and the data-level controls counted in its governance score run in Gateway, a proxy that clients connect through, so using them puts Conduktor in the data path.
Managing Glue schemas 8 out of 10
Its schema registry guide lists AWS Glue as a supported registry type and documents creating subjects, updating schemas, changing compatibility, comparing versions and deleting without naming a restriction by type, a clean pass on that evidence.
Credentials and cross-account 8 out of 10
Its Glue configuration takes explicit credentials, an IAM profile, or an IAM role by ARN, a clean pass.
Inspecting topic data 8 out of 10
Console browses and filters topic data.

On Glue Schema Registry. Conduktor’s schema registry guide lists Confluent, Confluent-like and AWS Glue registry types and documents creating subjects, updating schemas, changing compatibility per subject, comparing versions and deleting. Its Console configuration examples connect Glue by Region and optional registry name with Credentials, FromContext or FromRole security.

Where it falls short. Console needs PostgreSQL. Conduktor’s data-level controls, such as encryption, masking of the data itself and virtual clusters for multi-tenancy, run in Gateway, a Kafka proxy that client applications connect through, which puts Gateway in the data path for those clients. On AWS Marketplace, Conduktor Enterprise lists Gateway Core at $60,000 a year and Console at $1,200 a seat for the first 100 seats. The same listing prices the encryption, data masking and message-level access enforcement as Gateway Protect, a $30,000 add-on that requires Gateway, so the data-level controls take the total to $122,880.

What teams on AWS Glue Schema Registry need

AWS Glue Schema Registry stores and version-checks the Avro, JSON Schema and Protobuf contracts a team’s producers and consumers share, and AWS runs it for free. It does not show engineers the records those schemas describe, and it leaves the question of who may read or change what, once several teams share a tool, to IAM policies written per principal. Everything on this page is about what a Kafka tool adds on top of the registry, not about replacing it. Most teams on Glue run it beside Amazon MSK, compared in the best Kafka UI tools for Amazon MSK, and registries of every kind are compared in Kafka schema registry tools.

A Glue registry is not a drop-in replacement for a Confluent-compatible one, and that difference sets most of what follows. A tool’s registry support has two separate parts: the serializers and deserializers that read and write records, and the API that manages schemas. Google Cloud’s Managed Service for Apache Kafka implements the Confluent Schema Registry REST API, so tools and clients built for Confluent work with it unchanged. AWS Glue has its own API and its own open-source SerDe libraries, so each tool has to build both parts for Glue separately, and the tools on this page differ in which parts they built: AKHQ and Kafbat UI read Glue records but do not manage Glue schemas, while Kpow, Lenses and Conduktor do both.

Governance beyond IAM. IAM decides what each principal may do, and CloudTrail records each Glue API call under that principal. When engineers share one tool, the principal is the tool’s role, so IAM and CloudTrail cannot say which engineer read a decoded record or changed a schema, and neither masks sensitive fields in the records a tool decodes. Glue’s permissions also stop at the schema. glue:GetSchemaVersion lets a principal fetch the schema that describes a record, while permission to read the records themselves comes from the cluster’s own access control, MSK IAM policies or Kafka ACLs, and neither layer hides a field inside a record once it is decoded. Without field-level masking, the only safe policy for a topic that carries personal data is to deny access to it, and developers then raise tickets for platform engineers to extract and sanitise records by hand, a slow queue that is itself an error-prone control. GDPR Article 32 asks for security measures appropriate to the risk of the processing, and masking is the measure that lets engineers keep reading those topics; it is one of the four reasons Belong gives for its tool choice in the card below.

An approval step carries more weight on Glue than on Confluent’s registry, because deleting a Glue schema, a schema version or a registry is permanent and cannot be undone. Confluent’s registry soft-deletes by default and keeps a deleted schema’s ID resolvable until a separate hard delete, so a mistaken deletion there can be reversed; on Glue the review has to happen before the action. Per-person roles, masking, an approval step in front of a schema deletion and an audit record of each engineer’s actions are what a shared tool has to add.

Reading Glue-encoded records. Producers on Glue write records with the AWS Glue Schema Registry library, not the Confluent client, so a tool that only understands Confluent-compatible registries shows a Glue-encoded topic as bytes. The difference sits at the front of every record. The Glue serializer writes one header version byte, one compression byte and a 16-byte schema version ID, as defined in the constants of AWS’s SerDe library, where the Confluent format writes a zero magic byte and a 4-byte integer ID. That 16-byte ID is a UUID, and AWS identifies a schema version by UUID or version number, so a reader has to look schemas up by UUID in Glue rather than by integer in a Confluent-style registry, and the registry type configured decides which deserializers a tool can offer. The library can also compress records when the producer turns compression on, which a reader has to undo before it can decode anything. Kpow, Lenses, Conduktor and AKHQ decode Glue records as a built-in registry type, AKHQ for reading only, Kafbat UI decodes them through a separate serde plugin, and Redpanda Console documents no Glue support. A record that fails to decode is the usual starting point of a Kafka deserialization error.

Out of the data path. Where the tool runs affects every requirement above. A tool that runs as a container in your own VPC and connects to the brokers and to Glue the way any Kafka client does adds nothing to the path your producers and consumers take. A tool whose controls are enforced by a proxy that every client connects through becomes part of that path, and it has to be sized, kept available and kept in step with every client upgrade. Kpow is one container with no external database, installed in your own environment and out of the data path. Conduktor Console also connects directly, with a PostgreSQL database of its own; Conduktor’s data-level controls, such as encryption, masking of the data itself and virtual clusters, run in Conduktor Gateway, a Kafka proxy that client applications connect through.

Glue itself is never in the Kafka data path. Producers and consumers call the registry API and cache what they fetch, the schema version ID on the producer side, by default for 24 hours, and the schema on the consumer side, so records flow between clients and brokers whether or not a tool is watching. A tool reaches Glue through the same API. In private subnets it can use an interface VPC endpoint for AWS Glue, which keeps the calls inside the AWS network with no internet gateway or NAT device, and where outbound traffic has to pass a corporate HTTP proxy, Kpow sends its AWS and schema registry calls through the standard HTTP_PROXY and HTTPS_PROXY settings (Kpow environment variables).

Managing Glue schemas. Glue’s eight compatibility modes, from NONE and DISABLED to FULL_ALL, are enforced only when a version is registered, so creating and evolving a schema is where mistakes reach production. Two Glue behaviours raise the stakes. A new version is checked against the schema’s checkpoint version, and in the console, editing a schema definition or its compatibility mode moves the checkpoint to the latest version by default, as the same AWS page explains. A schema’s data format applies to all of its versions, so moving to a different format means a new schema. Producers can also change the contract themselves: auto-registration in the Glue serializer is off by default, and when it is on, a record produced with a new schema registers a new version, in the default registry and under the topic’s name unless the producer sets them. AWS’s serializer policy example adds glue:CreateSchema and glue:RegisterSchemaVersion for this, and a producer that holds them can change a schema with no review. Siemens’ data integration team described the same risk in its schema quality talk, calling producer auto-registration self-certification and keeping schema uploads with a dedicated team instead. A team that does the same keeps those two permissions with its deployment pipeline and routes changes made by people through a tool that records who made them.

The AWS Glue console does this natively. Kpow shows each Glue subject with its version, compatibility mode and status, and creates, edits and deletes subjects and changes compatibility from the same view, with SCHEMA_CREATE, SCHEMA_EDIT_VERSION and SCHEMA_DELETE as separate permissions. Conduktor documents the same operations for the registry types it supports. Lenses described Glue schema management in 2023, with one registry connection per agent. Kafbat UI and AKHQ use Glue for messages only.

Credentials and cross-account. A Glue registry is regional and can sit in a different AWS account from the cluster and the tools, a setup AWS walks through in its cross-account Glue Schema Registry post. Readers need glue:GetSchema and glue:GetSchemaVersion on the registry and its schemas. The same post explains why assuming a role is the only route across accounts: the AWS Glue Schema Registry does not support resource-based policies, so the registry’s account cannot grant access with a policy on the registry, and clients in the cluster’s account assume a role in the registry’s account that trusts them. A tool that can only use the credentials of the machine it runs on cannot reach such a registry at all. Kpow and Lenses document assuming a role for this, and Conduktor accepts an IAM role by ARN.

The session name on that role is what the registry’s account sees. In cross-account access the role session name is visible to, and can be logged by, the account that owns the role, and AWS STS points administrators to that field in CloudTrail to help identify who performed an action. A shared tool assumes the role under one session name of its own, which Kpow sets with SCHEMA_REGISTRY_STS_SESSION_NAME, so CloudTrail in the registry account shows the tool’s session on every schema change, and the engineer behind each change is recorded only in the tool’s own audit log.

Inspecting topic data. When the Glue deserializer cannot deserialize a record, AWS’s description of the registry says the consumer can log the data from the record and move on, or halt the application. Either way, the first job in a Glue incident is usually to find that record and read it: which schema version its header names, whether that version still exists, and whether a Glue serializer wrote it at all. Topics that mix formats are normal during a move onto Glue. AWS’s migration guide has consumers run the Glue deserializer first and the previous registry’s deserializer as a secondary for records without the Glue header, and a topic with infinite retention keeps its old records, and its dependency on the old registry, until they are copied to a new topic. A tool used in that period has to reach both registries, which Kpow does by attaching both to the same Kafka cluster. Consumers are not only Kafka clients written in Java, either: AWS Lambda’s Kafka event sources can validate and deserialize Glue-encoded Avro, Protobuf and JSON Schema records, in provisioned mode only and with one schema registry per event source mapping.

No tool here leads on every criterion. The AWS Glue console is the native place to manage Glue schemas and needs nothing deployed, and Lenses has the stronger query model with SQL over Glue-backed topics. Kpow governs people working through Kpow, so applications keep their own IAM roles, and IAM policies stay the control for them.

Who runs Kpow on AWS Glue Schema Registry

One Kpow customer has described in public how it runs Kpow beside the AWS Glue Schema Registry: Belong, the Australian telco that is part of Telstra, in a talk by its Head of Enablement. The card is tagged with the rubric criteria its evidence speaks to, and the grey tags name the other things the talk covers. The talk also explains how Belong came to be on Glue. MSK was already an approved managed streaming platform inside Telstra and approving another vendor would have taken too long, so approval time decided the platform, and being on MSK then decided the registry, as the Belong talk explains.

Which customer shows which criterion

Governance beyond IAM
Belong
Reading Glue-encoded records
Belong
Inspecting topic data
Belong
  • Belong

    Consumer telco, part of Telstra, Australia

    • Reading Glue-encoded records
    • Inspecting topic data
    • Governance beyond IAM
    • Amazon MSK
    • Incident replay
    • Terraform-managed ACLs

    Belong runs Kafka on Amazon MSK and uses the AWS Glue Schema Registry because, in Nagaraj Ballapuram Gopal’s words, “given we’re on AWS MSK, we can’t use Confluent’s schema registry”. To look inside its topics the team bought Kpow, for four reasons he lists: real-time querying with kJQ, visualising messages, replaying messages during production issues, and “the PII masking feature in Kpow, which lets us mask fields like mobile number, first name, last name, or address.” He says masking has helped with Belong’s cyber security and risk teams and helps prevent people copying data out.

    Source: Belong talk, Implementing Kafka at Belong

How a team runs AWS Glue Schema Registry with Kpow

Installing it in the account. A team starts Kpow as an ECS task on Fargate from the CloudFormation templates, installs it on EKS with the Helm charts, or subscribes on AWS Marketplace and gets a container licensed to its AWS account, billed on the AWS invoice. Of the two AWS Marketplace listings, Kpow for Apache Kafka (Annual) is $4,500 per cluster credit a year and can be bought inside an Enterprise Discount Program by private offer. The full MSK walkthrough, including the Glue settings, is Set up Kpow with Amazon MSK.

Connecting the registry. Kpow takes the registry’s ARN and Region in SCHEMA_REGISTRY_ARN and SCHEMA_REGISTRY_REGION, and authenticates with the default AWS credentials chain, so the task or pod role is enough. Static keys go in SCHEMA_REGISTRY_ACCESS_KEY_ID and SCHEMA_REGISTRY_SECRET_ACCESS_KEY. A registry in another AWS account is reached by assuming a role with SCHEMA_REGISTRY_STS_ROLE_ARN, and the Glue Schema Registry documentation links an AWS walkthrough, with CloudFormation templates, for the cross-account role and trust policy. Several registries, Glue among them, can be attached to one Kafka cluster with SCHEMA_REGISTRY_RESOURCE_IDS.

Signing people in. Engineers sign in to Kpow through AWS IAM Identity Center over SAML, or through Okta, Microsoft Entra ID, Keycloak, OIDC or LDAP, so access follows the company directory rather than a shared IAM user.

Managing Glue schemas. The schema view lists each Glue subject with its type, version, compatibility mode and status. From there a permitted engineer creates a subject, edits it to register a new version, updates its compatibility or deletes it. RBAC separates SCHEMA_CREATE, SCHEMA_EDIT_VERSION and SCHEMA_DELETE, and staged mutations hold a change for an admin’s approval before it runs. Kpow’s features page also lists a visual diff between schema versions in both editions.

Reading Glue-encoded topics. Data inspect shows Glue-serialised Avro and Protobuf records decoded, and engineers filter them across topics with kJQ. Data policies mask sensitive fields in those results on the server.

Scripting it. The fh command line, released in September 2026, wraps the Kpow REST API with one fh kafka schema command tree for Confluent and AWS Glue registries, so listing, reading and creating subjects can run in CI or from a coding agent (fh CLI commands). State-changing commands go through the same approval step as the UI.

Giving teams their own view. Tenants limit which topics, groups and schemas each role can see, RBAC sets what each person may do, and temporary policies grant production access that expires at a set time.

Keeping the record. The audit log records each action with the user from the identity provider, and a webhook sends those records to Slack, Microsoft Teams or any endpoint.

Lineage from Glue schemas. Factor Platform reads the same registries as a lineage source. Its schema registry dataset mappings turn metadata annotated in Avro and JSON Schema schemas into OpenLineage datasets, with Glue as one of the two registry types it names.

The public Kpow demo needs no signup. Its MSK Secondary cluster has an AWS Glue Schema Registry attached, so the Schema view shows Glue subjects with their compatibility mode and status; sign-in, masking and temporary policies are the things to test in your own account. Glue has been part of Kpow since 2021, and the demo environment’s schema registries are AWS Glue, Karapace and Confluent, as described in the September 2026 product update.

Kpow live demo

See Kpow on an AWS Glue registry

The live Kpow demo connects to an AWS Glue Schema Registry on its MSK Secondary cluster. Open Schema to see each Glue subject with its version, compatibility mode and status, with no signup.

For platform teams choosing a Kafka tool for AWS Glue Schema Registry.

Try the Kpow demo

FAQ

What is the best Kafka UI for AWS Glue Schema Registry?

On this page’s rubric, Kpow, with 86 of 100 points: it decodes Glue-encoded Avro and Protobuf records, creates, edits and deletes Glue subjects and changes their compatibility, reaches a registry in another AWS account through an STS role, adds per-person roles, masking, approvals and an audit trail on top of IAM, and runs as one container in your account outside the data path. Kafbat UI is the highest-scoring open-source option, and Kpow Community Edition is free for up to 3 clusters and 10 users with the Glue Schema Registry included.

Which Kafka UI can read messages serialised with AWS Glue Schema Registry?

Kpow, Lenses, Conduktor and AKHQ decode Glue records as a built-in registry type; AKHQ deserialises Avro, Protobuf and JSON serialised Glue messages for reading only, using the default AWS credentials. Kafbat UI decodes them through the ui-serde-glue plugin. Redpanda Console documents no Glue support, and the AWS Glue console does not show records.

What is the difference between AWS Glue Schema Registry and Confluent Schema Registry?

Glue is a serverless AWS service that is free to use, and producers and consumers use AWS’s own Glue serializers; Confluent Schema Registry and compatible registries such as Karapace and Apicurio use the Confluent wire format that most Kafka serializers speak. Both version Avro, JSON Schema and Protobuf schemas under compatibility modes, but Glue enforces compatibility only when a version is registered. Its CheckSchemaVersionValidity API checks that a definition is valid for its format and performs no compatibility check, so there is no dry run like Confluent’s compatibility endpoint. Kpow connects to both kinds, and the registries are compared in Kafka schema registry tools.

How do you move from AWS Glue Schema Registry to Confluent Schema Registry or Karapace?

Glue and Confluent-compatible registries identify schemas differently, so moving from Glue to Karapace or Confluent’s registry means translating every schema ID rather than importing the schemas as they are, a hidden cost covered in the Factor House and NetApp Instaclustr talk Migrating to open source Kafka. During the move, Kpow can attach the Glue registry and the new registry to the same Kafka cluster, so engineers browse subjects in both and read records written under either from one place.

How do you audit who changed a schema in AWS Glue Schema Registry?

CloudTrail records each Glue API call, such as registering a schema version or changing compatibility, under the IAM principal that made it. When engineers work through a shared tool, that principal is the tool’s role, so Kpow’s audit log records each action with the user from the identity provider, and staged mutations can hold a schema change for an admin’s approval before it runs.

Can a Kafka UI manage schemas in AWS Glue Schema Registry, not only read them?

Yes. Kpow creates, edits and deletes Glue subjects and updates their compatibility, as the public demo’s Glue registry shows, with each action a separate permission. Conduktor documents the same operations for Glue, and Lenses described Glue schema management in 2023. Kafbat UI and AKHQ use Glue for messages only.

Can a Kafka UI reach a Glue registry in another AWS account?

Kpow assumes an STS role set in SCHEMA_REGISTRY_STS_ROLE_ARN (Kpow Glue docs), Lenses documents an assumed role on its AWS connection, and Conduktor accepts an IAM role by ARN. Kafbat UI’s plugin takes keys or a profile, and AKHQ uses the default credentials provider only.

Why does a Kafka UI need to assume a role to reach a Glue registry in another account?

Because the AWS Glue Schema Registry does not support resource-based policies, as AWS’s cross-account Glue Schema Registry post states, so the registry’s account cannot grant access with a policy on the registry itself. Clients and tools in the cluster’s account assume a role in the registry’s account instead, and the role session name they use is what that account’s CloudTrail shows, which for a shared tool is the tool’s session rather than the engineer’s.

Is there a free Kafka UI for AWS Glue Schema Registry?

Kpow Community Edition is free on up to 3 clusters and 10 users, includes the AWS Glue Schema Registry, and creates, edits and deletes subjects and changes their compatibility, which Kafbat UI and AKHQ do not do on Glue. Kafbat UI and AKHQ are open source and decode Glue records. RBAC, masking, staged approvals and the audit log need Kpow Enterprise. More free options are compared in the best free Kafka UI tools.

Can one Kafka UI use AWS Glue and a Confluent registry together?

Kpow attaches several registries to one Kafka cluster, Glue beside Confluent, Apicurio, Karapace, Google, Redpanda or Buf. Lenses allows one schema registry connection, and Kafbat UI manages one Confluent-compatible registry per cluster with Glue as a serde.

Does a Kafka UI need to sit in the data path to govern access to Glue-encoded data?

No. Kpow runs as one container in your account, connects like any Kafka client and applies roles, masking, approvals and the audit trail to the people working through it, so producers and consumers keep calling Glue and the brokers directly. Conduktor Console also connects directly, while Conduktor’s data-level controls run in Gateway, a Kafka proxy that client applications connect through.

Does AWS provide a UI for AWS Glue Schema Registry?

The AWS Glue console creates and updates registries, schemas, versions and compatibility modes. It does not read Kafka records, so seeing what a schema describes in a topic needs the Kafka CLI with the Glue deserializer, or a separate tool.

How these tools were scored

Four of the six criteria start from Amazon’s AWS Glue documentation; the other two are where the tool runs and how it shows topic data. They are listed here in order of weight. Each criterion is scored 0 to 10: 10 where a tool is the only one here doing it or clearly the best, 8 for a clean documented pass, 5 to 7 for partial support or support that needs work the reader must verify, 1 to 4 for a weak or indirect form, and 0 where it is absent.

1. Governance beyond IAM (counts three times). IAM decides what a principal may do, and CloudTrail records the Glue API calls each principal makes. Neither gives a per-person view of the records a shared tool decodes, masking, or an approval step before a schema version is deleted, and when engineers share a tool the principal on record is the tool’s role. This criterion scores per-person roles, production access granted on request and expiring, masking, directory sign-in, tenants for teams sharing a cluster, and an audit trail that names the person. It is scored the same way as on the Amazon MSK page. The requirements for regulated teams are covered in Kafka governance tools for financial services, and the masking options are compared in Kafka data masking tools.

2. Reading Glue-encoded records (counts twice). Producers that use the Glue serializers write records a Confluent-only tool cannot decode. A tool scores 8 when Glue decoding is built in and documented for the formats it names, 7 when it works through a separate plugin, and 0 when Glue is not supported.

3. Out of the data path (counts twice). The tool should run inside your AWS account and VPC, reach the brokers and Glue as an ordinary client, and keep no data outside your own cluster. Scored lower: tools that need an external database of their own, and tools whose controls work only when application traffic passes through a vendor’s proxy. A self-hosted container with no external database and no proxy scores 9, a tool with a database of its own 6, one with several databases or a component on the brokers 4, and one that needs both a database and a proxy for its controls 3; 10 is kept for an option with nothing to deploy at all, here the AWS Glue console. This criterion is scored the same way on every Factor House page that uses it, and only its weight changes with the reader.

4. Managing Glue schemas (counts once). Creating a schema, registering a version, changing a compatibility mode and deleting are the changes that break consumers when they go wrong. The AWS Glue console, as the registry’s own control plane, scores 10; a tool that documents or shows all four on Glue scores 8; one limited to a single registry or older evidence scores lower; one that uses Glue for messages only scores 1.

5. Credentials and cross-account (counts once). A tool should take its credentials from the task or pod role, accept static keys where a team needs them, and reach a registry in another account by assuming a role, with the glue:GetSchema and glue:GetSchemaVersion permissions that AWS’s read-only managed policy grants.

6. Inspecting topic data (counts once). Reading a message, searching a topic for one key or replaying a record after an incident is the day-to-day job engineers need a tool for. It is scored the same way as on the Amazon MSK page.

Costs are modelled for one production cluster, priced as Amazon MSK because that is where most Glue registries are used, and 25 engineers at $120 per engineer hour, using the same hours per tool class as Factor House’s other comparison pages. Tools with a licence carry the published price plus 2 hours a month to run. The open-source UIs carry 6 hours a month, $8,640 a year, to run, secure and keep current. The Glue registry itself is free and the console has nothing to run, and the Kafka CLI it leaves record reading to is modelled like the other tools with no access control of their own, at 8 hours a month, $11,520 a year. Kpow’s $7,380 uses the Annual price of $4,500 per cluster with 100 users included. Kpow Community Edition is free for 3 clusters and 10 users, so a 25-engineer team is on Enterprise.

The criteria map onto the Glue Schema Registry features in the figure below.

F1 From Glue Schema Registry feature to what a Kafka tool has to do
What Glue Schema Registry does What the tool has to do
Its own serializers Producers serialise records with the AWS Glue Schema Registry library, not the Confluent client Decode Glue-encoded records, rather than assume every record carries a Confluent schema ID
Formats Schemas are Avro, JSON Schema or Protobuf Read each format the team's producers use, and say which ones it supports
Compatibility Eight modes, from NONE and DISABLED to FULL_ALL, enforced when a version is registered Show each schema's mode and status, and let a permitted engineer change it
IAM access Readers need glue:GetSchema and glue:GetSchemaVersion on the registry and its schemas Take credentials from the task or pod role, from static keys, or by assuming a role
Registries and accounts Up to 100 registries per AWS Region in an account, which can sit in a different account from the cluster Reach a registry in another AWS account by assuming a role, and hold more than one registry
Who did what IAM authorises the principal that calls the Glue API When people share one tool, add per-person roles, masking and an audit trail, because the principal is the tool's role
Where the tool runs The registry is a regional AWS service, and producers and consumers call it directly Run in the same account and VPC as an ordinary Kafka client, not as a proxy that applications route through
Each row starts from Amazon's own AWS Glue documentation or from where the tool runs, then names what a UI or management tool needs in order to work with it.

Every option is scored from 0 to 10 on each criterion, from the evidence and sources this page cites, and the reason for each score is on its card. The criteria are weighted: Governance beyond IAM counts three times, Reading Glue-encoded records counts twice, Out of the data path counts twice, Managing Glue schemas counts once, Credentials and cross-account counts once and Inspecting topic data counts once, for a total out of 100. Governance beyond IAM counts three times because a decoded Glue record is readable data, and on a shared tool IAM authorises the tool's own role, so per-person roles, production access granted on request, masking, directory sign-in, tenants for shared clusters and a per-person audit trail are the only record of which engineer read or changed what. Reading Glue-encoded records and out of the data path count twice: a tool that cannot decode Glue's wire format shows engineers bytes, and a tool that clients connect through becomes part of the path every producer and consumer depends on, while one that needs a database of its own is one more component to run and secure. Managing Glue schemas, credentials and cross-account access, and inspecting topic data count once, because each matters but none decides on its own whether a team can use the tool on Glue. This page is published by Factor House, which makes Kpow. Every option is scored on the same rubric and the same sources: Kpow's per-criterion scores are set the same way as every other option's and are not adjusted, and the weights apply to every option alike. Kpow ranks first on its total of 86 out of 100. The other options follow by total. Conduktor is listed last whatever its total; on its total of 73 it would place second.

Related reading