OFICIAL AWS What's New

MSK Replicator now supports OAuth 2.0 (SASL/OAUTHBEARER) authentication for replication from external Apache Kafka clusters to Amazon MSK

What happened
Based on AWS What's New · Aug 24, 2026

Amazon MSK Replicator now supports OAuth 2.0 authentication for replicating data from external Kafka clusters to Amazon MSK, expanding authentication options beyond SASL/SCRAM and mTLS.

MSK Replicator now supports OAuth 2.0 (SASL/OAUTHBEARER) authentication for replication from external Apache Kafka clusters to Amazon MSK
AWS What's New — Amazon Web Services
Key points
·
Amazon MSK Replicator now supports OAuth 2.0 (SASL/OAUTHBEARER) authentication for data replication from external Apache Kafka clusters - including on-premises, self-managed on AWS, or other cloud providers - to Amazon MSK Provisioned clusters.
·
MSK Replicator is a feature of Amazon MSK that automates data replication between Kafka clusters, eliminating the need to manage custom replication infrastructure or configure open-source tools.
·
Previously, MSK Replicator supported SASL/SCRAM and mTLS authentication for connecting to external Apache Kafka clusters.
·
With this launch, you can now also use OAuth 2.0 authentication with MSK Replicator to replicate data from external Kafka clusters to Amazon MSK.

Amazon MSK Replicator has introduced support for OAuth 2.0 (SASL/OAUTHBEARER) authentication, enabling secure data replication from external Apache Kafka clusters—including on-premises, self-managed on AWS, or other cloud providers—to Amazon MSK Provisioned clusters. This enhancement allows organizations to migrate workloads, implement disaster recovery strategies, and distribute data across hybrid and multi-cloud environments using OAuth/OIDC-configured Kafka clusters. Previously limited to SASL/SCRAM and mTLS, the new capability broadens compatibility with modern authentication frameworks.

MSK Replicator automates data replication between Kafka clusters, removing the need for custom infrastructure or open-source tools. The feature retains original Kafka topic names during replication and prevents infinite loops, while synchronizing consumer group offsets bidirectionally. This ensures producers and consumers can be moved independently across clusters without coordination constraints or data loss risks, supporting flexible migration and failover scenarios.

The OAuth 2.0 support is now available in all AWS Regions where MSK Replicator is offered, aligning with existing authentication methods. Organizations can leverage this capability to streamline replication workflows while maintaining security and operational consistency across diverse Kafka deployments.

For implementation details, users can refer to the MSK Replicator documentation, product page, pricing page, and an AWS blog post outlining the new authentication support and its use cases.

Original source → Deals on Clipraptor.com →