| Version | Supported |
|---|---|
| 1.1.x | ✅ |
| 1.0.x | ❌ |
1.0.x is end-of-support — upgrade to 1.1.x.
Kview is designed for local development and trusted internal networks.
The REST API ships built-in bearer-token authentication (kview.auth.*), disabled by default:
KVIEW_AUTH_MODE |
Behavior |
|---|---|
none (default) |
API is open — acceptable on the default loopback binding for a single-user machine. |
token |
Static tokens from KVIEW_AUTH_TOKENS (TOKEN = admin, TOKEN:readonly = read-only). |
oidc |
JWTs validated against any OIDC issuer (spring.security.oauth2.resourceserver.jwt.issuer-uri); a configurable claim separates admin from read-only. |
In authenticated modes: every request needs Authorization: Bearer <token>; read-only covers
dashboard, browsing, tailing and schema decoding, while produce, topic create/delete/edit, offset
resets, group deletion and connection management require the admin role. CORS is closed unless
KVIEW_AUTH_ALLOWED_ORIGINS lists browser origins. The web UI prompts for the token (🔑 in the top
bar), the CLI takes --token / KVIEW_TOKEN, and the MCP server takes KVIEW_TOKEN. Cluster
secrets stay server-side and masked in responses regardless of mode.
KVIEW_READONLY=truedisables every mutation server-side — for all clients (UI, CLI, MCP agents) and all roles. Pair it withKVIEW_AUTH_MODEfor an explore-only deployment, or run it alone to turn a shared Kview into a pure viewer.KVIEW_AUDIT=trueappends one JSONL line per mutation to<data-dir>/audit.log: timestamp, client identification (X-Kview-Client—kview-mcp/x.y.zfor AI agents,kview-cli,kview-ui), method, full path (cluster, topic, action) and response status. Message payloads are never logged. Restrict the MCP server further withKVIEW_ALLOWED_TOOLS(comma-separated tool allowlist)./actuator/prometheus(metrics scraping) follows the same rules as the rest of the actuator: public whilekview.auth.mode=none, and any-role-required once authentication is on — give your scraper a token or permit the path at the reverse proxy.
To prevent inadvertent exposure on shared servers or cloud VMs, Kview binds to 127.0.0.1 by default (server.address: ${KVIEW_BIND:127.0.0.1}).
- When running in Docker containers,
KVIEW_BINDis set to0.0.0.0so that ports can be forwarded explicitly. - Do not expose port
8090directly to the public Internet without enabling the built-in authentication or placing Kview behind a proxy.
If deploying Kview in a team environment or shared private cloud:
- Enable built-in authentication (
KVIEW_AUTH_MODE=tokenoroidc) — for OIDC you can still front Kview with your identity provider of choice. - Alternatively/ additionally, deploy behind an authenticating reverse proxy such as:
- OAuth2-Proxy
- NGINX with
http_auth_basic_moduleor OIDC - Caddy with forward auth
- Cloudflare Access or AWS ALB / Azure App Gateway with authentication.
- Restrict file permissions on the storage directory (
./databy default), which containsconnections.jsonand saved cluster credentials.
If you discover a potential security vulnerability in Kview:
- Do not open a public GitHub issue.
- Report it privately — either by emailing ritikbansod.dev@gmail.com or via a GitHub Security Advisory.
- Include detailed steps to reproduce the issue, the affected versions, and any proof-of-concept scripts.
- You will receive an acknowledgment within 48 hours, followed by updates on the fix and a public disclosure timeline.