Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Epic: BYOIDC bearer-token authentication for `confluent_sql`

Open
#148 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
5/5
Estimated time
Over a week
Newbie friendliness
35/100
Issue type
Feature
Clarity
Needs clarification
Activity status
Quiet
Tech stack
python

Research direction

No files, tests, or entry points are named in the issue. Start by identifying the independently shippable children for the Flink data plane, then verify the stated authorization boundary against the Cloud OpenAPI specification. Done means covering the static external token and refreshing client-credentials modes while failing closed for control-plane requests.

Written by the indexing model from the issue text.

Description

Confluent Cloud customers who run their own OAuth/OIDC identity provider need to authenticate this driver with a bearer token they mint themselves — an external token, in Confluent's authorization vocabulary — rather than a Confluent API key + secret. This epic covers that BYOIDC (bring-your-own-IdP) surface end to end, as small independently-shippable children.

Scope boundary: Flink data plane only

By Confluent's authorization model (verified against the Cloud OpenAPI spec's per-operation AUTHORIZATIONS blocks), a raw external token authenticates the Flink data plane and nothing on api.confluent.cloud. None of /tableflow/v1, /connect/v1, /cmk/v2/clusters, or /org/v2/organizations accept external-access-token. So every child here is Flink-only, and the control plane fails closed with an error. Reaching the control plane with a caller identity is a different problem, covered in a separate epic, which mints Confluent's own tokens.

The bar: cover plugin #399's BYOIDC half

The neighboring Java Table API client shipped two BYOIDC-flavoured modes in one large PR: a static external-access-token and a refreshing client-credentials provider. This epic covers the same ground as a sequence of bounded children rather than one mega-PR

Dominant language
Python
Stars
6
Forks
1
Avg merge
14h 58m
Merged PRs (30d)
22

Getting set up

This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from confluentinc/confluent-sql

All issues in confluentinc/confluent-sql

Similar issues

More Python issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.