---
title: "ACL Management - Pilot Docs"
description: "Kafka ACL creation, viewing, and deletion"
url: "https://docs.calinora.io/features/acls/"
---

# ACL Management

Pilot provides a UI and API for viewing and managing Kafka Access Control Lists (ACLs).

## Overview

Kafka ACLs control which principals (users, services) can perform specific operations on cluster resources. Pilot makes it easy to view, create, update, and delete ACLs without direct Kafka CLI access.

## ACL Components

Each ACL binding consists of:

| Field | Description |
| - | - |
| **Resource Type** | `Topic`, `Group`, `Cluster`, `TransactionalId`, `DelegationToken` |
| **Resource Name** | Name of the resource (e.g., topic name) |
| **Pattern Type** | `Literal` (exact match) or `Prefixed` (prefix match) |
| **Principal** | User identity (e.g., `User:alice`) |
| **Host** | Client host (`*` for any) |
| **Operation** | `Read`, `Write`, `Create`, `Delete`, `Alter`, `Describe`, `All`, etc. |
| **Permission Type** | `Allow` or `Deny` |

## API Endpoints

| Method | Path | Description | License |
| - | - | - | - |
| `GET` | `/api/v1/acls` | List all ACL bindings | No |
| `POST` | `/api/v1/acls` | Create ACL bindings | Yes |
| `PUT` | `/api/v1/acls` | Update (replace) an ACL binding | Yes |
| `DELETE` | `/api/v1/acls` | Delete ACL bindings by filter | Yes |

### Example: Create a Read ACL

```bash
curl -X POST http://localhost:8080/api/v1/acls \
  -H "Content-Type: application/json" \
  -d '{
    "bindings": [{
      "resourceType": "Topic",
      "resourceName": "my-topic",
      "patternType": "Literal",
      "principal": "User:consumer-app",
      "host": "*",
      "operation": "Read",
      "permissionType": "Allow"
    }]
  }'
```

### Example: List ACLs for a Principal

```bash
curl "http://localhost:8080/api/v1/acls?principal=User:consumer-app"
```
