Security Token Exchange - Confluent Cloud
Confluent Security Token Service exchange of an external identity-provider JWT for a short-lived Confluent access token. Generated from Confluent's hash-locked aggregate OpenAPI 3.0.0 snapshot (0803fa3bd07e…) and carries 1 of the suite's 489 admitted current operations. The enrolled confluent-sts connection supplies an unauthenticated origin-pinning connection; token material stays in the request body and fixes the runtime origin; credentials never enter this pack. JSON bodies are required and sent verbatim, the one STS form owns its fixed token-type constants, unbounded integer parameters become exact strings, and parameter arrays carry a Recued 256-item safety ceiling that is not presented as a provider limit. Reads are uncached and not approval-gated; every mutation requires approval. Token collections walk automatically without inventing a stable provider page-size maximum. Vendor-only +json responses remain honest text, binary image reads become private file_refs, seven deprecated operations and one unsupported binary upload are absent, and no infrastructure or streaming resource is misrepresented as a task, note, or user-work project Source.
What this pack installs
- confluent-sts Ingredient
Trust & control
What installing this whole pack would let it do. Recued grants these permissions at install — review them there before approving.