SCRAM

A SASL mechanism that proves a client knows its password without sending it.

Kafka stores salted SCRAM credentials in the cluster metadata, where kafka-configs creates and changes them. The client and broker exchange challenges, so a captured exchange does not reveal the password.

Related terms

Certification courses