<a id="cc-mqtt-sink"></a>

# MQTT Sink Connector for Confluent Cloud

The fully managed MQTT Sink connector for Confluent Cloud streams data from Apache Kafka® to
an MQTT broker.

#### NOTE
* This Quick Start is for the fully managed Confluent Cloud connector. If you are
  installing the connector locally for Confluent Platform, see [MQTT
  Sink Connector for Confluent Platform](https://docs.confluent.io/kafka-connectors/mqtt/current/mqtt-sink-connector/).
* If you require private networking for fully managed connectors, make sure to set up the proper
  networking beforehand. For more information, see [Manage Networking for Confluent Cloud Connectors](networking/internet-resource.md#clusters-connect-cloud).

## Features

The MQTT Sink connector provides the following features:

* **At least once delivery**: The connector guarantees that records are delivered at least once to the MQTT topic.
* **Supports multiple tasks**: The connector supports running one or more tasks. More tasks may improve performance.
* **Schemas**: The connector supports Avro, JSON Schema, and Protobuf input data formats. [Schema Registry](../get-started/schema-registry.md#cloud-sr-config) must be enabled to use a Schema Registry-based format. Note that the connector only supports bytes and string schemas. It does not support structs. If you want to have struct type schemas, you can store the struct data as bytes and select bytes in the connector.

For more information and examples to use with the Confluent Cloud API for Connect,
see the [Confluent Cloud API for Connect Usage Examples](connect-api-section.md#ccloud-connect-api) section.

## Limitations

Be sure to review the following information.

* For connector limitations, see [MQTT Sink Connector](limits.md#cc-mqtt-sink-limits) limitations.
* If you plan to use one or more Single Message Transformations (SMTs), see [SMT Limitations](single-message-transforms.md#cc-single-message-transforms-limitations).

## Quick Start

Use this quick start to get up and running with the Confluent Cloud MQTT sink
connector. The quick start provides the basics of selecting the connector and
configuring it to stream events to an MQTT broker.

<a id="cc-mqtt-sink-prereqs"></a>

Prerequisites
: - Authorized access to a [Confluent Cloud](https://www.confluent.io/confluent-cloud/) cluster on Amazon Web Services (AWS), Microsoft Azure (Azure), or Google Cloud.
  - Access to an MQTT broker.
  - The Confluent CLI installed and configured for the cluster. See [Install the Confluent CLI](https://docs.confluent.io/confluent-cli/current/install.html).
  - [Schema Registry](../get-started/schema-registry.md#cloud-sr-config) must be enabled to use a Schema Registry-based format (for example, Avro, JSON_SR (JSON Schema), or Protobuf).
  - For networking considerations, see [Networking and DNS](overview.md#connect-internet-access-resources). To use a set of public egress IP addresses, see [Public Egress IP Addresses for Confluent Cloud Connectors](static-egress-ip.md#cc-static-egress-ips).
  - [Schema Registry](../get-started/schema-registry.md#cloud-sr-config) must be enabled to use a Schema Registry-based format (for example, Avro, JSON_SR (JSON Schema), or Protobuf).
  <br/>
  - Kafka cluster credentials. The following lists the different ways you can provide credentials.
    - Enter an existing [service account](service-account.md#s3-cloud-service-account) resource ID.
    - Create a Confluent Cloud [service account](service-account.md#s3-cloud-service-account) for the connector. Make sure to review the ACL entries required in the [service account documentation](service-account.md#s3-cloud-service-account). Some connectors have specific ACL requirements.
    - Create a Confluent Cloud API key and secret. To create a key and secret, you can use [confluent api-key create](https://docs.confluent.io/confluent-cli/current/command-reference/api-key/confluent_api-key_create.html) *or* you can autogenerate the API key and secret directly in the Cloud Console when setting up the connector.

### Using the Confluent Cloud Console

#### Step 1: Launch your Confluent Cloud cluster

To create and launch a Kafka cluster in Confluent Cloud, see [Create a kafka cluster in Confluent Cloud](../get-started/index.md#cloud-create-kafka-cluster).

#### Step 2: Add a connector

In the left navigation menu, click **Connectors**. If you already have connectors in your cluster, click **+ Add
connector**.

#### Step 3: Select your connector

Click the **MQTT Sink** connector card.

![MQTT Sink Connector Card](images/ccloud-mqtt-sink-icon.png)

<a id="cc-mqtt-sink-setup-connection"></a>

#### Step 4: Enter the connector details

#### NOTE
* Ensure you have all your [prerequisites](#cc-mqtt-sink-prereqs) completed.
* An asterisk ( \* ) designates a required entry.

At the **Add MQTT Sink Connector** screen, complete the following:

### Topic selection

If you’ve already populated your Kafka topics, select the topics you want
to connect from the **Topics** list.

To create a new topic, click **+Add new topic**.

### Kafka access

1. Select the way you want to provide **Kafka Cluster credentials**. You can
   choose one of the following options:
   - **My account**: This setting allows your connector to globally access everything
     that you have access to. With a user account, the connector uses an API key and
     secret to access the Kafka cluster. This option is not recommended for production.
   - **Service account**: This setting limits the access for your connector by using a
     [service account](service-account.md#s3-cloud-service-account). This option is recommended for
     production.
   - **Use an existing API key**: This setting allows you to specify an API key and a
     secret pair. You can use an existing pair or create a new one. This method is not
     recommended for production environments.

   #### NOTE
   Freight clusters support only service accounts for Kafka authentication.
2. Click **Continue**.

### Authentication

1. Configure the authentication properties:

   **How should we connect to MQTT Broker?**
   - **List of Server URIs**: The MQTT broker URI. Must be in the format
     `<PROTOCOL>//:URI`. The supported protocols are TCP, SSL, WS, and
     WSS. For TLS connections you must additionally provide credentials
     and upload Keystore and Truststore files.
   - **Username**: Username to connect with, or blank to connect without a
     username.
   - **Password**: Password to connect with, or blank to connect without a
     password.

   **MQTT secure connection**
   - **SSL Keystore**: The location of the Java KeyStore file containing
     the private key to use for authenticating with the server.
   - **Keystore Password**: Password used to open the Java KeyStore file.
   - **Key Password**: Password for the client certificate contained in
     the Java KeyStore.
   - **SSL Truststore**: The location of the Java TrustStore file
     containing the certificates required to validate the SSL connection
     to the server.
   - **Truststore Password**: The password used to open the Java KeyStore
     file.
2. Click **Continue**.

### Configuration

#### NOTE
Configuration properties that are not shown in the
Cloud Console use the default values. See
[Configuration Properties](#cc-mqtt-sink-config-properties) for all property values and
definitions.

- **Input Kafka record value format**: Select the Input Kafka record value format (data coming from the
  Kafka topic). Valid options are AVRO, JSON_SR (JSON Schema), PROTOBUF, JSON (schemaless),
  or BYTES. A valid schema must be available in [Schema Registry](../get-started/schema-registry.md#cloud-sr-config) to use a schema-based message format (for example,
  AVRO, JSON_SR (JSON Schema), or PROTOBUF).
- **MQTT QOS**: The default value is `0` which means the message
  gets delivered once, with no confirmation. The QOS property must
  be set to at least `1` or `2` for unreceived messages to be
  received when the client and server reconnect. For more
  information, see Quality of Service in [this man page](https://mosquitto.org/man/mqtt-7.html).

### **Show advanced configurations**

- **Schema context**: Select a schema context to use for this connector, if using
  a schema-based data format. This property defaults to the **Default** context,
  which configures the connector to use the default schema set up for Schema Registry in your
  Confluent Cloud environment. A schema context allows you to use separate schemas (like
  schema sub-registries) tied to topics in different Kafka clusters that share the
  same Schema Registry environment. For example, if you select a non-default context, a
  **Source** connector uses only that schema context to register a schema and a
  **Sink** connector uses only that schema context to read from. For more
  information about setting up a schema context, see [What are schema contexts and when should you use them?](../sr/faqs-cc.md#faq-schema-contexts).
- **Retain Messages**: Set whether messages should be retained
  for future clients.

**Auto-restart policy**

- **Enable Connector Auto-restart**: Enables the auto-restart behavior of the connector and its
  task in the event of user-actionable errors. Defaults to `true`, enabling the connector to
  automatically restart in case of user-actionable errors. Set this property to `false` to
  disable auto-restart for failed connectors. If disabled, you must manually restart the connector.

**Additional Configs**

- **Value Converter Decimal Format**: Specifies the `JSON` or `JSON_SR` serialization format for Connect `DECIMAL` logical type values with two allowed literals:
  `BASE64` to serialize `DECIMAL` logical types as base64 encoded binary data, and
  `NUMERIC` to serialize `DECIMAL` logical type values in `JSON` or `JSON_SR` as a number representing the decimal value.
- **Schema GUID For Key Converter**: Sets the schema GUID to use for deserialization when using `ConfigSchemaIdDeserializer`. This lets you specify a fixed schema GUID for deserializing message keys. This property is applicable only when `key.converter.key.schema.id.deserializer` is set to `ConfigSchemaIdDeserializer`.
- **Value Converter Schema ID Deserializer**: Sets the class name of the schema ID deserializer for values. The deserializer reads schema IDs from message headers.
- **Schema GUID For Value Converter**: Sets the schema GUID to use for deserialization when using `ConfigSchemaIdDeserializer`. This lets you specify a fixed schema GUID for deserializing message values. This property is applicable only when `value.converter.value.schema.id.deserializer` is set to `ConfigSchemaIdDeserializer`.
- **Value Converter Reference Subject Name Strategy**: Sets the subject reference name strategy for values. Valid entries are `DefaultReferenceSubjectNameStrategy` or `QualifiedReferenceSubjectNameStrategy`. You can use this strategy only with `PROTOBUF` format; the default strategy is `DefaultReferenceSubjectNameStrategy`.
- **Schema ID For Value Converter**: Sets the schema ID to use for deserialization when using `ConfigSchemaIdDeserializer`. This lets you specify a fixed schema ID for deserializing message values. This property is applicable only when `value.converter.value.schema.id.deserializer` is set to `ConfigSchemaIdDeserializer`.
- **Value Converter Connect Meta Data**: Enables the Connect converter to add its metadata to the output schema. Applies to Avro converters.
- **Value Converter Value Subject Name Strategy**: Determines how to construct the subject name under which the value schema is registered with Schema Registry.
- **Key Converter Key Subject Name Strategy**: Determines how to construct the subject name for key schema registration.
- **Key Converter Schema ID Deserializer**: Sets the class name of the schema ID deserializer for keys. The deserializer reads schema IDs from message headers.
- **Schema ID For Key Converter**: Sets the schema ID to use for deserialization when using `ConfigSchemaIdDeserializer`. This lets you specify a fixed schema ID for deserializing message keys. This property is applicable only when `key.converter.key.schema.id.deserializer` is set to `ConfigSchemaIdDeserializer`.

**Connection Details**

- **Clean Session?**: Sets whether the client and server should
  remember their state after restarts and reconnects. For unreceived
  messages to be received when the client and server reconnect,
  the MQTT Quality of Service (QOS) property must be set to at least
  `1` or `2`. For more information, see Quality of Service in
  [this man page](https://mosquitto.org/man/mqtt-7.html).
- **Connection Timeout**: The amount of time to wait in seconds when
  connecting to the MQTT broker. The default is 30 seconds.
- **Connection Keepalive**: Defines the maximum time interval
  between messages sent or received (in seconds). In the absence of
  a data-related message during the time period entered, the client
  sends a very small ping message for the broker to acknowledge. The
  default value is 60 seconds.
- **Max Retry Time**: The maximum time in milliseconds (ms) the
  connector spends backing off and retrying a connection to the MQTT
  broker. The default value is 30000 ms (30 seconds).

**Consumer configuration**

- **Max poll interval(ms)**: Sets the maximum delay between subsequent consume requests to Kafka. Use this property to
  improve connector performance in cases when the connector cannot send records to the sink system.
  The default is 300,000 milliseconds (5 minutes).
- **Max poll records**: Sets the maximum number of records to consume from Kafka in a single request. Use this property to
  improve connector performance in cases when the connector cannot send records to the sink system.
  The default is 500 records.

**Transforms**

- **Single Message Transformations**: To add a new SMT, see [Add transforms](single-message-transforms.md#cc-single-message-transforms-ui).
  For more information about unsupported SMTs, see
  [Unsupported transformations](single-message-transforms.md#cc-single-message-transforms-unsupported-transforms).

**Processing position**

- **Set offsets**: Click **Set offsets** to define a specific offset for
  this connector to begin procession data from. For more information
  on managing offsets, see [Manage offsets](offsets.md#connect-custom-offsets).

- Click **Continue**.

### Sizing

Based on the number of topic partitions you select, you will be provided
with a recommended number of tasks.

1. To change the number of recommended tasks, enter the number of
   [tasks](/platform/current/connect/concepts.html#tasks) for the connector to use in
   the **Tasks** field.
2. Click **Continue**.

### Review and Launch

1. Verify the connection details.
2. Click **Launch**.

   The status for the connector should go from **Provisioning** to
   **Running**.

#### Step 5: Check the results on the broker

Verify that new records are being added to the MQTT broker

For more information and examples to use with the Confluent Cloud API for Connect,
see the [Confluent Cloud API for Connect Usage Examples](connect-api-section.md#ccloud-connect-api) section.

### Using the Confluent CLI

Complete the following steps to set up and run the connector using the Confluent CLI.

#### NOTE
Make sure you have all your [prerequisites](#cc-mqtt-sink-prereqs) completed.

#### Step 1: List the available connectors

Enter the following command to list available connectors:

```none
confluent connect plugin list
```

#### Step 2: List the connector configuration properties

Enter the following command to show the connector configuration properties:

```none
confluent connect plugin describe <connector-plugin-name>
```

The command output shows the required and optional configuration properties.

#### Step 3: Create the connector configuration file

Create a JSON file that contains the connector configuration properties. The following example shows the required connector properties.

```none
{
  "connector.class": "MqttSink",
  "name": "MqttSink_0",
  "input.data.format": "AVRO",
  "kafka.auth.mode": "KAFKA_API_KEY",
  "kafka.api.key": "<my-kafka-api-key>",
  "kafka.api.secret": "<my-kafka-api-secret>",
  "mqtt.server.uri" : ""tcp://192.0.0.1:1881",
  "topics" : "kafka_topic_0",
  "tasks.max" : "1"
}
```

Note the following property definitions:

* `"name"`: Sets a name for your new connector.
* `"connector.class"`: Identifies the connector plugin name.
* `"input.data.format"`: Supports AVRO, BYTES, JSON, JSON_SR (JSON Schema), or PROTOBUF. A valid schema must be available in [Schema Registry](../get-started/schema-registry.md#cloud-sr-config) to use a schema-based message format.

* `"kafka.auth.mode"`: Identifies the connector authentication mode you want to use. There are two options: `SERVICE_ACCOUNT` or `KAFKA_API_KEY` (the default). To use an API key and secret, specify the configuration properties `kafka.api.key` and `kafka.api.secret`, as shown in the example configuration (above).  To use a [service account](service-account.md#s3-cloud-service-account), specify the **Resource ID** in the property `kafka.service.account.id=<service-account-resource-ID>`. To list the available service account resource IDs, use the following command:
  ```bash
  confluent iam service-account list
  ```

  For example:
  ```bash
  confluent iam service-account list

     Id     | Resource ID |       Name        |    Description
  +---------+-------------+-------------------+-------------------
     123456 | sa-l1r23m   | sa-1              | Service account 1
     789101 | sa-l4d56p   | sa-2              | Service account 2
  ```

* `"mqtt.server.uri"`: The MQTT broker URI. Must be in the format
  `<PROTOCOL>//:URI`. The supported protocols are TCP, SSL, WS, and WSS. For
  TLS connections you must additionally provide credentials and upload Keystore
  and Truststore files. See the [MQTT Sink configuration properties](#cc-mqtt-sink-config-properties) for these property values and definitions.

  #### NOTE
  If the MQTT broker does not support anonymous mode, you must add the following two additional properties:
  * `"mqtt.username"`: `"<mqtt_broker_username>"`
  * `"mqtt.password"`: `"<user_password>"`
* `"topics"`: The Kafka topic name (or comma-separated topic names) where the data for the MQTT broker is located.
* `"tasks.max"`: Enter the number of [tasks](/platform/current/connect/concepts.html#tasks) in use by the connector. The connector supports multiple tasks. More tasks may improve performance.

#### NOTE
The MQTT topic name where data lands is the same as the Kafka topic name.

**SMTs**: For details about adding SMTs using the Confluent CLI, see the [Single Message Transformations](single-message-transforms.md#cc-single-message-transforms) documentation.

See [Configuration Properties](#cc-mqtt-sink-config-properties) for all property values and
definitions.

#### Step 4: Load the configuration file and create the connector

Enter the following command to load the configuration and start the connector:

```none
confluent connect cluster create --config-file <file-name>.json
```

For example:

```none
confluent connect cluster create --config-file mqtt-server-sink-config.json
```

Example output:

```none
Created connector MqttSink_0 lcc-ix4dl
```

#### Step 5: Check the connector status

Enter the following command to check the connector status:

```none
confluent connect plugin list
```

Example output:

```none
ID          |       Name   | Status  | Type
+-----------+--------------+---------+------+
lcc-ix4dl   | MqttSink_0   | RUNNING | sink
```

#### Step 6: Check the results in the database.

Verify that new records are being added to the MQTT database.

For more information and examples to use with the Confluent Cloud API for Connect,
see the [Confluent Cloud API for Connect Usage Examples](connect-api-section.md#ccloud-connect-api) section.

<a id="cc-mqtt-sink-config-properties"></a>

## Configuration Properties

Use the following configuration properties with the fully managed connector. For
self-managed connector property definitions and other details, see the connector
docs in [Self-managed connectors for Confluent Platform](/platform/current/connect/kafka_connectors.html).

### How should we connect to your data?

`name`
: Sets a name for your connector.
  <br/>
  * Type: string
  * Valid Values: A string at most 64 characters long
  * Importance: high

### Which topics do you want to get data from?

`topics.regex`
: A regular expression that matches the names of the topics to consume from. This is useful when you want to consume from multiple topics that match a certain pattern without having to list them all individually.
  <br/>
  * Type: string
  * Importance: low

`topics`
: Identifies the topic name or a comma-separated list of topic names.
  <br/>
  * Type: list
  * Importance: high

### Schema Config

`schema.context.name`
: Add a schema context name. A schema context represents an independent scope in Schema Registry. It is a separate sub-schema tied to topics in different Kafka clusters that share the same Schema Registry instance. If not used, the connector uses the default schema configured for Schema Registry in your Confluent Cloud environment.
  <br/>
  * Type: string
  * Default: default
  * Importance: medium

### Input messages

`input.data.format`
: Sets the input Kafka record value format. Valid entries are AVRO, JSON_SR, PROTOBUF, JSON or BYTES. Note that you need to have Confluent Cloud Schema Registry configured if using a schema-based message format like AVRO, JSON_SR, and PROTOBUF.
  <br/>
  * Type: string
  * Importance: high

### Kafka Cluster credentials

`kafka.auth.mode`
: Kafka Authentication mode. It can be one of KAFKA_API_KEY or SERVICE_ACCOUNT. It defaults to KAFKA_API_KEY mode, whenever possible.
  <br/>
  * Type: string
  * Valid Values: SERVICE_ACCOUNT, KAFKA_API_KEY
  * Importance: high

`kafka.api.key`
: Kafka API Key. Required when kafka.auth.mode==KAFKA_API_KEY.
  <br/>
  * Type: password
  * Importance: high

`kafka.service.account.id`
: The Service Account that will be used to generate the API keys to communicate with Kafka Cluster.
  <br/>
  * Type: string
  * Importance: high

`kafka.api.secret`
: Secret associated with Kafka API key. Required when kafka.auth.mode==KAFKA_API_KEY.
  <br/>
  * Type: password
  * Importance: high

### How should we connect to MQTT Broker?

`mqtt.server.uri`
: The URI of the MQTT broker. This must be given in the format <PROTOCOL>//:URI. The supported protocols are tcp, ssl, ws, wss. Note that for a connection that uses TLS, you must provide the required key stores and trust stores.
  <br/>
  * Type: list
  * Importance: high

`mqtt.username`
: Username to connect with, or blank if a username is not required. Note: username field is masked as it may contain sensitive information
  <br/>
  * Type: password
  * Importance: high

`mqtt.password`
: Password to connect with, or blank if a password is not required.
  <br/>
  * Type: password
  * Default: [hidden]
  * Importance: high

### MQTT secure connection

`mqtt.ssl.key.store.file`
: The location of the Java KeyStore file containing the private key to use for authenticating with the server.
  <br/>
  * Type: password
  * Default: [hidden]
  * Importance: low

`mqtt.ssl.key.store.password`
: Password used to open the Java KeyStore file.
  <br/>
  * Type: password
  * Default: [hidden]
  * Importance: medium

`mqtt.ssl.key.password`
: Password for the client certificate contained in the Java KeyStore.
  <br/>
  * Type: password
  * Default: [hidden]
  * Importance: high

`mqtt.ssl.trust.store.file`
: The location of the Java TrustStore file containing the certificates required to validate the SSL connection to the server.
  <br/>
  * Type: password
  * Default: [hidden]
  * Importance: medium

`mqtt.ssl.trust.store.password`
: Password used to open the Java TrustStore file.
  <br/>
  * Type: password
  * Default: [hidden]
  * Importance: medium

### Connection Details

`mqtt.clean.session.enabled`
: Sets whether the client and server should remember state across restarts and reconnects. Note that for unreceived messages to be received after reconnect you should set the QOS to 1 or above.
  <br/>
  * Type: boolean
  * Default: false
  * Importance: medium

`mqtt.connect.timeout.seconds`
: Sets the connection timeout value in seconds.
  <br/>
  * Type: int
  * Default: 30
  * Importance: medium

`mqtt.keepalive.interval.seconds`
: This value, measured in seconds, defines the maximum time interval between messages sent or received. In the absence of a data-related message during the time period, the client sends a very small “ping” message, which the server will acknowledge.
  <br/>
  * Type: int
  * Default: 60
  * Importance: medium

`max.retry.time.ms`
: The maximum time in milliseconds (ms) the connector will spend backing off and retrying failed operations (connecting to the MQTT broker and publishing records).
  <br/>
  * Type: int
  * Default: 30000 (30 seconds)
  * Importance: medium

`mqtt.retained.enabled`
: Set it to true for messages to be retained for future clients.
  <br/>
  * Type: boolean
  * Default: true
  * Importance: medium

`mqtt.qos`
: The QOS level to write messages to the MQTT broker with.
  <br/>
  * Type: int
  * Default: 0
  * Importance: medium

### Consumer configuration

`max.poll.interval.ms`
: The maximum delay between subsequent consume requests to Kafka. This configuration property may be used to improve the performance of the connector, if the connector cannot send records to the sink system. Defaults to 300000 milliseconds (5 minutes).
  <br/>
  * Type: long
  * Default: 300000 (5 minutes)
  * Valid Values: [60000,…,1800000] for non-dedicated clusters and [60000,…] for dedicated clusters
  * Importance: low

`max.poll.records`
: The maximum number of records to consume from Kafka in a single request. This configuration property may be used to improve the performance of the connector, if the connector cannot send records to the sink system. Defaults to 500 records.
  <br/>
  * Type: long
  * Default: 500
  * Valid Values: [1,…,500] for non-dedicated clusters and [1,…] for dedicated clusters
  * Importance: low

### Number of tasks for this connector

`tasks.max`
: Maximum number of tasks for the connector.
  <br/>
  * Type: int
  * Valid Values: [1,…]
  * Importance: high

### Auto-restart policy

`auto.restart.on.user.error`
: Enable connector to automatically restart on user-actionable errors.
  <br/>
  * Type: boolean
  * Default: true
  * Importance: medium

### Additional Configs

`consumer.override.auto.offset.reset`
: Defines the behavior of the consumer when there is no committed position (which occurs when the group is first initialized) or when an offset is out of range. You can choose either to reset the position to the “earliest” offset (the default) or the “latest” offset. You can also select “none” if you would rather set the initial offset yourself and you are willing to handle out of range errors manually. More details: [https://docs.confluent.io/platform/current/installation/configuration/consumer-configs.html#auto-offset-reset](https://docs.confluent.io/platform/current/installation/configuration/consumer-configs.html#auto-offset-reset)
  <br/>
  * Type: string
  * Importance: low

`consumer.override.isolation.level`
: Controls how to read messages written transactionally. If set to read_committed, consumer.poll() will only return transactional messages which have been committed. If set to read_uncommitted (the default), consumer.poll() will return all messages, even transactional messages which have been aborted. Non-transactional messages will be returned unconditionally in either mode.  More details: [https://docs.confluent.io/platform/current/installation/configuration/consumer-configs.html#isolation-level](https://docs.confluent.io/platform/current/installation/configuration/consumer-configs.html#isolation-level)
  <br/>
  * Type: string
  * Importance: low

`header.converter`
: The converter class for the headers. This is used to serialize and deserialize the headers of the messages.
  <br/>
  * Type: string
  * Importance: low

`key.converter.use.schema.guid`
: The schema GUID to use for deserialization when using ConfigSchemaIdDeserializer. This allows you to specify a fixed schema GUID to be used for deserializing message keys. Only applicable when key.converter.key.schema.id.deserializer is set to ConfigSchemaIdDeserializer.
  <br/>
  * Type: string
  * Importance: low

`key.converter.use.schema.id`
: The schema ID to use for deserialization when using ConfigSchemaIdDeserializer. This allows you to specify a fixed schema ID to be used for deserializing message keys. Only applicable when key.converter.key.schema.id.deserializer is set to ConfigSchemaIdDeserializer.
  <br/>
  * Type: int
  * Importance: low

`value.converter.allow.optional.map.keys`
: Allow optional string map key when converting from Connect Schema to Avro Schema. Applicable for Avro Converters.
  <br/>
  * Type: boolean
  * Importance: low

`value.converter.auto.register.schemas`
: Specify if the Serializer should attempt to register the Schema.
  <br/>
  * Type: boolean
  * Importance: low

`value.converter.connect.meta.data`
: Allow the Connect converter to add its metadata to the output schema. Applicable for Avro Converters.
  <br/>
  * Type: boolean
  * Importance: low

`value.converter.enhanced.avro.schema.support`
: Enable enhanced schema support to preserve package information and Enums. Applicable for Avro Converters.
  <br/>
  * Type: boolean
  * Importance: low

`value.converter.enhanced.protobuf.schema.support`
: Enable enhanced schema support to preserve package information. Applicable for Protobuf Converters.
  <br/>
  * Type: boolean
  * Importance: low

`value.converter.flatten.unions`
: Whether to flatten unions (oneofs). Applicable for Protobuf Converters.
  <br/>
  * Type: boolean
  * Importance: low

`value.converter.generate.index.for.unions`
: Whether to generate an index suffix for unions. Applicable for Protobuf Converters.
  <br/>
  * Type: boolean
  * Importance: low

`value.converter.generate.struct.for.nulls`
: Whether to generate a struct variable for null values. Applicable for Protobuf Converters.
  <br/>
  * Type: boolean
  * Importance: low

`value.converter.int.for.enums`
: Whether to represent enums as integers. Applicable for Protobuf Converters.
  <br/>
  * Type: boolean
  * Importance: low

`value.converter.latest.compatibility.strict`
: Verify latest subject version is backward compatible when use.latest.version is true.
  <br/>
  * Type: boolean
  * Importance: low

`value.converter.object.additional.properties`
: Whether to allow additional properties for object schemas. Applicable for JSON_SR Converters.
  <br/>
  * Type: boolean
  * Importance: low

`value.converter.optional.for.nullables`
: Whether nullable fields should be specified with an optional label. Applicable for Protobuf Converters.
  <br/>
  * Type: boolean
  * Importance: low

`value.converter.optional.for.proto2`
: Whether proto2 optionals are supported. Applicable for Protobuf Converters.
  <br/>
  * Type: boolean
  * Importance: low

`value.converter.use.latest.version`
: Use latest version of schema in subject for serialization when auto.register.schemas is false.
  <br/>
  * Type: boolean
  * Importance: low

`value.converter.use.optional.for.nonrequired`
: Whether to set non-required properties to be optional. Applicable for JSON_SR Converters.
  <br/>
  * Type: boolean
  * Importance: low

`value.converter.use.schema.guid`
: The schema GUID to use for deserialization when using ConfigSchemaIdDeserializer. This allows you to specify a fixed schema GUID to be used for deserializing message values. Only applicable when value.converter.value.schema.id.deserializer is set to ConfigSchemaIdDeserializer.
  <br/>
  * Type: string
  * Importance: low

`value.converter.use.schema.id`
: The schema ID to use for deserialization when using ConfigSchemaIdDeserializer. This allows you to specify a fixed schema ID to be used for deserializing message values. Only applicable when value.converter.value.schema.id.deserializer is set to ConfigSchemaIdDeserializer.
  <br/>
  * Type: int
  * Importance: low

`value.converter.wrapper.for.nullables`
: Whether nullable fields should use primitive wrapper messages. Applicable for Protobuf Converters.
  <br/>
  * Type: boolean
  * Importance: low

`value.converter.wrapper.for.raw.primitives`
: Whether a wrapper message should be interpreted as a raw primitive at root level. Applicable for Protobuf Converters.
  <br/>
  * Type: boolean
  * Importance: low

`key.converter.key.schema.id.deserializer`
: The class name of the schema ID deserializer for keys. This is used to deserialize schema IDs from the message headers.
  <br/>
  * Type: string
  * Default: io.confluent.kafka.serializers.schema.id.DualSchemaIdDeserializer
  * Importance: low

`key.converter.key.subject.name.strategy`
: How to construct the subject name for key schema registration.
  <br/>
  * Type: string
  * Default: TopicNameStrategy
  * Importance: low

`value.converter.decimal.format`
: Specify the JSON/JSON_SR serialization format for Connect DECIMAL logical type values with two allowed literals:
  <br/>
  BASE64 to serialize DECIMAL logical types as base64 encoded binary data and
  <br/>
  NUMERIC to serialize Connect DECIMAL logical type values in JSON/JSON_SR as a number representing the decimal value.
  <br/>
  * Type: string
  * Default: BASE64
  * Importance: low

`value.converter.flatten.singleton.unions`
: Whether to flatten singleton unions. Applicable for Avro and JSON_SR Converters.
  <br/>
  * Type: boolean
  * Default: false
  * Importance: low

`value.converter.reference.subject.name.strategy`
: Set the subject reference name strategy for value. Valid entries are DefaultReferenceSubjectNameStrategy or QualifiedReferenceSubjectNameStrategy. Note that the subject reference name strategy can be selected only for PROTOBUF format with the default strategy being DefaultReferenceSubjectNameStrategy.
  <br/>
  * Type: string
  * Default: DefaultReferenceSubjectNameStrategy
  * Importance: low

`value.converter.value.schema.id.deserializer`
: The class name of the schema ID deserializer for values. This is used to deserialize schema IDs from the message headers.
  <br/>
  * Type: string
  * Default: io.confluent.kafka.serializers.schema.id.DualSchemaIdDeserializer
  * Importance: low

`value.converter.value.subject.name.strategy`
: Determines how to construct the subject name under which the value schema is registered with Schema Registry.
  <br/>
  * Type: string
  * Default: TopicNameStrategy
  * Importance: low

## Frequently asked questions

Find answers to frequently asked questions about the MQTT Sink connector for Confluent Cloud.

### Why is my connector failing to connect to the MQTT broker?

Connection failures can occur for several reasons:

* **Incorrect broker URI format**: Ensure your `mqtt.server.uri` is in the correct format. Supported protocols are `tcp`, `ssl`, `ws`, and `wss`.
* **Authentication required**: If your MQTT broker does not support anonymous mode, provide `mqtt.username` and `mqtt.password` in your connector configuration.
* **Network access**: Verify that the connector can reach your MQTT broker. Check firewall rules, VPC peering configurations, or private networking requirements.
* **Connection timeout**: Adjust the `mqtt.connect.timeout.seconds` property (default: 30 seconds) if your broker requires more time to establish connections.

### Why am I getting authentication errors after providing credentials?

Authentication errors can occur if:

* Your `mqtt.username` or `mqtt.password` contains special characters. Avoid using backslashes (`\`) in passwords or secret keys, as these can cause connection failures.
* Credentials are incorrectly formatted or have leading or trailing spaces.
* The MQTT broker has additional authentication requirements beyond username and password.
* Your credentials have expired or been revoked on the broker side.

### Why am I getting `Schema not found` or `Incompatible schema` errors?

Schema-related errors typically indicate:

* Confluent Cloud Schema Registry is not enabled for your environment. Schema-based formats require [Schema Registry](../get-started/schema-registry.md#cloud-sr-config).
* The schema is not registered in Confluent Cloud Schema Registry for your Kafka topic.
* The `input.data.format` property does not match the actual data format in your Kafka topic.
* Schema evolution compatibility rules are being violated.

To troubleshoot, verify that your schema is properly registered and that the format specified in the connector configuration matches your Kafka topic data.

### Why are some messages not appearing in my MQTT broker?

Missing messages can result from:

* **Unsupported Schema types**: Check if you are using an unsupported schema type. The connector only supports `bytes` and `string` type schemas even when using Confluent Cloud Schema Registry. If your topic contains complex structures like nested JSON or Avro records, the connector will return a schema error.
* **Connection interruptions**: Check if the connector status shows as `Running` in the Confluent Cloud Console. If the connector is not running, review error messages and logs for details.
* **MQTT broker issues**: Verify that your MQTT broker is accepting and storing messages correctly.
* **QoS level**: Ensure the QoS level is appropriate for your reliability requirements.

### How can I improve the connector performance?

To optimize performance:

* **Increase tasks**: The connector supports multiple tasks. Increase the number of tasks (`tasks.max`) based on the number of topic partitions. The Confluent Cloud Console provides recommended task counts based on your topic selection.
* **Review timeout settings**: Adjust `mqtt.connect.timeout.seconds` and `mqtt.max.retry.time.ms` based on your network conditions and broker responsiveness.
* **Use appropriate data formats**: Schema-based formats can improve performance and data quality when used with Confluent Cloud Schema Registry.

### Why does the connector fail with authorization errors when using SSL/TLS?

This error typically occurs when the connector is not properly configured to send client certificates during the SSL handshake. To resolve this issue:

* **Verify certificate configuration**: Ensure that both the keystore and truststore files are configured with the following properties:
  - `mqtt.ssl.key.store.file`: Contains your client certificate.
  - `mqtt.ssl.trust.store.file`: Contains the CA certificate chain.
  - `mqtt.ssl.key.store.password`: Password for the keystore.
  - `mqtt.ssl.trust.store.password`: Password for the truststore.
* **Use correct base64 encoding**: Ensure the keystore and truststore files are base64-encoded and prefixed with `data:text/plain;base64`.
* **Verify MQTT broker configuration**: Ensure that your MQTT broker is configured to require and accept client certificate authentication.

### What configuration should I use for production deployments?

For production deployments:

* **Use SSL/TLS**: Always use encrypted connections like `ssl://` or `wss://` to protect data in transit.
* **Use supported Schema types**: Always use supported schema types. The connector only supports `bytes` and `string` type schemas even when using Confluent Cloud Schema Registry.
* **Implement proper authentication**: Configure `mqtt.username` and `mqtt.password` rather than relying on anonymous access.
* **Enable Schema Registry**: For structured data, use schema-based formats with Confluent Cloud Schema Registry to ensure data quality and compatibility.
* **Configure appropriate timeouts**: Set `mqtt.connect.timeout.seconds` and `mqtt.max.retry.time.ms` based on your network conditions.
* **Monitor the DLQ**: Set up alerts to notify you when records appear in the Dead Letter Queue.
* **Scale appropriately**: Configure `tasks.max` based on your throughput requirements and number of partitions.

## Next Steps

For an example that shows fully managed Confluent Cloud connectors in action with
Confluent Cloud for Apache Flink, see the [Cloud ETL Demo](/platform/current/tutorials/examples/cloud-etl/docs/index.html).
This example also shows how to use Confluent CLI to manage your resources in
Confluent Cloud.

[![image](images/topology.png)](https://docs.confluent.io/platform/current/tutorials/examples/cloud-etl/docs/index.html)
