<!-- **IMPORTANT:** IF YOU REVISE THIS TOPIC, YOU MUST GET IT REVIEWED BY THE LEGAL TEAM. -->

<a id="cp-license-overview"></a>

# Manage Confluent Platform Licenses

Confluent Platform components are licensed under one of three license types.

* The Confluent Enterprise License covers commercial features.
* The Confluent Community License covers community features.
* The Apache 2.0 License covers Apache Kafka® core.

Commercial and Premium Connectors fall under the Confluent
Enterprise License. For the full breakdown, see
[License types](#cp-license-types).

For information on how to configure licenses in automated
deployments of Confluent Platform with Confluent for Kubernetes, refer to [Configure licenses with Confluent for
Kubernetes](https://docs.confluent.io/operator/current/co-license.html).

<a id="cp-license-types"></a>

## License types

Each Kafka and Confluent feature is covered by the
[Enterprise license](#cp-enterprise-subs-license), the
[Community license](https://www.confluent.io/confluent-community-license/),
or the [Apache Kafka 2.0 license](https://github.com/apache/kafka/blob/trunk/LICENSE).
For more information, see the
[Community license FAQ](https://www.confluent.io/confluent-community-license-faq/).

Items marked with an asterisk (\*) are only included if they are specified in the license purchase order.

 <style type="text/css">
 .tg  {border-collapse:collapse;border-spacing:0;}
 .tg td{border-color:black;border-style:solid;border-width:1px;font-family:Arial, sans-serif;font-size:18px;
   overflow:hidden;padding:10px 5px;word-break:normal;}
 .tg th{border-color:black;border-style:solid;border-width:1px;font-family:Arial, sans-serif;font-size:18px;
   font-weight:normal;overflow:hidden;padding:10px 5px;word-break:normal;}
 .tg .tg-cdrw{background-color:#01CEDB;border-color:inherit;color:#ffffff;text-align:left;vertical-align:top}
 .tg .tg-0lax{background-color:#f5f7ff;text-align:left;vertical-align:top;border-color:inherit}
 .tg .tg-0pky{background-color:#f5f7ff;border-color:inherit;text-align:left;vertical-align:top}
 .tg .tg-c6of{background-color:#f5f7ff;;border-color:inherit;text-align:left;vertical-align:top}
 </style>
  <table class="tg" width="75%">
  <thead>
  <tr>
  <th class="tg-cdrw" colspan="7">Confluent Enterprise License for Confluent Platform subscription</th>
  </tr>
  </thead>
  <tbody>
  <tr>
  <td class="tg-0pky" rowspan="2">Kafka Connect</td>
  <td class="tg-0pky" colspan="4">Commercial Connectors \*</td>
  </tr>
  <tr>
  <td class="tg-0pky" colspan="4">Premium Connectors \*</td>
  </tr>
  <tr>
 <td class="tg-0pky" colspan="5">Health+ \*</td>
 </tr>
 <tr>
 <td class="tg-0pky" colspan="5">Control Center</td>
 </tr>
 <tr>
 <td class="tg-c6of" colspan="5">Confluent for Kubernetes</td>
 </tr>
 <tr>
 <td class="tg-c6of" colspan="5">Confluent Replicator</td>
 </tr>
 <tr>
 <td class="tg-0pky" colspan="5">MQTT Proxy</td>
 </tr>
 <tr>
 <td class="tg-0pky" colspan="4">Secrets Protection</td>
 </tr>
 <tr>
 <td class="tg-0pky" colspan="4">Client-side Field Level Encryption (CSFLE) \*</td>
 </tr>
 <tr>
 <td class="tg-0pky" colspan="5">Confluent Platform for Apache Flink \*</td>
 </tr>
 <tr>
 <td class="tg-0pky" colspan="5">Confluent Unified Stream Manager (USM) \*</td>
 </tr>
 <tr>
 <td class="tg-0pky" rowspan="8">Confluent Server</td>
 <td class="tg-0pky" colspan="4">Cluster Linking</td>
 </tr>
 <tr>
 <td class="tg-0pky" colspan="4">Role-based Access Control</td>
 </tr>
 <tr>
 <td class="tg-0pky" colspan="4">Structured Audit Logs</td>
 </tr>
 <tr>
 <td class="tg-0pky" colspan="4">Schema Validation</td>
 </tr>
 <tr>
 <td class="tg-0pky" colspan="4">Multi-Region Clusters</td>
 </tr>
 <tr>
 <td class="tg-0pky" colspan="4">Tiered Storage</td>
 </tr>
 <tr>
 <td class="tg-0pky" colspan="4">Self-Balancing Clusters</td>
 </tr>
 <tr>
 <td class="tg-0lax" colspan="5">Auto Data Balancer</td>
 </tr>
 <tr>
 <th class="tg-cdrw" colspan="7">Confluent Enterprise License for Confluent Private Cloud subscription</th>
 </tr>
 <tr>
 <td class="tg-0pky" rowspan="2">Kafka Connect</td>
 <td class="tg-0pky" colspan="4">Commercial Connectors</td>
 </tr>
 <tr>
 <td class="tg-0pky" colspan="4">Premium Connectors</td>
 </tr>
 <tr>
 <td class="tg-0pky" colspan="5">Control Center</td>
 </tr>
 <tr>
 <td class="tg-c6of" colspan="5">Confluent for Kubernetes</td>
 </tr>
 <tr>
 <td class="tg-c6of" colspan="5">Confluent Replicator</td>
 </tr>
 <tr>
 <td class="tg-0pky" colspan="4">Client-side Field Level Encryption (CSFLE)</td>
 </tr>
 <tr>
 <td class="tg-0pky" colspan="5">Confluent Private Cloud Gateway</td>
 </tr>
 <tr>
 <td class="tg-0pky" colspan="4">Secrets Protection</td>
 </tr>
 <tr>
 <td class="tg-0pky" colspan="4">Intelligent Replication</td>
 </tr>
 <tr>
 <td class="tg-0pky" colspan="5">Confluent Platform for Apache Flink \*</td>
 </tr>
 <tr>
 <td class="tg-0pky" colspan="5">Confluent Unified Stream Manager (USM) \*</td>
 </tr>
 <tr>
 <td class="tg-0pky" rowspan="8">Confluent Private Cloud Server</td>
 <td class="tg-0pky" colspan="4">Cluster Linking</td>
 </tr>
  <tr>
 <td class="tg-0pky" colspan="4">Role-based Access Control</td>
 </tr>
 <tr>
 <td class="tg-0pky" colspan="4">Structured Audit Logs</td>
 </tr>
 <tr>
 <td class="tg-0pky" colspan="4">Schema Validation</td>
 </tr>
 <tr>
 <td class="tg-0pky" colspan="4">Multi-Region Clusters</td>
 </tr>
 <tr>
 <td class="tg-0pky" colspan="4">Tiered Storage</td>
 </tr>
 <tr>
 <td class="tg-0pky" colspan="4">Self-Balancing Clusters</td>
 </tr>
 <tr>
 <td class="tg-0lax" colspan="5">Auto Data Balancer</td>
 </tr>
 <tr>
 <td class="tg-cdrw" colspan="8">Confluent Enterprise License for Customer-managed Confluent Platform for Confluent Cloud subscription</td>
 </tr>
 <tr>
 <td class="tg-0lax" rowspan="2">Kafka Connect Worker</td>
 <td class="tg-0lax" colspan="4">Commercial Connectors \*</td>
 </tr>
 <tr>
 <td class="tg-0lax" colspan="4">Premium Connectors \*</td>
 </tr>
 <tr>
 <td class="tg-0lax" colspan="5">Control Center</td>
 </tr>
 <tr>
 <td class="tg-0lax" colspan="5">Confluent for Kubernetes</td>
 </tr>
 <tr>
 <td class="tg-0lax" colspan="5">Replicator</td>
 </tr>
 <tr>
 <td class="tg-0lax" colspan="5">Confluent Cloud Gateway</td>
 </tr>
 <tr>
 <td class="tg-cdrw" colspan="5">Confluent Community License</td>
 </tr>
 <tr>
 <td class="tg-0lax" colspan="5">Admin REST API</td>
 </tr>
 <tr>
 <td class="tg-0pky" colspan="5">Confluent CLI</td>
 </tr>
 <tr>
 <td class="tg-0lax">Kafka Connect</td>
 <td class="tg-0lax" colspan="4">Community-licensed Connectors</td>
 </tr>
 <tr>
 <td class="tg-0pky" colspan="5">ksqlDB</td>
 </tr>
 <tr>
 <td class="tg-0lax" colspan="5">REST Proxy</td>
 </tr>
 <tr>
 <td class="tg-0pky" colspan="5">Schema Registry</td>
 </tr>
 <tr>
 <td class="tg-cdrw" colspan="5">Apache 2.0 License</td>
 </tr>
 <tr>
 <td class="tg-0lax" colspan="5">Apache Kafka (with Connect and Streams)</td>
 </tr>
 <tr>
 <td class="tg-0lax" colspan="5">Ansible Playbooks</td>
 </tr>
 <tr>
 <td class="tg-0lax" colspan="5">Apache ZooKeeper</td>
 </tr>
 <tr>
 <td class="tg-0lax" colspan="5">Confluent Clients</td>
 </tr>
 <tr>
 <td class="tg-0pky" colspan="5">Open Source Connectors</td>
 </tr>
 </tbody>
 </table>

\* If purchased, as specified in purchase order.

<a id="cp-enterprise-subs-license"></a>

### Enterprise license subscription

An enterprise license provides access to the Confluent commercial features for a production environment.
An enterprise license is a paid subscription that expires at an interval determined by the subscription contract.
The software ceases to function after the license expires. For details, refer to [Renew licenses](#cp-proprietary-components-post-expire).

#### Enterprise license for Confluent Platform subscription

The following Confluent Platform components are under the Confluent Enterprise license for Confluent Platform subscription:

* [Confluent Server](available_packages.md#confluent-server-package)

  The following are a few key features included in Confluent Server:
  * [Cluster Linking](../multi-dc-deployments/cluster-linking/index.md#cluster-linking)
  * [Multi-Region Clusters](../multi-dc-deployments/multi-region.md#bmrr)
  * [Role-based Access Control (RBAC)](../security/authorization/rbac/overview.md#rbac-overview)
  * [Structured Audit Logs](../security/compliance/audit-logs/audit-logs-concepts.md#audit-logs-concepts)
  * [Schema Validation](../schema-registry/schema-validation.md#schema-validation)
  * [Schema Registry Security Plugin for Confluent Platform](../confluent-security-plugins/schema-registry/introduction.md#confluentsecurityplugins-schema-registry-security-plugin)
  * [Secrets Protection](../security/compliance/secrets/overview.md#secrets)
  * [Self-Balancing Clusters](../clusters/sbc/index.md#sbc)
  * [Tiered Storage](../clusters/tiered-storage.md#tiered-storage)
* [Schema Linking](../schema-registry/schema-linking-cp.md#schema-linking-cp-overview)
* [Data Contracts](/platform/current/schema-registry/fundamentals/data-contracts.html)
* [Control Center for Confluent Platform](https://docs.confluent.io/control-center/current/overview.html)
* [Confluent for Kubernetes](https://docs.confluent.io/operator/current/overview.html)
* [Confluent Replicator](../multi-dc-deployments/replicator/index.md#replicator-detail)
* [MQTT Proxy for Confluent Platform](../kafka-mqtt/index.md#mqtt-proxy)

The following Confluent Platform components are under the Confluent Enterprise license for Confluent Platform subscription only when
specified in the purchase order:

* [Confluent Platform for Apache Flink](/cp-flink/current/overview.html)
* [Client-side Field Level Encryption (CSFLE)](../security/protect-data/csfle/overview.md#csfle-overview)
* [Health+](../health-plus/index.md#health-plus)
* [Confluent Unified Stream Manager (USM)](../usm/overview.md#usm-overview)
* [Confluent Private Cloud Gateway](https://docs.confluent.io/private-cloud-gateway/current/)
* Pre-built Connectors

  In [Confluent Marketplace](https://www.confluent.io/hub), filter by the Premium and
  Commercial license types to view the Connectors under the Confluent Enterprise
  license.

<a id="customer-managed-cp-cc-license"></a>

#### Enterprise license for Confluent Private Cloud subscription

The following Confluent Platform components are under the Confluent Enterprise license for Confluent Private Cloud subscription:

* Confluent Private Cloud server

  The following are a few key features included in Confluent Private Cloud server:
  * [Cluster Linking](../multi-dc-deployments/cluster-linking/index.md#cluster-linking)
  * [Multi-Region Clusters](../multi-dc-deployments/multi-region.md#bmrr)
  * [Role-based Access Control (RBAC)](../security/authorization/rbac/overview.md#rbac-overview)
  * [Structured Audit Logs](../security/compliance/audit-logs/audit-logs-concepts.md#audit-logs-concepts)
  * [Schema Validation](../schema-registry/schema-validation.md#schema-validation)
  * [Self-Balancing Clusters](../clusters/sbc/index.md#sbc)
  * [Tiered Storage](../clusters/tiered-storage.md#tiered-storage)
* [Control Center for Confluent Platform](https://docs.confluent.io/control-center/current/overview.html)
* [Confluent for Kubernetes](https://docs.confluent.io/operator/current/overview.html)
* [Confluent Replicator](../multi-dc-deployments/replicator/index.md#replicator-detail)
* [Confluent Private Cloud Gateway](https://docs.confluent.io/private-cloud-gateway/current/)
* [Intelligent Replication](../private-cloud/intelligent-replication/overview.md#intelligent-replication-overview)

The following Confluent Platform components are under the Confluent Enterprise license for Confluent Private Cloud subscription only when
specified in the purchase order:

* [Confluent Platform for Apache Flink](/cp-flink/current/overview.html)
* [Confluent Unified Stream Manager (USM)](../usm/overview.md#usm-overview)

A valid Confluent Private Cloud Enterprise license is required for production use. This license grants access to
Confluent Private Cloud components in production environments according to your subscription contract terms and duration.

##### Confluent Private Cloud license enforcement and migration path

Confluent Private Cloud uses the Confluent Enterprise license for Confluent Private Cloud subscription to control access to enterprise-only capabilities,
including Confluent Private Cloud Gateway and Intelligent Replication.

Confluent Private Cloud applies license enforcement at startup for these enterprise-only capabilities.

- If you have configured a valid Confluent Private Cloud Enterprise license key with appropriate entitlements
  that has not expired, enterprise-only capabilities operate normally.
- If you have not configured a valid license key, or if the license has expired, Confluent Private Cloud starts
  but enterprise-licensed capabilities remain disabled. For example, [Intelligent Replication](../private-cloud/intelligent-replication/overview.md#intelligent-replication-overview)
  does not start until you apply a valid license key and restart the relevant services.

##### Upgrading to Confluent Private Cloud version 8.2 or later with enterprise features

When upgrading from Confluent Private Cloud 8.1 to version 8.2 or later, you must apply a valid Enterprise license before initiating the version upgrade.
This ensures that enterprise-only capabilities remain active during the rolling restart.

If you upgraded to Confluent Private Cloud version 8.2 without applying the Confluent Private Cloud Enterprise license key, refer to [Restore capabilities after an unlicensed upgrade](#cpc-restore-capabilities).

Perform the following steps to upgrade to Confluent Private Cloud version 8.2
or later with a valid Confluent Private Cloud Enterprise license:

1. Get your Confluent Private Cloud Enterprise license key:
   - Ensure the license key includes entitlements for Confluent Private Cloud capabilities such as Confluent Private Cloud Gateway and Intelligent Replication.
   - Ensure the subscription term is valid for your upgrade window.
2. Configure the license key while the cluster is still running version 8.1 to prevent service interruption:
   - Configure the Confluent Private Cloud Enterprise license key using your preferred deployment method.
   - Verify that the license key has been applied to the shared license topic.
   - Ensure the updated license status is visible across all Confluent Private Cloud components before proceeding.
3. Upgrade the Confluent Private Cloud version:
   - After the Enterprise license is confirmed as active, upgrade brokers and associated components following a rolling upgrade procedure.
     Enterprise capabilities automatically re-enable as each service restarts with the new version.

<a id="cpc-restore-capabilities"></a>

###### Restore capabilities after an unlicensed upgrade

If you upgrade Confluent Private Cloud to version 8.2 or later without a valid Confluent Private Cloud Enterprise license key, the system automatically disables
all enterprise-only capabilities during service startup. In this state, you can observe changes in cluster behavior as enterprise-licensed capabilities are no longer active.

To restore the cluster behavior and performance, you must apply a valid Enterprise license and restart all affected services.

1. Apply a valid Confluent Private Cloud Enterprise license key using your preferred configuration method.
2. Restart the affected components or perform a rolling restart of the brokers so the services can detect
   the new Enterprise license key and start the enterprise-licensed capabilities.

#### Enterprise license for Customer-Managed Confluent Platform for Confluent Cloud subscription

This enterprise license only supports self-managed components connecting with Confluent Cloud.

The Customer-Managed Confluent Platform for Confluent Cloud license key enables you to use self-managed Confluent Platform components exclusively
with Confluent Cloud services.

Prerequisites for installing the Customer-Managed Confluent Platform for Confluent Cloud license:

1. Ensure all your self-managed Confluent Platform components are connected with Confluent Cloud and used for Confluent Cloud
   broker-related use cases. Confluent does not provide support for any self-managed
   Confluent Platform components that are used exclusively for Confluent Platform broker use cases under the Customer-Managed Confluent Platform for Confluent Cloud subscription.
2. You must upgrade Confluent Platform to the recommended minimum patch version, or later, for each version of Confluent Platform,
   as shown in the following table.

You must upgrade Confluent Platform components or Control Center before you apply a new Confluent Enterprise
license key, otherwise the license key update may fail.
The failure is recorded as an error in the component logs, and it is shown in Control Center if the license key was
applied using Control Center.

<!-- This file contains just the table for easy inclusion in other documents -->

| Confluent Platform version   | Minimum patch version   |
|------------------------------|-------------------------|
| 8.2.x                        | 8.2.0                   |
| 8.1.x                        | 8.1.0                   |
| 8.0.x                        | 8.0.2                   |
| 7.9.x                        | 7.9.4                   |
| 7.8.x                        | 7.8.5                   |
| 7.7.x                        | 7.7.6                   |
| 7.6.x                        | 7.6.8                   |
| 7.5.x                        | 7.5.11                  |
| 7.4.x                        | 7.4.12                  |
<!-- Lets comment this out as 8.1.x hasn't shipped -->
<!-- All |cp| versions from 8.1.x support the Enterprise license key for |cmcpcc| subscription. -->

The license key must be configured for each self-managed Confluent Platform component:

- If you are using Control Center, you should apply the license key in Control Center. For more information, see
  [Manage Licenses using Control Center](/control-center/current/installation/license.html).
- Alternatively, configure the license key for each Confluent Platform component.
  For more information, see [Configure component licenses](#cp-configure-license).

#### NOTE
If you are an existing customer, your current license key will continue to function until its expiration date.

The following Confluent Platform components are under the Confluent Enterprise license for Customer-Managed Confluent Platform for Confluent Cloud subscription:

<style type="text/css">
.tg  {border-collapse:collapse;border-spacing:0;}
.tg td{border-color:black;border-style:solid;border-width:1px;font-family:Arial, sans-serif;font-size:18px;
  overflow:hidden;padding:10px 5px;word-break:normal;}
.tg th{border-color:black;border-style:solid;border-width:1px;font-family:Arial, sans-serif;font-size:18px;
  font-weight:normal;overflow:hidden;padding:10px 5px;word-break:normal;}
.tg .tg-cdrw{background-color:#01CEDB;border-color:inherit;color:#ffffff;text-align:left;vertical-align:top}
.tg .tg-0lax{background-color:#f5f7ff;text-align:left;vertical-align:top;border-color:inherit}
.tg .tg-0pky{background-color:#f5f7ff;border-color:inherit;text-align:left;vertical-align:top}
.tg .tg-c6of{background-color:#f5f7ff;;border-color:inherit;text-align:left;vertical-align:top}
</style>
<table width=75% class="tg">
<thead>
  <tr>
    <th class="tg-cdrw" colspan="7">            Commercial features            </th>
  </tr>
</thead>
<tbody>
<tr>
    <td class="tg-0lax" rowspan="2">Kafka Connect Worker</td>
    <td class="tg-0lax" colspan="4">Commercial Connectors</td>
  </tr>
  <tr>
    <td class="tg-0lax" colspan="4">Premium Connectors</td>
  </tr>
  <tr>
  <td class="tg-0lax" colspan="5">Control Center</td>
  </tr>
  <tr>
   <td class="tg-0lax" colspan="5">Confluent for Kubernetes</td>
  </tr>
  <tr>
    <td class="tg-0lax" colspan="5">Replicator</td>
  </tr>
  <tr>
    <td class="tg-0lax" colspan="5">Confluent Cloud Gateway</td>
  </tr>
  <tr>
    <th class="tg-cdrw" colspan="7">            Community features            </th>
  </tr>
<tr>
    <td class="tg-0lax">Kafka Connect Worker</td>
    <td class="tg-0lax" colspan="4">Community-licensed Connectors</td>
  </tr>
  <tr>
  <td class="tg-0lax" colspan="5">REST Proxy</td>
  </tr>
   <tr>
    <td class="tg-0lax" colspan="5">ksqlDB</td>
  </tr>
  <tr>
    <td class="tg-0lax" colspan="5">Schema Registry</td>
  </tr>
</tbody>
</table>

<a id="cp-community-license"></a>

### Community license

The following Confluent Platform components are under the Confluent Community license:

* Pre-built Connectors

  In [Confluent Marketplace](https://www.confluent.io/hub), filter by the **Apache**
  license type to view the Connectors under the free license.
* [Confluent REST Proxy](../kafka-rest/index.md#kafkarest-intro)
* [ksqlDB](../ksqldb/overview.md#ksql-home)
* [Confluent Schema Registry](../schema-registry/index.md#schemaregistry-intro)
* [Confluent Admin REST API](../kafka-rest/production-deployment/confluent-server/index.md#confluent-server-rest-deployment)
* [Confluent CLI](https://docs.confluent.io/confluent-cli/current/index.html)

### Apache 2.0 license

The following features are covered by the Apache 2.0 license.

- Apache Kafka® including [Kafka Connect for Confluent Platform](../connect/index.md#kafka-connect) and [Kafka Streams API for Confluent Platform](../streams/introduction.md#streams-intro)
- [Ansible Playbooks](https://docs.confluent.io/ansible/current/overview.html)
- [Kafka Clients](../clients/overview.md#kafka-clients)

### Other license types

Following are some additional licenses with limited scope.

<a id="cp-developer-license"></a>

#### Developer license

A developer license allows full use of Confluent Platform features free of charge for an indefinite duration.
The license is limited to a single broker configuration per cluster. The developer license
gives developers the freedom to try the Confluent Platform commercial features available in a non-production setting.

The developer license also accommodates multiple single-broker clusters so that developers can try
the [Replicator](../multi-dc-deployments/replicator/index.md#replicator-detail) between those instances, or develop failover applications,
for example. Those multiple single-broker clusters share the same license.

#### WARNING
Adding a broker starts a trial license that expires in 30 days. You cannot revert from
a trial back to a developer license.

<a id="cp-trial-eval-license"></a>

#### Trial (evaluation) license

A trial (evaluation) license allows a free trial of commercial features in a production setting.
Expires after 30 days. The trial license is governed by the
[Confluent evaluation licenses agreement](https://www.confluent.io/software-evaluation-license).
The software ceases to function when the license expires. For details, refer to
[Renew licenses](#cp-proprietary-components-post-expire).

<a id="cp-configure-license"></a>

## Configure component licenses

You must configure a license for each individual Confluent Platform commercial component as
described in the following sections.

Each licensed component requires a valid license key to start. After startup, the
component checks a shared license topic on the Kafka cluster for the latest valid
license key.

### Default license topic behavior

By default, all Confluent Platform components use the `_confluent-command` internal topic to store and retrieve license information.

The following components use `_confluent-command` by default:

* Confluent Control Center
* Confluent Server
* Confluent Schema Registry
* Connect
* Replicator

The shared license topic simplifies license management across your Confluent Platform deployment. When you update
the license through Control Center or update the license key in any Confluent Platform component’s configuration file,
such as `/etc/kafka/kraft/server.properties` for Confluent Server, the component writes the updated
license to the `_confluent-command` topic.

Other Confluent Platform components automatically use the updated license if they meet the following criteria:

* Share the same Kafka cluster that hosts the `_confluent-command` topic.
* Have not overridden the [license topic configuration](configuration/license-configs.md#cp-config-lincense) to use a different license topic.

Components that meet these criteria don’t require a manual license update in their properties files.
The components automatically retrieve the current license from the `_confluent-command` topic.

#### NOTE
For backward compatibility, Confluent Server brokers and Confluent Schema Registry continue to use the legacy
`_confluent-license` topic if it exists in your deployment. If this topic exists when
these components start, they use it as the default license topic instead of
`_confluent-command`. This ensures compatibility with existing deployments that were
configured before `_confluent-command` became the standard. However, the
`_confluent-command` topic is the recommended approach for all new
deployments.

### Configure license keys

You can specify a license key in each component’s properties file. The component evaluates the key
during startup and stores it on the configured license topic (`_confluent-command` by default).
Each component’s section describes its properties file location.

For more information about managing licenses in Confluent Control Center, refer to [Manage Confluent Platform Licenses Using Control Center](/control-center/current/installation/license.html).

### Confluent Control Center

For Control Center, the license key can be [entered in the Control Center License tab](/control-center/current/installation/license.html),
or in the `confluent.license` parameter in the `/etc/control-center/control-center.properties`
file.

### Confluent Replicator

Configure the parameter `confluent.license` in various Replicator `.properties` files. For more
information, refer to [Confluent Platform license](../multi-dc-deployments/replicator/configuration_options.md#replicator-connector-license-config) in [Replicator Configuration Reference for Confluent Platform](../multi-dc-deployments/replicator/configuration_options.md#replicator-config-options).

### Confluent Server

Configure the parameter `confluent.license` in the `/etc/kafka/server.properties` file. For more
information, refer to [Migrate Confluent Platform to Confluent Server](migrate-confluent-server.md#migrate-confluent-server).

<a id="sr-license"></a>

### Confluent Schema Registry

- Community License - The basic Schema Registry functionality is covered by the Community License and is free to use without a commercial license key.
- Commercial features - To use all features, you must enable the commercial components. Specifically, a license is required when using role-based access control (RBAC)
  by means of the [Schema Registry Security Plugins](../confluent-security-plugins/schema-registry/install.md#sr-security-plugin-authentication-mechanisms), [Schema Linking exporters](../schema-registry/schema-linking-cp.md#sr-license-schema-linking),
  and [broker-side Schema Validation](../schema-registry/schema-validation.md#schema-validation).

Each licensed component requires a valid license key to start. The component uses the key to check a shared license topic on the Kafka cluster.
By default, Schema Registry uses `_confluent-command`. If the `_confluent-license` topic exists, Schema Registry uses it for backward compatibility.

Schema exporters are functional with the Customer-Managed Confluent Platform for Confluent Cloud license, provided the source and destination Schema Registries
use the same license on the self-managed Schema Registry, or if the destination Schema Registry is in Confluent Cloud.

If you use the Customer-Managed Confluent Platform for Confluent Cloud license with Schema Registry, you can’t use [Schema ID validation](../schema-registry/schema-validation.md#schema-validation) with Kafka brokers on Confluent Platform.
For Schema ID Validation, the Confluent Enterprise license must be applied to the brokers; applying the Confluent Enterprise license to the Schema Registry nodes is not sufficient.

You can configure the license key for Schema Registry in the `confluent.license` parameter in the Schema Registry properties file: `$CONFLUENT_HOME/etc/schema-registry/schema-registry.properties`

#### NOTE
Enterprise support is not provided unless the `confluent-security` package is installed on all nodes and a valid Enterprise license key is configured.

### Confluent ksqlDB

Configure the parameter `confluent.license` in the KSQLDB `/etc/ksqldb/ksql-server.properties` file.

#### NOTE
Enterprise support is not provided unless the `confluent-security` package is installed on all nodes and a valid Enterprise license key is configured.

### Confluent Auto Data Balancer

A license is required only when using multiple broker configurations. Configure the parameter
`confluent.license` in the Kafka `server.properties` file. For more information, refer to
[Configure license for rebalancer](../clusters/rebalancer/configuration-options.md#rebalancer-config-options).

### Confluent MQTT Proxy

Configure the parameter `confluent.license` in the MQTT Proxy
`etc/confluent-kafka-mqtt/kafka-mqtt-production.properties` file. For more information, refer to
[Configure license for MQTT](../kafka-mqtt/configuration_options.md#mqtt-license).

<a id="crest-license"></a>

### Confluent REST Proxy

A license is required only when using the REST Proxy Security Plugins. For more information, refer to
[REST Proxy Authentication](../kafka-rest/production-deployment/rest-proxy/security.md#kafka-rest-security-http-auth).

#### NOTE
Enterprise support is not provided unless the `confluent-security` package is installed on all nodes and a valid Enterprise license key is configured.

### Confluent for Kubernetes

Add the license key for Confluent Platform components as described in [Confluent for
Kubernetes license](https://docs.confluent.io/operator/current/co-license.html).

<a id="enterprise-connectors-lm"></a>

### Confluent Platform commercial connectors

The Confluent Platform commercial connectors can be used on an unlimited basis with the developer license for
single-broker clusters. Multi-broker clusters can use these commercial connectors for a 30-day trial
without an enterprise license key. After the trial period expires, Confluent Platform software  ceases to function.

#### NOTE
Enterprise support is not provided for the Confluent Community licensed distributions of Kafka Connect workers
(CCS or `cp-kafka-connect`). Confluent recommends using the Confluent Enterprise distribution
of Kafka Connect workers (CE or `cp-server-connect`). Note that Confluent Enterprise distribution of
Kafka Connect workers fails without a valid enterprise license key.

You must [purchase an enterprise license](https://docs.confluent.io/control-center/current/installation/license.html#purchasing-a-cp-license) to continue
using commercial connectors in a multi-broker cluster.

#### NOTE
If you are using Control Center, apply the license key in Control Center (recommended). For more information, see
[Manage Confluent Platform licenses using Control Center](https://docs.confluent.io/control-center/current/installation/license.html#manage-cp-licenses-using-c3-short).

Alternatively, you can configure the `confluent.license` parameter in the Connect worker configuration,
or at the individual connector level for enterprise support of connectors and Connect workers.
For more information, see [Centralized License in the Kafka Connect Worker](../connect/license.md#central-connect-license).
Confluent recommends validating in lower environments before production upgrades.

Refer to the individual [connector](/kafka-connectors/self-managed/supported.html) documentation for the specific
license requirements.

<a id="kafka-rest-and-sasl-ssl-configs"></a>

## Configure license clients to authenticate to Kafka

When enabled with role-based access control (RBAC) or [Kafka REST Security plugins](../confluent-security-plugins/kafka-rest.md#kafka-rest-security-plugins-install),
license clients must be explicitly configured to authenticate to Apache Kafka®. For example, if a Kafka REST client
talks to Kafka over a SASL_SSL enabled listener, the configuration may look like this:

```properties
confluent.license.security.protocol=SASL_SSL
confluent.license.ssl.truststore.location=/var/ssl/private/kafka_rest.truststore.jks
confluent.license.ssl.truststore.password=confluent
confluent.license.ssl.keystore.location=/var/ssl/private/kafka_rest.keystore.jks
confluent.license.ssl.keystore.password=confluent
confluent.license.ssl.key.password=confluent
confluent.license.sasl.mechanism=OAUTHBEARER
confluent.license.sasl.login.callback.handler.class=io.confluent.kafka.clients.plugins.auth.token.TokenUserLoginCallbackHandler
confluent.license.sasl.jaas.config=org.apache.kafka.common.security.oauthbearer.OAuthBearerLoginModule required \
username="...." \
password="...." \
metadataServerUrls="....";
```

To learn more, refer to [Use TLS Authentication in Confluent Platform](../security/authentication/mutual-tls/overview.md#kafka-ssl-authentication) and [Deploy Secure Standalone REST Proxy in Confluent Platform](../kafka-rest/production-deployment/rest-proxy/security.md#kafkarest-security).

<a id="cp-proprietary-components-post-expire"></a>

## Renew licenses

When you renew your license subscription, you receive a new license key with a new expiration date.
Purchase and [configure a new license key](#cp-configure-license) before your old license expires.

Following is a list of commercial components and their behavior when you restart them after your
license expires:

| Component        | Reaction after license expiration                                                                                                                                                                                                                                                                                                                                  |
|------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Control Center   | Fails to start.                                                                                                                                                                                                                                                                                                                                                    |
| Replicator       | Will shut down if running, or fails to start and throws an exception.                                                                                                                                                                                                                                                                                              |
| Connectors       | Fails to start and throws an exception.                                                                                                                                                                                                                                                                                                                            |
| JMS client       | Fails to connect to any brokers and issues a license expiration message.                                                                                                                                                                                                                                                                                           |
| ADB              | Fails to calculate the rebalance plan and issues a license expiration message.                                                                                                                                                                                                                                                                                     |
| MQTT Proxy       | Fails to start.                                                                                                                                                                                                                                                                                                                                                    |
| Security plugins | Fails to start.                                                                                                                                                                                                                                                                                                                                                    |
| Confluent Server | Confluent Server starts, but generates frequent errors until a new license is provided.<br/>Note Confluent Server is the default broker found in the enterprise<br/>`confluent-<version>.tar.gz` download. To migrate from Confluent Server to Kafka,<br/>refer to [Migrating from confluent-server to confluent-kafka](migrate-confluent-server.md#migrate-cs-k). |
| CFK              | No license required. CFK is not affected by license expiration.<br/>The Confluent Platform components deployed by CFK are subject to their own<br/>license requirements.                                                                                                                                                                                           |

Developer licenses never expire.

Confluent REST Proxy, and Confluent Schema Registry are covered by the [Community license](#cp-community-license), unless you are using the
security plugins for those components. If you are using the security plugins, refer to [REST Proxy](#crest-license) or
[Schema Registry](#sr-license).

ksqlDB is covered by the [Community license](#cp-community-license).
