Compatibility

Controlled BetaPreview ContractVerification Required

Message Broker route and auth compatibility matrix.

Compatibility matrix for Message Broker route families, auth modes, queue behavior, replication surfaces, CLI and SDK boundaries, and Kafka compatibility scope.

Current availability

Private Beta. Public beta is scheduled for .

Matrix Snapshot

Matrix rows
17
Status values
6
Auth modes
4

Audience

Use this matrix when deciding whether a Message Broker route family, auth mode, replication surface, queue behavior, CLI/SDK path, or Kafka compatibility statement is active controlled-beta behavior, locally bounded, unsupported, preview-only, future-facing, or still waiting on reviewer acceptance.

Maturity Status

Controlled-Beta Routes

Controlled Beta

Health, stream, record, cursor, queue, audit, metrics, storage, and replication route rows map back to the current route classifier, handler modules, and local workflow evidence.

Auth And Protocol Review

Verification Required

Tenant boundaries, mTLS or external identity posture, replication outcomes, and Kafka compatibility wording need reviewer acceptance before stronger public commitments.

Compatibility Scope

Route Families

The matrix covers health, streams, records, cursors, queue delivery mutation, audit, metrics, storage inspection, and replication routes.

Auth Boundary

Only health is public. Protected route behavior depends on insecure-local, API-key, mTLS trust-file, or trusted-header external mode.

Protocol Boundary

The Kafka-shaped adapter and harness are preview contract evidence; there is no current Kafka network listener.

Status Legend

Supported

Implemented and validated for the exact documented scope.

Partial

Some behavior works, but documented gaps, limits, or exclusions apply.

Unsupported

Not implemented, intentionally unavailable, or rejected at runtime.

Preview

Contract, fixture, or bounded surface exists before complete customer-facing support.

Future

Roadmap direction only; no current runtime behavior should be expected.

Verification Required

Evidence or reviewer acceptance is missing for a support claim.

Route And Auth Matrix

Matrix owner: message-broker-docs-owner. Required reviewers: message-broker-product-sme, docs-qa-reviewer.

Review cadence
45 days
Warning window
14 days
Due soon rows
0
Stale rows
0
Message Broker route, auth, queue, replication, and protocol compatibility rows
CapabilityStatusMaturityNotesEvidenceLast reviewed
Health readiness routeSupportedControlled BetaGET /health is public and reports readiness, storage, release metadata, and configured security posture without exposing credentials.
  • SMB-EVID-002
  • SMB-EVID-008
  • DOCS-031
2026-08-16Due 2026-09-30Current
Runtime auth modesPartialVerification Requiredinsecure-local, api-key, mTLS trust-file, and trusted-header external modes are documented; mTLS and external modes rely on a trusted upstream.
  • SMB-EVID-005
  • SMB-EVID-008
  • runtime-authentication-middleware.md
2026-08-16Due 2026-09-30Current
Stream management routesSupportedControlled BetaPUT /v1/streams/{stream}, GET /v1/streams, and GET /v1/streams/{stream} are implemented with create, list, and describe permissions.
  • SMB-EVID-002
  • SMB-EVID-003
  • SMB-EVID-008
2026-08-16Due 2026-09-30Current
Versioned publish and replay routesSupportedControlled BetaPOST and GET /v1/streams/{stream}/records support single-record publish and bounded replay by offset or time selectors.
  • SMB-EVID-003
  • SMB-EVID-008
  • DOCS-031
2026-08-16Due 2026-09-30Current
Cursor and consumer-group inspectionSupportedControlled BetaConsumer group, cursor list, lease list, delayed retry, replay-consumer, cursor commit, and cursor rewind routes are implemented.
  • SMB-EVID-003
  • SMB-EVID-008
  • DOCS-031
2026-08-16Due 2026-09-30Current
Shared queue claim and delivery mutationSupportedControlled BetaQueue claim, ack, nack, renew, retry, and dead-letter routes persist delivery state and recover payloads from SegmentStorage.
  • SMB-EVID-004
  • SMB-EVID-007
  • SMB-EVID-008
2026-08-16Due 2026-09-30Current
Audit query/export and metrics scrapePartialControlled BetaAudit routes are administrator-only and tenant-filtered in protected modes. Metrics are available only when HTTP metrics exposure is enabled.
  • SMB-EVID-002
  • SMB-EVID-008
  • DOCS-031
2026-08-16Due 2026-09-30Current
Storage administration inspectionPartialControlled BetaStorage routes expose catalog, retention dry-run, tiering readiness, archive manifest, and quarantine inspection; they do not move, delete, upload, archive, or compact data.
  • SMB-EVID-002
  • SMB-EVID-008
  • DOCS-031
2026-08-16Due 2026-09-30Current
Replication status and worker controlPartialVerification RequiredStatus, poll, pause, and resume routes exist, but worker actions require configured bindings and do not by themselves prove cross-site outcomes.
  • SMB-EVID-005
  • SMB-EVID-008
  • DOCS-031
2026-08-16Due 2026-09-30Current
Replication target applyPartialVerification RequiredPOST /v1/replication/target/apply accepts bounded target batches, but target-environment proof and accepted gaps are still required for stronger claims.
  • SMB-EVID-005
  • SMB-EVID-008
  • runtime-replication-worker.md
2026-08-16Due 2026-09-30Current
Tenant visibility, RBAC, and quota boundariesVerification RequiredVerification RequiredTenant-scoped stream visibility, auth policy, quota accounting, metrics labels, and audit filtering need security and operations acceptance before stronger wording.
  • SMB-EVID-005
  • SMB-EVID-008
  • SMB-EVID-010
2026-08-16Due 2026-09-30Current
Remote CLI management readsPartialControlled BetaRemote CLI can call HTTP health, management inspection, and diagnostics routes over http:// targets; remote data writes and mTLS credentials are outside current CLI transport.
  • SMB-EVID-009
  • DOCS-032
2026-08-16Due 2026-09-30Current
Rust SDK HTTP workflowsPartialControlled BetaHttpNativeClient covers publish, replay, cursor, and queue helpers for http:// targets but does not inject runtime credentials without caller-provided transport behavior.
  • SMB-EVID-009
  • DOCS-032
  • native-sdk.md
2026-08-16Due 2026-09-30Current
Compatibility adapter harnessPreviewPreview ContractNative, HTTP, and Kafka-shaped scenario harnesses are contract and fixture evidence for produce, consume, cursor, offset, and unsupported-feature behavior.
  • SMB-EVID-009
  • native-api-contract.md
  • compatibility-adapter-test-harness.md
2026-08-16Due 2026-09-30Current
Kafka-shaped migration prototypePreviewPreview ContractKafkaCompatibilityAdapter maps typed produce, fetch, and offset commit requests to the native in-memory broker. It is not a network listener.
  • SMB-EVID-005
  • native-api-contract.md
  • kafka-compatibility-scope.md
2026-08-16Due 2026-09-30Current
Kafka network listener and external Kafka clientsUnsupportedVerification RequiredThere is no current Kafka network listener, Kafka wire-protocol compatibility, or external Kafka client smoke evidence.
  • SMB-EVID-005
  • PRODUCT_SPEC.md
  • kafka-compatibility-scope.md
2026-08-16Due 2026-09-30Current
Future protocol compatibility expansionFutureFutureReal Kafka protocol work or additional broker protocols remain future roadmap direction until a listener, client smoke evidence, and reviewer acceptance exist.
  • SMB-EVID-005
  • PROJECT_MANAGEMENT.md
2026-08-16Due 2026-09-30Current

Current Limits

Route, auth, queue, replication, and tooling limits
LimitValueApplies to
Auth modesinsecure-local, api-key, mtls, externalRuntime route admission
Public route count1GET /health
Default fetch page size100 recordsVersioned fetch, legacy fetch, audit events, audit export
Maximum fetch page size1000 recordsVersioned fetch, legacy fetch, audit events, audit export
Default queue claim count1 messageQueue claim route
Maximum queue claim count1000 messagesQueue claim route
Default queue lease timeout30000 msQueue claim route
Replica apply batch records1000 records/v1/replication/target/apply
Replica apply payload metadata64 MiB/v1/replication/target/apply aggregate payload metadata
Remote CLI transporthttp:// onlyRemote health, management reads, and diagnostics
Metrics route exposureopt-in--metrics-exposure http and GET /metrics

Explicit Exclusions

General broker replacement wording, production support, performance, scale, security, availability, direct identity-provider validation, strict cross-site durability, failover, Kafka wire-protocol compatibility, and customer commitments are outside the active controlled-beta route surface described by this matrix.

Evidence

DOCS-040 evidence map
Matrix areaEvidenceStatusLast reviewed
Runtime route and auth mapSMB-EVID-008 and DOCS-031pending2026-08-16
Local workflow coverageSMB-EVID-003, SMB-EVID-007, and /products/message-broker/quickstart/pending2026-08-16
Queue behaviorSMB-EVID-004 and runtime shared-queue docspending2026-08-16
CLI and SDK boundariesSMB-EVID-009 and DOCS-032pending2026-08-16
Kafka and protocol boundariesSMB-EVID-005, native API contract, and Kafka scopepending2026-08-16
Compatibility page artifactSMB-EVID-010 and docs/compatibility/DOCS-040-message-broker-route-auth-compatibility.mdpending2026-08-16

Internal review records track this Message Broker compatibility matrix and the evidence required to change row status.

Limits

This matrix covers current Message Broker route, auth, CLI, SDK, and compatibility-scope documentation only. It does not approve broad support, security, performance, scale, availability, direct identity-provider, strict replication, failover, or Kafka network listener claims.

See the HTTP reference for route behavior and the CLI and SDK reference for tooling boundaries.

Safe Next Steps

  • Available: DOCS-023

    Run stream and queue quickstart

    Exercise stream create, publish, replay, queue claim, ack, inspection, and the local replication boundary.

  • Available: DOCS-031

    Read HTTP reference

    Use route shapes, auth requirements, examples, errors, and limits behind each matrix row.

  • Available: DOCS-032

    Read CLI and SDK reference

    Check lifecycle flags, diagnostics, remote CLI limits, SDK HTTP boundaries, and queue helper coverage.

  • Available

    Review Message Broker evidence

    Check source records before expanding auth, tenant, replication, protocol, support, security, or operations wording.

  • Available: DOCS-042

    Read known limits

    See unsupported Kafka listener behavior, replication outcome boundaries, auth posture, and remote CLI limits.

  • Available: DOCS-043

    Track matrix review workflow

    Use the workflow for stale-row checks, evidence refresh, owner review, and release-note updates.