# rpk security acl list

> For the complete documentation index, see [llms.txt](https://docs.redpanda.com/llms.txt). Component-specific: [streaming-full.txt](https://docs.redpanda.com/streaming-full.txt)

---
title: rpk security acl list
latest-redpanda-tag: v26.2.1
latest-console-tag: v3.10.0
latest-operator-version: v26.2.1
# EOL = End-of-Life (support lifecycle status)
page-is-nearing-eol: "false"
page-is-past-eol: "false"
page-eol-date: July 28, 2027
latest-connect-version: 4.104.0
docname: rpk/rpk-security/rpk-security-acl-list
page-component-name: streaming
page-version: "26.2"
page-component-version: "26.2"
page-component-title: Streaming
page-relative-src-path: rpk/rpk-security/rpk-security-acl-list.adoc
page-edit-url: https://github.com/redpanda-data/docs/edit/main/modules/reference/pages/rpk/rpk-security/rpk-security-acl-list.adoc
description: List ACLs. See the <code>rpk security acl</code> help text for a full write up on ACLs.
page-git-created-date: "2024-04-30"
page-git-modified-date: "2026-08-01"
support-status: supported
---

<!-- Source: https://docs.redpanda.com/streaming/current/reference/rpk/rpk-security/rpk-security-acl-list.md -->

List ACLs.

See the `rpk security acl` help text for a full write up on ACLs. List flags work in a similar multiplying effect as creating ACLs, but list is more advanced: listing works on a filter basis. Any unspecified flag defaults to matching everything (all operations, or all allowed principals, etc).

As mentioned, not specifying flags matches everything. If no resources are specified, all resources are matched. If no operations are specified, all operations are matched. You can also opt in to matching everything with `any`: `--operation` any matches any operation.

The `--resource-pattern-type`, defaulting to `any`, configures how to filter. resource names: \* `any` returns exact name matches of either prefixed or literal pattern type \* `match` returns wildcard matches, prefix patterns that match your input, and literal matches \* `prefix` returns prefix patterns that match your input (prefix `fo` matches `foo`) \* `literal` returns exact name matches

The list command lists ACLs for both Kafka and Schema Registry. To limit the results to a specific subsystem, use the `--subsystem` flag with either `kafka` or `registry`.

## [](#usage)Usage

```bash
rpk security acl list [flags]
```

## [](#aliases)Aliases

```bash
rpk security acl ls
rpk security acl describe
```

## [](#examples)Examples

This section provides examples of how to use `rpk security acl list`.

List all ACLs.

```bash
rpk security acl list
```

List all Schema Registry ACLs.

```bash
rpk security acl list --subsystem registry
```

List all ACLs for topic "foo".

```bash
rpk security acl list --topic foo
```

List all ACLs for user "bar" on topic "foo".

```bash
rpk security acl list --allow-principal bar --topic foo
```

List all ACLs for role "admin" on schema registry subject "foo-value".

```bash
rpk security acl list --allow-role admin --registry-subject foo-value
```

## [](#flags)Flags

| Value | Type | Description |
| --- | --- | --- |
| --allow-host | stringSlice | Allowed host ACLs to match (repeatable). |
| --allow-principal | stringSlice | Allowed principal ACLs to match (repeatable). |
| --allow-role | stringSlice | Allowed role ACLs to match (repeatable). |
| --cluster | bool | Whether to match ACLs to the cluster. |
| --deny-host | stringSlice | Denied host ACLs to match (repeatable). |
| --deny-principal | stringSlice | Denied principal ACLs to match (repeatable). |
| --deny-role | stringSlice | Denied role ACLs to match (repeatable). |
| --format | string | Output format (json,yaml,text,wide,help). |
| --group | stringSlice | Group to match ACLs for (repeatable). |
| --operation | stringSlice | Operation to match (repeatable). |
| -f, --print-filters | bool | Print the filters that were requested (failed filters are always printed). |
| --registry-global | bool | Whether to match ACLs for the schema registry. |
| --registry-subject | stringSlice | Schema registry subjects to match ACLs for (repeatable). |
| --resource-pattern-type | string | Pattern to use when matching resource names (any, match, literal, or prefixed). |
| --subsystem | stringSlice | The subsystem to match ACLs for (kafka, registry, or both). |
| --topic | stringSlice | Topic to match ACLs for (repeatable). |
| --transactional-id | stringSlice | Transactional IDs to match ACLs for (repeatable). |

## [](#global-flags)Global flags

| Value | Type | Description |
| --- | --- | --- |
| --config | string | Redpanda or rpk config file; default search paths are ~/.config/rpk/rpk.yaml, $PWD/redpanda.yaml, and /etc/redpanda/redpanda.yaml. |
| -X, --config-opt | stringArray | Override rpk configuration settings; -X help for detail or -X list for terser detail. |
| --ignore-profile | bool | Ignore rpk.yaml and redpanda.yaml; use default settings. |
| --profile | string | rpk profile to use. |
| -v, --verbose | bool | Enable verbose logging. |