/v1/organizations/{organizationId}/services/{serviceId}/clickpipes/schemaDiscoveryThis endpoint is in beta. API contract is stable, and no breaking changes are expected in the future.
Infers the schema (field names and ClickHouse data types) of a ClickPipe source without creating a pipe. Supported for Kafka, Kinesis, Pub/Sub, and object storage sources. Object storage inference runs on the destination service, which must be running.
Permission
The API key must have the control-plane:service:manage-clickpipes permission.
Authorizations
- AuthorizationstringheaderrequiredUse key ID and key secret obtained in ClickHouse Cloud console: https://clickhouse.com/docs/cloud/manage/openapi
Path parameters
Request bodyJSON
- sourceobject{ … }required
4 properties
- kafkaoptionalobject{ … }
15 properties
- authenticationoptionalPLAINorSCRAM-SHA-256orSCRAM-SHA-512orIAM_ROLEorIAM_USERorMUTUAL_TLS+1 more
Authentication method of the Kafka source. SERVICE_ACCOUNT_WORKLOAD_IDENTITY is in Private Preview. ClickPipes uses the GCP service account returned in gcpWorkloadIdentity.principal by the operation with operationId clickPipesServiceContextGet; grant it access to the source resources. Supported authentication methods: kafka: PLAIN, SCRAM-SHA-256, SCRAM-SHA-512, MUTUAL_TLS, msk: SCRAM-SHA-512, IAM_ROLE, IAM_USER, MUTUAL_TLS, gcmk: PLAIN, MUTUAL_TLS, SERVICE_ACCOUNT_WORKLOAD_IDENTITY, confluent: PLAIN, MUTUAL_TLS, warpstream: PLAIN, azureeventhub: PLAIN, redpanda: SCRAM-SHA-256, SCRAM-SHA-512, MUTUAL_TLS, dokafka: SCRAM-SHA-256, MUTUAL_TLS
- iamRoleoptionalstring | null
IAM role for the Kafka source. Use with IAM role authentication. Read more in ClickPipes documentation: https://clickhouse.com/docs/en/integrations/clickpipes/kafka#iam
Example: "arn:aws:iam::123456789012:role/MyRole" 2 variants
One of the following:
- ClickPipeKafkaOffset{ … }
2 properties
- strategyoptionalfrom_beginningorfrom_latestorfrom_timestamp
Offset strategy.
- timestampoptionalstring | null
A minute precision UTC timestamp to start from. Required for "from_timestamp" strategy.
Example: "2021-01-01T00:00"
- null
- tombstoneModeoptionaldeleteorsoft_delete
How Kafka tombstone records are handled. Set to "delete" to delete the matching destination row; this requires exactly-once delivery. Set to "soft_delete" to write a row with the _is_deleted virtual column set to true; exactly-once delivery is not required. Can only be set at pipe creation.
Example: "soft_delete" Credentials for Kafka source. Choose one that is supported by the authentication method.
4 variants
One of the following:
- PLAIN{ … }
2 properties
- usernameoptionalstring
Database username.
Example: "postgres_user" - passwordoptionalstring
Database password.
format: passwordExample: "your_secure_password"
- MskIamUser{ … }
2 properties
- accessKeyIdoptionalstring
IAM access key ID.
- secretKeyoptionalstring
IAM secret key.
- AzureEventHub{ … }
1 properties
- connectionStringoptionalstring
Connection string for Azure EventHub source.
- MutualTLS{ … }
2 properties
- certificateoptionalstring
PEM encoded client certificate for mTLS authentication.
- privateKeyoptionalstring
PEM encoded client private key for mTLS authentication.
format: password
- kinesisoptionalobject{ … }
11 properties
2 variants
One of the following:
4 properties
- typegluerequired
Type of the schema registry. Kinesis ClickPipes support the AWS Glue Schema Registry, which authenticates with IAM instead of credentials.
- glueRegionstringrequired
AWS region of the Glue Schema Registry.
Example: "us-east-1" - glueRegistryNamestringrequired
Name of the Glue Schema Registry.
Example: "my-registry" - glueRoleArnoptionalstring | null
IAM role to assume for Glue Schema Registry access. Defaults to the IAM identity of the Kinesis source.
Example: "arn:aws:iam::123456789012:role/MyGlueRegistryRole"
- null
2 variants
One of the following:
- MskIamUser{ … }
2 properties
- accessKeyIdoptionalstring
IAM access key ID.
- secretKeyoptionalstring
IAM secret key.
- null
2 variants
One of the following:
10 properties
- formatJSONEachRoworAvroorProtobufrequired
Format of messages in the Pub/Sub topic. GCP Pub/Sub ClickPipes are in limited preview — contact support to enable this feature for your organization.
Example: "JSONEachRow" - projectIdstringrequired
GCP project ID that owns the Pub/Sub topic.
Example: "my-gcp-project" - topicstringrequired
Pub/Sub topic name (not the fully-qualified path).
Example: "my-topic" - authenticationSERVICE_ACCOUNTrequired
Authenticate with a GCP service account JSON key.
Example: "SERVICE_ACCOUNT" - seekTypelatestorearliestortimestamprequired
Starting position strategy for consuming the subscription. The seekTimestamp companion is required only when seekType is "timestamp"; setting it for a mismatched seek type is rejected.
Example: "earliest" - serviceAccountKeyobject{ … }required
1 properties
- serviceAccountFilestringrequired
Google Cloud service account JSON key file content, base64 encoded.
- seekTimestampoptionalstring | null
RFC 3339 / ISO 8601 timestamp to seek to. Required when seekType is "timestamp"; must be omitted otherwise.
format: date-timeExample: "2026-04-10T12:00:00Z" - filteroptionalstring | null
Optional Pub/Sub subscription filter expression (CEL). Maximum 256 characters.
maxLength: 256 - enableOrderingoptionalboolean | null
Whether to enable ordered delivery of messages (requires messages to be published with ordering keys).
- ackDeadlineoptionalinteger | null
Acknowledgement deadline for messages, in seconds. Must be between 10 and 600.
maximum: 600, minimum: 10
9 properties
- formatJSONEachRoworAvroorProtobufrequired
Format of messages in the Pub/Sub topic. GCP Pub/Sub ClickPipes are in limited preview — contact support to enable this feature for your organization.
Example: "JSONEachRow" - projectIdstringrequired
GCP project ID that owns the Pub/Sub topic.
Example: "my-gcp-project" - topicstringrequired
Pub/Sub topic name (not the fully-qualified path).
Example: "my-topic" - authenticationSERVICE_ACCOUNT_WORKLOAD_IDENTITYrequired
SERVICE_ACCOUNT_WORKLOAD_IDENTITY is in Private Preview. ClickPipes uses the GCP service account returned in gcpWorkloadIdentity.principal by the operation with operationId clickPipesServiceContextGet; grant it access to the source resources.
Example: "SERVICE_ACCOUNT_WORKLOAD_IDENTITY" - seekTypelatestorearliestortimestamprequired
Starting position strategy for consuming the subscription. The seekTimestamp companion is required only when seekType is "timestamp"; setting it for a mismatched seek type is rejected.
Example: "earliest" - seekTimestampoptionalstring | null
RFC 3339 / ISO 8601 timestamp to seek to. Required when seekType is "timestamp"; must be omitted otherwise.
format: date-timeExample: "2026-04-10T12:00:00Z" - filteroptionalstring | null
Optional Pub/Sub subscription filter expression (CEL). Maximum 256 characters.
maxLength: 256 - enableOrderingoptionalboolean | null
Whether to enable ordered delivery of messages (requires messages to be published with ordering keys).
- ackDeadlineoptionalinteger | null
Acknowledgement deadline for messages, in seconds. Must be between 10 and 600.
maximum: 600, minimum: 10
- objectStorageoptionalobject{ … }
16 properties
- urloptionalstring
Provide a path to the file(s) you want to ingest. You can specify multiple files using bash-like wildcards. For more information, see the documentation on using wildcards in path: https://clickhouse.com/docs/en/integrations/clickpipes/object-storage#limitations
Example: "https://datasets-documentation.s3.eu-west-3.amazonaws.com/http/**.ndjson.gz" - queueUrloptionalstring | null
Queue URL for event-based continuous ingestion. For S3, provide an SQS queue URL. For GCS, provide a Pub/Sub subscription (e.g. projects/{project}/subscriptions/{name}). When provided, files are ingested based on event notifications rather than lexicographical order. Only applicable when isContinuous is true and authentication is not public.
Example: "https://sqs.us-east-1.amazonaws.com/123456789012/MyQueue" - authenticationoptionalIAM_ROLEorIAM_USERorCONNECTION_STRINGorSERVICE_ACCOUNTorSERVICE_ACCOUNT_WORKLOAD_IDENTITY
Authentication method. IAM_USER is for S3, GCS, and DigitalOcean Spaces. IAM_ROLE is for S3 only. SERVICE_ACCOUNT is for GCS only. For GCS, SERVICE_ACCOUNT_WORKLOAD_IDENTITY is in Private Preview. ClickPipes uses the GCP service account returned in gcpWorkloadIdentity.principal by the operation with operationId clickPipesServiceContextGet; grant it access to the source resources. CONNECTION_STRING is for Azure Blob Storage. PUBLIC uses no authentication.
- iamRoleoptionalstring | null
IAM role to be used with IAM role authentication. Read more in ClickPipes documentation: https://clickhouse.com/docs/en/integrations/clickpipes/object-storage#authentication
Example: "arn:aws:iam::123456789012:role/MyRole" - pathoptionalstring | null
Path to the file(s) within the Azure container. Used for Azure Blob Storage sources. You can specify multiple files using bash-like wildcards. For more information, see the documentation on using wildcards in path: https://clickhouse.com/docs/en/integrations/clickpipes/object-storage#limitations
Example: "data/logs/*.json" 2 variants
One of the following:
- MskIamUser{ … }
2 properties
- accessKeyIdoptionalstring
IAM access key ID.
- secretKeyoptionalstring
IAM secret key.
- null
Response
200
Successful response
400
The request cannot be processed due to a client error. Please verify your request parameters and try again.
500
An internal server error has occurred. If this issue persists, please contact ClickHouse Cloud support for assistance.