If your architecture contains Kafka, you can use Kafka ACLs to authorize access to any resource, not just Kafka ones. Based on a principal, a named resource (derived from, eg, a URL path) and the requested operation, the Kafka admin client can tell you whether there is a matching ACL that permits the request.
I've had success doing this.