# Kubernetes secret decoder — no upload

> Decode the base64 values in a Kubernetes Secret manifest to readable text (and encode back), in your browser. Nothing is uploaded.

Paste a Kubernetes Secret manifest to decode its base64-encoded values into readable text — and encode values back — right in the browser. Nothing is uploaded.

Kubernetes stores Secret values as base64, which trips people up: the values look scrambled but aren't encrypted. Decoding them locally lets you verify what a Secret contains without exposing it to an online base64 site.

Because these are real credentials, doing it in the browser is essential. Scan manifests for other exposures with the secret scanner, and validate Compose files with the Compose validator.

## How to

1. **Paste the manifest.** Paste your Secret YAML with base64 data values.
2. **Decode.** See each key's decoded plaintext value.
3. **Edit & re-encode.** Change values and get the base64 form back.

## FAQ

### Why are Kubernetes secrets base64?

Secret values are base64-encoded (not encrypted) in manifests, so they're not human-readable at a glance. This tool decodes them so you can verify what's actually stored.

### Is base64 encoding secure?

No — it's encoding, not encryption. Anyone can decode it, which is why keeping this decode step local (rather than pasting into a website) matters.

### Is my manifest uploaded?

No. Decoding and encoding run in the browser, so your secret values stay in the tab.


## Related tools

- [Base64](https://www.safepaper.app/dev/base64)
- [Secret scanner](https://www.safepaper.app/dev/secret-scanner)
- [.env manager & diff](https://www.safepaper.app/dev/env-manager)
- [Compose validator](https://www.safepaper.app/dev/docker-compose)

---

Canonical HTML: https://www.safepaper.app/dev/k8s-secret
Markdown: https://www.safepaper.app/dev/k8s-secret.md

There is no upload endpoint — your files are processed in this browser tab. Open your network tab and check.
