CodeConverter

About the Kubernetes Secret Decoder

The Kubernetes Secret Decoder reads a Secret manifest (for example the output of kubectl get secret -o yaml) and shows every data value decoded. It supports multi-document YAML and kind: List, skips objects that are not Secrets, and leaves binary values encoded with a warning.

How to use the Kubernetes Secret Decoder

  1. Paste the Secret manifest (YAML or JSON).
  2. Click Decode.
  3. Read or download the decoded values.

Frequently asked questions

Does it work with several Secrets at once?

Yes. Multi-document YAML and kind: List are both supported. Non-Secret objects are skipped and mentioned in the warnings.

What about binary values and stringData?

Values that are not valid UTF-8 stay base64-encoded with a warning. If a key appears in both data and stringData, stringData wins, as it does in the Kubernetes API server.

Are my data stored when I use the Kubernetes Secret Decoder?

The text you submit is processed in memory to produce the result and is not saved. Like any web server, Code Converter logs basic visit data (page, IP address and browser) but never the content you paste. Even so, use placeholder values instead of real production credentials.

Is the Kubernetes Secret Decoder free, and can I call it from a script?

It is free and needs no account or signup. The same tool is available as a REST endpoint at POST /api/k8s-secret-decode; see the API documentation for the fields and examples.