How to Decode Data with CyberChef
To decode data with CyberChef, open cyberchef.org in a browser, paste the encoded text into the Input pane, search the Operations list for the matching decode operation (Base64, From Hex, URL Decode, etc.), and drag it into the Recipe area. The Output pane updates immediately. This works for single-layer encodings and, by stacking operations, for layered data — as long as you can identify or guess the encoding scheme first.
Identify the encoding before you decode
Decoding fails most often because the wrong operation was chosen. Use the shape of the input as a first clue:
| Input looks like | Likely encoding | CyberChef operation |
|---|---|---|
SGVsbG8gd29ybGQ= |
Base64 | From Base64 |
48656c6c6f |
Hex | From Hex |
Hello%20world |
URL/percent encoding | URL Decode |
%E4%BD%A0%E5%A5%BD |
URL-encoded UTF-8 | URL Decode |
1010100 |
Binary | From Binary |
5L2g5aW9 |
Base64 of UTF-8 text | From Base64 |
If the string ends in = or == and uses only A–Z a–z 0–9 + /, Base64 is the first thing to try. If it uses only 0–9 a–f, try From Hex. If it contains % followed by two hex digits, try URL Decode.
Run a single decode operation
- Paste the encoded value into the Input pane (top-left).
- Type the operation name into the Operations search box (e.g.
base64,hex,url). - Drag the operation into the Recipe pane, or double-click it.
- Read the result in the Output pane (top-right).
The Output pane refreshes as you type, so you can paste a new value and watch the decoded result change without rebuilding the recipe.
Adjusting settings
Most decode operations expose options in the recipe step:
- From Base64 lets you choose the alphabet (standard, URL-safe) and whether to remove non-alphabet characters. If your input came from a URL or JWT, switch to the URL-safe alphabet.
- From Hex lets you set the delimiter (space, comma,
0x, none) so it can parse48 65 6c 6c 6fas well as48656c6c6f. - Character encoding matters when the decoded bytes are not plain ASCII. If the output looks like
éinstead ofé, the bytes are UTF-8 being read as Latin-1 — check the operation's encoding setting or add a Decode text step with the correct encoding.
Decode layered data with a Recipe
Real-world data is often encoded more than once — for example, Base64 wrapping hex, or a URL-encoded Base64 blob. CyberChef handles this by chaining operations in the Recipe pane.
Example: a string that is Base64 of hex of the text Hi.
- Add From Base64 → output is
48 69. - Add From Hex → output is
Hi.
Order matters: operations run top to bottom, each feeding the next. If the result is garbled, remove the last operation and inspect the intermediate output before adding it back.
Useful chaining patterns
- Base64 → From Hex for tokens that encode hex payloads.
- URL Decode → From Base64 for values pulled from query strings.
- From Base64 → Gunzip when the decoded bytes are compressed (common in web APIs).
- From Base64 → From Hex → Decode text (UTF-8) for multi-layer text payloads.
CyberChef also has a Magic operation that auto-detects common encodings and ciphers. It is a fast starting point, but treat its guess as a hypothesis and confirm it against the expected format — Magic can misidentify short or ambiguous inputs.
Verify the output
A correct decode usually produces readable text, valid JSON, or recognizable structure. Check for:
- Printable characters — if the output is mostly control characters or
�, the encoding guess is wrong or the character set is mismatched. - Structure — decoded JSON should start with
{or[; decoded HTML should contain tags. - Length — Base64 output is roughly 3/4 the length of the input; a wildly different size suggests the wrong operation.
Troubleshoot common failures
"Invalid Base64" or empty output. The input contains characters outside the chosen alphabet, or it is not Base64 at all. Try the URL-safe alphabet, or strip whitespace and newlines first.
Garbled text like é or ’. The bytes are correct but interpreted with the wrong character encoding. Add or adjust a Decode text step and select UTF-8.
Output is still encoded-looking. You likely need another operation. Add the next decode step and watch the Output pane after each addition.
Hex decode produces odd-length errors. Hex requires an even number of digits. Remove stray characters or delimiters, or set the correct delimiter in the operation.
Magic gives a plausible but wrong result. Short inputs are ambiguous. Decode manually with the operation you expect and compare.
When to use CyberChef for decoding
CyberChef is a good fit when you need to decode something quickly in a browser without installing tools, when the data has multiple layers, or when you want to experiment with operations interactively. It runs entirely client-side, so pasted data is processed in the browser rather than sent to a server. For a single known encoding, a one-line script or a dedicated decoder may be faster; for layered or unfamiliar data, CyberChef's recipe model and live output make iteration much easier.