apache/seatunnel · error

Failed to decode 'auth.api_key_encoded' as Base64

Error message

Failed to decode 'auth.api_key_encoded' as Base64

What it means

ElasticsearchValidators' ApiKeyEncodedValidator validates that auth.api_key_encoded is valid Base64 encoding of 'id:api_key'. If Base64 decoding throws IllegalArgumentException, this warn is logged and the validator returns false, failing config validation before the job runs.

Solutions

  1. Base64-encode the 'id:api_key' string (standard Base64, with padding) and use that value
  2. Alternatively use the plain auth.api_key (id and key separately) option
  3. Verify with: echo -n 'id:api_key' | base64

Example fix

// before
auth.api_key_encoded = "myId:myKey" // raw, not base64
// after
auth.api_key_encoded = "bXlJZDpteUtleQ==" // base64("myId:myKey")
Defensive patterns

Strategy: validation

Validate before calling

// validate base64 before submitting config
String v = config.getString("auth.api_key_encoded");
boolean ok = v != null && v.matches("[A-Za-z0-9+/]+={0,2}")
    && new String(java.util.Base64.getDecoder().decode(v)).contains(":");

Type guard

java.util.function.Predicate<String> isStdBase64 = s -> s != null && s.matches("[A-Za-z0-9+/]+={0,2}");

Prevention

When it happens

Trigger: Supplying an auth.api_key_encoded value that is not valid Base64 (wrong padding, URL-safe base64, or a raw id:key string pasted directly).

Common situations: Users pasting the Elasticsearch API key with URL-safe characters or without padding; providing an unencoded 'id:secret' pair instead of the encoded form.

Understand the failure class

Background: "Invalid ... format", "must be in format X", "does not look like a ..." — invalid argument format errors across CLI tools and libraries — this error's family across 17 libraries.

Related errors


AI-assisted analysis of apache/seatunnel@cf67b549a7 (2026-09-10). Data as JSON: /api/errors/db19888cc4d2bed3. Report an issue: GitHub.

Appendix: source

Thrown at seatunnel-connectors-v2/connector-elasticsearch/src/main/java/org/apache/seatunnel/connectors/seatunnel/elasticsearch/config/ElasticsearchValidators.java:61

     * the corresponding conditional rules.
     */
    @Slf4j
    public static class ApiKeyEncodedFormatValidator implements ConditionExtension<String> {
        @Override
        public String description() {
            return "'auth.api_key_encoded' must be a Base64-encoded 'id:key' string";
        }

        @Override
        public boolean evaluate(ReadonlyConfig config, String value) {
            if (value == null || value.trim().isEmpty()) {
                return true;
            }
            try {
                byte[] decoded = Base64.getDecoder().decode(value);
                return new String(decoded, StandardCharsets.UTF_8).contains(":");
            } catch (IllegalArgumentException e) {
                log.warn("Failed to decode 'auth.api_key_encoded' as Base64", e);
                return false;
            }
        }
    }
}

View on GitHub (pinned to cf67b549a7)