apache/seatunnel · error
Failed to decode 'auth.api_key_encoded' as Base64
Error message
Failed to decode 'auth.api_key_encoded' as Base64
What it means
ElasticsearchValidators' ApiKeyEncodedValidator validates that auth.api_key_encoded is valid Base64 encoding of 'id:api_key'. If Base64 decoding throws IllegalArgumentException, this warn is logged and the validator returns false, failing config validation before the job runs.
Solutions
- Base64-encode the 'id:api_key' string (standard Base64, with padding) and use that value
- Alternatively use the plain auth.api_key (id and key separately) option
- Verify with: echo -n 'id:api_key' | base64
Example fix
// before
auth.api_key_encoded = "myId:myKey" // raw, not base64
// after
auth.api_key_encoded = "bXlJZDpteUtleQ==" // base64("myId:myKey") Defensive patterns
Strategy: validation
Validate before calling
// validate base64 before submitting config
String v = config.getString("auth.api_key_encoded");
boolean ok = v != null && v.matches("[A-Za-z0-9+/]+={0,2}")
&& new String(java.util.Base64.getDecoder().decode(v)).contains(":"); Type guard
java.util.function.Predicate<String> isStdBase64 = s -> s != null && s.matches("[A-Za-z0-9+/]+={0,2}"); Prevention
- Generate the encoded key with: echo -n 'id:api_key' | base64
- Never paste the raw id:key pair into api_key_encoded
- Watch for URL-safe Base64 (- and _) which the validator rejects
When it happens
Trigger: Supplying an auth.api_key_encoded value that is not valid Base64 (wrong padding, URL-safe base64, or a raw id:key string pasted directly).
Common situations: Users pasting the Elasticsearch API key with URL-safe characters or without padding; providing an unencoded 'id:secret' pair instead of the encoded form.
Understand the failure class
Background: "Invalid ... format", "must be in format X", "does not look like a ..." — invalid argument format errors across CLI tools and libraries — this error's family across 17 libraries.
- Parsing and encoding errors: unexpected token, malformed input — why parsers reject input and how to find the real culprit.
Related errors
- ADD_FIELD_FAILED
- All candidate sink tables were skipped during job parsing.
- AmazonDocumentDB option 'uri' must include authentication…
- Attempted to clear scroll with empty scroll ID
- batch_size must be >= 1, got:
AI-assisted analysis of apache/seatunnel@cf67b549a7 (2026-09-10).
Data as JSON: /api/errors/db19888cc4d2bed3.
Report an issue: GitHub.
Appendix: source
Thrown at seatunnel-connectors-v2/connector-elasticsearch/src/main/java/org/apache/seatunnel/connectors/seatunnel/elasticsearch/config/ElasticsearchValidators.java:61
* the corresponding conditional rules.
*/
@Slf4j
public static class ApiKeyEncodedFormatValidator implements ConditionExtension<String> {
@Override
public String description() {
return "'auth.api_key_encoded' must be a Base64-encoded 'id:key' string";
}
@Override
public boolean evaluate(ReadonlyConfig config, String value) {
if (value == null || value.trim().isEmpty()) {
return true;
}
try {
byte[] decoded = Base64.getDecoder().decode(value);
return new String(decoded, StandardCharsets.UTF_8).contains(":");
} catch (IllegalArgumentException e) {
log.warn("Failed to decode 'auth.api_key_encoded' as Base64", e);
return false;
}
}
}
}
View on GitHub (pinned to cf67b549a7)