Skip to content

CyberChef

Local encoding, hashing and cipher workbench

VerifiedMisc· Encoding & DecodingBeginnerApache-2.0Open sourceEntry revised 27 Dec 2025
  • Web
  • Docker
  • Linux
  • macOS
  • Windows
  • Source
This entry is thinner than the rest of the directory — missing sections are shown as such rather than filled with filler.Improve this pageContribute

Overview

4 commands documented

CyberChef turns data transformations into a recipe: Base64, hex, URL, gzip, JWT inspection, XOR, hash calculations, timestamp conversion — chained operations with the output of one feeding the next. It is a teaching tool and a daily utility at the same time.

It runs entirely in the browser, and the recommended setup is a local copy, so nothing you paste leaves your machine. That matters: encoded data in a decoder on someone else's server is data you have handed over.

Supported platforms

6

Documented install or usage guidance

Learning curve

beginner

Difficulty of becoming productive, not of the underlying theory

Tags

encoding, base64, hashing, recipes, offline

Dataset entry

cyberchef.ts

Reviewed 2025-12-27

Installation

Grouped by platform. Elevation requirements are marked per method.

Self-hosted container

Alternativedocker

Community-maintained image, useful for a shared lab container.

docker run -d --rm -p 127.0.0.1:8080:80 --name cyberchef mpepping/cyberchef:latest
  • Community image, not a vendor release — pin a version tag you have checked.

Package availability follows your distribution and enabled repositories. Entry revised 27 Dec 2025 — confirm the current release on the project's own download page.

Commands

4 entries

Every command carries its purpose, an example where useful, and the limitations that change how you should read the output.

01Build a decode chain

bash

Recipes are ordered operations; the state of each step is visible, which is the pedagogic value.

From Base64 → Gunzip → Extract Text

Notes

  • This is a recipe, not a shell command — it is written into the Operations pane and executed in the page.

02Inspect a JWT

bash

Decode header and payload, check the algorithm field and expiry without sending the token anywhere.

JWT Decode
  • A token in a shared decoder is a live credential. Use the local build for anything real.

03Compare digests

bash

Reproduce a published checksum when you are verifying a download.

MD5 / SHA-256 (algorithm selector)

Notes

  • The CLI equivalent: `sha256sum file` on Linux, `Get-FileHash file` on Windows.

04Share a recipe as a URL fragment

bash

The recipe is encoded in the URL, so a colleague reopens exactly your chain.

Save → Recipe (or copy the #INPUT=… fragment)
  • The fragment contains your INPUT text. Never share a recipe URL that embeds real data.

What it is used for

  • Learning encodings

    See exactly what Base64, URL-encoding and hex do to a string.

  • Payload triage

    Peel a chain of obfuscation layers in a lab sample.

  • Checksum verification

    Compute digests offline when no CLI tool is available.

Common errors

Symptoms you will actually hit, with the cause and the legitimate fix.

Output is mojibake after 'Raw From Hex'Cause 1/2

Possible causes

  • The input encoding assumption differs from the data's actual encoding.

Usual fix

Set the correct character encoding on the operation, and inspect the hex view rather than guessing.

Recipe loads with empty inputCause 2/2

Possible causes

  • URL length limits truncated the fragment, or the shared link was sanitised.

Usual fix

Share the recipe JSON (Save → Recipe) separately from the input data.

Tips

  • Pin a release locally and keep it in your tools folder; offline capability is the feature.
  • Recipes can be exported and version-controlled — that is a real way to document a workflow.

Alternatives & comparisons

References

Where to verify anything on this page. External links open in a new tab.

Found something wrong?Suggest an editMore in Misc