Why is my base64 encoded twice?
You decoded a base64 string and got another base64 string. Nothing is broken, and you have not made a mistake: the value really was encoded more than once, and each decode peels off exactly one layer.
Almost nobody double-encodes on purpose. It happens because two systems each did their job without knowing the other had already done it. A service encodes a value before putting it in a field; the transport that carries the whole message encodes that too. A Kubernetes secret holds a value that was already base64 when someone pasted it into the YAML, which base64-encodes it again. A webhook signs a payload, encodes the signature, and the delivery pipeline encodes the envelope. A logging system encodes anything it cannot guarantee is printable, including a field that was encoded upstream for the same reason.
You cannot tell how many layers there are by looking. Base64 output is base64 input, so a value wrapped once and a value wrapped four times are the same kind of string. The only visible hint is length: each layer makes the text about a third longer, so deeply wrapped values get conspicuously large.
The way through is to decode repeatedly until the output stops being base64. Doing that by hand means pasting each result back into the input and losing count, which is why a tool that unwraps every layer in one action and tells you how many there were is worth having.
There is one trap in automating it, and it is worth knowing about whichever tool you use: some ordinary text is also valid base64. A decoder that keeps peeling while the input merely looks decodable will happily decode a word like "Password" into noise and report a layer that was never there. Stopping correctly is harder than decoding, and a tool that reports a layer count without judging whether each layer was real is reporting a guess.