Common Regex Patterns for JavaScript (Copy-Ready Examples)

//
Flags:

Common Patterns Library

Curated, production-tested regular expressions ready to copy or test.

Email AddressWeb & Network
/^[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\.[a-zA-Z]{2,}$/gm

Matches standard RFC-compliant email addresses with domain extensions.

Matches:
user@example.comfirst.last@company.co.ukdev+regex@sub.domain.org
Rejects:
plainaddress@missing-user.comuser@.comspaces in@email.com
URL / Web AddressWeb & Network
/https?:\/\/(?:www\.)?[-a-zA-Z0-9@:%._+~#=]{1,256}\.[a-zA-Z0-9()]{1,6}\b(?:[-a-zA-Z0-9()@:%_+.~#?&/=]*)/g

Matches HTTP and HTTPS URLs with domain, port, path, parameters, and fragments.

Matches:
https://example.comhttp://sub.domain.org/path/to/page?query=1#sectionhttps://ashusevim.dev/tools/regex
Rejects:
ftp://server.orghttp://not a urljust.text
IPv4 AddressWeb & Network
/(?<![0-9.])(?:(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.){3}(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)(?![0-9.])/g

Matches valid IPv4 addresses strictly enforcing each octet between 0 and 255.

Matches:
192.168.1.1127.0.0.1255.255.255.010.0.0.254
Rejects:
256.0.0.1192.168.1192.168.1.1.1abc.def.ghi.jkl
IPv6 AddressWeb & Network
/^((?:[0-9a-fA-F]{1,4}(?::[0-9a-fA-F]{1,4})*)?)::((?:[0-9a-fA-F]{1,4}(?::[0-9a-fA-F]{1,4})*)?)$|^(?:[0-9a-fA-F]{1,4}:){7}[0-9a-fA-F]{1,4}$/im

Matches hexadecimal IPv6 network addresses including compressed double-colon formats.

Matches:
2001:0db8:85a3:0000:0000:8a2e:0370:7334fe80::12001:db8::2:1
Rejects:
192.168.1.12001:xyz::1fe80:::1
Phone Number (US / Canada)Web & Network
/^(?:\+?1[-. ]?)?\(?([0-9]{3})\)?[-. ]?([0-9]{3})[-. ]?([0-9]{4})$/gm

Matches 10-digit North American telephone numbers with optional country code and formatting.

Matches:
(555) 123-4567555-123-4567+1 555 123 45675551234567
Rejects:
123-456555-ABCD00-123-4567
Phone Number (International)Web & Network
/^\+?[1-9]\d{1,14}$/gm

Matches ITU-T E.164 international phone numbers with up to 15 digits.

Matches:
+919313696660+14155552671+442071838750
Rejects:
0000not-a-number+0123456789012345678
UsernameIdentifiers & Auth
/^[a-zA-Z0-9_-]{3,16}$/gm

Matches usernames 3 to 16 characters containing letters, numbers, underscores, and hyphens.

Matches:
ashusevimdev_user99cool-coderalex123
Rejects:
abuser@nameuser name with spacesthis_username_is_way_too_long_for_system
Strong PasswordIdentifiers & Auth
/^(?=.*[a-z])(?=.*[A-Z])(?=.*\d)(?=.*[@$!%*?&#_])[A-Za-z\d@$!%*?&#_]{8,}$/gm

Requires at least 8 characters with lowercase, uppercase, digit, and special symbol.

Matches:
P@ssw0rd2024!Str0ng#Token$K33p$afe_Now!
Rejects:
weakpassNoSpecial123NOLOWER123!Short1!
JSON Web Token (JWT)Identifiers & Auth
/^[A-Za-z0-9-_]+\.[A-Za-z0-9-_]+\.[A-Za-z0-9-_]+$/gm

Matches 3-part Base64URL-encoded JWT tokens (header.payload.signature).

Matches:
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIn0.dozG4B1s_V8xXG89
Rejects:
singleparttokenheader.payloadinvalid.char$.here
UUID / GUIDIdentifiers & Auth
/\b[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-5][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}\b/g

Matches canonical UUID versions 1 through 5 (e.g. standard v4 RFC 4122 format).

Matches:
123e4567-e89b-12d3-a456-426614174000c9a646d3-9c61-4cb7-89cd-7e2c36ab35e2
Rejects:
12345678-1234-1234-1234not-a-uuid-at-all
Hex Color CodeText & Code
/#(?:[0-9a-fA-F]{3,4}|[0-9a-fA-F]{6}|[0-9a-fA-F]{8})\b/g

Matches CSS hex colors in 3, 4 (with alpha), 6, or 8 character format.

Matches:
#fff#000000#3b82f6#ff00aa80
Rejects:
#gg0011rgb(0,0,0)#12#12345
Date (ISO 8601: YYYY-MM-DD)Dates & Times
/^\d{4}-(?:0[1-9]|1[0-2])-(?:0[1-9]|[12]\d|3[01])$/gm

Matches ISO 8601 formatted calendar dates with proper month (01-12) and day (01-31) bounds.

Matches:
2026-09-032024-01-151999-12-31
Rejects:
2024-13-012024-02-3209/03/20262024-1-5
Time (24-hour: HH:MM:SS)Dates & Times
/^(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d)?$/gm

Matches 24-hour time notation (00:00 to 23:59) with optional seconds.

Matches:
14:3000:0023:59:5908:15:30
Rejects:
24:0012:6025:12:008:5
Numbers Only (Integer)Numbers & Currency
/^-?\d+$/gm

Matches whole integers with optional leading negative sign.

Matches:
0421337-9999
Rejects:
42.51,00012a--5
Decimal / Floating Point NumberNumbers & Currency
/^-?\d+(?:\.\d+)?$/gm

Matches integers and floating point decimal numbers.

Matches:
3.14159-0.051000.0
Rejects:
3.14.15.512,34NaN
Currency (USD / Price)Numbers & Currency
/^\$?\d{1,3}(?:,\d{3})*(?:\.\d{2})?$/gm

Matches dollar prices with comma thousands separators and two-decimal cents.

Matches:
$1,234.5699.99$500$10,000,000.00
Rejects:
$12,34.51.234$$free
Credit Card NumberNumbers & Currency
/^(?:4[0-9]{12}(?:[0-9]{3})?|5[1-5][0-9]{14}|3[47][0-9]{13}|3(?:0[0-5]|[68][0-9])[0-9]{11}|6(?:011|5[0-9]{2})[0-9]{12})$/gm

Matches Visa, MasterCard, American Express, Diners Club, and Discover card numbers.

Matches:
41111111111111115500000000000004378282246310005
Rejects:
1234-567841110000000000000000
HTML TagsText & Code
/<([a-zA-Z1-6]+)(?:\s+[^>]*)?>.*?<\/\1>|<([a-zA-Z1-6]+)(?:\s+[^>]*)?\/>/gis

Matches open/close HTML elements and self-closing tags with attributes.

Matches:
<div class="header">Title</div><img src="avatar.png" /><p>Hello</p>
Rejects:
not a tag< div >just text < 5
URL SlugIdentifiers & Auth
/^[a-z0-9]+(?:-[a-z0-9]+)*$/gm

Matches kebab-case web slugs with no consecutive, leading, or trailing hyphens.

Matches:
regex-toolkithow-to-learn-typescriptpost-123
Rejects:
Regex-Toolkit-leading-hyphentrailing-hyphen-double--hyphen
Postal Code (US ZIP)Web & Network
/^\d{5}(?:-\d{4})?$/gm

Matches standard 5-digit US ZIP code or ZIP+4 extended format.

Matches:
9021010001-123494107
Rejects:
1234902101ABCDE90210-12
MAC AddressWeb & Network
/^(?:[0-9A-Fa-f]{2}[:-]){5}(?:[0-9A-Fa-f]{2})$/gm

Matches standard 6-octet hardware MAC addresses separated by colons or hyphens.

Matches:
00:1A:2B:3C:4D:5E00-1A-2B-3C-4D-5Ea1:b2:c3:d4:e5:f6
Rejects:
00:1A:2B:3C:4D00:1A:2B:3C:4D:5E:6F00:GG:2B:3C:4D:5E
Your regex and test data stay in your browser.
3 lines · 54 bytes
Support project

Common Regex Patterns for JavaScript (Copy-Ready Examples)

Every pattern here is compiled and matched against its own example by the toolkit, so a snippet cannot rot into a syntax error. Open one, load it into the tester, and adapt the bounds to your data.

  • Treat each pattern as a starting point: tighten the quantifier bounds to your real data.
  • Anchors decide whether you are validating or searching — check them before pasting.
  • Copy the pattern into the tester and add your own failing example before you trust it.

This tool runs entirely in your browser. Your patterns and text are not uploaded, stored, or logged.

Patterns that are safe to ship

Email is the standard cautionary example: a pattern that accepts every valid address and rejects nothing invalid does not exist, because the specification is broader than any product needs. The useful question is not "is this regex correct?" but "which inputs do I intend to reject, and does this pattern reject exactly those?"

The patterns in this library are conservative and documented with their intent — an email pattern that follows the practical shape used in form validation, a URL pattern that handles scheme, host, path and query, a date pattern that distinguishes ISO from slash formats rather than accepting both and guessing later.

Reading a pattern library honestly

A snippet with no example is unverifiable. Each entry pairs the pattern with sample input, which means a broken entry is a failing test rather than a subtly wrong production behaviour. When you copy one out, keep the example next to it — that pair is the part that stays correct over time.

  • Escaping inside a character class differs from escaping outside it; `[.` is literal, `\.` is escaped.
  • `\d` matches ASCII digits only, so non-Latin numerals need `\p{Nd}` with the `u` flag.
  • A pattern anchored with `^` and `$` behaves differently in multiline mode — check the flags.

Performance and catastrophic backtracking

Pattern libraries propagate ReDoS faster than any other class of bug, because a nested quantifier copied from a snippet runs against attacker-controlled input. If a pattern applies quantifiers to a group that itself contains a quantifier, test it against a long near-miss string before it reaches a request handler.

Frequently asked questions

Are these patterns tested?

Yes. Every entry is compiled and matched against its example in the test suite, so an entry that no longer compiles or no longer matches its sample fails the build rather than sitting on the page.

Which regex flavor do the patterns target?

ECMAScript, as implemented by Node.js and current browsers. Lookaheads, lookbehinds, named groups and unicode property escapes are supported; PCRE-only constructs are not used.

Why does an email pattern reject addresses I know are valid?

Because most email patterns trade specification coverage for predictability. Decide which inputs your product should reject and adjust the local-part and top-level-domain rules to that decision.

Related

Support the free tools