regexhelper
Test a pattern. Copy a ready-made one. No signup.

Regex to Match a JWT Token

Copy the pattern, paste your text below, and see every JWT it finds. Below the tester: what the three segments are and why you should never trust a token by shape alone.

/ /

What this pattern matches

This expression matches a JSON Web Token: a header, a payload, and a signature, each Base64URL-encoded and joined by dots. JWTs always start with eyJ, the Base64URL encoding of {", which this pattern anchors on.

How it works, part by part

eyJ — the literal start of a Base64URL-encoded JSON object.

[A-Za-z0-9_-]+ — the rest of the header, in the URL-safe Base64 alphabet.

\.[A-Za-z0-9_-]+ — a dot then the payload.

\.[A-Za-z0-9_-]+ — a dot then the signature.

Shape is not trust

Matching the shape of a JWT tells you nothing about whether it is valid. You still have to verify the signature against the issuer's key and check the exp claim. Use this pattern to locate or redact tokens in logs — never to authorise a request.

Use it in your code

Python
import re
text = "Authorization: Bearer eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiIxMjMifQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c"
pattern = r'''eyJ[A-Za-z0-9_-]+\.[A-Za-z0-9_-]+\.[A-Za-z0-9_-]+'''
for m in re.finditer(pattern, text):
    print(m.group())
JavaScript
const text = "Authorization: Bearer eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiIxMjMifQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c";
const re = new RegExp(String.raw`eyJ[A-Za-z0-9_-]+\.[A-Za-z0-9_-]+\.[A-Za-z0-9_-]+`, "g");
console.log(text.match(re));

FAQ

Do all JWTs start with eyJ?

Practically yes. The header is a JSON object, and its Base64URL encoding almost always begins eyJ. Drop that anchor if you handle unusual encodings.

Does it verify the signature?

No. A regex only checks structure. Verify the signature and expiry with a real JWT library before trusting a token.

Why use [A-Za-z0-9_-] and not +/?

JWT uses URL-safe Base64, which replaces + and / with - and _ so tokens are safe in URLs and headers.