.*RegexQuick

JWT Regex

Regex for matching and validating JWT token format.

^[A-Za-z0-9-_]+\.[A-Za-z0-9-_]+\.[A-Za-z0-9-_]*$
//
0 matches

About this pattern

A JSON Web Token is three base64url segments joined by dots: header, payload, and signature. This pattern checks that shape and nothing more. The character class [A-Za-z0-9-_] is base64url rather than standard base64 — the + and / of ordinary base64 are replaced with - and _ so the value survives being placed in a URL without escaping, and the = padding is dropped.

The third segment is allowed to be empty, which is not an oversight. A token using the "none" algorithm has an empty signature, and matching it means your code can detect and reject one rather than failing to parse it. That is worth having: accepting alg=none is a well-known authentication bypass, where an attacker strips the signature and rewrites the payload.

The important limitation is that this tells you nothing about whether a token is valid. It does not verify the signature, check expiry, or confirm the issuer — and those are the only things that matter for security. Use it to reject obviously malformed input early, then hand the token to a real JWT library for verification. The payload is base64-encoded, not encrypted, so never put secrets in it: anyone holding the token can read it.

Worked examples

Matches

  • eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiIxMjMifQ.abc123

Does not match

  • not.a
  • plainstring

FAQ

Does matching this pattern mean a JWT is valid?

No. It confirms the shape only. Signature verification, expiry, and issuer checks are what establish validity, and all of them require a JWT library and your signing key.

Why is base64url used instead of base64?

Standard base64 uses + and /, which need escaping in URLs. Base64url substitutes - and _ and drops the = padding so the token can appear in a URL or header unescaped.

Why does the pattern allow an empty signature?

So a token using the "none" algorithm still matches and can be explicitly rejected. Accepting alg=none is a known authentication bypass — an attacker removes the signature and edits the payload freely.

Is the payload encrypted?

No, only base64-encoded. Anyone with the token can decode and read it. Never place secrets in a JWT payload.

More patterns