October 4, 2026 · Yunus Emre Vurgun

What Are the Essential Regex Patterns Every Developer Should Know?

regex · reference · cheat-sheet · cli

Regular expressions match text patterns with a compact syntax built from character classes, quantifiers, anchors, and groups. About twenty constructs cover nearly everything developers do with regex, from validating form input to searching logs. This cheat sheet lists each one with a plain explanation and an example you can adapt.

Character classes and shortcuts

Character classes define which single characters can match at one position. Learn these first, because every longer pattern is built out of them.

PatternWhat it matchesExample
.Any single character except a newlinec.t matches cat, cut, c3t
\dAny digit, same as [0-9]\d\d:\d\d matches 14:30
\DAny non-digit character\D+ matches abc in abc123
\wWord character: letters, digits, underscore\w+ matches user_name1
\WAny non-word character\W+ matches spaces and punctuation
\sWhitespace: space, tab, newlinefirst\slast matches first last
\SAny non-whitespace character\S+ matches each token
[abc]One of the listed charactersgr[ae]y matches gray or grey
[^abc]Any character except the listed ones[^,]+ matches up to a comma
[a-z]Any character in the range[A-Za-z]+ matches letters only

Uppercase shortcuts are always the negation of the lowercase ones: \d versus \D, \w versus \W, \s versus \S. Ranges can be combined inside one bracket set, so [A-Za-z0-9_] is exactly what \w means in most engines.

Quantifiers and greediness

Quantifiers control how many times the preceding element may repeat. They are greedy by default, meaning they match as much text as possible.

PatternWhat it meansExample
*Zero or more repetitionsab*c matches ac, abc, abbbc
+One or more repetitions\d+ matches 7 or 42 or 1000
?Zero or one, making the item optionalcolou?r matches color or colour
{n}Exactly n repetitions\d{4} matches a year like 2026
{n,}n or more repetitions\w{3,} matches words of 3+ chars
{n,m}Between n and m repetitions\d{1,3} matches 1 to 3 digits
*?Lazy version: match as little as possible<.*?> matches one tag only
+?Lazy version of one-or-more".+?" matches one quoted string

Greediness surprises beginners. Against the string <b>hi</b>, the greedy pattern <.*> swallows the whole string, while the lazy <.*?> stops at the first closing bracket. When a pattern matches too much, adding ? after the quantifier is usually the fix.

Anchors, groups, and alternation

Anchors pin a match to a position, groups bundle subpatterns together, and alternation expresses either-or choices.

PatternWhat it meansExample
^Start of the string or line^# matches a markdown heading
$End of the string or line\.pdf$ matches filenames ending in .pdf
\bWord boundary between word and non-word\bcat\b skips catalog and cats
(...)Capturing group, also numbered for reuse(\d+)-(\d+) captures two numbers
(?:...)Non-capturing group for structure only(?:https?://)?\S+ for optional scheme
a|bAlternation: match a or bjpg|png|gif matches image extensions
\1Backreference to capture group 1(['"]).*?\1 matches balanced quotes
(?=...)Positive lookahead, checks without consuming\w+(?=@) matches the name in an email

Always anchor validation patterns. Without ^ and $, a pattern like \d{5} happily matches the first five digits of a ten-digit string, which is almost never what validation should accept. Anchors turn a search into a full-string check.

Patterns developers actually reuse

Most working regexes are variations on a short list of recipes. Copy these as starting points and tighten them for your own input.

TaskPatternNotes
Email, pragmatic^[\w.+-]+@[\w-]+\.[\w.]+$Covers real addresses; full RFC validation is not worth it
URLhttps?://[^\s"'<>]+Matches http and https links in text
ISO date^\d{4}-\d{2}-\d{2}$Matches 2026-10-04; add range checks in code
IPv4 address\b\d{1,3}(\.\d{1,3}){3}\bLoose; validate octet ranges separately
Hex color^#[0-9a-fA-F]{6}([0-9a-fA-F]{2})?$Matches #rrggbb with optional alpha
Slug^[a-z0-9]+(-[a-z0-9]+)*$Lowercase words joined by single dashes
Trim whitespace^\s+|\s+$Replace matches with empty string
Quoted string"(?:\\.|[^"])*"Handles escaped quotes inside

Resist the urge to validate everything with one giant pattern. A loose regex plus a few lines of code — checking that month 13 does not exist, or that an email domain has mail records — beats a 200-character pattern that nobody on your team can read or fix.

Using regex in grep, sed, and editors

The same ideas appear in command-line tools, but the flavor differs. GNU grep in basic mode treats (, +, and | as literals unless escaped or unless you pass -E for extended regex. Prefer grep -E or egrep-style patterns so the syntax matches what you test online.

grep -rEn "TODO|FIXME" src/
grep -Eo "[0-9]{3}-[0-9]{4}" contacts.txt
sed -E "s/[[:space:]]+/ /g" messy.txt
find . -name "*.log" | grep -E "error|warn"

These one-liners pair well with everyday terminal work — see the Unix file commands cheat sheet for the navigation half, and the Unix text processing commands catalog entry for grep, awk, and friends as structured data. For stream editing specifically, the sed reference covers substitutions in depth.

Why does my regex work online but fail in grep or code?

Almost always, the engine or the escaping changed. Online testers usually run PCRE or JavaScript, while grep defaults to basic regular expressions, Python needs raw strings (r"\d+" instead of "\\d+"), and shell double quotes eat backslashes before grep ever sees them. Quote patterns in single quotes in the shell, use raw strings in code, and check whether your tool needs -E or -P for the syntax you wrote. When in doubt, test with the smallest input that should match and add one construct at a time until the pattern breaks — the last addition is the unsupported one. As a final sanity check, run your pattern against both a matching and a non-matching sample in the target tool itself before shipping it.