Download Cheat sheet PDF 12 pages · syntax, editors, patterns, Unicode, performance, debugging
Pattern

Regex for Mastercard

Mastercard credit/debit card, including 2-series BINs.

The Mastercard regex is ^(5[1-5]\d{2}|222[1-9]|22[3-9]\d|2[3-6]\d{2}|27[01]\d|2720)\d{12}$ — copy it below, or open it in the explainer for a token-by-token breakdown.

The pattern

^(5[1-5]\d{2}|222[1-9]|22[3-9]\d|2[3-6]\d{2}|27[01]\d|2720)\d{12}$
Open in explainer → Download cheat sheet ↓

Token-by-token breakdown

Every part of the pattern, left to right:

TokenMeaning
^start of string (or line in multiline mode)
(start of a capturing group
5literal text “5”
[1-5]any of: 1–5
\d{2}exactly 2 times: digit (0–9)
|OR — try the alternative
222literal text “222”
[1-9]any of: 1–9
|OR — try the alternative
22literal text “22”
[3-9]any of: 3–9
\dany digit (0–9)
|OR — try the alternative
2literal text “2”
[3-6]any of: 3–6
\d{2}exactly 2 times: digit (0–9)
|OR — try the alternative
27literal text “27”
[01]any of: “0”, “1”
\dany digit (0–9)
|OR — try the alternative
2720literal text “2720”
)end of group
\d{12}exactly 12 times: digit (0–9)
$end of string (or line in multiline mode)

About this pattern

Financial identifiers (cards, bank routing, currencies) have format rules plus checksum algorithms. Regex validates the structure; always run the checksum (Luhn, mod-97, etc.) for production use.

Quick usage in different languages

This exact pattern — with the correct escaping and idioms for each language:

  • JavaScript: /^(5[1-5]\d{2}|222[1-9]|22[3-9]\d|2[3-6]\d{2}|27[01]\d|2720)\d{12}$/.test(value)
  • Python: re.match(r"^(5[1-5]\d{2}|222[1-9]|22[3-9]\d|2[3-6]\d{2}|27[01]\d|2720)\d{12}$", value)
  • Java: Pattern.compile("^(5[1-5]\\d{2}|222[1-9]|22[3-9]\\d|2[3-6]\\d{2}|27[01]\\d|2720)\\d{12}$").matcher(value).matches()
  • C# / .NET: Regex.IsMatch(value, @"^(5[1-5]\d{2}|222[1-9]|22[3-9]\d|2[3-6]\d{2}|27[01]\d|2720)\d{12}$")
  • Go: regexp.MustCompile(`^(5[1-5]\d{2}|222[1-9]|22[3-9]\d|2[3-6]\d{2}|27[01]\d|2720)\d{12}$`).MatchString(value)
  • Ruby: /^(5[1-5]\d{2}|222[1-9]|22[3-9]\d|2[3-6]\d{2}|27[01]\d|2720)\d{12}$/.match?(value)
  • PHP: preg_match('~^(5[1-5]\d{2}|222[1-9]|22[3-9]\d|2[3-6]\d{2}|27[01]\d|2720)\d{12}$~', $value)

The explainer’s Code tab regenerates these for any pattern you paste, and the downloadable cheat sheet bundles the breakdown, all seven snippets, and the pitfalls below onto one printable page.

Common pitfalls

  • Anchored to the whole string. This pattern uses ^ and $, so it requires the entire input to match. To find it inside a longer text, drop the anchors and use the global (g) flag.
  • Escape it correctly per language. In Java and JavaScript strings each backslash must be doubled (\\d); in Python, Go, and C# use raw/verbatim strings so the backslashes survive.
  • Validate beyond format. Matching the format doesn't guarantee the value is real. Confirm the mastercard against a source of truth (database, API, or checksum) where it matters.

Standards & sources

This pattern is based on the following authoritative specification(s) and issuing authorities. Formats can change — always confirm against the primary source.

Related patterns

More patterns in the Financial category:

See also

Browse all 300 patterns in the library, or open this regex in the interactive explainer for a token-by-token breakdown, live testing, and code in seven languages.


Want more patterns? Browse the full library →