Download Cheat sheet PDF 12 pages · syntax, editors, patterns, Unicode, performance, debugging
Pattern

Regex for GSTIN

15-character Goods and Services Tax Identification Number.

The GSTIN regex is ^[0-9]{2}[A-Z]{5}[0-9]{4}[A-Z][1-9A-Z]Z[0-9A-Z]$ — copy it below, or open it in the explainer for a token-by-token breakdown.

The pattern

^[0-9]{2}[A-Z]{5}[0-9]{4}[A-Z][1-9A-Z]Z[0-9A-Z]$
Try in explainer → Download cheat sheet ↓

What it matches

  • 27AAPFU0939F1ZV
  • 22BOSPC9911H1Z5
  • 29ABCDE1234F1Z5

What it doesn't match

  • 27aapfu0939f1zv
  • 27AAPFU0939F1Z
  • ABCDE12345F1ZV

Notes & gotchas

Format: 2-digit state code + 10-char PAN + 1-digit entity number + Z (fixed) + 1 check digit. State codes range 01–37 (with some unused). Issued by GST authorities after registration.

Code in your language

Use the explainer's Code tab to generate ready-to-paste snippets in JavaScript, Python, Java, .NET, Go, Ruby, and PHP for this pattern.

Open in explainer →

Token-by-token breakdown

Every part of the pattern, left to right:

TokenMeaning
^start of string (or line in multiline mode)
[0-9]{2}exactly 2 times: any of: digits
[A-Z]{5}exactly 5 times: any of: uppercase letters
[0-9]{4}exactly 4 times: any of: digits
[A-Z]any of: uppercase letters
[1-9A-Z]any of: 1–9, uppercase letters
Zliteral text “Z”
[0-9A-Z]any of: digits, uppercase letters
$end of string (or line in multiline mode)

About this pattern

India-specific identifiers are governed by various authorities (UIDAI for Aadhaar, Income Tax Dept for PAN, RBI for IFSC, GSTN for GSTIN, etc.). Regex confirms format; for definitive validation, integrate with the issuing authority's verification API.

Quick usage in different languages

This exact pattern — with the correct escaping and idioms for each language:

  • JavaScript: /^[0-9]{2}[A-Z]{5}[0-9]{4}[A-Z][1-9A-Z]Z[0-9A-Z]$/.test(value)
  • Python: re.match(r"^[0-9]{2}[A-Z]{5}[0-9]{4}[A-Z][1-9A-Z]Z[0-9A-Z]$", value)
  • Java: Pattern.compile("^[0-9]{2}[A-Z]{5}[0-9]{4}[A-Z][1-9A-Z]Z[0-9A-Z]$").matcher(value).matches()
  • C# / .NET: Regex.IsMatch(value, @"^[0-9]{2}[A-Z]{5}[0-9]{4}[A-Z][1-9A-Z]Z[0-9A-Z]$")
  • Go: regexp.MustCompile(`^[0-9]{2}[A-Z]{5}[0-9]{4}[A-Z][1-9A-Z]Z[0-9A-Z]$`).MatchString(value)
  • Ruby: /^[0-9]{2}[A-Z]{5}[0-9]{4}[A-Z][1-9A-Z]Z[0-9A-Z]$/.match?(value)
  • PHP: preg_match('~^[0-9]{2}[A-Z]{5}[0-9]{4}[A-Z][1-9A-Z]Z[0-9A-Z]$~', $value)

The explainer’s Code tab regenerates these for any pattern you paste, and the downloadable cheat sheet bundles the breakdown, all seven snippets, and the pitfalls below onto one printable page.

Common pitfalls

  • Anchored to the whole string. This pattern uses ^ and $, so it requires the entire input to match. To find it inside a longer text, drop the anchors and use the global (g) flag.
  • Uppercase only. Ranges like [A-Z] won't match lowercase. Add a-z (or the i flag) if lowercase input should be accepted.
  • Validate beyond format. Matching the format doesn't guarantee the value is real. Confirm the gstin against a source of truth (database, API, or checksum) where it matters.

Standards & sources

This pattern is based on the following authoritative specification(s) and issuing authorities. Formats can change — always confirm against the primary source.

Related patterns

More patterns in the India 🇮🇳 category:

See also

Browse all 300 patterns in the library, or open this regex in the interactive explainer for a token-by-token breakdown, live testing, and code in seven languages.


Want more patterns? Browse the full library →