Regex for SHA-1 hash
40-character SHA-1 hash.
The SHA-1 hash regex is ^[0-9a-fA-F]{40}$ — copy it below, or open it in the explainer for a token-by-token breakdown.
The pattern
^[0-9a-fA-F]{40}$
What it matches
356a192b7913b04c54574d18c28d46e6395428abDA39A3EE5E6B4B0D3255BFEF95601890AFD80709
What it doesn't match
short356a192b7913b04c54574d18c28d46e639542
Notes & gotchas
Same length as a Git commit SHA. SHA-1 is deprecated for security but still used in legacy systems.
Code in your language
Use the explainer's Code tab to generate ready-to-paste snippets in JavaScript, Python, Java, .NET, Go, Ruby, and PHP for this pattern.
Open in explainer →Token-by-token breakdown
Every part of the pattern, left to right:
| Token | Meaning |
|---|---|
^ | start of string (or line in multiline mode) |
[0-9a-fA-F]{40} | exactly 40 times: any of: digits, a–f, A–F |
$ | end of string (or line in multiline mode) |
About this pattern
Identifier formats like UUIDs, hashes, and version strings have well-defined structures that regex captures cleanly. The pattern verifies format; checksums and validity against a registry need additional checks.
Quick usage in different languages
This exact pattern — with the correct escaping and idioms for each language:
- JavaScript:
/^[0-9a-fA-F]{40}$/.test(value) - Python:
re.match(r"^[0-9a-fA-F]{40}$", value) - Java:
Pattern.compile("^[0-9a-fA-F]{40}$").matcher(value).matches() - C# / .NET:
Regex.IsMatch(value, @"^[0-9a-fA-F]{40}$") - Go:
regexp.MustCompile(`^[0-9a-fA-F]{40}$`).MatchString(value) - Ruby:
/^[0-9a-fA-F]{40}$/.match?(value) - PHP:
preg_match('~^[0-9a-fA-F]{40}$~', $value)
The explainer’s Code tab regenerates these for any pattern you paste, and the downloadable cheat sheet bundles the breakdown, all seven snippets, and the pitfalls below onto one printable page.
Common pitfalls
- Anchored to the whole string. This pattern uses ^ and $, so it requires the entire input to match. To find it inside a longer text, drop the anchors and use the global (g) flag.
- Case sensitivity. Letter ranges are case-sensitive — use the i flag if the input case can vary.
- Validate beyond format. Matching the format doesn't guarantee the value is real. Confirm the sha-1 hash against a source of truth (database, API, or checksum) where it matters.
Standards & sources
This pattern is based on the following authoritative specification(s) and issuing authorities. Formats can change — always confirm against the primary source.
Related patterns
More patterns in the Codes & IDs category:
See also
Browse all 300 patterns in the library, or open this regex in the interactive explainer for a token-by-token breakdown, live testing, and code in seven languages.
Want more patterns? Browse the full library →