Regex for URL slug
Lowercase URL slug — letters, digits, hyphens.
The URL slug regex is ^[a-z0-9]+(?:-[a-z0-9]+)*$ — copy it below, or open it in the explainer for a token-by-token breakdown.
The pattern
^[a-z0-9]+(?:-[a-z0-9]+)*$
What it matches
my-blog-posthello-worldseo-friendly-url-2024
What it doesn't match
My-Blog-Postmy_blog_post-leading-dashtrailing-dash-
Notes & gotchas
No leading/trailing/consecutive hyphens. Lowercase letters and digits only. Used for SEO-friendly URLs.
Code in your language
Use the explainer's Code tab to generate ready-to-paste snippets in JavaScript, Python, Java, .NET, Go, Ruby, and PHP for this pattern.
Open in explainer →Token-by-token breakdown
Every part of the pattern, left to right:
| Token | Meaning |
|---|---|
^ | start of string (or line in multiline mode) |
[a-z0-9]+ | one or more: any of: lowercase letters, digits |
(?: | start of a non-capturing group |
- | literal text “-” |
[a-z0-9]+ | one or more: any of: lowercase letters, digits |
)* | end of group, zero or more |
$ | end of string (or line in multiline mode) |
About this pattern
Identifying and validating user identity (names, contact info, IDs) is one of the most common reasons developers reach for regex. The pattern below handles the format check; for full validation always confirm against a source of truth (database, API, or document).
Quick usage in different languages
This exact pattern — with the correct escaping and idioms for each language:
- JavaScript:
/^[a-z0-9]+(?:-[a-z0-9]+)*$/.test(value) - Python:
re.match(r"^[a-z0-9]+(?:-[a-z0-9]+)*$", value) - Java:
Pattern.compile("^[a-z0-9]+(?:-[a-z0-9]+)*$").matcher(value).matches() - C# / .NET:
Regex.IsMatch(value, @"^[a-z0-9]+(?:-[a-z0-9]+)*$") - Go:
regexp.MustCompile(`^[a-z0-9]+(?:-[a-z0-9]+)*$`).MatchString(value) - Ruby:
/^[a-z0-9]+(?:-[a-z0-9]+)*$/.match?(value) - PHP:
preg_match('~^[a-z0-9]+(?:-[a-z0-9]+)*$~', $value)
The explainer’s Code tab regenerates these for any pattern you paste, and the downloadable cheat sheet bundles the breakdown, all seven snippets, and the pitfalls below onto one printable page.
Common pitfalls
- Anchored to the whole string. This pattern uses ^ and $, so it requires the entire input to match. To find it inside a longer text, drop the anchors and use the global (g) flag.
- Lowercase only. Ranges like [a-z] won't match uppercase. Add A-Z (or the i flag) if uppercase input should be accepted.
- Watch for backtracking. This pattern nests quantifiers; on adversarial input that can cause exponential backtracking (ReDoS). Test with long non-matching strings, or use an RE2-based engine.
- Validate beyond format. Matching the format doesn't guarantee the value is real. Confirm the url slug against a source of truth (database, API, or checksum) where it matters.
Related patterns
More patterns in the Identity & contact category:
See also
Browse all 300 patterns in the library, or open this regex in the interactive explainer for a token-by-token breakdown, live testing, and code in seven languages.
Want more patterns? Browse the full library →