JSON Web Token in compact serialisation: two base64url segments that both start with ey, the encoding of an opening brace and quote, then a signature segment. Expired and sample tokens match as readily as live ones, which is usually what you want, and a signature shorter than ten characters is missed. The payload of a JWT routinely carries an email, a subject and a name, so this pattern is personal data cover as much as secret cover. No whole-span collision, but a long digit run inside the token body triggers credit-card, uk-nhs or de-phone on a sub-span, so jwt must be resolved before those.
Label: JWT
\bey[A-Za-z0-9_-]{10,}\.ey[A-Za-z0-9_-]{10,}\.[A-Za-z0-9_=-]{10,}(?![\w=-])
The API answered with eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c in its body. → eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5ctoken=eyJ0eXAiOiJKV1QiLCJhbGciOiJub25lIn0.eyJpc3MiOiJodHRwczovL2V4YW1wbGUuY29tIn0.QUJDREVGR0hJSktM → eyJ0eXAiOiJKV1QiLCJhbGciOiJub25lIn0.eyJpc3MiOiJodHRwczovL2V4YW1wbGUuY29tIn0.QUJDREVGR0hJSktMeyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9keyboard.eyesight.eyelashTags: international, secrets, software-dev