Docker Image Reference Parser

Parse a Docker image reference into registry, namespace, repository, tag, and digest — including the implicit docker.io/library and :latest defaults, stated explicitly.

Parsed 100% in your browser — nothing you type is transmitted or stored.

How to Use the Docker Image Reference Parser

  1. Paste a Docker/OCI image reference — anything from a bare
    nginx
    to a fully-qualified
    registry.example.com:5000/team/app@sha256:...
    — into the box.
  2. Click Parse. The tool splits it into registry, namespace, repository, tag, and digest instantly in your browser.
  3. Read the breakdown — every part Docker filled in implicitly (registry, namespace, or tag) is clearly badged default so you can see exactly what Docker would actually pull.
  4. Nothing you paste is uploaded anywhere — this is pure string parsing running as JavaScript in your browser tab.

The Full Reference Grammar

A Docker/OCI image reference has this general shape:

[registry[:port]/]repository[/repository...][:tag][@digest]

Every part except the repository name itself is optional — which is exactly why

docker pull nginx
works, even though the fully-qualified reference Docker actually resolves it to is
docker.io/library/nginx:latest
.

The Three Implicit Defaults, Explained

This is the part most people don't realize is happening every time they type a short image name:

  1. No registry given →
    docker.io
    .
    If the first path segment doesn't look like a hostname (no dot, no colon-with-port, and isn't literally
    localhost
    ), Docker assumes you mean Docker Hub.
  2. No namespace given (single-segment repo name on Docker Hub) →
    library
    .
    Docker Hub's own "official images" (like
    nginx
    ,
    redis
    ,
    ubuntu
    ) all technically live in a reserved
    library/
    namespace.
    nginx
    and
    library/nginx
    refer to the exact same image — this tool shows both forms are equivalent and marks the namespace as a default when you don't type it explicitly.
  3. No tag AND no digest given →
    :latest
    .
    :latest
    is not special magic that always points at "the newest version" — it's just a normal, if conventional, tag name that happens to be applied by default when nothing else is specified. An image publisher can tag any version
    latest
    , or none at all.

So the bare string

nginx
and the fully-qualified
docker.io/library/nginx:latest
are exactly the same reference — this tool shows you that expansion explicitly.

Distinguishing a Registry Host from a Repository Path

Docker uses a specific heuristic to decide whether the first

/
-separated segment of a reference is a registry hostname or the start of the repository path: it's treated as a registry only if it contains a dot (
.
), a colon (
:
, for an explicit port), or is exactly the literal string
localhost
. This is why
myregistry.example.com:5000/myapp
correctly identifies
myregistry.example.com:5000
as the registry, while
myteam/myapp
(no dot, no colon, not localhost) is correctly read as a two-segment Docker Hub repository path (
myteam
as namespace,
myapp
as the image), not an attempt to reach a registry host named
myteam
.

Tags vs. Digests: What Actually Pins an Image

A tag (like

:1.25-alpine
) is a mutable, human-friendly label — the same tag can be re-pointed at a different image over time (this is exactly how
:latest
keeps "moving" as new versions are published). A digest (like
@sha256:<64 hex characters>
) is a cryptographic hash of the image's actual content — it can never silently change; pulling the same digest always gets you the exact same bytes. When a reference includes both a tag and a digest, the digest is what actually pins the content for the pull — the tag is present purely as a human-readable label alongside it, and this tool notes that explicitly when both are present.

Worked Examples

  • nginx
    → registry docker.io (default), namespace library (default), repository
    nginx
    , tag latest (default), no digest.
  • redis:7-alpine
    → registry docker.io (default), namespace library (default), repository
    redis
    , tag
    7-alpine
    (explicit — no default applied).
  • myregistry.example.com:5000/myapp:1.2.3
    → registry
    myregistry.example.com:5000
    (explicit), repository
    myapp
    , tag
    1.2.3
    .
  • gcr.io/my-project/my-app@sha256:<64 hex chars>
    → registry
    gcr.io
    , namespace
    my-project
    , repository
    my-project/my-app
    , no tag, digest pins the exact content.

What This Tool Does NOT Do

This is a structure-only parser. It does not call Docker Hub, any other container registry, or a container runtime, and it cannot confirm the image actually exists, is pullable, or that the tag/digest you typed currently resolves to anything real.

Frequently Asked Questions

Is

:latest
guaranteed to be the newest version of an image? No — it's just a conventional tag name. A publisher decides what
:latest
points to (or whether to publish it at all); nothing in Docker's tooling enforces that it's actually the most recent build.

Why does my repository path get rejected as invalid? Repository path components must be lowercase, and each segment can only use single (not doubled/repeated in a row) separators among

.
,
_
,
__
, and
-
between alphanumeric runs — this tool validates each path segment against that exact grammar.

Is my image reference uploaded or stored anywhere? No. The parsing runs entirely as JavaScript inside your browser tab — nothing is sent to a server, logged, or stored.

Is this tool free? Yes, completely free, no login, no limit.

A free browser tool by Toolzer Hub. It runs on your device; files you add are not uploaded. More free tools