How to Use the Docker Image Reference Parser
- Paste a Docker/OCI image reference — anything from a bare to a fully-qualified
nginx— into the box.registry.example.com:5000/team/app@sha256:... - Click Parse. The tool splits it into registry, namespace, repository, tag, and digest instantly in your browser.
- Read the breakdown — every part Docker filled in implicitly (registry, namespace, or tag) is clearly badged default so you can see exactly what Docker would actually pull.
- Nothing you paste is uploaded anywhere — this is pure string parsing running as JavaScript in your browser tab.
The Full Reference Grammar
A Docker/OCI image reference has this general shape:
[registry[:port]/]repository[/repository...][:tag][@digest]
Every part except the repository name itself is optional — which is exactly why
docker pull nginxdocker.io/library/nginx:latestThe Three Implicit Defaults, Explained
This is the part most people don't realize is happening every time they type a short image name:
- No registry given → . If the first path segment doesn't look like a hostname (no dot, no colon-with-port, and isn't literally
docker.io), Docker assumes you mean Docker Hub.localhost - No namespace given (single-segment repo name on Docker Hub) → . Docker Hub's own "official images" (like
library,nginx,redis) all technically live in a reservedubuntunamespace.library/andnginxrefer to the exact same image — this tool shows both forms are equivalent and marks the namespace as a default when you don't type it explicitly.library/nginx - No tag AND no digest given → .
:latestis not special magic that always points at "the newest version" — it's just a normal, if conventional, tag name that happens to be applied by default when nothing else is specified. An image publisher can tag any version:latest, or none at all.latest
So the bare string
nginxdocker.io/library/nginx:latestDistinguishing a Registry Host from a Repository Path
Docker uses a specific heuristic to decide whether the first
/.:localhostmyregistry.example.com:5000/myappmyregistry.example.com:5000myteam/myappmyteammyappmyteamTags vs. Digests: What Actually Pins an Image
A tag (like
:1.25-alpine:latest@sha256:<64 hex characters>Worked Examples
- → registry docker.io (default), namespace library (default), repository
nginx, tag latest (default), no digest.nginx - → registry docker.io (default), namespace library (default), repository
redis:7-alpine, tagredis(explicit — no default applied).7-alpine - → registry
myregistry.example.com:5000/myapp:1.2.3(explicit), repositorymyregistry.example.com:5000, tagmyapp.1.2.3 - → registry
gcr.io/my-project/my-app@sha256:<64 hex chars>, namespacegcr.io, repositorymy-project, no tag, digest pins the exact content.my-project/my-app
What This Tool Does NOT Do
This is a structure-only parser. It does not call Docker Hub, any other container registry, or a container runtime, and it cannot confirm the image actually exists, is pullable, or that the tag/digest you typed currently resolves to anything real.
Frequently Asked Questions
Is :latest
:latestWhy does my repository path get rejected as invalid? Repository path components must be lowercase, and each segment can only use single (not doubled/repeated in a row) separators among
.___-Is my image reference uploaded or stored anywhere? No. The parsing runs entirely as JavaScript inside your browser tab — nothing is sent to a server, logged, or stored.
Is this tool free? Yes, completely free, no login, no limit.