What a lookup can and cannot tell you
A reference record can identify an issuer, country, network, type and product level. It cannot confirm that a card exists, belongs to a person, has funds or will be accepted. Do not use a BIN response as the sole risk decision.
Account and API protection
Create a separate API key for each environment, store it in a secret manager or environment variable and restrict allowed IPs. If exposure is suspected, deactivate the key and issue a new one without posting the old value in messages or logs.
Frequently asked questions
Should I enter all 16 card digits?
No. Send only the required BIN/IIN prefix—at most the first 11 digits for supported extended lookup.
What should I do if an API key leaks?
Deactivate the key in your account immediately, create a replacement, update the integration and review request statistics.
Ready to test a real workflow?
Create an account, review the available features and confirm the plan terms before payment.