BINchek / Safer usage
Safer usage

BIN lookup does not require a full card number

The first 6–11 digits are enough to identify reference properties. Never send a full PAN, CVV, expiry date, cardholder name, password or one-time code—BINchek does not need them for lookup.

6–11prefix digits only
0CVV fields needed
IPAPI allowlist

What a lookup can and cannot tell you

A reference record can identify an issuer, country, network, type and product level. It cannot confirm that a card exists, belongs to a person, has funds or will be accepted. Do not use a BIN response as the sole risk decision.

Do not store full card numbers in notes or CSV files
Verify critical decisions through your payment provider
Remember that issuers can reassign ranges

Account and API protection

Create a separate API key for each environment, store it in a secret manager or environment variable and restrict allowed IPs. If exposure is suspected, deactivate the key and issue a new one without posting the old value in messages or logs.

Never embed a private key in browser JavaScript
Never send a key in a query string
Never commit keys or .env files to GitHub

Frequently asked questions

Should I enter all 16 card digits?

No. Send only the required BIN/IIN prefix—at most the first 11 digits for supported extended lookup.

What should I do if an API key leaks?

Deactivate the key in your account immediately, create a replacement, update the integration and review request statistics.

Ready to test a real workflow?

Create an account, review the available features and confirm the plan terms before payment.