A simple, free REST API for BIN and IIN lookups. No authentication, no registration, no rate-limiting for standard use. JSON responses with full card metadata — served from Cloudflare's global edge network.
Sponsored content
curl "https://binlist.wellcart.pk/api/lookup/45717360"Replace 45717360 with any 6–8 digit BIN. That's it.
https://binlist.wellcart.pk/api/lookup/:binPath Parameters
:bin{
"bin": "45717360",
"scheme": "visa",
"type": "debit",
"card_tier": "classic",
"luhn": true,
"issuer": "Jyske Bank",
"country_a2": "DK",
"country_a3": "DNK",
"country_n3": "208",
"country_isd": "+45",
"country_name": "Denmark",
"country_continent": "EU"
}| Field | Type | Description |
|---|---|---|
| bin | string | The BIN/IIN that was looked up |
| scheme | string | Card network — visa · mastercard · amex · discover · unionpay · jcb · etc. |
| type | string | Card type — credit · debit · prepaid |
| card_tier | string | Card tier — classic · gold · platinum · world · etc. (may be empty) |
| luhn | boolean | Whether numbers in this range follow the Luhn checksum algorithm |
| issuer | string | Name of the issuing bank or institution (may be empty for some ranges) |
| country_a2 | string | ISO 3166-1 alpha-2 country code (e.g. US, GB, DK) |
| country_a3 | string | ISO 3166-1 alpha-3 country code (e.g. USA, GBR, DNK) |
| country_n3 | string | ISO 3166-1 numeric-3 country code (e.g. 840, 826, 208) |
| country_isd | string | International dialing code (e.g. +1, +44, +45) |
| country_name | string | Full country name (e.g. United States, Denmark) |
| country_continent | string | Continent code — EU · NA · AS · AF · OC · SA |
200OKSuccessful lookup. JSON body returned.400Bad RequestInvalid BIN — not 6–8 digits, or contains non-digits.404Not FoundBIN not found in database.429Too Many RequestsRate limit hit. Back off and retry after a delay.502Bad GatewayUpstream lookup service unreachable.Sponsored content
async function lookupBin(bin) {
const res = await fetch(`https://binlist.wellcart.pk/api/lookup/${bin}`);
if (!res.ok) throw new Error(`BIN lookup failed: ${res.status}`);
return res.json();
}
// Usage
const data = await lookupBin("45717360");
console.log(data.scheme, data.issuer, data.country_name);
// → "visa" "Jyske Bank" "Denmark"const res = await fetch('https://binlist.wellcart.pk/api/lookup/45717360');
const data = await res.json();
console.log(data); // Full JSON objectimport requests
def lookup_bin(bin_number):
url = f"https://binlist.wellcart.pk/api/lookup/{bin_number}"
response = requests.get(url)
response.raise_for_status()
return response.json()
data = lookup_bin("45717360")
print(data['scheme'], data['issuer'], data['country_name'])$bin = '45717360';
$url = "https://binlist.wellcart.pk/api/lookup/{$bin}";
$data = json_decode(file_get_contents($url), true);
echo $data['scheme'] . ' ' . $data['issuer'] . ' ' . $data['country_name'];import { useState } from 'react';
export default function CardInput() {
const [scheme, setScheme] = useState(null);
const handleChange = async (e) => {
const digits = e.target.value.replace(/D/g, '');
if (digits.length >= 6) {
const res = await fetch(`/api/lookup/${digits.slice(0,8)}`);
const data = await res.json();
setScheme(data.scheme); // e.g. "visa"
}
};
return (
<div>
<input type="text" onChange={handleChange} placeholder="Card number" />
{scheme && <img src={`/icons/${scheme}.svg`} alt={scheme} />}
</div>
);
}https://binlist.wellcart.pk/api/lookup/:binGETNone required6–8 digits, no spaces429 on excess — use exponential back-off86,400 seconds (24 hours) per BINAccess-Control-Allow-Origin: *application/jsonHow developers use the BIN lookup API in production.
As a user types their card number at checkout, fetch the BIN at 6 digits and display the correct card network logo instantly — no full number needed.
Flag transactions where the card's BIN country doesn't match the user's billing or shipping country. Stop high-risk regions automatically at payment intent creation.
Route transactions to the optimal acquirer or processor based on card network and country. Reduce interchange fees by matching card type to the right gateway.
Block prepaid cards, flag debit-as-credit mismatches, or require 3DS for specific BIN countries — all using data returned by this API at checkout.
Enforce geographic card restrictions for regulated products. Identify the card's country of issue before accepting payment — complementing IP-based geo-detection.
Show 'Credit' or 'Debit' labels on checkout forms before submission. Pre-fill currency fields by detecting the card's home country from the BIN.
Test lookups manually before integrating the API.
Common developer questions about the BIN lookup API.
No. The BIN lookup API at binlist.wellcart.pk/api/lookup/:bin requires no API key, no authentication header, and no registration. Simply make a GET request and receive JSON.
Yes. The API includes Access-Control-Allow-Origin: * CORS headers, so you can call it directly from browser JavaScript without a backend proxy. This makes it ideal for real-time checkout card detection.
The API returns HTTP 429. Implement exponential back-off: wait 1 second, then 2 seconds, then 4 seconds before retrying. For high-volume use, note that edge caching means repeated lookups of the same BIN are served instantly without counting against rate limits.
Yes. The API runs on Cloudflare's global edge network with 300+ Points of Presence. Responses are cached for 86,400 seconds per BIN. Sub-10ms response times are typical for most users worldwide.
All responses are Content-Type: application/json. Successful lookups return HTTP 200 with a JSON object. Errors return appropriate HTTP status codes (400, 404, 429, 502) with a JSON object containing an error field.
Yes. The card type field returns credit, debit, or prepaid where the data is available. Not all BIN ranges have prepaid classification data — in those cases the type field may be credit or debit without further distinction.
Sponsored content