BinList.wellcart.pk
Developer API

Free BIN Lookup API
No Key Required

A simple, free REST API for BIN and IIN lookups. No authentication, no registration, no rate-limiting for standard use. JSON responses with full card metadata — served from Cloudflare's global edge network.

✓ No API Key✓ CORS Enabled✓ Edge Cached✓ JSON Response✓ Free Forever

Sponsored content

Quick Start — 60 SecondsNo setup needed
curl
curl "https://binlist.wellcart.pk/api/lookup/45717360"

Replace 45717360 with any 6–8 digit BIN. That's it.

Endpoint
GEThttps://binlist.wellcart.pk/api/lookup/:bin

Path Parameters

:bin
string · required6–8 digit BIN/IIN. Digits only, no spaces or dashes.
JSON Response
json
{
  "bin":                "45717360",
  "scheme":             "visa",
  "type":               "debit",
  "card_tier":          "classic",
  "luhn":               true,
  "issuer":             "Jyske Bank",
  "country_a2":         "DK",
  "country_a3":         "DNK",
  "country_n3":         "208",
  "country_isd":        "+45",
  "country_name":       "Denmark",
  "country_continent":  "EU"
}
Response Fields
FieldTypeDescription
binstringThe BIN/IIN that was looked up
schemestringCard network — visa · mastercard · amex · discover · unionpay · jcb · etc.
typestringCard type — credit · debit · prepaid
card_tierstringCard tier — classic · gold · platinum · world · etc. (may be empty)
luhnbooleanWhether numbers in this range follow the Luhn checksum algorithm
issuerstringName of the issuing bank or institution (may be empty for some ranges)
country_a2stringISO 3166-1 alpha-2 country code (e.g. US, GB, DK)
country_a3stringISO 3166-1 alpha-3 country code (e.g. USA, GBR, DNK)
country_n3stringISO 3166-1 numeric-3 country code (e.g. 840, 826, 208)
country_isdstringInternational dialing code (e.g. +1, +44, +45)
country_namestringFull country name (e.g. United States, Denmark)
country_continentstringContinent code — EU · NA · AS · AF · OC · SA
HTTP Status Codes
200OKSuccessful lookup. JSON body returned.
400Bad RequestInvalid BIN — not 6–8 digits, or contains non-digits.
404Not FoundBIN not found in database.
429Too Many RequestsRate limit hit. Back off and retry after a delay.
502Bad GatewayUpstream lookup service unreachable.

Sponsored content

JavaScript / Fetch API
js
async function lookupBin(bin) {
  const res = await fetch(`https://binlist.wellcart.pk/api/lookup/${bin}`);
  if (!res.ok) throw new Error(`BIN lookup failed: ${res.status}`);
  return res.json();
}

// Usage
const data = await lookupBin("45717360");
console.log(data.scheme, data.issuer, data.country_name);
// → "visa" "Jyske Bank" "Denmark"
Node.js (server-side)
node
const res  = await fetch('https://binlist.wellcart.pk/api/lookup/45717360');
const data = await res.json();
console.log(data); // Full JSON object
Python (requests)
python
import requests

def lookup_bin(bin_number):
    url = f"https://binlist.wellcart.pk/api/lookup/{bin_number}"
    response = requests.get(url)
    response.raise_for_status()
    return response.json()

data = lookup_bin("45717360")
print(data['scheme'], data['issuer'], data['country_name'])
PHP
php
$bin  = '45717360';
$url  = "https://binlist.wellcart.pk/api/lookup/{$bin}";
$data = json_decode(file_get_contents($url), true);

echo $data['scheme'] . ' ' . $data['issuer'] . ' ' . $data['country_name'];
React (checkout card detection)
jsx
import { useState } from 'react';

export default function CardInput() {
  const [scheme, setScheme] = useState(null);

  const handleChange = async (e) => {
    const digits = e.target.value.replace(/D/g, '');
    if (digits.length >= 6) {
      const res = await fetch(`/api/lookup/${digits.slice(0,8)}`);
      const data = await res.json();
      setScheme(data.scheme); // e.g. "visa"
    }
  };

  return (
    <div>
      <input type="text" onChange={handleChange} placeholder="Card number" />
      {scheme && <img src={`/icons/${scheme}.svg`} alt={scheme} />}
    </div>
  );
}
Limits & Caching
Base URLhttps://binlist.wellcart.pk/api/lookup/:bin
MethodGET
AuthenticationNone required
BIN format6–8 digits, no spaces
Rate limit429 on excess — use exponential back-off
Edge cache TTL86,400 seconds (24 hours) per BIN
CORSAccess-Control-Allow-Origin: *
Response typeapplication/json

Common API Use Cases

How developers use the BIN lookup API in production.

Live Card Logo Detection

As a user types their card number at checkout, fetch the BIN at 6 digits and display the correct card network logo instantly — no full number needed.

Fraud Prevention

Flag transactions where the card's BIN country doesn't match the user's billing or shipping country. Stop high-risk regions automatically at payment intent creation.

Payment Routing

Route transactions to the optimal acquirer or processor based on card network and country. Reduce interchange fees by matching card type to the right gateway.

Chargeback Reduction

Block prepaid cards, flag debit-as-credit mismatches, or require 3DS for specific BIN countries — all using data returned by this API at checkout.

Compliance & Geo-Blocking

Enforce geographic card restrictions for regulated products. Identify the card's country of issue before accepting payment — complementing IP-based geo-detection.

Card Type Display

Show 'Credit' or 'Debit' labels on checkout forms before submission. Pre-fill currency fields by detecting the card's home country from the BIN.

Related Tools

Test lookups manually before integrating the API.

BIN API – FAQs

Common developer questions about the BIN lookup API.

Does the BIN API require an API key?+

No. The BIN lookup API at binlist.wellcart.pk/api/lookup/:bin requires no API key, no authentication header, and no registration. Simply make a GET request and receive JSON.

Can I call the BIN API from a browser / frontend?+

Yes. The API includes Access-Control-Allow-Origin: * CORS headers, so you can call it directly from browser JavaScript without a backend proxy. This makes it ideal for real-time checkout card detection.

What happens if I hit the rate limit?+

The API returns HTTP 429. Implement exponential back-off: wait 1 second, then 2 seconds, then 4 seconds before retrying. For high-volume use, note that edge caching means repeated lookups of the same BIN are served instantly without counting against rate limits.

Is the BIN API suitable for production use?+

Yes. The API runs on Cloudflare's global edge network with 300+ Points of Presence. Responses are cached for 86,400 seconds per BIN. Sub-10ms response times are typical for most users worldwide.

What format does the BIN API return?+

All responses are Content-Type: application/json. Successful lookups return HTTP 200 with a JSON object. Errors return appropriate HTTP status codes (400, 404, 429, 502) with a JSON object containing an error field.

Can I look up prepaid card BINs?+

Yes. The card type field returns credit, debit, or prepaid where the data is available. Not all BIN ranges have prepaid classification data — in those cases the type field may be credit or debit without further distinction.

Sponsored content