You have payment forms to ship and need to validate cards fast. By the end of this guide, you’ll call the Credit Card Validator - BIN Checker API from PHP to validate the first 6 digits (BIN/IIN), read issuer and brand data, and harden your checkout or risk pipeline without building and maintaining your own BIN tables.
Why BIN validation matters and what you’ll build
The BIN (Bank Identification Number) — the first 6 digits of a card — tells you the issuer, brand, type, and often the country. You’ll wire a lightweight pre-authorization step that:
- Accepts the customer’s first 6 digits (never the full PAN),
- Calls a single endpoint to validate the BIN,
- Reads card brand (e.g., AMERICAN EXPRESS), type (CREDIT), and issuer hints,
- Branches your flow (e.g., 3DS or SCA prompts, allowed brands, or extra KYC triggers).
Everything below is built on Credit Card Validator - BIN Checker API in the Finance & Payments category on Zyla API Hub.
About the Credit Card Validator - BIN Checker API
This API validates any credit card’s BIN (first 6 digits) and returns:
- Card brand and type,
- Card level (when available),
- Issuer information (when available via API),
- Country information (when available).
It exposes one HTTP GET endpoint that takes a single required query parameter, bin, and returns a concise JSON payload confirming validity in addition to card metadata.
Billing on Zyla is subscription + quota (not pay-per-call). For this API, you’ll typically find a first API option like a 7-day trial or 50 requests. There’s no Free Plan; check the API page for current access options and pricing.
Getting started on Zyla API Hub
To get an API key and start calling endpoints:
- Open the API page: Credit Card Validator - BIN Checker API.
- Click Subscribe (or Start Free Trial if available) and complete checkout. Remember: subscription + quota model; no pay-per-call.
- Copy your API key from the dashboard.
- Authenticate every request with the header:
Authorization: Bearer YOUR_API_KEY.
If you don’t have an account yet, you can quickly Register to get an API key and try it from your environment.
Endpoint reference and implementation (cURL included)
There’s one endpoint for BIN validation:
- Method: GET
- URL:
https://zylalabs.com/api/40/credit-card-validator-bin-checker-api/1885/bin-checker - Required query parameter:
bin(string): The first 6 digits, e.g.,346350
- Auth:
Authorization: Bearer YOUR_API_KEY
cURL
curl -s -X GET "https://zylalabs.com/api/40/credit-card-validator-bin-checker-api/1885/bin-checker?bin=346350" \
-H "Authorization: Bearer YOUR_API_KEY"
This returns a JSON body indicating whether the BIN is valid and, when available, brand and issuer metadata.
PHP integration guide
The snippet below uses curl_init to invoke the same endpoint from PHP. It demonstrates request construction, authentication, and basic JSON decoding for downstream logic.
PHP (cURL)
<?php
$apiKey = 'YOUR_API_KEY';
$bin = '346350';
$url = 'https://zylalabs.com/api/40/credit-card-validator-bin-checker-api/1885/bin-checker?bin=' . urlencode($bin);
$ch = curl_init($url);
curl_setopt_array($ch, [
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
'Authorization: Bearer ' . $apiKey,
'Accept: application/json',
],
CURLOPT_TIMEOUT => 10,
]);
$response = curl_exec($ch);
$httpCode = curl_getinfo($ch, CURLINFO_HTTP_CODE);
$err = curl_error($ch);
curl_close($ch);
if ($err) {
// Transport-level error (DNS, TLS, timeout)
error_log('cURL error: ' . $err);
http_response_code(502);
exit('Upstream error, try again');
}
if ($httpCode < 200 || $httpCode >= 300) {
// Non-2xx status from the Hub
http_response_code(502);
exit('BIN checker unavailable');
}
$data = json_decode($response, true);
// Defensive checks before reading fields
if (!is_array($data) || !isset($data['success'])) {
http_response_code(502);
exit('Malformed response');
}
// Example branching logic
if (!empty($data['isValid'])) {
$brand = $data['data']['card_brand'] ?? 'UNKNOWN';
$type = $data['data']['card_type'] ?? 'UNKNOWN';
// Enforce allowed brands/types at the edge (example)
$allowedBrands = ['AMERICAN EXPRESS', 'VISA', 'MASTERCARD'];
if (!in_array($brand, $allowedBrands, true)) {
http_response_code(400);
exit('Unsupported card brand');
}
// Continue with checkout or pre-auth flow
echo 'BIN valid. Brand: ' . $brand . ' | Type: ' . $type . PHP_EOL;
} else {
http_response_code(400);
exit('Invalid BIN');
}
JavaScript (fetch)
const apiKey = 'YOUR_API_KEY';
const bin = '346350';
const url = `https://zylalabs.com/api/40/credit-card-validator-bin-checker-api/1885/bin-checker?bin=${encodeURIComponent(bin)}`;
fetch(url, {
method: 'GET',
headers: {
'Authorization': `Bearer ${apiKey}`,
'Accept': 'application/json'
}
})
.then(async (res) => {
const text = await res.text();
if (!res.ok) {
throw new Error(`HTTP ${res.status}: ${text}`);
}
return JSON.parse(text);
})
.then((json) => {
if (json.isValid) {
const brand = json.data?.card_brand ?? 'UNKNOWN';
const type = json.data?.card_type ?? 'UNKNOWN';
console.log(`BIN valid. Brand: ${brand}, Type: ${type}`);
} else {
console.log('Invalid BIN');
}
})
.catch((err) => {
console.error('Request failed:', err);
});
Response structure and field mapping
The response includes a top-level validity flag and a data object with several card attributes you can use for routing or compliance checks. Below is the official sample response you will get from the provided request.
JSON (official sample)
{
"status": 200,
"success": true,
"isValid": true,
"message": "The BIN number is valid.",
"data": {
"bin_iin": "346350",
"card_brand": "AMERICAN EXPRESS",
"card_type": "CREDIT",
"card_level": "------",
"issuer_name_bank": "------",
"issuer_bank_website": "API Only",
"issuer_bank_phone": "API Only",
"iso_country_name": null,
"iso_country_code": null
}
}
Field notes you’ll actually use:
isValid: Boolean. The decisive signal for your flow. If false, reject early.data.card_brand: e.g., AMERICAN EXPRESS. Drive brand-level routing and acceptance policies.data.card_type: e.g., CREDIT. Useful to differentiate debit/credit handling if your acquirer settings vary.data.bin_iin: Echo of the request BIN; good for logging and audits.data.issuer_* / iso_country_*: When available, use for risk controls and country-based rules.
Below are additional full JSON examples repeating the same official sample so you can copy/paste into tests or fixtures without modification.
JSON (fixture A)
{
"status": 200,
"success": true,
"isValid": true,
"message": "The BIN number is valid.",
"data": {
"bin_iin": "346350",
"card_brand": "AMERICAN EXPRESS",
"card_type": "CREDIT",
"card_level": "------",
"issuer_name_bank": "------",
"issuer_bank_website": "API Only",
"issuer_bank_phone": "API Only",
"iso_country_name": null,
"iso_country_code": null
}
}
JSON (fixture B)
{
"status": 200,
"success": true,
"isValid": true,
"message": "The BIN number is valid.",
"data": {
"bin_iin": "346350",
"card_brand": "AMERICAN EXPRESS",
"card_type": "CREDIT",
"card_level": "------",
"issuer_name_bank": "------",
"issuer_bank_website": "API Only",
"issuer_bank_phone": "API Only",
"iso_country_name": null,
"iso_country_code": null
}
}
JSON (fixture C)
{
"status": 200,
"success": true,
"isValid": true,
"message": "The BIN number is valid.",
"data": {
"bin_iin": "346350",
"card_brand": "AMERICAN EXPRESS",
"card_type": "CREDIT",
"card_level": "------",
"issuer_name_bank": "------",
"issuer_bank_website": "API Only",
"issuer_bank_phone": "API Only",
"iso_country_name": null,
"iso_country_code": null
}
}
Use cases, MCP integration, and production notes
Real-world finance use cases
- Checkout pre-validation: Reject obviously wrong BINs before hitting your PSP, saving gateway fees and latency.
- Brand whitelisting: Accept only supported brands by country or merchant category.
- SCA/3DS triggers: Apply adaptive checks based on brand and type.
- Risk scoring: Feed
isValid,card_brand, andiso_country_code(when available) into your risk model. - Support and reporting: Store
bin_iinandcard_brandfor reconciliation dashboards.
Calling the API from AI agents via MCP
Every Zyla API can be invoked through the Model Context Protocol (MCP) gateway. Point any MCP-compatible client (e.g., Claude Code, Cursor, Windsurf) to the MCP endpoint and provide your API key:
- MCP gateway:
https://mcp.zylalabs.com/mcp?apikey=YOUR_API_KEY - Learn more here: MCP
Within your agent, configure a tool that issues a GET to the BIN Checker endpoint with the bin query and the Authorization: Bearer header. The agent can then branch on isValid and read data.card_brand for downstream steps.
Production notes that save time
- Authentication: Always send
Authorization: Bearer YOUR_API_KEY. Do not pass keys in query strings. - Input validation: Ensure the
binis exactly 6 numeric characters before calling the API. - Timeouts and retries: Network calls fail; set a client timeout (e.g., 5–10s) and retry with backoff for transient 5xx/timeout conditions.
- Caching: BIN data is relatively stable. Cache responses keyed by
binfor hours or days to reduce latency and quotas. - Error handling: Check HTTP status and verify the JSON schema before reading nested fields. Fall back gracefully if fields are null or obfuscated (e.g., “API Only”).
- Data minimization: Only transmit the BIN, never full card PANs or CVV to this endpoint.
- Observability: Log
bin,isValid,card_brand, and HTTP status for audit and tuning (avoid storing full PANs). - Environment separation: Different keys per environment; never commit keys to code.
For quotas and current access options, review the API page on Zyla API Hub. Billing is subscription + quota, not pay-per-call; there is no Free Plan. First API access often provides 7-day trial or 50 requests—verify on the listing.
FAQ
1) What’s the exact endpoint and method I should call?
Use GET against: https://zylalabs.com/api/40/credit-card-validator-bin-checker-api/1885/bin-checker?bin=346350 (replace the bin value). Include header Authorization: Bearer YOUR_API_KEY.
2) Which parameters are required?
Only one query parameter is required: bin (string), the first six digits of the card.
3) What does the response look like?
The body includes status, success, isValid, message, and a data object with fields like bin_iin, card_brand, and card_type. See the JSON samples above.
4) How is billing handled?
Zyla uses a subscription + quota model (not pay-per-call). There’s no Free Plan. For this API, the first API typically offers a 7-day trial or 50 requests. Check the API page for current details.
5) Can I call this from an AI agent?
Yes. Use the Zyla MCP gateway at https://mcp.zylalabs.com/mcp?apikey=YOUR_API_KEY and configure your agent to issue a GET to the BIN Checker endpoint with the required authorization header.
Ready to validate BINs in your PHP checkout or risk service? Create your account, subscribe to the API, and grab your key: Register. You can explore additional Finance & Payments APIs anytime on Zyla API Hub and the dedicated listing page for the Credit Card Validator - BIN Checker API.