Validate credit card
Validate card is an API that checks whether a card number is well-formed (Luhn checksum) and detects its network (Visa, Mastercard, Amex, Discover, Diners, JCB), before you store it or send it to your payment processor. It doesn't charge anything or move money: it only tells you whether the number itself makes sense.
How it works
You send the number (with or without spaces/dashes) and it mathematically checks whether it passes the Luhn algorithm, the same one every card network uses to catch typos. It doesn't call any bank or know whether the card exists, has funds, or is active: only whether the number is well-formed.
An invalid card isn't a request error: the response is 200 with "valid": false, same as when it's valid.
About privacy
The number you send is never stored or written to usage logs: only whether it was valid and which network was detected gets logged. The response doesn't return the number either, only whether it's valid, the network, and its length.
All you need
- Your API key. Create it in your dashboard with "+ Create key". It's shown only once, so copy and save it.
- In your automation platform, an "HTTP Request" step (n8n, Make, Zapier, Pipedream… all have one).
How to use it in n8n (step by step)
In the HTTP Request node:
- Method:
POST - URL:
https://api.cofferdock.com/validate-card - Send Headers: on → add two:
x-api-key= your key, andContent-Type=application/json - Send Body: on → Body Content Type: JSON →
{ "number": "4111 1111 1111 1111" }
In Make (HTTP → Make a request module): same method and URL, Body type: Raw, Content type: JSON, with the same body.
Options (inside the JSON)
| Option | Default | What it does |
|---|---|---|
number | - | Required. The card number, with or without spaces/dashes. |
API overview
- Endpoint:
POST https://api.cofferdock.com/validate-card - Auth: header
x-api-key: YOUR_KEY. - Input:
application/jsonONLY. - Algorithm: Luhn checksum + network detection by IIN range, pure JS (no external dependency or third-party service).
- Detected networks: Visa, Mastercard, Amex, Discover, Diners, JCB (most common ranges; some rarely-used Discover/JCB sub-ranges may not be recognized).
- Limits: 30 requests/min per IP. 1 call = 1 credit, whether the card is valid or not.
Options
| Option | Default | Description |
|---|---|---|
number | - | Required. Non-empty string, 12-19 digits after stripping spaces/dashes (400 otherwise), up to 40 characters before stripping. |
Examples
curl:
curl -X POST "https://api.cofferdock.com/validate-card" \
-H "x-api-key: YOUR_KEY" \
-H "Content-Type: application/json" \
-d '{"number":"4111111111111111"}'
JavaScript (Node 18+):
const r = await fetch('https://api.cofferdock.com/validate-card', {
method: 'POST',
headers: { 'x-api-key': 'YOUR_KEY', 'Content-Type': 'application/json' },
body: JSON.stringify({ number: '4111111111111111' }),
});
const { valid, network } = await r.json();
Response
{ "success": true, "valid": true, "network": "visa", "length": 16,
"meta": { "used": 12, "remaining": 488 } }
What you get back
valid (true/false), network (visa/mastercard/amex/discover/diners/jcb, or null if none match) and length (how many digits it had). Never the number.