CARD

Credit Card Validator

Validate card number with Luhn check

Validation
🔒 100% client-side — your data never leaves this page
Maintained by Evan•Updated: September 29, 2026•Reviewed: September 28, 2026

Check format, a limited set of network prefixes, and the Luhn checksum separately. Passing these checks does not establish that a card is issued, usable, or funded.

Up to 1,000 nonempty lines. Input is processed in this page without saving a local draft. Results show only the last four digits.

How to read the checks

Luhn is a checksum that catches some input mistakes. Even all-zero numbers satisfy the arithmetic, so the tool separately rejects all-zero input, checks the 12–19 digit range, and applies length rules for recognized patterns. Letters and arbitrary punctuation are rejected rather than silently removed.

Prefix matching covers Visa, Mastercard, Amex and selected Discover ranges without a live BIN lookup. An unrecognized pattern does not establish that a network is invalid. Expiry, cardholder, CVV, account status and payment authorization are outside these checks; verify payment flows in your provider’s test environment.

Page reading mode

The full guide also includes pitfalls, worked examples, snippets, FAQs, and related tools for checking results or troubleshooting.

About this tool

Check each input line for supported characters, number length, a limited card-network prefix pattern, and the Luhn checksum. These are separate results: all-zero numbers pass the checksum arithmetic but fail the format check. Mastercard prefixes 51–55 and 2221–2720 are recognized with a 16-digit length. Use payment-provider test numbers to debug form validation. Passing local checks does not prove issuance, account status, identity, or payment authorization. Inputs are not saved as a browser draft; output shows only the last four digits.

Practical Notes

Card validation on the client improves form quality, but it is not fraud prevention. Treat it as input hygiene only.

Validation layers

Run Luhn checks and brand pattern detection client-side to catch typos early.

Always revalidate server-side and rely on payment gateway responses for final authorization.

Compliance mindset

Do not store full PAN in logs or analytics events.

Keep PCI scope minimal by tokenizing and using hosted payment fields whenever possible.

Frequently Asked Questions

Does passing Luhn mean a card is usable?

No. Luhn is checksum arithmetic. It does not verify issuance, expiry, cardholder identity, CVV, funds, account status, or payment authorization.

Why does an all-zero number pass Luhn but fail format?

The sum of zero digits is divisible by ten, so the arithmetic passes. The separate format check rejects all-zero input, lengths outside 12–19 digits, and lengths inconsistent with recognized prefix patterns.

Which separators can I remove?

Enable Allow spaces and hyphens to accept those two presentation separators. Letters, decimal points and other punctuation remain invalid; the tool does not silently strip all nondigits.

What do the network labels mean?

They are limited prefix-pattern matches for Visa, Mastercard, Amex and selected Discover ranges, not a live BIN or issuer lookup. Unknown patterns can still satisfy Luhn; unsupported networks are not automatically invalid.

Is input stored or uploaded?

Card checking runs in the current page. This tool does not upload input or save a local draft. Results expose only the last four digits; website analytics records task counts rather than the input numbers.

Can I check duplicate test inputs?

Yes. There is a limit of 1,000 nonempty lines and 100,000 characters. Optional deduplication combines identical numeric candidates after the selected separator handling; malformed lines remain visible for review.

Keep browsing