Check if a credit or debit card number is correctly formed: Luhn (mod 10) check, length rules and network detection for Visa, Mastercard, Amex and more. Runs in your browser.
A credit card validator answers one narrow question: is this card number correctly formed? It does that offline, in a fraction of a second, by running three checks that every major card network builds into its numbers:
That makes this credit card number validator ideal for catching typos before a payment form is submitted, testing a checkout integration, or checking whether a number in a spreadsheet is plausible. What it cannot do, and what no honest validator can do, is tell you whether a card is real, active or funded. More on that below.
Not sure what to try? Use one of the official test numbers under the box, such as Stripe's Visa test card 4242 4242 4242 4242. Never type a real card's number into a website you do not trust, and never type a real CVV anywhere other than the checkout you are paying at.
| Result line | What it means |
|---|---|
| Valid format / Invalid number | The overall verdict: the number passes the Luhn check and has a length its network allows. |
| Network | The card scheme detected from the prefix. "Not recognised" means the prefix does not match the major international ranges, which is common for domestic schemes. |
| Luhn (mod 10) check | Whether the check digit matches the rest of the number. |
| Length | How many digits you entered, and what the network expects. |
| BIN / IIN | The first 6 digits, plus the 8-digit version for longer numbers. Open it in our BIN checker to see the issuing bank and country. |
| Security code | How many digits the card's CVV, CVC or CID has, and what that network calls it. The tool never asks for the code itself. |
The check behind every card number validator was invented by IBM engineer Hans Peter Luhn, who filed his "Computer for Verifying Numbers" patent on 6 January 1954. It was granted on 23 August 1960 as US Patent 2,950,048, and the method is now specified in the card numbering standard ISO/IEC 7812-1.
For the test number 4242 4242 4242 4242, the eight doubled 4s become 8s and add up to 64, the eight untouched 2s add up to 16, and the total of 80 ends in 0. Valid. Change any one digit and the total no longer ends in 0, which is exactly why a single typo is always caught.
| Error type | Example | Caught? |
|---|---|---|
| Any single wrong digit | 4242 → 4243 | Always |
| Two neighbouring digits swapped | …42… → …24… | Almost always |
| Swapping 0 and 9 | …09… → …90… | No |
| "Twin" errors | …22… → …55…, 33 → 66, 44 → 77 | No |
| A made-up number with the right check digit | Any random number ending in the "correct" digit | No |
The last row matters most. For any string of digits, exactly one of the ten possible final digits makes the Luhn check pass, so one random number in ten looks "valid". Luhn was designed to catch accidental errors, not deliberate fakes.
A card number starts with a Major Industry Identifier (its first digit) and an Issuer Identification Number of 6 or 8 digits, a format the 2017 revision of ISO/IEC 7812 extended from the old 6-digit IIN. Card numbers can be up to 19 digits long. These are the ranges this validator recognises:
| Network | Starts with | Length | Security code |
|---|---|---|---|
| Visa | 4 | 13, 16, 19 | 3-digit CVV2 |
| Mastercard | 51–55, 2221–2720 | 16 | 3-digit CVC2 |
| American Express | 34, 37 | 15 | 4-digit CID, on the front |
| Discover | 6011, 644–649, 65 | 16–19 | 3-digit CID |
| JCB | 3528–3589 | 16–19 | 3-digit CAV2 |
| Diners Club International | 30, 36, 38, 39 | 14–19 | 3 digits |
| UnionPay | 62 | 16–19 | 3-digit CVN2 |
| Maestro | 5018, 5020, 5038, 5893, 6304, 6759–6763 | 12–19 | 3 digits |
| Mir | 2200–2204 | 16–19 | 3 digits |
| RuPay | 60, 65, 81, 82, 508 | 16 | 3 digits |
Two details trip up older validators. Mastercard numbers starting with 2 (the 2-series) are fully valid, and some UnionPay cards do not use a Luhn check digit at all, as noted in Baymard Institute's card pattern reference. This tool handles both.
Alongside Visa and Mastercard, Egyptian banks issue cards on Meeza, the national payment scheme launched in 2019, owned by Egyptian Banks Company and regulated by the Central Bank of Egypt. Meeza's number ranges are not published in an official public list, so this validator may show its network as "Not recognised". The Luhn and length checks still run, and Egyptian Visa and Mastercard cards are detected like any others.
US cards follow the same international rules, with no extra local format. Validation matters there for another reason: according to the Nilson Report, the US generated 25.29% of the world's card volume in 2023 but 42.32% of its $33.83 billion in card fraud losses.
Plenty of people search for a "credit card validator with CVV" or a "validator with expiry date and CVV". Here is the honest answer: the security code is not mathematically linked to the card number, so no formula can check it. The CVV2, CVC2 or CID is verified only by the card issuer, during a real authorization.
The payment industry treats the code as so sensitive that the PCI Data Security Standard requires that "the card verification code is not retained upon completion of the authorization process" (PCI DSS v4.0, Requirement 3.3.1.2), even with the customer's consent, as the PCI Security Standards Council confirms in its FAQ. A website that asks you to "validate" your CVV is asking for exactly the data merchants are forbidden to keep. Our validator only tells you how many digits the code should have: 4 on the front for American Express, 3 on the back for the others.
An expiry date can be checked for format (a month from 01 to 12 and a date in the future), but whether it matches the card is again something only the issuer knows. Cards are generally valid until the last day of the month printed on them; U.S. Bank, for example, states that its cards are valid through the last day of the listed month.
Searches like "live credit card validator", "real credit card number validator" or "credit card generator and validator" usually come from one of two places: curiosity, or fraud. A Luhn check can never tell you whether a card is live. The only way to find out is to attempt a real payment, and running card numbers through small test payments to find working ones is a recognised fraud technique called card testing or an enumeration attack.
Stripe lists "card checking" as another name for the same attack and blocks it with rate limits, CAPTCHAs and velocity rules (Stripe documentation). Numbers from a "generator" pass the Luhn check because the check digit is calculated, but they are not real accounts, and using them to buy anything is fraud. That is why this page has a validator and no generator. If you need a card that actually works online, get a legitimate virtual Visa or Mastercard issued for you.
Developers and QA testers do not need generated numbers. Every major payment processor publishes official test cards that pass validation and work in its sandbox:
| Processor | Example test numbers | Expiry and CVC |
|---|---|---|
| Stripe | 4242 4242 4242 4242 (Visa), 5555 5555 5555 4444 (Mastercard), 2223 0031 2200 3222 (Mastercard 2-series), 3782 822463 10005 (Amex), 6011 1111 1111 1117 (Discover) | Any future date; any 3 digits, or 4 for Amex |
| PayPal sandbox | 4005 5192 0000 0004 (Visa), 2223 0000 4840 0011 (Mastercard), 3714 496353 98431 (Amex) | Any future date; 3 digits, or 4 for Amex |
| Adyen | 4111 1111 1111 1111 (Visa), 5555 5555 5555 4444 (Mastercard) | 03/2030, CVC 737 |
These numbers only work in each provider's test environment, and Stripe's own guidance is simple: don't use real card details when testing.
Checkout friction is expensive. Baymard Institute puts the average online cart abandonment rate at 70.22%; among shoppers who abandoned during checkout, 19% did not trust the site with their card details and 17% found checkout too long or complicated (Baymard, 2025). Card-field design is a direct lever on both:
| Question | Use |
|---|---|
| Did I type this card number correctly? | Credit card validator (this page) |
| Is it Visa, Mastercard or Amex, and how long should it be? | Credit card validator |
| Which bank issued it, in which country, and is it prepaid? | BIN checker |
| Is the card active, and does it have money on it? | Only the issuing bank, through a real payment |
| What will a dispute cost me compared with a refund? | Chargeback vs refund calculator |
This validator runs entirely in your browser in JavaScript. The number you type is not sent to our server or anyone else's, and it is not saved. You can confirm it yourself: open your browser's developer tools, switch to the Network tab and press Validate, and you will see no request. The only time anything leaves the page is if you choose to click the BIN checker link, and then only the first 8 digits are used. There is also no app or APK to install, which is safer: be cautious of downloadable "card validator" apps that ask for full card details.
If your real card keeps getting declined online even though the number validates, the problem is usually the issuer, the card's country or its type rather than the number itself. Our guides on virtual cards for online purchases and the best virtual card providers explain the alternatives.