IBAN validation API
IBAN Validation API
Send an IBAN and get back whether it is valid, which check failed if it is not, and its parts. For IBANs from Germany, Austria, Switzerland, Liechtenstein, Belgium and the Czech Republic the response also holds the bank from the national bank code directory: its name and, where the directory lists them, its BIC and town. Validate one IBAN per request, or up to 100 with the batch endpoint.
Example request and response
The example from the IBAN documentation. Spaces and lower case are accepted. An IBAN that fails a check is not an error: the response is a 200 with valid: false and the first failed check in reason.
curl -G https://api.vatcheckapi.com/v2/iban \
-d iban=DE89370400440532013000 \
-H "apikey: YOUR-API-KEY"
{
"iban": "DE89370400440532013000",
"iban_print_format": "DE89 3704 0044 0532 0130 00",
"valid": true,
"reason": null,
"checks": {
"length": true,
"structure": true,
"checksum": true,
"national_checksum": true
},
"country_code": "DE",
"sepa": true,
"bban": "370400440532013000",
"bank_code": "37040044",
"branch_code": null,
"account_number": "0532013000",
"bank": {
"name": "Commerzbank",
"bic": "COBADEFFXXX",
"city": "Köln",
"source": "Quelle: Deutsche Bundesbank"
},
"notice": "A valid IBAN is well formed and has correct check digits. It does not prove that the account exists, is open, or who holds it."
}
Response fields
- valid, reason
- Whether every check passed, and otherwise the first check that failed:
invalid_characters,unsupported_country,invalid_length,invalid_structure,invalid_checksumorinvalid_national_checksum. - checks
- The result of each check:
length,structure,checksum(ISO 7064 MOD 97-10) andnational_checksum, which is null where no national algorithm is applied, for example for AT, CH, GB and NL. - iban, iban_print_format
- The IBAN in electronic format and in groups of four characters.
- country_code, sepa
- The country and whether it takes part in SEPA, according to the IBAN Registry.
- bban, bank_code, branch_code, account_number
- The domestic account number and its parts as the IBAN Registry defines them, also when the check digits are wrong, which helps to spot a typo.
- bank
- The bank from the national directory for DE, AT, CH, LI, BE and CZ: its name, BIC and town, with the source attribution the directory requires in
bank.source. The BIC is null where the directory lists none, and the town is null for BE and CZ, whose directories list no town. Null for other countries. - notice
- A valid IBAN does not prove that the account exists or who holds it.
Use cases
Payment and direct debit forms
Catch typos in an IBAN while the customer is still on the page, before you create a SEPA direct debit mandate or store payment details.
Supplier and payout data
Check IBANs before you pay suppliers, refunds or payouts, and show the bank name so the person who entered the IBAN can confirm it.
Cleaning stored bank details
Validate the IBANs in your database with batches of up to 100 per request. Each unique IBAN counts once.
Bank data and its sources
The bank object comes from the bank code directories that the national central banks and, for Switzerland and Liechtenstein, SIX Interbank Clearing publish. Names, BICs and towns are passed on as the directory publishes them; only padding and the spaces in printed BICs are removed. The Belgian and Czech directories list no town, so bank.city is null for BE and CZ. The directories’ terms of use require the source to be named when the data is passed on, so every bank record carries it in bank.source. Keep it with the data if you show or forward it.
| IBAN country | Directory | bank.source |
|---|---|---|
| DE | Bankleitzahlendatei, Deutsche Bundesbank | Quelle: Deutsche Bundesbank |
| AT | SEPA-Zahlungsverkehrsverzeichnis, Oesterreichische Nationalbank | Source: Oesterreichische Nationalbank (OeNB), SEPA-Zahlungsverkehrsverzeichnis (excerpt), © OeNB, licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/), provided without warranty |
| CH, LI | Bank Master, SIX Interbank Clearing | Source: SIX Interbank Clearing Ltd, Bank Master. BIC are the property of SWIFT SCRL, 1310 La Hulpe, Belgium. |
| BE | Bank identification codes, National Bank of Belgium | Source: National Bank of Belgium (NBB). This information is also available free of charge at https://www.nbb.be/en/payments-and-securities/bank-identification-codes |
| CZ | Číselník kódů platebního styku, Česká národní banka | Zdroj: ČNB |
The Belgian bank identification codes are also available free of charge on the National Bank of Belgium’s website. How often each directory is published and how the data is imported is described in the documentation.
Privacy
GET /v2/iban carries the IBAN in the URL. For lists, use POST /v2/iban/batch: it reads the IBANs from the request body only and refuses them in the query string. Send your API key in the apikey header. The IBANs are validated on our servers from the published formats and directories; no bank or other third party is contacted.
Not covered
- Whether an account exists, is open, or who holds it (no account holder or payee verification).
- Calculating an IBAN from a domestic account number.
- Account numbers that are not IBANs, such as US routing numbers or UK sort codes on their own.
IBAN formats derived from the SWIFT IBAN Registry (ISO 13616), Release 103, September 2026.
Start on the free plan
Each IBAN counts as one request, valid or not; a batch counts its unique IBANs, and a request refused with a validation error costs nothing. The free plan includes 150 requests a month (10 a minute). Paid plans start at $9.99 a month for 2,000 requests.
Frequently asked questions
What does the IBAN validation API check?
reason names the first check that failed.Does a valid IBAN mean the account exists?
For which countries does the response include the bank?
bank is null.Which national check digits are checked?
national_checksum is null and does not make an IBAN invalid.How much does a validation cost?
X-Cost header states the cost of each call.Can I validate many IBANs at once?
POST /v2/iban/batch takes up to 100 IBANs in a JSON body and returns the results keyed by the normalised IBAN, in the order sent. The IBANs stay out of the URL. If your plan does not include batch requests, the endpoint answers 403.