Technical fundamentals
What a card BIN is and what its first digits reveal
Published: · 8 min read
The BIN (Bank Identification Number) is the set of the first 6 or 8 digits of a card: it identifies the issuer and, in many cases, reveals the country, the payment network and the product type.
Key points
- The BIN is the first 6 or 8 digits of a card and its purpose is to identify the issuer.
- The card number is split into BIN + account number + check digit (Luhn).
- BIN and IIN (Issuer Identification Number) designate practically the same thing; IIN is the more current term.
- The ISO/IEC 7812 standard governs the structure and use of these identifiers.
- Each network has a characteristic prefix: Visa starts with 4, Mastercard with 5 or 2, Amex with 3, Discover with 6.
- The BIN does not confirm that the card exists or that it has funds.
When a validator tells you that a number is a "Visa from the United States", it is actually reading the BIN. It is one of the most useful parts of a card number for developers and QA teams: it lets you recognise the network and the correct format before processing a payment, without querying the bank. In this guide you will see exactly what the BIN is, how a card number is structured, the difference between BIN and IIN, the prefixes of each network and how it is applied in testing.
What the BIN is and what IIN means
The BIN is the prefix that issuers assign to their cards. The first digits identify the bank or entity that issued the card, and that assignment is managed by international bodies. As its name no longer reflected all its uses (it is not only used by banks), the industry adopted the term IIN (Issuer Identification Number).
In practice, BIN and IIN are the same thing. Many documents, tools and APIs still use "BIN" because it is the better-known term, but if you see "IIN" in a specification, it refers to the same concept.
The standard that governs it is ISO/IEC 7812, which defines how a card identification number is structured and how issuer ranges are registered. Among other things, this standard establishes that the number consists of an issuer identifier and an individual part assigned by the issuer itself.
Anatomy of a card number
A card number is not a random block: it has a structure. It is divided into three parts:
- BIN / IIN (first 6 or 8 digits): identifies the issuer, the network and the country.
- Account number (middle digits): assigned by the issuer to each specific card. It identifies your account within that issuer.
- Check digit (last digit): calculated with the Luhn algorithm and used to detect typing errors.
For example, in the number 4539 1488 0343 6467:
- 4539 14 → BIN: identifies the network (Visa, because of the prefix 4) and the issuer.
- 88 0343 646 → account number.
- 7 → check digit (Luhn).
This structure is why a validator can tell you the card type offline: the first digits already contain that information.
What the BIN reveals: issuer, country and type
When you look up a BIN, you can obtain several pieces of data:
- Payment network: Visa, Mastercard, American Express, Discover, JCB, Diners Club, UnionPay…
- Issuer (bank): the entity that issued the card.
- Country: the country where the BIN range was registered.
- Product type: credit, debit, prepaid, gift.
- Level or category: classic, gold, platinum, etc. (depending on the range).
This is very useful in development. If your form only accepts Visa and Mastercard, you can read the BIN and warn the user instantly if they try to pay with another network, without sending the transaction to the processor. It also helps to apply anti-fraud rules, such as blocking ranges from high-risk countries.
It is worth remembering that BIN information is not always up to date or universal. Ranges get reassigned, some BINs belong to aggregators (not to a visible bank) and certain issuers share ranges. Treat it as a useful clue, not as an absolute truth.
6-digit BIN vs 8-digit BIN
For years, the standard BIN was 6 digits. With the growth in the number of cards and issuers, the 6-digit ranges became exhausted, so the industry extended the identifier to 8 digits. Today both coexist:
| Feature | 6-digit BIN | 8-digit BIN |
|---|---|---|
| Identifier length | 6 digits | 8 digits |
| Historical use | Classic standard | Extension due to range exhaustion |
| Issuer accuracy | Lower (shares ranges) | Higher (more specific) |
| Example reading | 453914 | 45391488 |
For anyone working with testing, the important thing is that some BIN databases use 6 digits and others use 8. If your tool does not recognise a BIN, try truncating it to 6 digits or extending it to 8 before concluding that it is invalid.
Our card validator reads the 6-digit BIN and detects the card type, in addition to checking the number with the Luhn algorithm. It is a quick way to know what you are working with.
Prefixes by payment network
Each network has one or more starting prefixes that identify it:
| Network | Usual prefix(es) | Typical length |
|---|---|---|
| Visa | 4 | 13, 16, 19 digits |
| Mastercard | 51–55, 2221–2720 (series 2) | 16 digits |
| American Express | 34, 37 | 15 digits |
| Discover | 6011, 65, 644–649 | 16 digits |
| JCB | 3528–3589 | 16–19 digits |
| Diners Club | 300–305, 36, 38 | 14–16 digits |
| UnionPay | 62 | 16–19 digits |
Recognising these prefixes lets you classify a number quickly. For example, if a number starts with 4, it is Visa; if it starts with 5 or with the series 2 (2221–2720), it is Mastercard. You can try it by generating batches per network with our Mastercard card generator or the credit card selection page.
BIN vs IIN: a quick clarification
Although they are used as synonyms, there is a nuance:
- IIN is the formal, current term, defined in ISO/IEC 7812. It covers any issuer identifier, not only banks.
- BIN is the historical, colloquial term, which was born when only banks issued cards.
In practice, when a developer says "the card BIN", they mean the IIN. Both expressions describe the first digits that identify the issuer.
How the BIN is used in software testing
The BIN has a very specific role in the development and testing of payment systems:
- Network validation. Checking that the card belongs to an accepted network before processing.
- Correct format. Adjusting the expected length according to the network (15 for Amex, 16 for most).
- Type detection. Distinguishing credit, debit or prepaid to apply different rules.
- Test segmentation. Generating batches of numbers per network to cover all cases.
- Routing. Directing the transaction to the appropriate processor according to the network.
With the BIN and the Luhn algorithm you can already build a basic validator that recognises the card type and verifies the format. That is exactly what the most widely used card validation libraries do.
A real testing case
A QA team was testing a checkout and found that American Express payments always failed. When reviewing the code, they saw that the frontend validation required 16 digits, but Amex has 15. In addition, the CVV field accepted only 3 digits, when Amex uses 4. The root cause was that the system was not reading the BIN to adapt the rules. After adding prefix detection (34 and 37 → Amex), the form automatically adjusted the length of the number and the CVV, and the tests passed. The BIN was not decoration: it was the key to handling each network according to its format.
Testing several networks at once? Generate batches of numbers per network with the credit card generator and validate each one with the validator.
Conclusion
The BIN (or IIN) is the part of the card number that identifies the issuer, the network and the country. Together with the account number and the Luhn check digit, it forms the complete structure of a card governed by ISO/IEC 7812.
For a developer, reading the BIN is the fastest way to classify a card, validate its format and apply rules per network, all without querying the bank. Just remember its limit: the BIN does not confirm that the card exists, it only describes which range it belongs to.
With a validator that reads the BIN and a generator to create test batches per network, you will be able to cover any payment testing scenario.
Responsible use notice: the numbers generated on this site are fictitious and valid only under the Luhn algorithm. They do not correspond to real cards and must be used only for software testing. Using them for fraud is illegal.
Sources and further reading
- bincheck.io, "BIN / IIN Database" (BIN lookup): bincheck.io
- ISO/IEC 7812, "Identification cards — Identification of issuers" (IIN structure standard)
- Luhn algorithm: what it is and how it works
- Stripe and PayPal test cards: official numbers
Frequently Asked Questions
Does the BIN confirm that a card is real?
No. The BIN identifies the issuer range, but it does not prove that the card exists or is active. An invented number can have a valid BIN.
How many digits does the BIN have?
Traditionally 6, but the industry migrated to 8 digits to expand capacity. Today you can find both.
Are BIN and IIN exactly the same?
In practice, yes. IIN is the more current and formal term; BIN is the historical name that is still used every day.
Can I know the issuing bank from the BIN alone?
You can get an approximation using a BIN database, but the information may be out of date or belong to an aggregator. It is not an infallible source.
BINIINISO 7812issuer
Ready to generate your test numbers?
Use the free generator and get Luhn-valid cards with CVV and expiry in seconds.