What we store about your API requests
Last updated: September 20, 2026
We store a record of each API request. This article lists the data that we keep.
Data that we store
- The API key that sent the request.
- The BIN that you sent.
- The HTTP status and the response time.
- The IP address of the client.
- The request headers, without the
Authorizationheader and other sensitive headers. - The request body, limited to 1 KB.
- The response body, limited to 4 KB.
Data that we do not store
- Your full API key. We store a secure hash only.
- Full card numbers. The API rejects them before it stores anything.
Retention
We keep the request records for as long as your account is open. We can change this policy at any time. We announce changes on the changelog at https://binlookupapi.com/changelog.
Where you can see the records
The Usage page shows the request history of your organisation. See Read the Usage page.