Skip to main content
For test environments. The API has no authentication. It listens on 127.0.0.1 by default. Don’t expose it on a public network, except in public mode (below).

Public demo

A public demo runs at https://api.iso8583sim.com, and the REST API reference playground calls it by default. Try it without installing anything:
It runs in public mode, so LLM features are off and requests are rate limited. Only send test card numbers. Switch the playground’s server to http://127.0.0.1:8000 to use your own instance.

Running

The server starts on http://127.0.0.1:8000. Options: --host, --port and --reload (restart on code changes). You can also run it with uvicorn directly:
Interactive API docs are served at /docs and the OpenAPI schema at /openapi.json.

Endpoints

Common request fields:
  • message: raw message string (MTI, hex bitmap, field data)
  • version: "1987" (default), "1993" or "2003"
  • network: VISA, MASTERCARD, AMEX, DISCOVER, JCB or UNIONPAY. Detected from the PAN when omitted.

Examples

Generate a test message and explain it:
Build a message. Field numbers are JSON object keys, so they are strings:
Check a message against every network (an empty against list means all):

Errors

/validate is the exception: a message that fails to parse is returned as {"valid": false, "errors": ["Parse error: ..."]} with status 200.

Docker

The repository includes a Dockerfile that runs the API with the security extra installed:
Inside the container the server listens on all interfaces so the port mapping works. -p 127.0.0.1:8000:8000 keeps it reachable from your machine only. To use LLM features, pass the provider’s API key:
The image installs the anthropic extra only. Build with --build-arg EXTRAS=web,security,llm for all providers.

Public mode

Set ISO8583SIM_PUBLIC=1 to run the API as a public demo:
In public mode:
  • LLM features return 403, even when an API key is set, so nobody can spend your key.
  • Browsers on any site can call the API (CORS allows every origin). There are no cookies or credentials, so this allows nothing that curl can’t already do.
Every server rejects oversized requests: messages over 32,768 characters, field values over 1,998 characters and descriptions over 2,000 characters. Put rate limiting in front of a public server, for example at a reverse proxy.