Age Verification
Age verification by CPF
for ECA Digital.
ECA Digital is Brazil's digital child protection law. Look up a CPF (Brazil's individual taxpayer ID) and get the holder's date of birth in JSON. Your system calculates the age and applies the cutoff your rule needs: 18+, 16+ or 21+. No selfie, no document upload. 50 free credits per month to try it out.
CPFHub.io provides the data. Compliance with ECA Digital remains the platform's responsibility.
What you get
The data the law asks for, under your rule.
ECA Digital requires reliable age assurance, and self-declaration alone does not solve it. The date of birth tied to a CPF is the starting point.
The date of birth
In DD/MM/YYYY and also split into day, month and year. Calculating age becomes a comparison of numbers.
The holder's name
Useful to check that the CPF entered really belongs to the person signing up, by comparing it with the name they typed.
The cutoff is yours
The API does not return a ready-made age bracket. You define 18+, 16+ or 21+ and change the rule without depending on us.
No selfie, no document
It is a registry lookup. There is no camera, no OCR and no file upload, so your signup flow does not gain an extra step.
How it works
Three steps, one age calculation.
The lookup returns the date of birth. The age is calculated in your backend, with the rule your product needs.
01
Look up the CPF provided
A GET /cpf/{cpf} request with the x-api-key header, at signup, at checkout or on first access. The CPF goes in the URL, with or without formatting.
02
Read the date of birth
The JSON includes birthDate in DD/MM/YYYY and also day, month and year as separate fields. No string parsing to get the year.
03
Apply your rule
Your backend calculates the age and decides: allow access, ask for parental consent or trigger another age assurance method. The decision belongs to the platform.
const res = await fetch(`https://api.cpfhub.io/cpf/${cpf}`, {
headers: { 'x-api-key': process.env.CPFHUB_API_KEY },
})
if (res.status === 404) {
// CPF with no record: use another age assurance method
}
const { data } = await res.json()
const { day, month, year } = data
const hoje = new Date()
let idade = hoje.getFullYear() - year
if (hoje.getMonth() + 1 < month || (hoje.getMonth() + 1 === month && hoje.getDate() < day)) {
idade -= 1
}
const maiorDeIdade = idade >= 18Where to use it
Where age changes access.
From signup to checkout, the lookup fits into the flow you already have, with no extra step for the user.
Limits
What the lookup covers, and what it does not.
A CPF that is not found does not use any credits. For people who have no CPF or do not appear in the database, the alternative flow is up to your platform.
| Situation | What happens |
|---|---|
| CPF found | HTTP 200 with birthDate. Uses 1 credit. |
| Valid CPF with no record | HTTP 404. No date of birth and no cost. Use another age assurance method. |
| CPF with an incorrect format or check digit | HTTP 400 or 422. No cost. Ask the person to correct it. |
| User with no CPF | Outside the lookup. The platform defines another age assurance method. |
| Credits used up on the Free plan | HTTP 403. The API stops until the next cycle or until you move to another plan. |
CPFHub.io does not do biometric verification or read documents. It does not block anyone either: it returns the date of birth and the platform decides.
Plans
1 credit per verification. Start on the Free plan.
Each CPF found uses 1 credit from the plan balance. On the Free plan, the API stops when the credits run out. Overage exists only on paid plans. All prices are in Brazilian reais (BRL).
Free
R$ 0
50 credits per month, no card required
SLA 95%
Pro
From R$ 19
100 to 10,000 credits/month, overage from R$ 0.19 to R$ 0.10
SLA 99%
Enterprise
Custom pricing
Over 10,000 credits per month
SLA 99.9%
Integrate in any language
REST API with an OpenAPI spec and ready-made examples, simple enough for your AI agent to integrate on its own.
curl -X GET \
'https://api.cpfhub.io/cpf/12345678909' \
-H 'x-api-key: YOUR_API_KEY'{
"success": true,
"data": {
"cpf": "12345678909",
"name": "Fulano de Tal",
"nameUpper": "FULANO DE TAL",
"gender": "M",
"birthDate": "15/06/1990",
"day": 15,
"month": 6,
"year": 1990
}
}50 free credits per month, no credit card required.
FAQ
Frequently asked questions
Can I verify a user's age with just the CPF?
Yes, for users who give a CPF that is registered. The Simple Lookup (GET /cpf/{cpf}) returns name, gender and date of birth (birthDate in DD/MM/AAAA format, plus day, month and year). Your system calculates the age and applies the cutoff the rule requires. CPFHub.io does not return a ready-made age and does not block the user.
Does the API calculate the age or return an age band?
No. The response carries the date of birth and you do the math in your backend, comparing with today's date. The year field comes separate to make it easier. This way the cutoff (18+, 16+, 21+) and the business rule stay under your control.
Is self-declared age still enough under the ECA Digital?
The ECA Digital (Law 15.211/2025) asks for reliable age assurance mechanisms, and simple self-declaration is not the way. Looking up the CPF and checking the date of birth provides registration data for that assurance. The choice of method and final compliance are the platform's responsibility.
Does a CPF lookup replace ECA Digital compliance?
No. The law requires age assurance, and CPFHub.io delivers the date of birth for your system to decide. Policies, flows, parental consent and the other obligations remain the platform's. If in doubt, consult your legal team and the guidance of ANPD, Brazil's data protection authority.
What happens if the CPF is not found?
The API responds 404 and does not use a credit. Without a record there is no date of birth, so your system needs an alternative path for that user, such as another assurance method or manual review. A CPF with an incorrect format or check digit returns 400 or 422, also at no cost.
Does it work for people without a CPF?
Not directly. The lookup depends on the user giving a CPF. People without a CPF, such as some foreigners, need another assurance method, defined by the platform.
Does CPFHub.io use selfie, biometrics or document reading?
No. The Simple Lookup is a registration lookup: no camera, selfie, OCR or document upload. It is not a biometric identity verification.
How much does it cost to verify age?
A lookup with a found CPF costs 1 credit. The Free plan includes 50 credits a month, no card, and the API stops when the credits run out. Pro starts at R$ 19 per month with 100 credits and has tiers of up to 10,000, with overage from R$ 0.19 to R$ 0.10 per lookup. A CPF that is not found is not charged.
Can I check the age of a user base I already have?
Yes. The Batch Lookup (POST /cpf/bulk) accepts up to 10,000 CPFs per asynchronous job and returns the same fields. Only the CPFs that are found use credits.
When does ECA Digital enforcement start?
The law has been in force since March 17, 2026 and was regulated by Decree 12.880/2026. Under the implementation schedule, enforcement with fines starts in January 2027. Confirm deadlines and requirements with ANPD and your legal team.
Still have questions?
Get in touchVerify age
at signup.
50 free credits a month, no card. The key shows up in the dashboard right away.
Instant access to your API key and the documentation.