Simple Lookup
CPF lookup API.
Name and date of birth, instantly.
Send only the CPF (Brazil's individual taxpayer ID) and get name, gender and date of birth in JSON. Typical time ~150 ms. No e-CNPJ (Brazilian company ID), no digital certificate, no sales meeting. 50 free credits per month to try it out.
No credit card. Your key appears in the dashboard right away.
What you get
The CPF goes in. The person comes out.
Eleven digits become a completed record, before the person finishes typing.
The holder's name
Full name, with accents and capitalization already normalized. It goes into your database ready to use, with no cleanup in between.
The date of birth
Formatted and also split into day, month and year. Applying an age-of-majority rule becomes a number comparison, not string parsing.
The gender
M or F, as recorded in the registry. Enough to personalize communication and to reinforce a matching rule at signup.
All of that in ~150 ms
Fast enough to sit inside the form, the checkout and the login, without the user noticing a lookup happened.
Where to use it
Built for the critical path.
Responds fast enough to sit inside signup, checkout and login without the user noticing.
Fill in the signup form
The person types the CPF and the rest of the form completes itself. Fewer fields to fill in means less abandonment, and the data goes into your database already standardized.
Fraud prevention at signup and checkout
Compare the name and date the person entered with what the API returns. A mismatch becomes a manual review instead of a chargeback.
Age verification
The year field comes separate precisely for this. Calculate the age without parsing a string and apply your age-bracket rule.
Database cleanup and enrichment
An old database with misspelled names or missing dates of birth. Run the CPFs through the API and normalize the whole file.
Checks in customer support
The agent confirms the holder's name and date of birth during the call, without depending on what the customer remembers on the spot.
AI agents via MCP
The official MCP server exposes the lookup as a tool. Claude, Cursor and Windsurf can look up a CPF without you writing an HTTP client.
Credits and errors
A CPF that is not found does not use any credits.
You pay for results, not for attempts. A messy database does not turn into an inflated invoice.
How credits are used
- A lookup that finds the CPF uses 1 credit.
- A valid CPF with no record returns 404 and uses nothing.
- A CPF with an incorrect check digit is never even looked up.
- GET /quota shows your balance and never uses a credit.
- There is no per-second request limit. The control is the monthly credit pool.
Response codes
| 200 | CPF found. Uses 1 credit. |
| 400 | The CPF does not have 11 digits after stripping non-numeric characters. |
| 401 | API key missing or invalid. |
| 403 | Monthly credits used up, on a plan without overage. |
| 404 | Valid CPF, but no record. Does not use a credit. |
| 422 | Incorrect check digit, including repeated sequences. |
How it works
Three steps, none of them bureaucratic.
From a new account to your first JSON in production, with no sales intermediary in the way.
01
Create an account and copy your key
Self-serve signup at app.cpfhub.io. No e-CNPJ (Brazilian company ID), no digital certificate, no signed contract. Your API key appears in the dashboard on the same screen.
02
Call GET /cpf/{cpf}
One HTTP request with the x-api-key header. The CPF goes in the URL, with or without formatting. There is no body, no OAuth and no expiring token.
03
Get the JSON and move on
Name, gender and date of birth come back in ~150 ms (typical time), already normalized. Your form fills itself in, or your matching rule decides on the spot.
Response
What the API returns
Eight fields, always the same, always in the same format. No field that shows up only sometimes.
| Field | Type | Description |
|---|---|---|
| cpf | string | CPF with 11 digits, unformatted, always in the same format. |
| name | string | Full name of the holder, with accents and capitalization normalized. |
| nameUpper | string | The same name in uppercase, ready for comparison without normalizing again. |
| gender | string | M or F. |
| birthDate | string | Date of birth in DD/MM/YYYY. |
| day | number | Day of birth, already split out. |
| month | number | Month of birth, already split out. |
| year | number | Year of birth, already split out. Useful for calculating age without parsing a string. |
This route does not return registration status, year of death, score, address, phone number or email. If you need registration status, year of death and proof, the way to go is the Real-Time Lookup.
Plans
Start on the Free plan. Move up when you need to.
The same balance applies to the Simple Lookup (1 credit) and the Real-Time Lookup (1.5 credits). You switch routes without switching plans. All prices are in Brazilian reais (BRL).
Free
R$ 0
50 credits per month, no card required
SLA 95%
Pro
From R$ 19
100 to 10,000 credits/month, overage from R$ 0.19 to R$ 0.10
SLA 99%
Enterprise
Custom pricing
Over 10,000 credits per month
SLA 99.9%
In production
Already running in the signup flow of teams that scale.
6,000+
companies served
30M+
CPFs verified
50
free lookups per month, no card required
Integrate in any language
REST API with an OpenAPI spec and ready-made examples, simple enough for your AI agent to integrate on its own.
curl -X GET \
'https://api.cpfhub.io/cpf/12345678909' \
-H 'x-api-key: YOUR_API_KEY'{
"success": true,
"data": {
"cpf": "12345678909",
"name": "Fulano de Tal",
"nameUpper": "FULANO DE TAL",
"gender": "M",
"birthDate": "15/06/1990",
"day": 15,
"month": 6,
"year": 1990
}
}50 free credits per month, no credit card required.
FAQ
Frequently asked questions
What does the CPF lookup API return?
Full name, gender (M/F) and date of birth. Fields: cpf (11 digits, unformatted), name, nameUpper, gender, birthDate, day, month and year. It does not return a score, address, phone number or email. For registration status, year of death and proof, use the Real-Time Lookup at /en/cpf-lookup-federal-revenue.
Is there a single GET and batch?
Yes. The Simple Lookup is GET /cpf/{cpf} and batch is POST /cpf/bulk (up to 10,000 CPFs, an asynchronous job polled with GET /cpf/bulk/{jobId}). There is also GET /quota for balance and plan, which does not use credits.
Do I need an e-CNPJ or a digital certificate?
No. The integration is self-serve: create the account, copy the API key and send it in the x-api-key header. No e-CNPJ and no biometrics.
How much does the CPF lookup API cost?
Free: 50 credits/month, no card, 95% SLA. Pro: from R$19/month with 100 credits (up to 10,000), overage from R$0.19 to R$0.10 per credit depending on volume, 99% SLA. Enterprise: custom pricing, 99.9% SLA. See /en/pricing.
What is the difference from the Real-Time Lookup?
The Simple Lookup needs only the CPF and has a typical time of ~150 ms (not an SLA) from our database, with name, gender and date of birth, for 1 credit. The Real-Time Lookup also needs the holder's date of birth, queries Receita Federal (Brazil's federal tax authority) in real time and returns registration status, year of death (deathYear, integer or null), control code and HTML proof, in about 1 second (typical time, not an SLA), for 1.5 credits per successful lookup. Both use the same key and the same balance.
Is there a limit on requests per second?
No. There is no per-second throttling and no rate limit header. The only limit is the plan's credit balance. On Free (50 credits/month), the API stops when the credits run out. Paid plans with overage enabled keep responding and the overage is billed in the next cycle.
Does a CPF that is not found use a credit?
No. Only a lookup that returns data debits a credit. A valid CPF with no record returns 404 without charge, and a CPF with a wrong check digit returns 422 without even being looked up.
Can I use it with AI agents?
Yes. The official MCP server is at https://api.cpfhub.io/mcp and exposes the lookup as a tool for Claude, Cursor and Windsurf, with the same x-api-key. You do not need to write an HTTP client.
Is the API LGPD compliant?
Yes. We process personal data with a legal basis and privacy practices. LGPD is Brazil's data protection law. DPO: dpo@cpfhub.io. Policy at /en/privacy.
Still have questions?
Get in touchIntegrate the CPF API
in minutes.
50 free credits a month. No e-CNPJ, no digital certificate, no card.
Instant access to your API key and documentation.