Look up a CPF with Next.js
Look up a CPF (Brazil's individual taxpayer ID) with Next.js on the server, using a dynamic App Router Route Handler. The API key never reaches the browser.
Using Cursor, Lovable, v0 or another AI? Copy the Simple Lookup prompt and paste it into your assistant.
Before you start
- Create a free account at app.cpfhub.io: the Free plan includes 50 credits and does not ask for a card.
- Copy your API key from app.cpfhub.io/api-keys.
- Store the key in an environment variable, never in your code:
export CPFHUB_API_KEY="your_api_key"Example
// app/api/cpf/[cpf]/route.ts
export async function GET(
_req: Request,
{ params }: { params: Promise<{ cpf: string }> },
) {
const cpf = (await params).cpf.replace(/\D/g, '')
if (cpf.length !== 11) {
return Response.json({ error: 'CPF must have 11 digits' }, { status: 400 })
}
const res = await fetch(`https://api.cpfhub.io/cpf/${cpf}`, {
headers: { 'x-api-key': process.env.CPFHUB_API_KEY! },
cache: 'no-store',
signal: AbortSignal.timeout(10_000),
})
const body = await res.json()
if (res.ok) return Response.json(body.data)
if (res.status === 404) return Response.json({ error: 'CPF not found' }, { status: 404 })
if (res.status === 422) return Response.json({ error: 'Invalid CPF' }, { status: 422 })
// 401, 403, 429 and 5xx: key, credit or limit problem. Log it and do not expose it to the client.
console.error('CPFHub.io', res.status, body.error)
return Response.json({ error: 'CPF lookup unavailable at the moment' }, { status: 503 })
}Put CPFHUB_API_KEY in .env.local (without the NEXT_PUBLIC_ prefix, so it does not go to the browser). On the front end, call /api/cpf/12345678909.
Response
Found CPF (200, uses 1 credit):
{
"success": true,
"data": {
"cpf": "12345678909",
"name": "Fulano de Tal",
"nameUpper": "FULANO DE TAL",
"gender": "M",
"birthDate": "15/06/1990",
"day": 15,
"month": 6,
"year": 1990
}
}CPF not found (404, does not use a credit):
{
"success": false,
"data": null,
"error": { "message": "CPF não encontrado na base de dados" }
}The CPF 12345678909 is fictional, used only in the examples. gender can be null. The error.message text comes from the API in Portuguese ("CPF not found in the database").
Errors
| Status | What it means | What to do |
|---|---|---|
404 | CPF is not in the database | Treat it as "not found". Does not use a credit. |
400 / 422 | CPF does not have 11 digits or has an invalid check digit | Fix the input. Does not use a credit. |
401 | Missing or invalid API key | Check the CPFHUB_API_KEY variable. |
403 | Credits used up or inactive account | Check your balance with GET /quota or top up in the dashboard. |
429 | Per-minute request limit | Wait the number of seconds in the Retry-After header and try again. |
5xx | Temporary failure | Try again after a few seconds. |
The error field can be text ("error": "...") or an object ("error": { "message": "..." }), depending on the status. The examples above handle both formats. Full list in Error Codes.