# Validation (SBX-VAL)

IBAN (87 countries, with the bank for Turkish IBANs), Turkish national id, tax number and phone number validation.

Version: v1.0

## Authentication

Send your API key on every request, either as a Bearer token or as the `apikey` query parameter:

```
Authorization: Bearer <YOUR_API_KEY>
https://api.servicebox.io/v1/validation/...?apikey=<YOUR_API_KEY>
```

Get a key: sign up at https://servicebox.io/en/signup and create one on the dashboard. An agent can sign up itself with `POST https://api.servicebox.io/v1/accounts` and `{"email": "...", "apis": ["validation"]}`: the owner of the mailbox approves by email and the agent collects a short-lived key by polling the returned `poll_url`.

## Base URL

`https://api.servicebox.io`

## Endpoints

### GET /v1/validation/banks

**List Turkish banks**

The participants of the Turkish central bank's payment systems (EFT/FAST) with their codes; a Turkish IBAN's bank code is `0` followed by the participant code. From TCMB's published list. Free. Not paged: the whole list in one answer.

**Credits:** free (0 credits per call)

No parameters.

**Example**

```bash
curl "https://api.servicebox.io/v1/validation/banks" \
  -H "Authorization: Bearer $SBX_API_KEY"
```

### GET /v1/validation/ibans/lookup

**Check an IBAN**

Validates an IBAN of any of 87 countries (ISO 13616: country, length, mod-97 checksum; for Turkey also the reserved digit) and returns its electronic and print forms. A Turkish IBAN also names its bank from TCMB's payment-systems participant list. Spaces and dashes are ignored. Nothing is stored or cached.

**Credits:** 1 per call

**Parameters**

| Name | In | Type | Required | Description |
|---|---|---|---|---|
| `iban` | query | string | yes | The IBAN, with or without spaces. |

**Example**

```bash
curl "https://api.servicebox.io/v1/validation/ibans/lookup?iban=<iban>" \
  -H "Authorization: Bearer $SBX_API_KEY"
```

### GET /v1/validation/national-ids/lookup

**Check a Turkish national id (TCKN)**

Checks that an 11-digit T.C. kimlik numarası (or a foreigner's YKN, starting 99) is well formed and its two check digits hold. Only the number's form is checked — nothing is looked up, and a valid number is not proof that the person exists. Nothing is stored or cached; the number does appear in the request URL, so do not log URLs you would not log the number in.

**Credits:** 1 per call

**Parameters**

| Name | In | Type | Required | Description |
|---|---|---|---|---|
| `id` | query | string | yes | The 11-digit number. |

**Example**

```bash
curl "https://api.servicebox.io/v1/validation/national-ids/lookup?id=<id>" \
  -H "Authorization: Bearer $SBX_API_KEY"
```

### GET /v1/validation/phone-numbers/lookup

**Check a Turkish phone number**

Parses a Turkish phone number in any common spelling (`0532 123 45 67`, `+90 532…`, `0090…`) and returns its E.164 and national forms and its kind from the national numbering plan: mobile (5xx), landline (2xx–4xx), toll-free (800), shared-cost (850), single-number (444) or premium (900). Nothing is stored or cached.

**Credits:** 1 per call

**Parameters**

| Name | In | Type | Required | Description |
|---|---|---|---|---|
| `number` | query | string | yes | The phone number. |

**Example**

```bash
curl "https://api.servicebox.io/v1/validation/phone-numbers/lookup?number=<number>" \
  -H "Authorization: Bearer $SBX_API_KEY"
```

### GET /v1/validation/tax-ids/lookup

**Check a Turkish tax number (VKN)**

Checks that a 10-digit vergi kimlik numarası is well formed and its check digit holds. Only the number's form is checked — nothing is looked up. Nothing is stored or cached.

**Credits:** 1 per call

**Parameters**

| Name | In | Type | Required | Description |
|---|---|---|---|---|
| `id` | query | string | yes | The 10-digit number. |

**Example**

```bash
curl "https://api.servicebox.io/v1/validation/tax-ids/lookup?id=<id>" \
  -H "Authorization: Bearer $SBX_API_KEY"
```

## Errors

Errors are RFC 9457 `application/problem+json` bodies with a machine-readable `type`.

- `401` — the key is missing, unknown, expired or revoked.
- `402` — not enough credits: the body carries `credits_required` and `upgrade_url` (https://servicebox.io/en/pricing).
- `403` — the key is not allowed to call this API.
- `429` — rate limited: wait `retry_after` seconds (also sent as the `Retry-After` header); `upgrade_url` points to a larger plan.

## Links

- OpenAPI document: https://api.servicebox.io/v1/validation/openapi.json
- Pricing: https://servicebox.io/en/pricing?api=SBX-VAL
- API page: https://servicebox.io/en/apis/validation
