POSTFetch PAN Details
Fetch the PAN holder's registered full name and category from the PAN number alone.
Fetch PAN is the lightest PAN lookup: pass only the PAN number and get back the registered full name, the holder category (person / company / firm …) and the PAN status. Unlike PAN Lite and PAN Advanced — which require the PAN number, holder name and date of birth to compute match flags — this endpoint needs no name or DOB, so use it when you have to discover the holder's name rather than verify one you already hold.
Request
Body parameters
| Field | Type | Required | Description |
|---|---|---|---|
initiator_id | string | required | Registered mobile number of the API user (see Platform Credentials).e.g. 9962981729 |
client_ref_id | string | optional | Unique reference ID per API call, generated by your system (max 20 characters).e.g. 2026010100123456789 |
pan_numberPAN Number | string | required | 10-character alphanumeric PAN identifier (5 letters, 4 digits, 1 letter).e.g. GGTPB7880Q |
source | string | optional | Origin of the request. Use 'API' for server-to-server calls.e.g. API |
initiator_idstringRequiredRegistered mobile number of the API user (see Platform Credentials).
example: 9962981729
client_ref_idstringoptionalUnique reference ID per API call, generated by your system (max 20 characters).
example: 2026010100123456789
pan_numberstringRequired· PAN Number10-character alphanumeric PAN identifier (5 letters, 4 digits, 1 letter).
example: GGTPB7880Q
sourcestringoptionalOrigin of the request. Use 'API' for server-to-server calls.
example: API
These headers authenticate and sign every request. See How Auth Works for details.
| Field | Type | Required | Description |
|---|---|---|---|
developer_key | string | required | Static API key issued to your account after KYC. |
secret-key | string | required | Dynamic per-request signature: base64(HMAC-SHA256(timestamp, base64(access_key))). |
secret-key-timestamp | string | required | Current time in milliseconds since UNIX epoch, used to compute secret-key. Must match server time. |
content-type | string | required | application/jsone.g. application/json |
developer_keystringRequiredStatic API key issued to your account after KYC.
secret-keystringRequiredDynamic per-request signature: base64(HMAC-SHA256(timestamp, base64(access_key))).
secret-key-timestampstringRequiredCurrent time in milliseconds since UNIX epoch, used to compute secret-key. Must match server time.
content-typestringRequiredapplication/json
example: application/json
Responses
statusnumberPrimary success indicator (0 = success).
messagestringHuman-readable response / error message.
response_status_idnumberGranular status id; see the shared error-codes table.
response_type_idnumberA unique id for every possible response shape (success or error) — useful for client logic branching and analytics.
dataobjectAPI-specific response payload.
upstream_rrnstringReference number of the lookup at the upstream source.
pan_nostringThe PAN number submitted in the request.
fullnamestringFull name registered against the PAN.
categorystringPAN holder category, e.g. 'person', 'company', 'firm', 'trust', 'huf'.
statusstringOutcome of the PAN lookup, e.g. 'success'.