What the NHTSA VIN Decoder API does
The NHTSA VIN Decoder API is a free tool run by the National Highway Traffic Safety Administration that reads the 17-character vehicle identification number on any car and returns detailed information about that vehicle's make, model, year, engine, transmission, and safety features. You send the VIN to NHTSA's servers, and the API returns structured data about what that vehicle was built with — not its history, ownership, or condition, but its original factory specifications.
The API is open to the public and requires no registration, login, or API key. It is designed for developers building applications that need vehicle data, but it can also be used directly by anyone with basic technical knowledge to look up a single vehicle. The data comes from NHTSA's own records of vehicles registered and tested in the United States.
This is different from a VIN history report (which shows accidents, title status, and ownership changes) or a dealer lookup (which shows inventory). The NHTSA decoder tells you what was in the vehicle when it left the factory.
Key Takeaways
- The NHTSA VIN Decoder API is free and requires no registration, but it returns only factory specifications, not vehicle history or current condition.
- You can query the API directly through a web browser by visiting a specific URL with the VIN, or use it in code if you are building an process.
- The API returns data about engine type, transmission, safety features, recalls, and other original equipment — useful for verifying what a vehicle should have.
- The data reflects what NHTSA has on file, which may not match every aftermarket modification or regional variation a specific vehicle received.
How to query the API directly in a browser
The simplest way to use the NHTSA VIN Decoder API without writing code is to construct a URL and paste it into your web browser. The URL structure is: https://vpic.nhtsa.dot.gov/api/vehicles/DecodeVin/[VIN]?format=json
Replace [VIN] with the actual 17-character VIN. For example, if the VIN is 1HGCV41JXMN109186, the full URL would be https://vpic.nhtsa.dot.gov/api/vehicles/DecodeVin/1HGCV41JXMN109186?format=json. When you visit this URL, the browser will display the response as a block of text in JSON format (a structured data format that lists fields and values).
The response includes fields like Make, Model, ModelYear, BodyClass, Engine Displacement, Transmission Type, and many others. Each field shows what NHTSA has recorded for that vehicle's specifications. If a field is blank or shows "Not Applicable," that information is not available in NHTSA's database for that VIN.
What information the API returns
The NHTSA VIN Decoder returns approximately 150 data fields, though not all are populated for every vehicle. Common fields include the vehicle's make and model, model year, body style (sedan, SUV, truck, etc.), engine displacement and type, transmission type, number of doors, gross vehicle weight rating, and safety features like airbag configuration and electronic stability control.
The API also returns information about recalls associated with that VIN, listed separately. If NHTSA has issued recalls for that vehicle, they appear as a distinct section with recall numbers, descriptions, and dates. This is one of the most useful parts of the API for consumers — you can see at a glance whether the vehicle you are considering has known safety issues.
The data does not include price, ownership history, accident history, title status, mileage, or current condition. It also does not tell you whether recalls have been completed on a specific vehicle — only that they exist for that model and year.
Using the API in code or applications
If you are a developer building a website, mobile app, or other software that needs to decode VINs at scale, you can integrate the NHTSA API directly into your code. The API accepts requests in both JSON and XML format and returns data in the format you specify. There is no rate limit published by NHTSA, but the agency asks that you use the API responsibly and not make excessive requests in a short time.
Most programming languages have libraries or frameworks that make HTTP requests straightforward. In Python, for example, you would use the requests library to send a GET request to the NHTSA endpoint and parse the JSON response. In JavaScript, you would use fetch() or a similar method. Documentation and examples are available on the NHTSA VPIC (Vehicle Product Information Catalog) website.
The API does not require authentication, so you do not need an API key or account. This makes it straightforward to get your free guide, but it also means NHTSA cannot track individual users or enforce per-user rate limits. If you are building a public-facing tool that will make thousands of requests, consider caching results locally so you do not query NHTSA for the same VIN repeatedly.
Limitations and what the API does not tell you
The NHTSA VIN Decoder returns only what NHTSA has in its database, which is based on manufacturer submissions and testing data. If a vehicle was modified after it left the factory — a different engine installed, a transmission swapped, or safety equipment removed — the API will still show the original specifications. It will not reflect those changes.
The API also does not account for regional variations or market-specific equipment. A vehicle sold in one country may have different features than the same model sold elsewhere, but the VIN decoder may not distinguish between them. Additionally, if a manufacturer submitted incorrect data to NHTSA, the API will return that incorrect data.
For used car purchases, the NHTSA VIN Decoder is useful for confirming what the vehicle should have (engine type, transmission, safety features) and checking for recalls, but it should not be your only source of information. A pre-purchase inspection by a mechanic, a vehicle history report from a service like Carfax or AutoCheck, and a test drive are all important steps that the API cannot replace.
Comparing the NHTSA API to other VIN lookup tools
Several commercial services offer VIN decoding, including Carfax, AutoCheck, and various dealer platforms. The key difference is that NHTSA's tool is free and public, while commercial services charge a fee and often include additional data like ownership history and accident reports. The NHTSA API is also more technical — it requires you to construct a URL or write code, whereas commercial services usually provide a straightforward web form.
If you only need factory specifications and recall information, the NHTSA API is sufficient and costs nothing. If you need a complete vehicle history (previous owners, accident history, title status, mileage records), you will need a commercial service. Many people use both: the NHTSA API for a quick factory check and recalls, then a paid service if they want more detail.
Some dealerships and used car websites have built their own tools on top of the NHTSA API, so you may already be using it indirectly when you look up a vehicle on their site. If you see a "decode VIN" button on a dealer's website, there is a good chance it is powered by NHTSA's data.
Frequently Asked Questions
Do I need an API key to use the NHTSA VIN Decoder?
No. The NHTSA VIN Decoder is completely open and requires no registration, login, or API key. You can query it directly from a web browser or integrate it into code without any authentication step.
Will the API tell me if a specific car has had recalls fixed?
No. The API shows which recalls exist for that vehicle's make, model, and year, but it does not track whether those recalls have been completed on the specific vehicle you are looking at. To learn about recalls have been done, you would need to contact the dealer or previous owner, or check the vehicle's service records.
Can I use the NHTSA API to look up vehicles outside the United States?
The API is designed for U.S. vehicles and uses VINs registered with NHTSA. Vehicles from other countries may have different identification systems and may not be in the database. If you try to decode a non-U.S. VIN, the API may return no data or incomplete data.
What should I do if the API returns blank fields or "Not Applicable"?
Blank fields usually mean NHTSA does not have that information on file for that vehicle. This is common for older vehicles or for fields that are not applicable to that vehicle type. It does not mean the data is wrong — it means the data was not submitted or is not relevant.
Is the NHTSA VIN Decoder the same as a vehicle history report?
No. A vehicle history report (from Carfax, AutoCheck, or similar) shows ownership, accidents, title status, and mileage. The NHTSA decoder shows only factory specifications and recalls. They serve different purposes and are often used together.