What the NHTSA VIN Decoder API does
The NHTSA VIN Decoder API is a free tool run by the National Highway Traffic Safety Administration that reads a vehicle identification number and returns detailed information about that vehicle's make, model, year, engine type, safety features, and recall history. You send the API a 17-character VIN, and it sends back structured data about what that VIN represents.
The API is open to the public — you do not need permission or a paid account to use it. It is commonly used by vehicle dealers, repair shops, insurance companies, and individual car buyers who want to verify vehicle details or check for open recalls before purchase.
This is an informational guide to how the API works and what data it returns. It does not cover how to build software that uses the API, only what the API does and how to make a basic request to it.
Key Takeaways
- The NHTSA VIN Decoder API accepts a 17-character VIN and returns vehicle specifications, including make, model, year, engine details, and known recalls.
- The API is free and requires no authentication key or account — you can make requests directly from a web browser or through any programming language.
- Responses include both basic vehicle data and safety-related information like airbag types, crash test ratings, and open recall notices.
- The API returns data in JSON format, which is readable by most software tools and can be parsed into spreadsheets or databases.
- Rate limits exist to prevent overuse — NHTSA allows a reasonable number of requests per minute from a single source, but extremely high-volume queries may be throttled.
How to make a basic API request
The simplest way to test the API is to type a request directly into your web browser's address bar. The basic URL structure is:
https://vpic.nhtsa.dot.gov/api/vehicles/DecodeVin/[VIN]?format=json
Replace [VIN] with the actual 17-character VIN you want to decode. For example, if you were decoding a VIN that starts with 1HGCV41JXMN109186, the full URL would be:
https://vpic.nhtsa.dot.gov/api/vehicles/DecodeVin/1HGCV41JXMN109186?format=json
When you visit this URL, your browser will display the response as plain text. The data comes back in JSON format, which looks like a series of labeled fields and values. Each field name is in quotes, followed by a colon, then the value.
If you do not include the ?format=json parameter at the end, the API will return XML format instead. JSON is easier to read and more widely supported by modern tools, so it is the better choice for most uses.
What data the API returns
The response includes dozens of fields, but the most commonly used ones are:
- Make — the manufacturer (Honda, Ford, Toyota, etc.)
- Model — the specific model name (Civic, F-150, Camry, etc.)
- Model Year — the year the vehicle was built
- Body Class — the vehicle type (sedan, truck, SUV, etc.)
- Engine Displacement — engine size in liters
- Engine Cylinders — number of cylinders
- Fuel Type — gasoline, diesel, electric, hybrid, etc.
- Transmission Type — automatic, manual, CVT, etc.
- Recalls — a list of any open safety recalls for that VIN
The API also returns safety-related fields such as airbag information, crash test results, and whether the vehicle has certain safety systems like electronic stability control or backup cameras. Not all fields are populated for every vehicle — older vehicles or those with incomplete records may have blank values for some fields.
The response always includes a Results section that contains the vehicle data, and a Count field that tells you how many results were returned. A count of 1 means the VIN was found and decoded successfully. A count of 0 means the VIN was not recognized.
Understanding VIN structure and validation
A VIN must be exactly 17 characters long and contain only letters and numbers (no spaces or special characters). The API will reject requests with VINs that are too short, too long, or contain invalid characters.
The VIN structure is standardized internationally. The first three characters identify the manufacturer and country of origin. Characters 4 through 8 describe the vehicle type, model, and body style. Character 9 is a check digit used to validate the entire VIN. Characters 10 through 17 are the serial number unique to that specific vehicle.
If you receive a response with a count of 0, the VIN may be invalid, or it may be a VIN that NHTSA's database does not yet have records for. Very new vehicles or vehicles from manufacturers with limited U.S. sales may not appear in the database when ready.
Common reasons the API returns no results
If you submit a VIN and get back a count of 0, the most common causes are a typo in the VIN itself, or a VIN from a vehicle that is not in NHTSA's database. The database covers vehicles sold in the United States, so imported vehicles or vehicles from very small manufacturers may not be present.
The API is case-insensitive, so uppercase and lowercase letters are treated the same way. However, the VIN itself must be exactly 17 characters — if you accidentally include a space or copy a VIN with a space in the middle, the request will fail.
If you are certain the VIN is correct and the vehicle should be in the database, the vehicle record may straightforward not have been added yet. NHTSA updates its database regularly, but there can be a lag between when a vehicle is sold and when it appears in the system.
Rate limits and responsible use
NHTSA does not publish exact rate limits for the VIN Decoder API, but the service is designed for reasonable public use. Making a few dozen requests per minute from a single IP address should not cause problems. However, if you are building an process that makes thousands of requests per hour, you may encounter throttling or temporary blocks.
If you are planning to decode a large batch of VINs — for example, an entire inventory of used cars — space out your requests over time rather than sending them all at once. A delay of even a few hundred milliseconds between requests will keep you well within acceptable limits.
If your process is blocked due to excessive requests, the block is usually temporary and will lift after a period of inactivity. Contact NHTSA directly if you have a legitimate high-volume use case and need to discuss rate limits.
Recall information and safety data
One of the most valuable parts of the API response is the recall data. The API returns a list of any open recalls associated with that specific VIN, including the recall number, the component affected, and a brief description of the issue.
This recall information comes from NHTSA's official recall database and is updated regularly. If you are buying a used vehicle, checking the VIN through this API is a straightforward way to see whether there are any unresolved safety recalls you should be aware of.
The API also returns information about safety features the vehicle should have, such as airbag types and electronic stability control. This data is based on the vehicle's model year and specifications, not on what is actually installed in that specific car, so it represents what the manufacturer was supposed to include rather than a may provide of what is present.
Frequently Asked Questions
Do I need an API key to use the NHTSA VIN Decoder?
No. The API is completely open and requires no authentication, API key, or account. You can make requests directly from a web browser or from any programming language without signing up for anything.
What format does the API return data in?
By default, the API returns JSON format, which is human-readable and works with most programming languages and tools. You can also request XML format by changing the URL parameter, but JSON is recommended for most uses.
Can I use the API to check for recalls before buying a used car?
Yes. The API returns any open recalls associated with that VIN. However, recall information alone does not tell you whether the recall work has been performed on that specific vehicle — you should always ask the seller or dealer directly and request documentation of any recall repairs.
What happens if the VIN is not in NHTSA's database?
The API will return a response with a count of 0 and no vehicle data. This usually means the VIN is invalid, contains a typo, or belongs to a vehicle that is not in the U.S. database. Check the VIN carefully and try again.
Can I decode multiple VINs at once?
The API accepts one VIN per request. To decode multiple VINs, you must make separate requests for each one. If you are decoding many VINs, write a straightforward script that loops through your list and makes one request per VIN with a small delay between requests.