Checks that the name matches the CPF, screens PEP and CEIS/CNEP/CEAF sanctions and, if you send the IP, geolocates it — with signals ready for your risk rules.
$ curl -X POST https://api.quecpf.com/v1/lookup \ -H "X-API-Key: qc_…" \ -d '{"cpf":"529.982.247-25", "name":"Maria da Silva", "ip":"200.147.3.10"}' { "cpf": { "valid": true, "fiscal_region": { "ufs": ["ES","RJ"] } }, "person": { "found": true, "name_masked": "MA**A DA SI**A", "matches": { "name": true } }, "pep": { "is_pep": false }, "sanctions": { "is_sanctioned": false }, "ip": { "country": "BR", "uf": "RJ", "is_hosting": false }, "signals": { "ip_uf_matches_cpf_region": true } }
Always the same shape. Anything missing comes back as null, never as an error.
Check digits, formatting, and the fiscal region (states) where it was issued, from the 9th digit.
The name you send is compared with the CPF record. Also returns sex and age range; birth date and mother’s name are checked if you send them.
Role, agency, start, end and grace period — and whether it is still active.
CEIS, CNEP and CEAF: sanction type, sanctioning body and validity period.
Country, state, city, ASN and carrier, with a datacenter/hosting flag.
Ready-made booleans: name matches, IP in Brazil, IP state matches the CPF region, active PEP, active sanction.
Check digits are verified locally. An invalid CPF returns 422 immediately, free and without using your quota.
Every provider answer is stored. A CPF looked up before is answered from our database in milliseconds.
PEP and sanctions from Brazil’s Transparency Portal, imported daily and matched by partial CPF + name.
Every response says where each block came from and the date of the file used.
| List | Source | Updated |
|---|---|---|
| PEP | Transparency Portal (CGU) | monthly |
| CEIS | Transparency Portal (CGU) | daily |
| CNEP | Transparency Portal (CGU) | daily |
| CEAF | Transparency Portal (CGU) | daily |
| Personal data | Partner provider + our own database | on demand |
| IP geolocation | DB-IP / MaxMind GeoLite2 | weekly |