GSTIN verification: a complete guide for onboarding vendors and merchants
A GSTIN check confirms a business is registered and returns its legal name, state, registration date and status. Here is how to use each field.
On this page
Anatomy of a GSTIN
A GSTIN is 15 characters: the first two are the state code, the next ten are the entity PAN, the thirteenth is the registration count for that PAN in that state, the fourteenth is a fixed Z, and the last is a checksum. You can validate the structure and the embedded PAN locally before ever calling the API.
Because the PAN is embedded, a GSTIN check doubles as a light PAN check for the business.
The status field is the decision
A GSTIN can be Active, Cancelled, Suspended, or Provisional. Cancelled means the registration is dead and invoices from that GSTIN will not support input tax credit. Suspended is a warning state, often pending cancellation. Only Active should pass an onboarding check without a second look.
Store the status with the date you checked it. A GSTIN that was active at onboarding can be cancelled later, so re-verify before annual renewals or large purchase orders.
Legal name vs trade name
The API returns the legal name of the business as registered, and often the trade name. Your contract and invoices should use the legal name; the trade name is what appears on the storefront. Mismatches between the two are normal, not a red flag.
Match the legal name against your KYC documents. If a vendor gives you a GSTIN whose legal name is a completely different entity, stop and ask.
Address and jurisdiction
The principal place of business and the state jurisdiction tell you where the business is really operating. For place-of-supply decisions and for e-way bills, the state code in the GSTIN must line up with the delivery reality. A mismatch is a compliance risk you want to catch before the first shipment.