How to Validate Credit Card Numbers Using Laravel‑Validate: ValidCreditCard Rule Explained
Laravel‑Validate ships with a ValidCreditCard rule—implemented in src/Rules/ValidCreditCard.php—that uses the Luhn algorithm to verify credit card syntax and can be used via object instantiation or string-based validation when container registration is enabled.
The milwad-dev/laravel-validate package extends Laravel's validation layer with domain-specific rules for common data types. When you need to validate credit card numbers, the package provides the ValidCreditCard rule, which performs industry-standard checksum verification without requiring external payment gateways.
How the ValidCreditCard Rule Works
According to the milwad-dev/laravel-validate source code, the ValidCreditCard class implements the Illuminate\Contracts\Validation\Rule contract and validates numbers using the Luhn algorithm (modulus 10).
Input Normalization
The passes method first sanitizes user input to handle real-world formatting variations. It strips all non-digit characters using preg_replace('/\D/', '', $value) (lines 14-15 of ValidCreditCard.php), ensuring that spaces, dashes, or other separators do not invalidate legitimate card numbers like 4111-1111-1111-1111.
Luhn Algorithm Verification
After normalization, the rule validates the checksum by reversing the cleaned string and processing each digit. Every second digit from the right is doubled; if the result exceeds 9, the algorithm subtracts 9. The implementation sums all digits and confirms the total is divisible by 10 ($sum % 10 == 0) according to lines 20-31 of src/Rules/ValidCreditCard.php. This detects most accidental transcription errors and invalid number sequences.
Implementing Credit Card Validation
You can apply the validator using two syntax patterns depending on your service provider configuration.
Object Instantiation Syntax
The most explicit method instantiates the rule directly. This approach is always available regardless of configuration settings:
use Milwad\LaravelValidate\Rules\ValidCreditCard;
return [
'credit_card' => ['required', new ValidCreditCard()],
];
Container-Based String Syntax
When you set using_container to true in the package configuration, the LaravelValidateServiceProvider (lines 75-88) registers the rule in Laravel's service container. This enables the shorter string syntax:
return [
'credit_card' => 'required|ValidCreditCard',
];
The package documentation in docs/1.x/valid-credit-card.md demonstrates validation using the test number 4111111111111111, which you can use in development to verify your implementation.
Customizing Error Messages
When validation fails, the rule returns a translatable error message. The message method returns __('validate.credit-card') (lines 37-40 of ValidCreditCard.php). To customize the text, publish the package's language files and override the credit-card key in your translation files.
Summary
- The
ValidCreditCardrule insrc/Rules/ValidCreditCard.phpvalidates credit card syntax using the standard Luhn algorithm. - Input is automatically normalized by stripping non-digit characters via
preg_replace('/\D/', '', $value)before checksum calculation. - You can instantiate the rule directly with
new ValidCreditCard()or use string syntax whenusing_containeris enabled in the service provider registration (lines 75-88). - Error messages are fully translatable through the
validate.credit-cardlanguage key.
Frequently Asked Questions
Does Laravel‑Validate support all credit card types?
The ValidCreditCard rule verifies the numeric checksum using the universal Luhn algorithm, which is valid for Visa, MasterCard, American Express, and other major issuers. However, it does not validate specific card type prefixes or lengths; for brand-specific validation, combine this rule with additional custom logic.
Can users enter credit card numbers with spaces or dashes?
Yes. The rule automatically strips non-digit characters during the normalization phase (lines 14-15 of ValidCreditCard.php), so formatted numbers like 4111-1111-1111-1111 or 4111 1111 1111 1111 are accepted and validated correctly against the Luhn checksum.
How do I customize the validation error message?
Publish the package's translation files and modify the validate.credit-card key. The rule retrieves the message using __('validate.credit-card') (lines 37-40), making it fully customizable per locale without modifying the vendor source code.
Is the Luhn algorithm implementation secure for production use?
The checksum verification in src/Rules/ValidCreditCard.php correctly implements the Luhn standard (lines 20-31) and safely detects most accidental input errors. While it validates syntax, always combine this with PCI-compliant payment processing and never log or store raw card data in application databases.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →