Magnetic Stripe Decoder and Encoder - SimeonOnSecurity
NOTE: This tool runs entirely in your browser with client-side JavaScript. Anything you paste is parsed locally and is never transmitted, logged, or stored. That matters here, because magnetic stripe data is the full contents of a payment card or identity document.
1. Paste Track Data
Paste either track, or both. Decoding fills the fields below and re-encodes as you type.
2. Fields
Issuer-defined. Commonly PVKI (1) then PVV (4) then CVV (3), but the layout is not standardized.
Service code
Three digits, each with defined meaning. Changing any of them updates the encoded output.
Options
3. Encoded Output
How to Read the Fields
- PAN is the primary account number, up to 19 digits. It usually matches the number printed on the front of the card, and not always.
- Expiry is stored as
YYMMon both tracks, so3112means December 2031. - Service code is three digits, each with a defined meaning. The selects above decode all three.
- Discretionary data is issuer-defined and not standardized. The common layout is a 1-digit PVKI, a 4-digit PVV, then a 3-digit CVV, with any remainder as issuer padding.
- Track 1 is the only track that carries alphabetic text, which is why the cardholder name appears there and nowhere else.
- Track 3 is effectively unused by the major card networks and is often not present on the card at all.
Why This Matters for Your Own Cards
Everything needed to authorise a card-not-present transaction is on track 2, and it is stored unencrypted on the stripe. A magnetic stripe can be read by any compatible reader, and the data can be written to a blank card with inexpensive hardware. That is the entire reason chip and contactless payment exist, and why tokenization replaced the number in mobile wallets.
Use this tool only on cards and documents you own or are authorised to test. Reading or cloning a payment card you do not own is a criminal offence in most jurisdictions.
