The 15 characters, position by position
The GST law describes the number in four parts. Rule 10 of the CGST Rules says a GSTIN is made of a two-character state code, the ten characters of the holder's PAN (or TAN, for those registered only to deduct or collect tax), a two-character entity code, and one check-sum character.
The example below is the GSTIN of a public-sector body, 33AAACC1206D1ZN, which our documentation already uses because it is a published identifier and not a customer's.
| Position | Length | Meaning | In 33AAACC1206D1ZN |
|---|---|---|---|
| 1-2 | 2 digits | State or UT code | 33 (Tamil Nadu) |
| 3-12 | 10 characters | PAN of the holder (TAN for TDS/TCS registrations) | AAACC1206D |
| 13 | 1 character | First half of the entity code, widely described as the count of registrations on that PAN in the state | 1 |
| 14 | 1 character | Second half of the entity code, widely described as a fixed Z | Z |
| 15 | 1 character | Check character, computed from positions 1-14 | N |
One thing to hold apart: the law and the GST Council's registration flyer both split the number as 2 + 10 + 2 + 1. The reading of position 13 as a registration counter and position 14 as "Z" comes from widely repeated explainers, and we could not find it stated on an official page. It fits the real GSTINs we work with, but treat it as a convention rather than a rule.
Sources: CGST Rules 2017, Rule 10 (CBIC) · GST Council flyer: Registration under GST Law
Characters 1-2: the state code
The first two digits identify the state or union territory of the registration, not of the business's head office. A company with a Pune headquarters and a Chennai warehouse would hold one GSTIN starting 27 and a separate one starting 33.
The list on the GST e-way bill portal runs 01 to 24, then 26, 27, and 29 to 38. There is no 25 and no 28. Code 26 is Dadra and Nagar Haveli and Daman and Diu, which are now one territory; code 38 is Ladakh. Two further codes are not states: 97 is "Other Territory" and 99 is "Other Country".
Not every GST portal list is equally current. The e-invoice portal's master list still shows Daman and Diu (25) and Dadra and Nagar Haveli (26) separately, so a validator built from an old list will wrongly reject a valid 26.
Sources: GST e-way bill portal: state codes · e-invoice portal: master codes
Characters 3-12: the PAN, and why one company has many GSTINs
Characters 3 to 12 are the PAN. That is why every GSTIN of one legal entity shares the same ten characters in the middle, and why the PAN is the key for finding all of a business's registrations.
A PAN can carry more than one GSTIN: one per state, and the GST portal also permits separate registrations for separate places of business or verticals within a state, subject to its category limits. So "one PAN, one GSTIN" is not true, and a GSTIN you have been given is one of possibly several.
For registrations made only to deduct or collect tax at source, the middle ten characters are a TAN rather than a PAN, so do not assume characters 3-12 will pass a PAN format check.
Sources: CGST Rules 2017, Rule 10 (CBIC) · GST portal: apply for registration (normal taxpayer)
Character 15: the check character, as working code
The last character exists so a mistyped number can be rejected before anyone looks it up. It is a base-36 checksum in the same family as the Luhn check on a card number. Each of the first 14 characters is given a value from 0-9 then A-Z (0 to 35), multiplied by 1 or 2 alternately starting from 1, and the product's two base-36 digits are added. The check character is whatever brings the total up to a multiple of 36.
We could not find the algorithm written down on an official GST page, which only says "one check-sum character". It is documented by third parties, and our own implementation agrees with it on real GSTINs, so the code below is "widely used and verified against real numbers" rather than "published by GSTN".
What it catches: every single-character error. We checked every possible one-character substitution on 5,000 random valid numbers and none passed. What it only mostly catches: swapping two neighbouring characters. In the same test, 0.16% of swaps still produced a number with a valid check character. So a failed check means "reject and ask again"; a passed check means only "plausibly typed correctly".
const CHARS = '0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZ';
function checkChar(first14) {
let sum = 0;
for (let i = 0; i < 14; i++) {
const product = CHARS.indexOf(first14[i]) * (i % 2 === 0 ? 1 : 2);
sum += Math.floor(product / 36) + (product % 36);
}
return CHARS[(36 - (sum % 36)) % 36];
}
function hasValidCheckChar(gstin) {
return /^[0-9A-Z]{15}$/.test(gstin) && checkChar(gstin.slice(0, 14)) === gstin[14];
}
hasValidCheckChar('33AAACC1206D1ZN'); // true
hasValidCheckChar('33AAACC1206D1ZM'); // false: last character mistyped
hasValidCheckChar('33AAACC1260D1ZN'); // false: two digits swappedWe ran this on 4 October 2026. It returns true for two real GSTINs and false for both corrupted versions above.
What the format can never tell you
A number can have a correct state code, a well-formed PAN and a valid check character and still not be anyone's GSTIN. Format validation cannot say whether it was ever issued, who holds it, whether the registration is active, suspended or cancelled, or whether the name on an invoice matches the name on record.
Those facts live only with the GST network, and they can change in a day. Checking them takes one live lookup that returns the legal name, trade name, status, taxpayer type and registration date. Do the cheap local format and check-character test first to save a call on obvious typos, then look up the rest.
Not every 15-character ID is a GSTIN
UN bodies, embassies and certain other notified persons get a UIN, also 15 characters but laid out differently: a 2-digit state code, a 2-digit year, a 3-character country code, a 5-digit serial and a three-letter ending ("UIN" or "ONP"). A validator that insists on a PAN in positions 3-12 will reject these, which may or may not be what you want for a given form.
Sources: CBIC registration FAQs (UIN format)
Frequently asked questions
What does each part of a GSTIN mean?
Characters 1-2 are the state code, 3-12 are the holder's PAN, 13-14 are the entity code, and 15 is a check character. The law describes the entity code as two characters; the common reading of it as a registration count plus a fixed Z is an unofficial convention.
Can I work out someone's GSTIN from their PAN?
You can build the candidates, because the check character is a fixed function of the first 14. For each state, state code plus PAN plus an entity code plus the computed check character gives a possible GSTIN. Whether that GSTIN actually exists still needs a lookup. Our PAN search endpoint does exactly that across all 36 state codes, trying entity code 1 in each, so a second registration on the same PAN in the same state would not be found.
How do I validate a GSTIN in code?
Test the 15-character pattern, test that the first two digits are a real state code, and recompute the check character as shown above. This rejects typos locally. To confirm the registration is real and active, you then need a lookup against the GST network.
Does a valid check character mean the GSTIN is active?
No. It only means the number is internally consistent. A cancelled or never-issued number can pass it.
More from the blog
Try it on a real GSTIN
Up to 100 free lookups: 25 on signup and 25 for each of three setup steps. No card, and they never expire.
Create a free account