Answer first
Authorize.Net publishes test card numbers for its sandbox. The main Visa number is 4007000000027. The main Mastercard number is 5424000000000015. Both return an approval in the sandbox. Neither works in live mode. A live gateway declines them.
Test card numbers by brand
- Visa: 4007000000027
- Visa: 4012888818888
- Mastercard: 5424000000000015
- American Express: 370000000000002
- Discover: 6011000000000012
- JCB: 3088000000000017
- Diners Club / Carte Blanche: 38000000000006
Use any expiration date in the future. An expired date triggers the expired card response. Authorize.Net does not tie test cards to a fixed expiry.
Card code (CVV) test values
The 3 or 4 digit code drives the card code verification result in the sandbox. Visa, Mastercard, Discover, and JCB use 3 digits. American Express uses 4 digits.
- 900: matches, transaction approved
- 901: does not match, transaction declined
- 902: not processed, transaction approved
- 903: should have been present, transaction declined
- 904: issuer unable to process, transaction approved
AVS test values
Address verification reads the street address and the ZIP code. Authorize.Net maps test values to AVS result codes: Y, A, Z, and N. Y means the street address and the 5 digit ZIP both match. A means the street address matches and the ZIP does not. Z means the ZIP matches and the street address does not. N means neither matches. The exact address and ZIP pairs sit in the Authorize.Net testing guide. I cannot confirm from memory which pair returns which code. Check the guide before you write assertions against those codes.
Where the numbers work
Sandbox traffic goes to the test API host, apitest.authorize.net. Live traffic goes to api.authorize.net. A sandbox merchant interface sits on test.authorize.net. Test card numbers pass on the test host with a sandbox account. A live account rejects them with a decline.
Common errors
- Running test cards against a live account. Result: decline.
- Using an expired date. Result: expired card response.
- Sending 3 digits for American Express. Result: card code error.
- Treating AVS pairs as permanent. Result: broken tests after a doc update.
What test cards are not
These numbers are public. They carry no funds. They hold no cardholder data. They cannot buy goods. A processor reads repeated use of published test numbers in live mode as a risk signal.