A dummy CVV is a fake card security code that pairs with test card numbers inside a payment sandbox. It follows the real format (three digits for Visa and Mastercard, four for American Express) but ties to no bank account. Live gateways decline it, and that is the point.
What Is a Dummy CVV?
Payment processors publish test card numbers plus matching dummy CVVs so developers can run a checkout flow from start to finish. The code acts as a placeholder. The sandbox reads the digits, returns an approve or decline response, and no money moves.
The phrase shows up in two very different places. One is developer documentation: "use test card 4242..., any future expiry, CVV 123." The other is storefronts that sell stolen card data, where "dummy" is used as a cover word for numbers taken from real people. The first is a normal engineering practice. The second is card fraud.
Where Do Dummy CVV Values Come From?
Published test card tables
Stripe, PayPal, Adyen, and Braintree all keep public lists of test cards. Each entry pairs a card number with a dummy CVV, an expiry date, and the response the sandbox should return.
- 4242 4242 4242 4242 with CVV 123: standard approval
- 4000 0000 0000 0002: generic decline
- 4000 0000 0000 9995: insufficient funds
- 3782 822463 10005: Amex test card with a four digit dummy CVV
These numbers work only when the API request carries a sandbox key. Send one to a live endpoint and the issuer rejects it in milliseconds.
Why the same digits repeat
Sandbox CVVs are static on purpose. A moving value would break test scripts and hide regressions. Common picks are 123, 000, and 999 because they read as obvious placeholders in a log file.
Dummy CVV vs a Real CVV
- Dummy: no account behind it, sandbox only, printed in public docs, reused by thousands of testers.
- Real: printed on the card (back for Visa and Mastercard, front for Amex), generated by the issuing bank, tied to one account.
The CVV exists to prove the buyer holds the physical card. That check works only if the code stays secret, which is why PCI rules forbid storing it after a transaction authorizes.
What You Can Test with a Dummy CVV
- Card form validation: length, spacing, and the three vs four digit rule.
- Approval paths: a successful charge, receipt email, and order record.
- Decline handling: expired card, insufficient funds, and wrong CVV responses.
- Risk rules: how your own fraud scoring reacts to a mismatch between number and code.
- Refunds, voids, and partial captures while the account sits in test mode.
What a Dummy CVV Cannot Do
A dummy CVV does not authorize on a live gateway, does not belong to anyone, and does not complete a real purchase. Test numbers respond only to requests signed with a sandbox key. The code is inert outside that environment.
Using a real card number without the cardholder's permission is card fraud. In the US it falls under 18 U.S.C. 1029, with penalties that include prison time and fines. Sites that advertise "fresh fullz" or "100% valid" CVVs are trading stolen data, and buying from them carries the same legal exposure as using the numbers yourself.
How to Handle Test Card Data
Keep test keys out of production
Sandbox keys and live keys should never sit in the same config file. One mixed-up key can fire a test charge at a real account and create a refund you have to explain.
Never log CVV values
PCI DSS bans storing the CVV after authorization, and that includes debug logs. Mask the field, keep the last four digits of the card number if you need a reference, and drop the rest.
Label test records
Tag sandbox orders so support and finance can filter them out of reports. A test order that reaches an invoice creates cleanup work for two teams.
Frequently Asked Questions
Does a dummy CVV work on a real store?
No. A live gateway passes the code to the issuer, which rejects anything not tied to an active account.
Can I invent my own dummy CVV?
In most sandboxes, yes. Any three digits pass the format check, and the processor decides the outcome from the card number. Some processors demand the exact CVV listed in their docs, so check the table before you hardcode a value.
Why do test CVVs use 123?
It is fast to type, easy to spot in a log, and impossible to confuse with a real code.
Is a dummy CVV the same as a test card?
Close but not identical. The card number is the main test object. The dummy CVV is one field in the test payload, next to a future expiry date and a test ZIP code.
Do dummy CVVs pass the Luhn check?
The number does, the CVV does not. Luhn is a checksum for the card number alone and has no effect on the security code.