Any 3-digit code works as the CVV for most Stripe test cards. Use 123 for the Visa, Mastercard, Discover, JCB, and UnionPay test numbers, and 1234 for the American Express test card. Stripe test mode accepts any future expiry date and any billing ZIP on the standard success card, so the CVC value does not need to match a real card.
Test cards exist so developers can run payments without moving real money. Stripe sends them through the same code paths as live cards, then returns a result you pick in advance.
What CVV should you use for a Stripe test card?
The CVC length follows the card brand, not a fixed table. Three digits for Visa, Mastercard, Discover, JCB, Diners Club, and UnionPay. Four digits for American Express.
- Visa
4242 4242 4242 4242(CVC123) - Visa debit
4000 0566 5566 5556(CVC123) - Mastercard
5555 5555 5555 4444(CVC123) - Mastercard 2-series
2223 0031 2200 3222(CVC123) - American Express
3782 822463 10005(CVC1234) - Discover
6011 1111 1111 1117(CVC123) - JCB
3566 0020 2036 0505(CVC123) - Diners Club
3056 9300 0902 0004(CVC123) - UnionPay
6200 0000 0000 0005(CVC123)
These numbers work only with test API keys, the ones that start with pk_test_ and sk_test_. Live keys block them.
How does Stripe handle the CVC field in test mode?
Stripe Elements splits the card into separate fields. The number and expiry sit in one element, and the CVC sits in a cardCvc element that Stripe renders and checks on its own.
- The CVC element takes 3 digits for Visa, Mastercard, Discover, JCB, and UnionPay.
- The same element takes 4 digits once the number starts with the Amex prefixes 34 or 37.
- Letters, spaces, and wrong-length values get rejected before the form submits.
If you use the combined Card Element instead, the CVC box appears inside the same iframe. Both setups behave the same in test mode. Stripe validates the format in the browser, then sends a token or PaymentMethod to your server.
Which Stripe test cards trigger a CVC failure?
Three test numbers target CVC behavior. They let you confirm that your app reads the right decline code from the API response.
4000 0000 0000 0101: charge declined,cvc_checkreturnsfail4000 0000 0000 0127: charge declined with the codeincorrect_cvc4000 0000 0000 0259: charge succeeds, butcvc_checkreturnsfail
The third card matters for most teams. It mimics an issuer that approves the payment while flagging the verification result, which is common on small-ticket transactions.
For a plain decline with no CVC signal, use 4000 0000 0000 0002. For an address mismatch, use 4000 0000 0000 0172 for a ZIP failure.
Which CVC error codes should your checkout handle?
Stripe returns a decline code inside the error object of the API response. Map each one to a message a shopper can act on.
incorrect_cvc: the issuer rejected the code. Ask the buyer to re-enter it.card_declined: a general decline, often paired with acvc_checkvalue offail.expired_card: the expiry date is in the past.incorrect_number: the digits fail the Luhn check.processing_error: a retryable fault, usually a routing or network issue.
Log the code, never the card data. The CVC is sensitive authentication data, and PCI DSS bans storing it after authorization. Stripe checks the value once and discards it.
Do test cards work with Checkout, Payment Links, and 3D Secure?
Yes, with one catch: 3D Secure needs its own card numbers. Use 4000 0025 0000 3155 for a card that forces 3DS authentication, and 4000 0000 0000 3220 for a 3DS2 challenge. The test CVC stays 123.
Stripe Checkout, Payment Links, and the mobile SDKs all accept the same set of numbers. The difference is the UI, not the test data.
Can you test CVC behavior without a card form?
Yes. Stripe ships test PaymentMethod tokens that skip the browser step. pm_card_visa creates a working Visa, and pm_card_visa_chargeDeclinedIncorrectCvc returns an incorrect_cvc error. These fit server-side integration tests where no card form exists.
Frequently asked questions
Does the CVC on a Stripe test card need to be valid?
No. Test mode ignores the CVC value on the success cards. Pick any digits and the charge goes through.
Why does a test charge fail with expired_card?
The expiry year must sit in the future. Use any date ahead of today, such as 12/34, and the card passes.
Can test card numbers be used on a live site?
No. A live key rejects test numbers, and a test key rejects real ones. A mixed pair of keys is the usual cause when a charge fails on both sides.
Is it safe to type real card details into test mode?
No. Stripe bans real card data in test mode, and real numbers there can flag your account. Use the documented test numbers and nothing else. Treat any CVC as confidential, whether it comes from a test card or a live one.