Short answer
Stripe does not publish a test card named v10. Stripe test cards are 16-digit card numbers. In test mode the CVC field accepts any 3-digit value, or 4 digits for American Express. The string "cvv v10" does not match any Stripe card, token, API version, or library version. When you see "v10" beside a card number, that label comes from a third-party list, not from Stripe documentation.
How Stripe test cards work
- Test mode only. The numbers work with test API keys that start with
pk_test_orsk_test_. Live keys reject them. - CVC. Any 3 digits. American Express test cards take 4 digits.
- Expiry. Any future date, such as 12/34.
- Postal code. Any value.
- Luhn check. Every published test number passes it.
- No money moves. No real account is charged or credited.
Test card numbers Stripe documents
- 4242 4242 4242 4242, Visa, payment succeeds.
- 4000 0025 0000 3155, Visa, 3D Secure authentication required.
- 4000 0000 0000 9995, decline code insufficient_funds.
- 4000 0000 0000 0002, generic decline.
- 4000 0000 0000 0069, expired card.
- 4000 0000 0000 0127, CVC check failure.
- 4000 0000 0000 0119, processing error.
CVC values in test mode
With 4242 4242 4242 4242 you can enter 123, 000, or any other 3 digits and the charge succeeds. Stripe ties CVC failures to specific card numbers, not to specific CVC values. There is no CVC code that Stripe labels v10.
What "v10" may refer to
Stripe version strings look like API dates, for example 2024-06-20. Test tokens look like tok_visa and tok_mastercard. Stripe.js releases sit in the v3 line. No Stripe product uses a v10 label for a CVC or a card.
Test 3D Secure and declines
- Use 4000 0025 0000 3155 to force an authentication step.
- Run
stripe trigger payment_intent.succeededfrom the Stripe CLI to create events without a browser. - Check that the dashboard shows the TEST DATA banner before you run any case.
Limits and legal notes
Test numbers carry no value outside test mode. A live payment gateway will reject them or return a decline. Using a real card number without the cardholder's authorization is a federal crime in the United States under 18 U.S.C. Section 1029, and card networks treat it as fraud. PCI DSS also bars merchants from storing the CVC after a transaction is authorized. Stripe publishes its test numbers for developers, so they are free to copy and share.