Short answer

With Stripe test cards, the CVV is almost always any three digits, and 123 is the value everyone types. American Express test cards take four digits, so 1234. There is no "v6" CVV format. A card verification value is a fixed-length field — three digits for Visa, Mastercard, Discover and Diners, four for Amex — and Stripe does not version its test card list. If you saw "v6" glued onto a set of test numbers, that label belongs to somebody's personal list revision, not to Stripe.

related article

How Stripe treats CVC in test mode

In test mode Stripe isn't comparing your CVC to a stored value, because nothing is stored. The simulated network just looks at which test number you typed and returns an outcome. That's why 4242 4242 4242 4242 approves with 123, 456 or 999 equally.

Stripe Test Card CVV V9: How to Use It for Secure Testing

The exceptions are a handful of numbers built to fail a CVC check on purpose. Those exist so you can watch your checkout handle a mismatch without touching a real card.

stripe test card cvv v6

Test numbers worth knowing

  • 4242 4242 4242 4242 — Visa, succeeds. Any future expiry, any three-digit CVC.
  • 4000 0000 0000 0002 — generic decline, whatever CVC you enter.
  • 4000 0000 0000 0127 — declined with an incorrect CVC code returned.
  • 4000 0000 0000 0101 — the charge goes through, but the CVC check comes back failed.
  • 5555 5555 5555 4444 — Mastercard success.
  • 3782 822463 10005 — Amex success, and it expects a four-digit CVC.

Verify these against Stripe's current testing page before you wire them into a suite. Numbers get retired and added, and a stale list is the usual reason a test suddenly behaves in a way nobody expected.

read more

Expiry, ZIP and the fields around CVC

Expiry should be a future date, and 12/34 is a safe habit. ZIP checks use any valid US postal code unless you deliberately pick a number that fails address verification. Authentication is separate again: the 3-D Secure test cards force a challenge screen, and the CVC rules on them are the same as everywhere else.

Where the "v6" idea comes from

Card number generators and forum posts often number their releases — v1 through v6, or a year label. That numbering describes the list, not the card. A CVC does not have versions, revisions or editions. Its length is set by the card brand and its value is whatever the cardholder typed. Any page promising a "version 6 CVV" is selling you a label.

Using test cards properly

  1. Stay in a sandbox with your own test API keys.
  2. Send test numbers only to test endpoints.
  3. Trigger a CVC decline on purpose and read your own error copy.
  4. Run a 3-D Secure test card to check the challenge flow end to end.

Test numbers behave as documented only inside Stripe's test mode. Pointing them at a live endpoint, or at an account you don't own, isn't testing — it's card fraud, and it ends careers as reliably as it ends sandbox sessions. Keep it in the sandbox and the numbers stay boring, which is exactly what you want.