A Stripe test CVV is any three digit number you type into a Stripe test card while your account is in test mode. Stripe's published test cards accept any CVC. The value only changes the outcome when you deliberately use a card number, or a token, that is built to return one specific CVC check result. For everyday checkout testing, start with 4242 4242 4242 4242 for Visa, any future expiry date, and 123 as the CVC. That combination approves. Everything beyond that is about reproducing a failure on purpose so your error handling gets exercised.
Nothing on this page involves real cardholder data. Live card numbers, CVV lists, and dumps sold in online markets are stolen payment credentials. Buying, selling, or using them is a federal crime in the United States under 18 U.S.C. 1029. Anyone advertising fresh fullz or 100 percent validity test CVVs is selling either stolen data or a worthless text file, so treat those offers as a warning sign rather than a shortcut.
How Stripe decides the CVC result
Test mode is a sandbox. No authorization request leaves Stripe for the card networks, so the CVC check result is synthetic. It comes from the test card number you used, or from a Stripe.js token when you are testing token creation directly. Stripe documents tokens such as tok_cvcCheckPass, tok_cvcCheckFail, tok_cvcCheckUnavailable, and tok_cvcCheckUnchecked for exactly this purpose.
If you want your application to see cvc_check: fail, use a test card that maps to that response, such as 4000 0000 0000 0127. If you want the check to pass, the generic Visa test card is enough. Do not assume the digits you type drive the result on a card that already has a fixed behavior.
What to look for when you pick a test card
Card brand sets the CVC length
Visa, Mastercard, Discover, and UnionPay test cards take a three digit code. American Express test cards take a four digit CID. If you paste three digits into an Amex field, your own form validation will usually reject the submission before Stripe ever sees it, which is a common source of confusion during testing.
Match the decline you need to reproduce
Stripe publishes test cards that force specific outcomes. The ones worth wiring into a test suite include:
- 4000 0000 0000 0002 for a generic decline
- 4000 0000 0000 9995 for an insufficient funds decline
- 4000 0000 0000 0069 for an expired card
- 4000 0000 0000 0127 for an incorrect CVC
- 4000 0000 0000 0119 for a processing error
- 4000 0000 0000 3220 for a 3DS authentication flow that completes
Stripe updates this list as its systems change, so confirm the current numbers against the official test card reference before you freeze them into automated tests.
Parameter bands to use in test mode
- CVC length: 3 digits for Visa, Mastercard, Discover, and UnionPay. 4 digits for American Express.
- CVC value: any digits work on generic test cards. 123 is the conventional choice.
- Expiry: any future month and year. Use 12/34 or similar so the date stays valid for years.
- ZIP and address: any plausible value passes on most cards. Stripe also publishes cards that force an address or ZIP mismatch, which is how you test AVS handling.
- Amount: test mode accepts ordinary amounts. Some decline behaviors are tied to the card rather than the amount, so pick the card first and the amount second.
Pitfalls that cost developers hours
- Using live keys with test cards. A live secret key against a test PAN returns an error, not a decline. Confirm your key prefix before you debug anything else.
- Expecting test CVCs to work in production. A test card number is rejected in live mode. There is no such thing as a test CVV that clears a real transaction.
- Buying CVC or fullz lists. Sellers in that market traffic in stolen credentials. Beyond the legal exposure, the data is often stale, and card issuers decline it on sight.
- Trusting third party card lists. Community lists go stale. Numbers get retired and behaviors shift between API versions.
- Skipping authentication paths. If your integration supports 3DS, test both the challenge and the frictionless branches, not just the happy path.
FAQ
What CVC do I use for Stripe test cards?
Any three digit number for Visa, Mastercard, Discover, and UnionPay. Any four digit number for American Express. 123 and 1234 are the usual picks.
Does the CVC value matter in test mode?
Only when you use a card or token that is designed to return a specific result. On generic test cards, the digits are ignored.
Can I test a CVC failure without a special card?
Yes, if you create tokens through Stripe.js. The tok_cvcCheckFail token returns a failing CVC check while the underlying test card still behaves normally.
Can I use a real card number as a test card?
No. Test mode accepts Stripe's published test numbers. A live PAN is rejected, which is the mechanism that keeps your sandbox separate from real money movement.
Why does my CVC check show as unavailable?
Some test cards and tokens return cvc_check: unavailable or unchecked by design, so you can exercise branches where the issuer does not supply a verification response.