Short answer

There is no CVV to buy for the PayPal sandbox, and you do not need one. Sandbox test cards are fake numbers that PayPal publishes in its developer documentation, and the CVV box on a sandbox checkout usually accepts any three digits you type. Nothing gets charged. No bank is contacted. The card does not exist, so there is no code to purchase.

If a site is advertising a "PayPal sandbox CVV" for sale, it is selling you something that is not what the label says.

What the PayPal sandbox actually is

The sandbox is a mirror of the live PayPal environment where developers build and test checkout flows without moving real money. You create sandbox accounts for a fake buyer and a fake seller, wire them into your integration, and run transactions. The buyer accounts come loaded with a pretend balance and pretend cards.

That is the whole point. It is a simulation, and simulations run on invented data.

Where the test card numbers come from

PayPal's developer documentation publishes a table of test card numbers you can use in sandbox checkouts, covering Visa, Mastercard, American Express, Discover, and a few region-specific cards. I pull from that table every time I set up a new sandbox because the numbers and their expected behaviors get updated. A screenshot you saved two years ago is a bad source. The docs page is the source.

Those numbers are designed to fail the Luhn check in some cases and pass in others, and PayPal labels which ones trigger approvals, declines, and specific error codes. That is how you test your error handling without waiting for a real customer's card to bounce.

What goes in the CVV field

  • Most sandbox test cards: any three digits. 123 is fine. 999 is fine.
  • Amex-format test cards: four digits, because the field layout matches the real card type.
  • Cards tied to a specific decline scenario: the documentation tells you which value produces which response, so read the row before you assume the CVV is the problem.

If a sandbox transaction fails, the CVV is almost never the cause. Check the ZIP code, the expiration date, and the card number first, since those actually get validated against the test profile.

Why a sandbox CVV cannot be bought

There is no inventory. The CVV in a sandbox checkout is an input field that a simulator reads and mostly ignores. It is not issued by a bank, it is not attached to an account, and it has no value outside your test run. Selling one would be like selling a blank line on a form.

If someone is offering you a real CVV

Real card verification values belong to real cardholders. Anyone selling them is trafficking in stolen payment credentials, and in the United States that falls under 18 U.S.C. § 1029, which prosecutors do charge and do win. Card networks also forbid merchants from storing the CVV after a transaction is authorized, which is exactly why stolen codes get resold fast and why the market depends on fraud rather than on any legitimate supply.

Buying one is not a shortcut around testing. It is the crime itself.

Before you run another sandbox test

  1. Confirm you are pointed at the sandbox API endpoint, not live.
  2. Pull the current test card table from PayPal's developer docs.
  3. Use a matching sandbox buyer account so the billing address lines up.
  4. Read the response code before blaming the CVV field.

That is the entire workflow. No purchase required, and none possible.