PayPal sandbox test cards are fake credit card numbers that process payments only inside the PayPal Sandbox, a developer copy of the live payment system. They let you run checkout, subscription, refund, and decline flows without touching a real card or moving real money. A sandbox test card is declined everywhere else, including the live PayPal checkout, so it cannot be used to buy anything.

What is a PayPal sandbox test card?

A PayPal sandbox test card is a number tied to a Sandbox account, not to a bank. PayPal routes it through its simulation engine, so authorizations, captures, refunds, and error codes all behave like production without charging anyone.

Because the number is fictional, there is no cardholder, no credit line, and no billing statement. The only place it resolves is the sandbox environment created by your developer account.

Which test card numbers can you use?

PayPal publishes its current list in the developer dashboard under sandbox test card tools, and that list is the authoritative source. The numbers below are the long-standing sandbox test values that most developers start with.

  • Visa: 4111111111111111 and 4012888888881881
  • Mastercard: 5555555555554444 and 5105105105105100
  • American Express: 378282246310005
  • Discover: 6011111111111117
  • Diners Club: 30569309025904
  • JCB: 3566002020360505

For every card, use any expiration date in the future, any three digit CSC (four digits for American Express), and any billing ZIP in a valid format such as 95131.

How do you use a test card in the PayPal Sandbox?

  1. Create or sign in to a PayPal developer account and open the Sandbox section.
  2. Create a sandbox business account and a sandbox personal account, then copy the sandbox client ID and secret into your test configuration.
  3. Load your checkout in sandbox mode and choose the card payment option.
  4. Enter a sandbox test card number, a future expiration date, a CSC, and a billing address.
  5. Confirm the result in the sandbox transaction log and in the sandbox account activity.

Card processing in the sandbox depends on the account region, so a number that approves in one sandbox store may fail in another. If a test card is rejected, generate a fresh one from the dashboard instead of guessing.

How do you test declines and other error paths?

PayPal documents specific sandbox cards that always fail, such as 4000000000000002, so you can verify your error handling before launch. Sandbox settings also let you force a three domain secure (3D Secure) challenge and inspect how your flow responds to authentication.

The sandbox additionally supports negative testing by amount. When you submit a payment amount that matches a documented PayPal error code value, the sandbox returns that error, which is useful for reproducing edge cases on demand.

Do sandbox test cards work on the live PayPal site?

No. Sandbox test cards are valid only against the sandbox API endpoints and the sandbox checkout experience. Entering one on the live PayPal site returns a decline, and no goods or services are delivered.

Stolen or purchased card data is a separate matter and carries real legal exposure. Card numbers that belong to actual cardholders are governed by the PCI DSS rules on storing and transmitting account data, and trading them is a criminal offense in the United States.

Frequently asked questions

Can I reuse the same sandbox test card number?

Yes. The static test numbers can be used as many times as you need, because no real account is debited.

Why does my sandbox test card get declined?

Common causes are a sandbox account in a different region, an expired test date, a card that is designed to fail, or a mismatch between your sandbox store country and the card type.

Where should I get the official test card list?

Always pull the list from your PayPal developer dashboard or the PayPal developer documentation, since PayPal updates sandbox test values over time.