In Stripe test mode, use 123 as the CVC for every Visa, Mastercard, and Discover test card, and 1234 for American Express test cards. Stripe does not contact a real issuer in test mode, so the digits you type are never validated against anything. The card number decides whether the CVC check passes, fails, or is skipped entirely.

more on this topic

Why the CVC Digits Do Not Matter in Test Mode

A test mode charge runs against a simulated acquirer. That simulator matches the card number against a fixed list and returns a canned result, including the result of the CVC check. Because no issuer is involved, a CVC of 123 behaves the same as 999 on a card whose test profile says the check passes. The value only matters when you want the profile to report a failure, and then you pick the card number that carries that behavior rather than a special CVC.

stripe test card cvv validation

Prerequisites

  • A Stripe account with test mode switched on.
  • Your test API keys, the ones beginning with pk_test_ and sk_test_.
  • A way to send requests: the Dashboard test form, the Stripe CLI, or an SDK.
  • Any future expiration date, such as 12/34, and any postal code, such as 12345.

CVC Values to Use by Card Brand

  • Visa test cards: 3 digits, use 123.
  • Mastercard test cards: 3 digits, use 123.
  • Discover test cards: 3 digits, use 123.
  • American Express test cards: 4 digits, use 1234.

Amex test cards use a 4-digit card identification number, so the field must accept four characters. If your form hard-codes a 3-digit limit, Amex test confirmations fail on input validation before Stripe ever sees the request.

Stripe Test Card CVV Verification System: How It Works

Run a CVC Failure Test End to End

  1. Load your secret test key into the tool or SDK you are using.
  2. Create a PaymentIntent for a small amount, such as 1000 in usd.
  3. Confirm the PaymentIntent with card number 4000 0000 0000 0127, expiration 12/34, and CVC 123.
  4. Read the returned error object and note the decline code, which is incorrect_cvc.
  5. Retrieve the PaymentIntent and inspect the charge's cvc_check value, which reports fail.
  6. Confirm a second PaymentIntent with 4242 4242 4242 4242 and the same CVC to verify the success path.
  7. Open the Dashboard test logs and compare both events side by side.

This pair of runs gives you the two branches your checkout code has to handle: a decline you can show to the customer and a success you can fulfill.

Stripe Test Card CVV Process Guide

Test Cards With CVC Behavior Worth Knowing

  • 4242 4242 4242 4242, a Visa that succeeds with any 3-digit CVC.
  • 4000 0000 0000 0127, a Visa whose CVC check fails, producing incorrect_cvc.
  • 4000 0000 0000 0002, a Visa declined for a generic reason, unrelated to CVC.
  • 3782 822463 10005, an Amex that succeeds with a 4-digit CVC.

Reading the cvc_check Field

Stripe reports the CVC result as pass, fail, unchecked, or unavailable. In test mode you will see pass for ordinary success cards and fail for the CVC failure card. You see unchecked when you confirm without collecting a CVC at all, which is common for off-session or merchant-initiated charges. You see unavailable when the issuer or processor cannot answer the check.

Test Mode Rules That Trip People Up

Test cards only work with test keys. Send 4242 4242 4242 4242 to a live key and the request fails, because Stripe rejects numbers that do not belong to the active mode. Never paste a real card number into test mode, and never paste a test number into a live account while debugging.

The CVC is sensitive authentication data under PCI DSS and must not be stored after authorization, in test or live environments. Keep it out of your database, your logs, and your analytics events. Store only the token or PaymentMethod identifier Stripe returns, then let Stripe handle the check on each new charge.