For a Stripe test card, enter any 3-digit CVC, such as 123, and any future expiration date. American Express test cards are the exception and require a 4-digit CID. The value you type rarely changes the outcome, because Stripe test mode does not send the CVC to a real issuer. A failed CVC check is produced by a specific card number or test token, not by the three digits you choose.

Stripe Card CVV Test Tool: How to Use It

Which Stripe test cards accept any CVC?

These commonly used test numbers accept any 3-digit CVC and any future expiry date.

stripe test card cvv process

  • Visa: 4242 4242 4242 4242
  • Visa debit: 4000 0566 5566 5556
  • Mastercard: 5555 5555 5555 4444
  • American Express: 3782 822463 10005 (4-digit CID)
  • Discover: 6011 1111 1111 1117

Stripe states that most test cards accept any CVC, but the testing reference is the source of truth for your API version. Stripe has revised these rules across releases, so confirm the current list before you build a regression suite around one number.

read more

How do you simulate a CVC check failure in Stripe?

Choose a test card or token that is documented to fail the CVC check rather than typing an unusual code. Stripe publishes dedicated test values for this case, including the test token tok_cvcCheckFail and specific card numbers listed under verification and decline tests. When the check fails, the resulting object reports cvc_check as fail and the decline code as incorrect_cvc.

read more

What values does cvc_check return?

  • pass: the CVC was verified successfully.
  • fail: the CVC did not match, or the issuer rejected it.
  • unavailable: the issuer could not be reached for verification.
  • unchecked: no CVC check was requested.

Branch your application logic on cvc_check instead of assuming that every successful test charge included a CVC check. Test mode returns these same statuses so you can exercise each path without real cards.

Do Amex test cards use a different CVC rule?

Yes. American Express uses a 4-digit CID rather than a 3-digit CVC, so the card number 3782 822463 10005 expects four digits, such as 1234. A 3-digit entry typically fails client-side validation in Stripe Elements and Checkout before the request ever reaches the API.

Do test CVC values work with live API keys?

No. Test card numbers, test tokens, and filler CVC values work only with test mode keys that begin with pk_test_ or sk_test_. Submitting a test number with a live key returns an error, and using real card data in test mode breaks Stripe's terms of service.

Should you store the CVC after authorization?

No. PCI DSS treats the card verification code as sensitive authentication data, which must not be retained after the authorization completes. Store the cvc_check result, a PaymentMethod ID, or a card fingerprint instead of the code itself.

Common mistakes when testing CVCs

  1. Typing a random CVC and expecting a decline. Declines come from the card number or test token.
  2. Using a 3-digit value on an Amex test card that requires 4 digits.
  3. Assuming cvc_check is pass on every successful test charge.
  4. Reusing test card numbers after switching to live keys.

Frequently asked questions

Does Stripe accept 000 as a test CVC?

In most current test setups, any 3-digit value works, including 000. To force a failed CVC check, use a documented CVC failure card or the CVC failure test token instead of relying on the digits, since Stripe has changed these rules between API versions.

What expiration date should I use with a Stripe test card?

Any future date works, such as 12/34. Separate test numbers exist for expired-card scenarios when you need to verify decline handling.

Is a CVC required to create a test token?

Token and PaymentMethod creation in test mode still validates that the CVC length matches the card brand. Supply a 3-digit value for Visa, Mastercard, and Discover, and a 4-digit value for American Express.