The Stripe test card CVV verification system is a test-mode feature that simulates a card verification value (CVC) check without contacting a real card network. In test mode, Stripe matches the CVC you submit against preset outcomes attached to specific test card numbers, so you can build, debug, and demo a checkout flow before you process live payments.
What Stripe Checks When It Verifies a Card
Card verification in Stripe covers three separate checks: the CVC, the postal code, and the street address. Each one returns its own result, and the CVC result is reported as cvc_check on the card object.
Stripe Card CVV Test Tool: How to Use It
- pass: the CVC matched what the issuer had on file.
- fail: the CVC did not match.
- unavailable: the issuer could not be reached for a check.
- unchecked: no CVC check was requested for that request.
Because test mode never reaches an issuer, Stripe simply returns the outcome associated with the test card you used.
stripe test card cvv validation
Test Card Numbers That Exercise CVC Behavior
Stripe publishes a set of public test numbers, and a few of them exist specifically to trigger CVC outcomes:
stripe test card cvv validation
- 4242 4242 4242 4242: the standard success card. Any three-digit CVC and any future expiration date works.
- 4000 0000 0000 0101: the charge succeeds, but the CVC check returns a failure. This is the number you want when testing how your UI reacts to a soft mismatch.
- 4000 0000 0000 0127: the charge is declined with an incorrect CVC error.
- 4000 0000 0000 0002: a generic decline, useful for testing decline messaging that is not CVC related.
American Express test cards use a four-digit CVC. For example, 3782 822463 10005 accepts a four-digit code and rejects a three-digit one.
How to Read the CVC Result in Your Code
After you create a PaymentIntent or SetupIntent in test mode, the result is available in two places. On the charge, look at the card checks object for the CVC entry. On the PaymentMethod, look at the card details and read the cvc_check value. Your integration should treat a failed CVC as one signal among several rather than an automatic hard stop, since a mismatch can also come from a typo.
Failed CVC Versus Declined Charge
These are two different events, and the test numbers above let you rehearse both. A card like 4000 0000 0000 0101 authorizes the payment while flagging the CVC as failed, which is common in markets where issuers approve and let the merchant decide. A card like 4000 0000 0000 0127 returns a decline instead, so no funds are captured. Build separate handling for each path.
Limits of Test Mode
Test card numbers only work with test API keys. A live-mode request that uses a published test number is rejected, and a test-mode request cannot move real money. Test-mode CVC results are generated by Stripe, not by an issuing bank, so they confirm that your logic works rather than that a specific card is valid.
A Note on Real Card Data
Test numbers exist so that you never need a real card to test a payment flow. Handling real card numbers, CVCs, or full magnetic stripe data that you are not authorized to process breaks card network rules and PCI DSS requirements, and buying or selling that data is illegal in the United States. Keep test credentials in test mode and route every live transaction through a compliant processor.