Stripe test cards accept any CVC value and return a passing CVC check, so in test mode you validate the field format rather than a real cardholder code. To simulate a failed CVV verification, use the test card number 4000 0000 0000 0127, which returns a cvc_check value of fail. No issuer is contacted in test mode and no funds move.

read more

How does Stripe verify a card's CVV?

CVV verification happens during authorization. The network forwards the CVC, CVV2, or CID to the issuer, and the issuer replies with one of four results: pass, fail, unchecked, or unavailable.

Stripe Card CVV Test Tool: How to Evaluate One Before You Commit

Stripe exposes that result on the Charge or PaymentIntent as cvc_check. A failure can still authorize in live mode unless your Radar rules or manual review block it, so the value is a signal you must act on rather than an automatic stop.

related article

Which Stripe test card numbers control the CVV check result?

  • 4242 4242 4242 4242: Visa, any CVC, check passes.
  • 4000 0000 0000 0127: CVC check fails.
  • 4000 0000 0000 0002: generic decline.
  • 4000 0000 0000 0069: expired card.
  • 4000 0000 0000 9995: insufficient funds.
  • 5555 5555 5555 4444: Mastercard success.
  • 3782 822463 10005: American Express, uses a 4-digit CID.

Pair any success card with a future expiration date and a 3-digit CVC to force an approved test charge. Stripe also publishes dedicated 3D Secure test cards for authentication and challenge flows.

more on this topic

What CVV format rules apply in test mode?

Stripe validates length and character type before the request reaches the network. Visa, Mastercard, and Discover require 3 digits, while American Express uses a 4-digit CID printed on the front of the card.

A wrong length returns a card error with the code incorrect_cvc and never attempts authorization. This is a client-side validation failure, so it appears even when the card number and expiry are otherwise valid.

How do you read the CVC check result in your code?

Inspect cvc_check on the charge object or on the payment method's card details once the PaymentIntent reaches a terminal state. A result of pass means the issuer matched the code, fail means it did not, and unavailable means the issuer could not respond.

Log the result value, never the code itself. The CVC must not be written to databases, log files, analytics events, or support tickets.

Can you store a CVV after authorization?

No. PCI DSS prohibits retaining the card verification value after authorization, even when the data is encrypted or tokenized. Stripe Elements and the mobile SDKs transmit the CVC directly to Stripe so it never touches your servers, which keeps the field out of PCI DSS scope for SAQ A merchants.

Does test mode behave like live mode for CVV?

Validation rules and response codes mostly match, but test mode never reaches an issuer, so results are scripted instead of real. Radar risk scores, rate limits, and 3DS challenges are all simulated.

Re-run your CVC handling logic against a small set of live transactions before launch to confirm the behavior you tested still holds.