For nearly every Stripe test card you can enter any three-digit number as the verification code, and any four-digit number for American Express test cards. Stripe does not validate that value on standard test cards, so 123 works as well as any other number. The code is only checked when you use a card number that is designed to simulate a specific CVC outcome.
What the verification code does in test mode
The card verification code (also called CVC, CVV, or CID) is the short number printed on a physical card, separate from the card number. Payment forms require it because real issuers check it during authorization.
In test mode, none of that happens against a real issuer. Stripe uses test card numbers that map to programmed responses, so the form still asks for a code and still validates its format, but the value itself is usually ignored. Any three digits satisfy a Visa or Mastercard test card, and any four digits satisfy an Amex test card, as long as the length matches the card brand.
Stripe Test Card CVV Verification System: How CVC Checks Work in Test Mode
Which code to use with common Stripe test cards
- 4242 4242 4242 4242 (Visa, success): any three digits, any future expiry date, any postal code.
- 5555 5555 5555 4444 (Mastercard, success): any three digits.
- 3782 822463 10005 (American Express): any four digits.
- 4000 0000 0000 0002 (Visa, generic decline): any three digits, the decline comes back regardless of the code.
- 4000 0000 0000 9995 (Visa, insufficient funds): any three digits.
Expiry dates on test cards must be in the future. Most developers use a date several years ahead so the card keeps working.
Stripe CVV Test for Stripe Card
How to test a failed CVC check
A generic success card will always report a passing CVC check, so a failure has to come from a card number that Stripe documents as a CVC failure card. One commonly used example is 4000 0000 0000 0101, where the simulated issuer approves the charge but the CVC check comes back as failed.
That result appears on the charge object, not as a declined payment, so you can exercise the branch of your code that reads the CVC check field. Because the exact card number and required code can change, confirm the pairing on the Stripe testing reference page before you build an automated test around it.
Test mode compared with live mode
A test card verification code only exists in test mode. Test keys paired with test card numbers stay inside the sandbox and no money moves. A live key will reject a test card number, and a test key will not charge a real card. Keep the two sets of keys separate so your staging environment never touches live card data.
Common mistakes with Stripe test card verification codes
- Entering a real card number while using a test key, which fails instantly.
- Using an expiry date in the past, which triggers a validation error before any simulated response.
- Building a custom form that skips the CVC field, so validation fails before Stripe sees the request.
- Assuming the code controls approval on a generic test card. It does not.
- Mixing a test card number with a live publishable key, which produces a card error rather than a test charge.
Handling verification codes in your own code
Real verification codes are sensitive authentication data. PCI DSS rules prohibit storing them after authorization, and Stripe's APIs do not return the code on a charge or customer object. If you need to test a stored payment method, create it in test mode with a test card number and let Stripe hold the token.
Real card data should only ever come from the cardholder through a compliant form. Buying, selling, or sharing live card numbers and verification codes is card fraud, and test mode exists exactly so that no real card is needed to build and verify an integration.