Short answer
A dummy CVV is a test security code for a payment gateway sandbox. It authorizes nothing on a live account. Stripe test cards take any 3-digit CVC on Visa, Mastercard, and Discover, and any 4-digit CID on American Express. Adyen test cards pair 4111 1111 1111 1111 with CVC 737. These values run inside a test environment that no bank sees.
Dummy CVV in Virtual Card Creation: What to Buy and What to Avoid
Test card sets by provider
- Stripe: 4242 4242 4242 4242 with any 3-digit CVC and any future expiry date.
- Adyen: 4111 1111 1111 1111 with CVC 737 and expiry 03/2030.
- Braintree: 4000 1111 1111 1111 with any CVC in the sandbox.
- PayPal: sandbox buyer accounts skip card entry in most hosted flows.
CVC failure cases
Stripe assigns decline reasons to test card numbers. 4000 0000 0000 0127 returns incorrect_cvc. 4000 0000 0000 0002 returns a generic decline. 4000 0000 0000 9995 returns insufficient funds. 4000 0000 0000 0069 returns an expired card. Use these numbers to test your error handling and your retry logic.
Rules that apply to real CVVs
PCI DSS Requirement 3.2 bans storage of sensitive authentication data after authorization. That data covers the full track, the CVV, and the PIN block. A gateway that holds a real CVV past the auth step fails a compliance audit. Test values carry no such risk because they map to no account.
Checks before you run a test
- Confirm test mode is on. A live key with a test card number returns a decline or fails the Luhn check.
- Match the CVC length to the brand. Amex uses 4 digits, other brands use 3.
- Set a future expiry date. Past dates fail before the CVC check runs.
- Verify that your sandbox validates CVC at all. Some providers skip the check in test mode unless you enable it.
- Log the gateway response code, not the CVC.
What is not public
Visa and Mastercard do not publish one universal dummy CVV. Test values come from each provider. Numbers and CVC values change when a provider updates its docs, so read the current test card page for your gateway.