A payment gateway CVV test sends a sandbox transaction to confirm that the gateway captures the card verification value, checks its format, and returns a CVV result code. You run it with the gateway's own test card numbers, so no real card data enters the flow. The gateway replies with a value such as pass, fail, unavailable, or unchecked.
What does a CVV test check?
A CVV test covers three points: that your checkout collects the code, that your integration passes it to the gateway, and that your code reads the CVV response.
- Capture: the field accepts 3 digits for Visa, Mastercard, and Discover, and 4 digits for American Express.
- Transmission: the value reaches the API in the right parameter, named cvc, cvv2, or card_code depending on the gateway.
- Response handling: your app flags, blocks, or approves the order based on the returned code.
Test card numbers for CVV testing
Each gateway publishes its own test card list. Stripe is the common reference point because its cards are public and stable.
Stripe test cards
- 4242 4242 4242 4242: payment succeeds and cvc_check returns pass. Any 3 digits work as the CVC and any future expiry works.
- 4000 0000 0000 0101: payment is declined and cvc_check returns fail.
- 4000 0000 0000 0128: payment is declined with a CVC failure.
- 4000 0000 0000 0002: generic decline with no CVC signal.
Braintree and Authorize.Net
Braintree's sandbox uses card 4000 1111 1111 1111 and lets you force a CVV outcome through its test values. Authorize.Net test mode returns the standard CVV codes without contacting the issuer. Both gateways list the full table in their developer docs.
How do you run a CVV test?
- Switch the account to test or sandbox mode and use test API keys.
- Pick a test card from the gateway docs that maps to the CVV result you want.
- Submit a small charge with a future expiry date and the matching CVV.
- Read the CVV field in the API response (cvc_check, cvv_result, or cvv_response_code).
- Repeat with a failing card, then check that your app blocks or flags the order as planned.
Which CVV response codes should you map?
Gateways use different labels for the same idea. Map them once in your code, then test each branch.
Stripe cvc_check values
- pass: the CVC matches.
- fail: the CVC does not match.
- unavailable: the issuer returned no CVC result.
- unchecked: no CVC was sent or the check was skipped.
Authorize.Net and Braintree codes
Authorize.Net returns a single letter: M for match, N for no match, P for not processed, S for unsupported, U for unavailable, and X for a missing code. Braintree uses a similar letter set in its CVV response field. Treat anything other than M as a soft or hard decline based on your risk rules.
Why does a live CVV test fail?
- Test keys paired with a live card, or the reverse. The gateway blocks the mismatch.
- 3D Secure step-up. The charge pauses for authentication before any CVV result returns.
- AVS mismatch. Many gateways decline on an address failure before the CVV check runs.
- Wrong field name. A typo in the request sends an empty CVC and returns unchecked.
- Issuer rules. Some issuers in some regions return no CVV data at all.
How does test mode differ from live mode?
In test mode the gateway reads a test card number and returns a scripted CVV result. In live mode the gateway forwards the CVV to the issuer in the authorization request and passes back whatever the issuer says.
Live results depend on the issuer and the region. A US Visa issuer may return a match while a European issuer returns unavailable for the same checkout setup.
Should you store the CVV after a test?
No. PCI DSS forbids storing the CVV after authorization, even in encrypted form. Your test should confirm the value flows through and is dropped, not written to logs. Log the response code, never the code itself.
Can you test a real card's CVV?
No. A sandbox never contacts the card issuer, so it cannot verify a real card's CVV. Sending real card numbers through a live gateway to see which ones pass is card testing, and US law treats it as access device fraud under 18 U.S.C. 1029. Use gateway test cards only.
FAQ
What CVV do I use for test payments?
Any 3-digit value works with a Stripe test card such as 4242 4242 4242 4242, and the sandbox returns pass. For a failure case, use 4000 0000 0000 0101.
Do I need a sandbox to run a CVV test?
Yes. A gateway account in test mode is the standard path. Some providers also offer a hosted test console that needs no code.
Does a CVV test prove my checkout is secure?
No. It confirms the data path and your response handling. Security comes from tokenization, PCI DSS scope, and TLS in production.
Why does my gateway return unchecked for CVV?
Unchecked means the gateway received no CVC value. Check the request parameter name, the form field, and whether the payment method supports CVV, since some digital wallets do not.
Can I force a CVV failure in sandbox mode?
Yes. Most gateways ship a test card that returns a fail code. Stripe uses 4000 0000 0000 0101 for that case.