What a PayPal sandbox CVV actually is
A PayPal sandbox CVV is the 3-digit verification code tied to a test card inside the PayPal developer sandbox. The sandbox is a working copy of the payments system that runs on fake buyer accounts, fake seller accounts, and fake money. Card numbers, expiry dates, and CVV values entered there cannot move real funds because no bank is attached to them.
Developers use these values to rehearse the parts of checkout that break in production: declined cards, 3D Secure prompts, refunds, partial captures, and webhook events. The data comes from PayPal's own testing tools, not from a card issuer.
Where do you get sandbox test cards and their CVVs?
PayPal publishes a table of test card numbers in its developer documentation, and the same values appear under Testing Tools in the developer dashboard. Each entry covers a brand, a card number, and the result that card is built to produce.
- Visa, Mastercard, American Express, and Discover test numbers
- CVV values listed next to each card
- Expiry dates you set in the future, since test cards do not age out
- Special cards that trigger declines, processor errors, or a 3D Secure challenge
Some test cards check the CVV and others accept any 3 digits. Use the published value when your test flow depends on a CVV match, and a placeholder like 123 when it does not.
Do sandbox CVVs work on real payments?
No. A sandbox CVV fails outside the sandbox because the card number behind it was never issued by a bank. Switch your integration from the sandbox API endpoint to the live endpoint and the same test data returns an error.
Test credentials also stop working inside the sandbox once you regenerate an app's client ID and secret or switch to a different sandbox account. Treat them as disposable, not as something to save in a shared document.
How to run a test checkout with a sandbox CVV
- Sign in to the PayPal developer dashboard and create a sandbox business account and a sandbox personal account.
- Create an app under those accounts and copy the client ID and secret into your staging configuration.
- Point your integration at the sandbox API base URL, not the live URL.
- Open the test card list and pick a card for the outcome you want to reproduce.
- Enter the card number, the future expiry date, and the matching CVV at checkout.
- Confirm the result in the sandbox activity log and check that your webhook listener received the event.
Repeat the run with a decline card to make sure your error handling shows the right message. A checkout that only passes happy-path tests will fail in front of a real customer.
Why does my sandbox CVV test fail?
You are hitting the live endpoint
A sandbox card number on the live endpoint returns a generic decline with no useful detail. Check the API base URL in your config first, because this is the most common cause.
The card is built to fail
PayPal test cards include numbers designed to simulate declines, expired cards, and processor faults. If the log shows a decline code, read the card description before you change your code.
No funding source on the buyer account
A sandbox buyer account needs a linked test card or a test balance before it can complete a payment. Create the buyer account through the dashboard so it arrives with test funds ready.
Mismatched environment keys
Client IDs and secrets are unique to each app and each environment. Mixing a sandbox key with a live account, or the reverse, produces authentication errors that look like card errors.
Should you ever use a real card CVV in a test environment?
No. Card verification values are sensitive authentication data under PCI DSS, and the standard forbids storing them after an authorization, let alone pasting them into a staging database or a support ticket. Sandbox testing exists so that no live card data ever touches a non-production system.
Buying card details from a third party to test with is also a crime in most jurisdictions, and it puts your own integration at risk of account termination. PayPal test cards cover the same scenarios at zero cost and zero legal exposure.
Frequently asked questions
Can I use 123 as a sandbox CVV?
Yes, for test cards that do not validate the code. Cards built to simulate a CVV mismatch need a different value, so check the documented entry for the card you picked.
Where is the CVV on a test card?
Test cards have no physical form, so there is no back of the card to read. The value sits in PayPal's published test card table, next to the number.
Does the sandbox store my test CVV?
Sandbox data is retained so you can review test transactions and debug webhooks. It is still good practice to keep test credentials out of public repos, since a leaked sandbox key can expose your integration setup.
How long do sandbox cards last?
They do not expire on their own, but PayPal can retire or change test card values when the platform updates. If a card stops working, pull the current list from the developer docs.
What to take away
Sandbox CVVs are test values for test cards, and they only function inside the PayPal developer environment. Pull them from the official test card list, keep your sandbox and live keys apart, and test the failure paths as well as the successes.