Short answer
A test CVV number is a fixed value that a payment processor assigns to a test card in a sandbox. It works against sandbox endpoints. Live endpoints reject it. The code does not come from a bank and it cannot check a real card. Stripe publishes test cards such as 4242 4242 4242 4242. In test mode those cards accept any 3-digit code, or a set value the processor documents.
What a CVV is
CVV stands for Card Verification Value. Visa, Mastercard, and Discover print 3 digits on the back of the card, inside the signature panel. American Express prints 4 digits on the front, above the card number. The issuer generates the code at card issue. The code is not encoded on the magnetic stripe and not stored on the chip.
How CVV verification works
In a card-not-present transaction, the merchant sends the card number, expiry date, and CVV in an authorization request. The issuer compares the submitted code with the code on file. The response is a match, no match, or not processed. The merchant does not verify the code. The issuer holds the data needed to compare.
No public algorithm maps a card number to its CVV. No tool validates a CVV offline. A site that claims to check a CVV sends the number to a live authorization system or collects it for fraud.
Storage rules
PCI DSS Requirement 3.2 prohibits storage of sensitive authentication data after authorization. That set includes the CVV, full track data, and the PIN block. A merchant that keeps CVV values in a database, log file, or CRM fails the requirement.
Test values in payment sandboxes
- Processors publish test card numbers with documented CVV values. Stripe test cards accept any CVC value in test mode.
- Some gateways require a fixed code, often 123 or 999, for a successful test charge.
- Test data works with test API keys and sandbox endpoints. A live key rejects test card numbers.
- Processors also publish decline cards that return specific error codes. Developers use those to test failure paths.
What testing a live card means
Running a card you do not own through an authorization request is unauthorized use of a payment card. In the United States, 18 U.S.C. 1029 covers fraud and related activity in connection with access devices. Penalties include fines and prison terms of up to 10 years for some offenses and 15 years for others. Buying or selling card data, CVVs included, falls under the same statute.
Issuers and networks monitor authorization attempts. Repeated failed CVV checks on one card trigger fraud alerts and account blocks.
For developers and merchants
Use the test suite your processor provides. Keep CVV fields out of logs, error reports, and analytics. Confirm the scope of your PCI DSS self-assessment questionnaire with your acquirer.
Open points
Rules differ by issuer and region. Some markets require the CVV for every card-not-present charge. Others let merchants skip it and accept higher fraud risk. Check the terms from your acquirer.