Short answer
Tokenization replaces a card number (PAN) with a token. The CVV is not part of that token. In a sandbox, a v2 tokenization endpoint issues a test token from a test card number, and the CVV field is ignored or checked against fixed test values. No live card data enters the flow.
What a token replaces
A payment token is a surrogate value for a 16-digit PAN. The token is scoped to one merchant, one channel, or one device. EMVCo maintains the Payment Tokenisation Specification Technical Framework, which defines the network tokens issued by card networks. The token maps back to the real PAN inside a token service provider vault. The merchant stores the token, not the PAN.
CVV Test Tokenization V9 Buying Guide
Tokens hold 16 digits in most gateway implementations and pass the Luhn check, so older systems accept them without code changes. The mapping runs one way from the merchant side: a token cannot be reversed into a PAN.
Why CVV is not tokenized
CVV, CVC2, and CID are sensitive authentication data under PCI DSS. The standard bars storage of sensitive authentication data after authorization, even in encrypted form. A token service provider cannot tokenize a value that merchants are forbidden to keep. Tokenized transactions carry no CVV for that reason.
Some flows send a cryptogram instead. 3-D Secure and network token transactions pass a dynamic cryptogram that expires with the transaction. That value is not a stored CVV and cannot be reused on a later authorization.
What v2 means here
The v2 in a tokenization endpoint is an API version label. It is not a card network standard. Gateways version their token APIs to change field names, response shapes, and error codes. A v2 token call returns a token object with a token ID, last four digits, expiry, and brand. It does not return a CVV.
Sandbox CVV behavior
- Test card numbers produce tokens in sandbox mode. Stripe publishes test tokens such as tok_visa and tok_mastercard.
- CVV fields in sandbox calls accept fixed test values, often 123, or any 3 digits, based on the gateway.
- Failed CVV checks are simulated with designated test card numbers.
- Sandbox tokens work in test mode and fail in live mode.
Checks before a test run
- Confirm the endpoint version in the gateway API reference.
- Use card numbers published by the gateway for testing.
- List the fields the token object returns.
- Record the request ID for each call.
CVV handling differs by gateway and by API version. Where a gateway does not document the rule, treat the behavior as unknown and confirm it in sandbox mode.