What Is CVV Test Tokenization v6?

CVV test tokenization v6 means running card verification value checks against version 6 test tokens inside a payment sandbox. The token replaces the card number, so you can test CVV logic without exposing live card data. The CVV itself is never tokenized, stored, or written to a database.

cvv test tokenization v4

Developers meet this topic when a processor ships a new token vault release and last quarter's test tokens stop working. Version labels come from the vault or network spec, not from the card brands.

cvv test tokenization v1

Why a CVV Can Never Be Part of a Token

A token is a surrogate for the primary account number. It is not a container for the whole magnetic stripe or chip record.

more on this topic

  • CVV, CVV2, CVC2, and CAV2 are sensitive authentication data under PCI DSS.
  • Requirement 3.2 forbids storing sensitive authentication data after authorization, even in encrypted form.
  • A vault may hold the PAN or a network token, but the CVV is discarded once the issuer responds.
  • Any system that keeps CVV values after the auth response fails a PCI assessment.

So "CVV test tokenization" is a loose phrase. What you are testing is whether your integration handles a token in the PAN field and a CVV in the verification field.

cvv test tokenization v4

What Does the v6 Label Mean?

The version number tracks the tokenization specification or the vault API, not a card brand. Acquirers, gateways, and card networks each publish their own releases.

  • Request and response formats
  • New decline codes and reason strings
  • Key rotation and key version handling
  • Token domain restrictions (ecommerce, recurring, card on file)
  • Token lifetime and expiry rules

A v6 token from one processor will not work at another. Ask your provider for the spec sheet and the sandbox token list before you write code.

Test Tokens vs Test Card Numbers

Both live in a sandbox. They fail in different ways when your integration is wrong.

  • Test card numbers pass the Luhn check and trigger issuer responses. Use them when you want a CVV mismatch on purpose.
  • Test tokens look like random strings. They confirm your vault calls, token lookup, and detokenization path.
  • Network test tokens follow the EMVCo token format and exercise provisioning flows.

Run both. A pass on test card numbers tells you nothing about token plumbing.

How to Run a CVV Token Test in a Sandbox

  1. Get sandbox credentials and the v6 test token list from your processor.
  2. Put the token in the PAN field and a test CVV in the verification field.
  3. Send an authorization for a small amount, often 1.00 in the sandbox currency.
  4. Log the response code and the raw response, minus the CVV.
  5. Check that your logger, traces, and error reports hold neither the CVV nor the full token.
  6. Repeat with an expired token, a wrong merchant ID, and a stale key version to see the failure paths.

Response Codes You Will See

  • 00: approval. Token resolved, CVV matched.
  • 05: do not honor. Issuer or simulator decline.
  • 51: insufficient funds.
  • 54: expired card. Test tokens often carry a fixed expiry date.
  • N7: CVV mismatch. The most useful code in a CVV test.
  • 65: soft decline, retry rules apply.

What Breaks in v6 Token Tests

Most failures come from configuration, not from code.

  • Expired test tokens from the previous spec version.
  • Merchant ID or token requestor ID not registered for the sandbox.
  • Key version mismatch between your request and the vault.
  • A CVV required flag set on a recurring or card-on-file transaction.
  • Amount limits that reject token-based auths above a threshold.

Security Rules That Apply in Test Too

Sandbox traffic still moves through production patterns and sometimes production infrastructure.

  • Never load a live PAN or a live CVV into a test vault.
  • Keep test and production keys in separate stores.
  • Scrub CVV from logs at the point of write, not later.
  • Restrict who can read the token list.

FAQ

Can I store a CVV if the card number is tokenized?

No. Tokenization covers the account number, not the verification value. PCI DSS treats the CVV as data you must not retain after authorization, with no exception for tokenized transactions.

Are v6 test tokens transferable between processors?

No. Tokens bind to the vault, the requestor ID, and the merchant account that created them. Copying a token string into another gateway produces a lookup failure.

Do test tokens expire?

Many vaults expire test tokens after 30 to 90 days and rotate keys on a set schedule. If a test that passed last month fails today, check token expiry and key version first.

Is a token the same as encryption?

No. Encryption is reversible with a key, while a token has no mathematical link to the card number. The vault holds the mapping, which is why a stolen token has limited value outside its domain.