Stripe test card CVV v1: the short answer

For the standard Stripe test card 4242 4242 4242 4242, the CVV is any three digits. Use 123, 456, or 000. Any future expiry date works, and any postal code or ZIP passes the address verification check.

read more

Stripe checks the shape of the value in test mode, not the value itself. Three digits pass. Two digits or five digits fail validation before the request reaches the card network simulator.

more on this topic

The same rule covers every non-American Express test card, including 5555 5555 5555 4444 for Mastercard, 6011 1111 1111 1117 for Discover, and 3566 0020 2036 0505 for JCB. American Express test cards such as 3782 822463 10005 use a four digit security code, so enter 1234.

read more

The "v1" label refers to Stripe's REST API surface, which is served under /v1 paths. Test card behavior stays the same across API versions, SDKs, and client libraries.

read more

Prerequisites

  • A Stripe account with access to the Dashboard
  • A test mode API key pair, which starts with pk_test_ and sk_test_
  • A test client, meaning the Stripe CLI, Postman, or your own code

Test cards only work against test keys. A test card number sent to a live key fails, and repeated attempts can trip your account's fraud controls.

Steps to run a test charge

  1. Open the Stripe Dashboard and turn on the Test mode toggle.
  2. Copy the test publishable key and the test secret key from the Developers section.
  3. Load your checkout page or API client with the test publishable key.
  4. Enter 4242 4242 4242 4242 in the card number field.
  5. Enter any future expiry date, for example 12/34.
  6. Enter 123 in the CVC field.
  7. Enter any five digit ZIP code in the postal code field.
  8. Submit the charge and confirm the response returns a succeeded status.
  9. Open the Payments list in the Dashboard and verify the charge appears under test mode.

Test cards that force a specific CVC result

Stripe publishes dedicated card numbers that trigger a chosen authorization outcome. Use them when you want to test your decline handling.

  • 4000 0000 0000 0101 returns a decline with a CVC check failure code.
  • 4000 0000 0000 0127 returns an incorrect CVC code.
  • 4000 0000 0000 0002 returns a generic card decline.
  • 4000 0000 0000 9995 returns insufficient funds.
  • 4000 0000 0000 0069 returns an expired card error.
  • 4000 0000 0000 0119 returns a processing error.

On these cards the CVC value you type still does not matter unless the card is built to fail the CVC check. The card number alone selects the outcome.

Rules that still apply in test mode

Test mode relaxes card values, not security obligations. Never store the CVC after an authorization, in test or live environments. PCI DSS treats the verification value as sensitive authentication data, so it cannot be retained once the transaction is complete.

Do not reuse test card numbers in production. Do not treat a passing test charge as proof that a live integration is compliant. Test mode bypasses issuer authentication unless you deliberately use a 3-D Secure test card such as 4000 0025 0000 3155.

Troubleshooting

If a test charge fails, check the error code before changing the card number. A stale API version in your request header can change how errors are worded, but it will not change which card succeeds. Confirm you are on test keys, confirm the CVC length matches the card brand, and confirm the expiry date is in the future.