What CVV do Stripe test cards use?
Stripe test cards accept any 3-digit CVC in test mode. Enter 123, 000, or 999 and a standard test card such as 4242 4242 4242 4242 still returns a successful charge. For American Express test cards, which use a 4-digit CID, enter any four digits.
Stripe Test Card CVV V10 Buying Guide
There is no separate "v4" CVV value issued by Stripe. The term usually refers to the four digit CID printed on Amex cards, or to a POS terminal software version, not to a verification code that Stripe generates for test purposes.
Does Stripe actually validate CVC on test cards?
By default, no. Successful test card numbers skip the CVC check entirely, so the value you type has no effect on the outcome. Stripe only simulates a CVC result when you deliberately use a card number built to fail that check.
- 4000 0000 0000 0101: the CVC check returns a failed result on the card
- 4000 0000 0000 0127: the charge declines with the code incorrect_cvc
- 4000 0027 6000 3184: requires 3D Secure authentication before the payment completes
After a charge attempt, inspect the cvc_check field on the response. It reports pass, fail, unchecked, or unavailable, which is how you confirm your failure handling works.
Why do some test cards ask for a "v4" code?
Card verification codes differ by network. Visa, Mastercard, and Discover print a 3-digit CVV2 or CVC2 on the signature panel, while American Express uses a 4-digit CID on the front of the card.
Stripe exposes a single CVC input field for all networks, and it accepts either length in test mode. That flexibility is why a four digit entry can look like a distinct "version 4" format rather than the Amex CID it really is.
How do you test CVC failure handling step by step?
- Switch your integration to test mode API keys so no real money or real card data is involved.
- Create a payment method with a documented CVC failure test card, such as 4000 0000 0000 0127.
- Send the charge or PaymentIntent request and read back
cvc_checkand the decline code. - Confirm your checkout shows a clear retry message instead of a generic error.
Repeat the run with a normal card like 4242 4242 4242 4242 to verify the success path still works with the same code.
What should you never do with test card data?
Only ever use card numbers published in Stripe's testing documentation. Real card numbers and their verification codes are sensitive authentication data, and PCI DSS forbids storing them after authorization.
Test mode exists to validate your integration logic, not to check whether a card is live. Attempting to verify real card details against any processor is illegal and will get your account terminated.