Test card: short answer
A test card is a payment card number that a payment processor publishes for use in its sandbox. The number passes format checks, so developers can run charges, refunds, and declines without moving real money. Test cards work only against test API keys. A live key paired with a test number returns an error.
Where the numbers come from
Each processor keeps its own list. Stripe, Adyen, PayPal, and Braintree publish test numbers in their developer documentation. The lists cover card brands, card lengths, and response codes. A number that approves on one gateway can fail on another, because routing rules and BIN tables differ.
What a test card can trigger
- Approval, for the happy path.
- Decline codes, such as insufficient funds or expired card.
- 3D Secure challenges, for authentication flows.
- CVV and postal code mismatches.
- Disputes and chargebacks, on some platforms.
Format rules
Card numbers follow ISO/IEC 7812. The first six to eight digits are the issuer identification number. The last digit is a check digit computed by the Luhn algorithm. Test numbers satisfy Luhn, so a format validator accepts them. Test numbers are not tied to an issuer, so a BIN lookup returns no bank.
Expiry and CVC
Sandboxes accept most future expiry dates. Some gateways reject a past date on purpose, to exercise that code path. CVC length follows the brand: three digits for most cards, four for American Express. Test CVC values are set by the processor documentation.
3D Secure test cards
Processors publish separate numbers that force a challenge, a frictionless pass, or an authentication failure. The outcome is set by the number, not by your code. Teams use these to cover both branches of the authentication step.
Test cards do not belong in production
PCI DSS covers cardholder data in production environments. Test data falls out of scope only when no real account data is present. Do not paste live numbers into a sandbox, and do not commit test keys to a public repository. Rotate keys after any exposure.
Frequent errors
- Using a test number with a live key.
- Using a live number with a test key.
- Expecting one test number to work across gateways.
- Reading a decline as a broken integration. Check the documentation table first.