CVV Test Response Code: Sandbox Codes Explained

A CVV test response code is the value a payment gateway returns in a sandbox to report whether the card verification value matched during a simulated transaction. Codes such as M (match), N (no match), P (not processed), S (issuer does not support verification), and U (unknown or not applicable) let developers confirm how a checkout flow handles each verification result without touching a live card.

What do the standard CVV test response codes mean?

Most processors use the same single-letter vocabulary for card verification results, so the same five codes appear across gateways.

How do test CVV values work in a sandbox?

Payment gateways publish test card numbers paired with the CVV values that trigger a specific response. A three-digit value covers most card brands, while American Express uses four digits. Trigger values differ by provider, so always confirm the exact numbers in that gateway's own test documentation before writing assertions.

How are CVV codes different from AVS response codes?

AVS verifies the billing address, while CVV verifies the card itself. Address checks return letter and number strings such as Y, A, or Z, and they arrive in a separate response field from the CVV result. A transaction can pass one check and fail the other, which is why sandbox suites test the two fields independently.

Which decline codes appear alongside CVV test results?

Verification often runs before authorization, so a test case can return both a CVV letter and a decline number. Common decline codes in sandbox datasets include:

  1. 05, do not honor
  2. 14, invalid card number
  3. 51, insufficient funds
  4. 54, expired card
  5. 82, CVV validation failed

Can you use a real card's CVV for testing?

No. PCI DSS classifies the CVV as sensitive authentication data that must never be stored after authorization, and sandbox testing exists precisely to keep real cardholder data out of development and staging systems. Buying, selling, or trading live card numbers and CVVs is illegal in the United States and most other jurisdictions, so a storefront advertising real CVV data is offering stolen data rather than a testing tool. Legitimate testing always uses gateway-issued test numbers and sandbox-only values.

More

Read our complete guide: Buy CVV Cheap: Pricing, Risks, and What First-Time Buyers Need to Know