Docs
Test cards
When a flow reaches a checkout, the agent pays with an official test card for your payment provider. Every number on this page comes from the provider's own docs, with a link to the source.
Set it up in three steps
-
Pick your provider and scenarios
Open Settings → Payments. Pick your provider and the scenarios to test. Success is always on. Add declines and 3D Secure to check that your app shows the right message.
Pick the provider and the scenarios to cover. -
The agent checks for test mode, then pays
Before it types a card, the live payment guard looks at the page for test mode signals. With a test key it pays. With a live key it stops. See Live payment guard.
The run log shows the test key it found and the card it used. -
Read the result per scenario
Each scenario passes when your app does the right thing: a confirmation for success, a clear error for a decline, and a working challenge for 3D Secure.
One line per scenario. The failed one links to its screenshots and logs.
Cards per provider
Checked against the official docs on 2026-10-06. If a provider changes its test data, its docs win. When a scenario is triggered by a cardholder name or an amount instead of a card number, the table says so.
Stripe · Paddle Billing · PayPal · Braintree · Adyen · Checkout.com
Stripe
Any future expiry date and any 3 digit CVC (4 digits for Amex).
| Scenario | Card number | Notes |
|---|---|---|
| Success | 4242 4242 4242 4242 Visa | |
| Generic decline | 4000 0000 0000 0002 Visa | card_declined / generic_decline |
| Insufficient funds | 4000 0000 0000 9995 Visa | card_declined / insufficient_funds |
| Expired card | 4000 0000 0000 0069 Visa | expired_card. The number triggers it, keep a future date. |
| 3D Secure, always | 4000 0027 6000 3184 Visa | Asks for authentication on every payment |
| 3D Secure, on session | 4000 0025 0000 3155 Visa | Asks for authentication unless the card is already set up |
Test or live: Publishable key starts with pk_live_ (live) or pk_test_ (test).
Source: Stripe testingStripe API keys
Paddle Billing
Any cardholder name and a valid future expiry date.
| Scenario | Card number | Notes |
|---|---|---|
| Success | 4242 4242 4242 4242 Visa | No 3D Secure |
| Success, debit | 4000 0566 5566 5556 Visa debit | |
| Generic decline | 4000 0000 0000 0002 Visa | |
| 3D Secure | 4000 0038 0000 0446 Visa | Succeeds after the 3D Secure challenge |
| Later payments decline | 4000 0027 6000 3184 Visa | First payment succeeds, renewals decline |
Paddle does not document test cards for insufficient funds or an expired card, so these scenarios are skipped for Paddle.
Test or live: Paddle.Environment.set("sandbox") on the page, and a client-side token that starts with test_ (sandbox) or live_ (production).
Source: Paddle card paymentsPaddle sandboxPaddle client-side tokensPaddle environment
PayPal
Future expiry date and any 3 digit CVV (4 digits for Amex). Decline triggers are case sensitive.
| Scenario | Card number | Notes |
|---|---|---|
| Success | 4012 8888 8888 1881 Visa | |
| Success | 2223 0000 4840 0011 Mastercard | |
| Generic decline | Any test card | Any test card with cardholder name CCREJECT-BANK_ERROR |
| Insufficient funds | Any test card | Any test card with cardholder name CCREJECT-IF |
| Expired card | Any test card | Any test card with cardholder name CCREJECT-EC |
| 3D Secure, frictionless | 4868 7191 9682 9038 Visa | |
| 3D Secure, challenge | 4868 7191 6610 1368 Visa | Challenge succeeds |
| 3D Secure, failed | 4868 7191 8189 5556 Visa | Challenge fails |
Test or live: The SDK usually loads from www.paypal.com in both sandbox and live, and the client ID does not show which one it is. The guard treats PayPal as live unless the SDK loads from sandbox.paypal.com, the page uses client-id=sb, or you mark the client ID as sandbox in payment settings.
Source: PayPal card testingPayPal 3D Secure testingPayPal JS SDK configuration
Braintree
Declines are triggered by the amount, not the card. 3D Secure cards use expiry month 01 and the current year + 3.
| Scenario | Card number | Notes |
|---|---|---|
| Success | 4111 1111 1111 1111 Visa | |
| Success | 5555 5555 5555 4444 Mastercard | |
| Generic decline | Any test card | Any valid test card with amount 2000.00 |
| Insufficient funds | Any test card | Any valid test card with amount 2001.00 |
| Expired card | Any test card | Any valid test card with amount 2004.00 |
| 3D Secure, frictionless | 4000 0000 0000 2701 Visa | |
| 3D Secure, challenge | 4000 0000 0000 2503 Visa | Challenge succeeds |
| 3D Secure, failed | 4000 0000 0000 2370 Visa | Challenge fails |
Test or live: Tokenization key starts with sandbox_ or production_.
Source: Braintree testingBraintree processor responsesBraintree 3D Secure testingBraintree tokenization keys
Adyen
Expiry 03/2030 and CVC 737. Declines are triggered by the cardholder name.
| Scenario | Card number | Notes |
|---|---|---|
| Success | 4111 1111 1111 1111 Visa | |
| Success | 5555 5555 5555 4444 Mastercard | |
| Generic decline | Any test card | Any test card with holder name DECLINED |
| Insufficient funds | Any test card | Any test card with holder name NOT_ENOUGH_BALANCE |
| Expired card | Any test card | Any test card with holder name CARD_EXPIRED |
| 3D Secure, challenge | 4212 3456 7891 0006 Visa | Challenge password: password |
| 3D Secure, frictionless | 5201 2815 0512 9736 Mastercard |
Test or live: Client key starts with test_ or live_. Test scripts and pages load from checkoutshopper-test hosts, such as checkoutshopper-test.cdn.adyen.com.
Source: Adyen test card numbersAdyen result codesAdyen 3D Secure testingAdyen client key
Checkout.com
Any future expiry date and any 3 digit CVV (4 digits for Amex).
| Scenario | Card number | Notes |
|---|---|---|
| Success | 4242 4242 4242 4242 Visa | |
| Success | 5436 0310 3060 6378 Mastercard | |
| Generic decline | 4539 4679 8710 9256 Visa | 20005 Do not honour |
| Insufficient funds | 4544 2491 6767 3670 Visa | 20051 |
| Expired card | 4532 4460 3792 6437 Visa debit | 20054. Use a past expiry date. |
| 3D Secure, challenge | 5137 2100 0000 0158 Mastercard | |
| 3D Secure, frictionless | 4485 0403 7153 6584 Visa |
Test or live: Sandbox public keys start with pk_sbox_. Sandbox API calls go to a {prefix}.api.sandbox.checkout.com host.