Docs

Test cards

When a flow reaches a checkout, the agent pays with an official test card for your payment provider. Every number on this page comes from the provider's own docs, with a link to the source.

Set it up in three steps

  1. Pick your provider and scenarios

    Open Settings → Payments. Pick your provider and the scenarios to test. Success is always on. Add declines and 3D Secure to check that your app shows the right message.

    Pick the provider and the scenarios to cover.
  2. The agent checks for test mode, then pays

    Before it types a card, the live payment guard looks at the page for test mode signals. With a test key it pays. With a live key it stops. See Live payment guard.

    The run log shows the test key it found and the card it used.
  3. Read the result per scenario

    Each scenario passes when your app does the right thing: a confirmation for success, a clear error for a decline, and a working challenge for 3D Secure.

    One line per scenario. The failed one links to its screenshots and logs.

Cards per provider

Checked against the official docs on 2026-10-06. If a provider changes its test data, its docs win. When a scenario is triggered by a cardholder name or an amount instead of a card number, the table says so.

Stripe · Paddle Billing · PayPal · Braintree · Adyen · Checkout.com

Stripe

Any future expiry date and any 3 digit CVC (4 digits for Amex).

ScenarioCard numberNotes
Success 4242 4242 4242 4242 Visa
Generic decline 4000 0000 0000 0002 Visa card_declined / generic_decline
Insufficient funds 4000 0000 0000 9995 Visa card_declined / insufficient_funds
Expired card 4000 0000 0000 0069 Visa expired_card. The number triggers it, keep a future date.
3D Secure, always 4000 0027 6000 3184 Visa Asks for authentication on every payment
3D Secure, on session 4000 0025 0000 3155 Visa Asks for authentication unless the card is already set up

Test or live: Publishable key starts with pk_live_ (live) or pk_test_ (test).

Source: Stripe testingStripe API keys

Paddle Billing

Any cardholder name and a valid future expiry date.

ScenarioCard numberNotes
Success 4242 4242 4242 4242 Visa No 3D Secure
Success, debit 4000 0566 5566 5556 Visa debit
Generic decline 4000 0000 0000 0002 Visa
3D Secure 4000 0038 0000 0446 Visa Succeeds after the 3D Secure challenge
Later payments decline 4000 0027 6000 3184 Visa First payment succeeds, renewals decline

Paddle does not document test cards for insufficient funds or an expired card, so these scenarios are skipped for Paddle.

Test or live: Paddle.Environment.set("sandbox") on the page, and a client-side token that starts with test_ (sandbox) or live_ (production).

Source: Paddle card paymentsPaddle sandboxPaddle client-side tokensPaddle environment

PayPal

Future expiry date and any 3 digit CVV (4 digits for Amex). Decline triggers are case sensitive.

ScenarioCard numberNotes
Success 4012 8888 8888 1881 Visa
Success 2223 0000 4840 0011 Mastercard
Generic decline Any test card Any test card with cardholder name CCREJECT-BANK_ERROR
Insufficient funds Any test card Any test card with cardholder name CCREJECT-IF
Expired card Any test card Any test card with cardholder name CCREJECT-EC
3D Secure, frictionless 4868 7191 9682 9038 Visa
3D Secure, challenge 4868 7191 6610 1368 Visa Challenge succeeds
3D Secure, failed 4868 7191 8189 5556 Visa Challenge fails

Test or live: The SDK usually loads from www.paypal.com in both sandbox and live, and the client ID does not show which one it is. The guard treats PayPal as live unless the SDK loads from sandbox.paypal.com, the page uses client-id=sb, or you mark the client ID as sandbox in payment settings.

Source: PayPal card testingPayPal 3D Secure testingPayPal JS SDK configuration

Braintree

Declines are triggered by the amount, not the card. 3D Secure cards use expiry month 01 and the current year + 3.

ScenarioCard numberNotes
Success 4111 1111 1111 1111 Visa
Success 5555 5555 5555 4444 Mastercard
Generic decline Any test card Any valid test card with amount 2000.00
Insufficient funds Any test card Any valid test card with amount 2001.00
Expired card Any test card Any valid test card with amount 2004.00
3D Secure, frictionless 4000 0000 0000 2701 Visa
3D Secure, challenge 4000 0000 0000 2503 Visa Challenge succeeds
3D Secure, failed 4000 0000 0000 2370 Visa Challenge fails

Test or live: Tokenization key starts with sandbox_ or production_.

Source: Braintree testingBraintree processor responsesBraintree 3D Secure testingBraintree tokenization keys

Adyen

Expiry 03/2030 and CVC 737. Declines are triggered by the cardholder name.

ScenarioCard numberNotes
Success 4111 1111 1111 1111 Visa
Success 5555 5555 5555 4444 Mastercard
Generic decline Any test card Any test card with holder name DECLINED
Insufficient funds Any test card Any test card with holder name NOT_ENOUGH_BALANCE
Expired card Any test card Any test card with holder name CARD_EXPIRED
3D Secure, challenge 4212 3456 7891 0006 Visa Challenge password: password
3D Secure, frictionless 5201 2815 0512 9736 Mastercard

Test or live: Client key starts with test_ or live_. Test scripts and pages load from checkoutshopper-test hosts, such as checkoutshopper-test.cdn.adyen.com.

Source: Adyen test card numbersAdyen result codesAdyen 3D Secure testingAdyen client key

Checkout.com

Any future expiry date and any 3 digit CVV (4 digits for Amex).

ScenarioCard numberNotes
Success 4242 4242 4242 4242 Visa
Success 5436 0310 3060 6378 Mastercard
Generic decline 4539 4679 8710 9256 Visa 20005 Do not honour
Insufficient funds 4544 2491 6767 3670 Visa 20051
Expired card 4532 4460 3792 6437 Visa debit 20054. Use a past expiry date.
3D Secure, challenge 5137 2100 0000 0158 Mastercard
3D Secure, frictionless 4485 0403 7153 6584 Visa

Test or live: Sandbox public keys start with pk_sbox_. Sandbox API calls go to a {prefix}.api.sandbox.checkout.com host.

Source: Checkout.com test cardsCheckout.com API keys