Test cards
The Sandbox environment accepts registered test cards only. A real card number is refused at tokenization — before it is stored, and before any provider sees it — so you can integrate against Sandbox without ever handling live card data.
Use any future expiry date and any CVC with the numbers below. The cardholder name is free text unless a card's notes say otherwise.
Which cards apply to you
Sandbox routes your payments the same way Live does, so which acquirer authorizes your test payment
depends on your account's routing — and the same card number can mean different things at different
acquirers. Read the provider field on the resulting transaction (it also
appears in the payment webhook payload) and use the section with that
name.
If you have not run a payment yet, ask support which provider your Sandbox account is routed to.
Reading the tables
- Result — whether the payment reaches
succeededor is declined. decline_code— the normalized code the transaction carries when it is declined. It is the same provider-agnostic vocabulary described in Decline codes, so your handling ofinsufficient_fundsis identical whichever acquirer produced it.- Notes — what the acquirer itself calls the scenario, so their documentation is easy to cross-reference.
Sandbox matches the whole card number, not just its first digits. A number copied from an acquirer's documentation — or a real card that happens to share a prefix with a test card — is rejected, and no token is created.
Nuvei
| Card number | Scheme | Result | decline_code | Notes |
|---|---|---|---|---|
4761 3441 3614 1390 | Visa | Succeeds | — | Non-3DS approval |
4244 9519 0100 5043 | Visa | Succeeds | — | Non-3DS approval |
4001 8886 8741 2469 | Visa | Succeeds | — | Non-3DS approval |
4000 2874 4738 6587 | Visa | Succeeds | — | Non-3DS approval |
4263 7046 3747 3241 | Visa | Succeeds | — | Non-3DS approval |
5221 7442 5052 5131 | Mastercard | Succeeds | — | Non-3DS approval |
5550 3438 7585 1690 | Mastercard | Succeeds | — | Non-3DS approval |
5413 0373 4073 6315 | Mastercard | Succeeds | — | Non-3DS approval |
5256 7871 7232 2309 | Mastercard | Succeeds | — | Non-3DS approval |
3755 105131 69537 | American Express | Succeeds | — | Non-3DS approval (15-digit PAN) |
3742 451718 46495 | American Express | Succeeds | — | Non-3DS approval (15-digit PAN) |
6011 4054 3345 5453 | Discover | Succeeds | — | Non-3DS approval |
6011 4945 8524 1663 | Discover | Succeeds | — | Non-3DS approval |
3612 5698 5608 8370 | Diners Club | Succeeds | — | Non-3DS approval |
6233 0527 0322 5398 | UnionPay | Succeeds | — | Non-3DS approval |
4485 0761 9129 4772 | Visa | Declined | card_lost_or_stolen | Lost or stolen card |
4344 1415 1067 1174 | Visa | Declined | generic_decline | Do not honor |
4000 1739 4619 4872 | Visa | Declined | insufficient_funds | Insufficient funds |
4000 2489 7322 1309 | Visa | Declined | expired_card | Expired card |
4521 1079 3879 6906 | Visa | Declined | invalid_cvc | Invalid CVV |
4107 6526 5195 0141 | Visa | Declined | three_ds_required | Soft decline - authentication advised |
5569 2699 6354 3635 | Mastercard | Declined | card_lost_or_stolen | Lost or stolen card |
5221 4224 8657 4534 | Mastercard | Declined | insufficient_funds | Insufficient funds |
5470 7132 9967 6435 | Mastercard | Declined | expired_card | Expired card |
5333 5820 3942 2930 | Mastercard | Declined | invalid_cvc | Invalid CVV |
3755 237581 57927 | American Express | Declined | card_lost_or_stolen | Lost or stolen card |
3755 262459 63088 | American Express | Declined | insufficient_funds | Insufficient funds |
4000 0231 6489 2261 | Visa | Succeeds | — | 3DS card; approves after authentication |
4021 9371 9565 8109 | Visa | Declined | three_ds_required | 3DS card; soft decline - authentication advised |
4871 0401 1654 3210 | Visa | Declined | card_lost_or_stolen | 3DS card; declines as stolen |
5408 4589 4706 7358 | Mastercard | Succeeds | — | 3DS card; approves after authentication |
5353 0296 0225 4618 | Mastercard | Succeeds | — | 3DS card; approves after authentication |
4000 0209 5159 5032 | Visa | Succeeds | — | Frictionless 3DS flow (cardHolderName FL-BRW1; amount >= 150) |
2221 0081 2367 7736 | Mastercard | Succeeds | — | Challenge 3DS flow (cardHolderName CL-BRW2; amount 151) |
4567 4910 0000 1113 | Visa | Succeeds | — | Frictionless 3DS flow (amount 83.1) |
4567 4910 0000 2228 | Visa | Succeeds | — | Challenge 3DS flow (amount 115.2) |
5545 0607 0000 1113 | Mastercard | Succeeds | — | Frictionless 3DS flow (amount 83.1) |
5545 0607 0000 2228 | Mastercard | Succeeds | — | Challenge 3DS flow (amount 115.2) |
Nuvei publishes a longer list in their testing documentation. Those numbers are not accepted in the Orchestr sandbox until we register them — tell support which scenario you need and we will add it.
Stripe
| Card number | Scheme | Result | decline_code | Notes |
|---|---|---|---|---|
4242 4242 4242 4242 | Visa | Succeeds | — | Successful payment |
4242 4242 4242 4242 | Visa | Succeeds | — | 3DS supported but the card is not enrolled |
4000 0566 5566 5556 | Visa | Succeeds | — | Successful payment on a debit card |
5555 5555 5555 4444 | Mastercard | Succeeds | — | Successful payment |
2223 0031 2200 3222 | Mastercard | Succeeds | — | Successful payment on a 2-series Mastercard |
5200 8282 8282 8210 | Mastercard | Succeeds | — | Successful payment on a debit card |
5105 1051 0510 5100 | Mastercard | Succeeds | — | Successful payment on a prepaid card |
3782 822463 10005 | American Express | Succeeds | — | Successful payment (15-digit PAN) |
3782 822463 10005 | American Express | Succeeds | — | 3DS is not supported on this card |
3714 496353 98431 | American Express | Succeeds | — | Successful payment (15-digit PAN) |
6011 1111 1111 1117 | Discover | Succeeds | — | Successful payment |
6011 0009 9013 9424 | Discover | Succeeds | — | Successful payment |
3056 9300 0902 0004 | Diners Club | Succeeds | — | Successful payment |
3566 0020 2036 0505 | JCB | Succeeds | — | Successful payment |
6200 0000 0000 0005 | UnionPay | Succeeds | — | Successful payment |
4000 0082 6000 0000 | Visa | Succeeds | — | Successful payment on a UK card |
4000 0025 0000 0003 | Visa | Succeeds | — | Successful payment on a French card |
4000 0027 6000 0016 | Visa | Succeeds | — | Successful payment on a German card |
4000 0000 0000 0002 | Visa | Declined | generic_decline | card_declined / generic_decline |
4000 0000 0000 9995 | Visa | Declined | insufficient_funds | card_declined / insufficient_funds |
4000 0000 0000 9987 | Visa | Declined | card_lost_or_stolen | card_declined / lost_card |
4000 0000 0000 9979 | Visa | Declined | card_lost_or_stolen | card_declined / stolen_card |
4000 0000 0000 0069 | Visa | Declined | expired_card | expired_card |
4000 0000 0000 0127 | Visa | Declined | invalid_cvc | incorrect_cvc |
4000 0000 0000 0119 | Visa | Declined | processing_error | processing_error |
4000 0000 0000 6975 | Visa | Declined | velocity_limit_exceeded | card_declined / card_velocity_exceeded |
4000 0000 0000 3055 | Visa | Succeeds | — | 3DS supported and optional; authentication succeeds |
4000 0084 0000 0027 | Visa | Succeeds | — | 3DS authentication required and succeeds |
4000 0084 0000 1629 | Visa | Declined | generic_decline | 3DS authentication required; the payment then declines |
Stripe publishes a longer list in their testing documentation. Those numbers are not accepted in the Orchestr sandbox until we register them — tell support which scenario you need and we will add it.
Testing 3-D Secure
The cards marked as requiring authentication trigger a real 3-D Secure challenge in Sandbox. See
Card payments for the confirmCardPayment() flow that handles it.
How the challenge appears depends on your account's presentation mode — inline, in a popup, or as a full-page redirect. Don't assume inline when testing: a redirect navigates away from your page, and an integration that keeps state in JavaScript will notice. If you charge a token from your server instead, the challenge reaches you as a 3-D Secure action rather than through the SDK at all.
A card that declines after authentication is worth testing explicitly: authentication succeeding
is not the same as the payment succeeding, and your integration should not treat a completed
challenge as a result. The authoritative outcome is always the payment.*
webhook.
Cards that cannot be registered
Acquirers publish some numbers that deliberately fail the Luhn checksum — Stripe's "incorrect number" card, for example. Those cannot be registered as test cards, and they do not need to be: card-number validation rejects them in the browser, before any request is made, which is the behaviour they were meant to demonstrate.
Next steps
- Card payments — the full Orchestr.js integration.
- Decline codes — the vocabulary the
decline_codecolumn uses. - Webhooks — the
payment.*events that carry the final result.