How to test a checkout form before you take real payments

How to test a checkout form before you take real payments

A checkout form has to reject a mistyped card number, accept every brand you support, and pass the numbers your payment sandbox expects. Generate numbers that pass the format check, then confirm what your form should accept and reject.

how to test a checkout form

What a payment form checks before the bank sees anything

Most payment forms check a card number before they contact a bank. They look at the first digits to find the brand, check that the length is allowed for that brand, and run the Luhn checksum, which catches a single wrong digit and most swaps of two neighbouring digits. A form that skips these checks sends obvious typos to the payment provider. A form that gets them wrong turns away good customers.

The brand rules are easy to get wrong. 4 is Visa. Mastercard uses 51 to 55 and also 2221 to 2720, a range added in 2017 that older validators still reject. 34 and 37 are American Express, which has 15 digits and a 4-digit CVV, while other brands use 3 digits. A form that hard-codes 16 digits or a 3-digit CVV breaks for Amex.

Real card numbers do not belong in a test. Payment sandboxes accept only their own documented test numbers, and special cases such as a declined card or 3-D Secure need the provider's specific numbers. A number that passes the format check is not a card. It is not linked to any account, and any real payment with it is declined.

Generate numbers, then check what the form accepts

Use the Test Card Number Generator to fill the form. Pick a brand and how many numbers you need, then press Generate. Each number starts with a real prefix for that brand, has random digits to the brand's length, and ends with the Luhn check digit, so it passes format validation. Each comes with an expiry date 12 to 60 months ahead and a CVV of the right length: 4 digits for American Express, 3 for the others. The numbers are made in your browser with crypto.getRandomValues and are not sent anywhere. For a payment sandbox, use the Official sandbox test numbers on the same page instead. In Stripe test mode, 4242 4242 4242 4242 with any future date and any CVC succeeds. In the Braintree sandbox, 4111 1111 1111 1111 is a Visa.

When a number fails and you need to know why, paste it into the Credit Card Validator. Spaces and dashes are fine. It shows the brand from the first digits, whether the Luhn check passes, whether the length is allowed, and the number grouped the way the brand prints it. 4111 1111 1111 1111 is a valid 16-digit Visa. 4111 1111 1111 1112 fails the Luhn check. 3782 822463 10005 is a valid 15-digit American Express, grouped 4-6-5. 2223 0031 2200 3222 is a valid Mastercard from the 2-series range. The check runs in your browser, and the number is never sent, stored, or logged. It confirms the format only. Whether a card exists or has funds is known only to the bank during a payment.

Test the card field on a checkout form

  1. Generate a few numbers for each brand you accept, including American Express, and paste them into the form one by one.
  2. Check that each brand is recognized, that a 15-digit Amex number is accepted, and that the CVV field asks for 4 digits for Amex and 3 for the others.
  3. Change one digit of a good number and confirm the form rejects it. Paste the changed number into the Credit Card Validator to see the failed Luhn check.
  4. Try a Mastercard number from the 2221 to 2720 range and confirm the form accepts it.
  5. For the full payment flow, switch to your provider's sandbox and use only the test numbers it documents, such as 4242 4242 4242 4242 in Stripe test mode.

What these two tools cannot test

  • Generated numbers pass format checks only. They are not real cards and cannot pay for anything.
  • Payment sandboxes accept only their own documented numbers. Declines and 3-D Secure need the provider's specific test numbers.
  • The validator checks format, not whether a card exists, is active, or has funds. Rare or new IIN ranges may show as Unknown.
  • Do not enter real card numbers you do not own. Both tools are for testing forms and fixing typos.

Frequently asked questions

Can a generated test card number be used to buy something?

No. It is not linked to any bank account, and any real payment with it is declined. It only passes the format check.

Which card number works in Stripe test mode?

4242 4242 4242 4242 with any future expiry date, any 3-digit CVC, and any postal code.

What is the Luhn check?

A checksum that every major card number passes. It catches a single wrong digit and most swaps of two neighbouring digits.

Why does my form reject a Mastercard that starts with 2?

Mastercard added the 2221 to 2720 range in 2017, and older validators still reject it. The form's brand rules need that range.

Tools used in this guide

More from the blog

All guides