AVS and CVV
Drive AVS and CVV results in sandbox from the values typed on the hosted page.
AVS and CVV results are driven by what the cardholder types on the hosted payment page — the security code, the street address, and the ZIP. None of it is sent to the Cresora API, so these scenarios can only be exercised through a hosted page session.
CVV
999 approves. 111 declines. Both are first-party verified
round-trips:
| CVV | HTTP | state | Result field |
|---|---|---|---|
999 | 200 | CAPTURED | cv_response_code M |
111 | 200 | FAILED | decline_code generic_decline |
The declining value is the same on every network. The approving value
belongs to the 99x family and differs per network — always pair a PAN
with the code on its own row:
| Network | PAN | Approving CVV |
|---|---|---|
| Visa | 4012000098765439 | 999 |
| MasterCard | 5146315000000055 | 998 |
| Discover | 6011000993026909 | 996 |
| Amex | 371449635392376 | 9997 |
CVV triggers fire only on CVV-present flows — that is, the hosted page, where the cardholder types the code. A charge against a stored token does not re-verify CVV and cannot exercise these scenarios at all.
AVS
Verified on Visa in sandbox. The address line and the ZIP each match or do not, independently, and the pair selects the AVS result:
| Address | ZIP | AVS | Meaning |
|---|---|---|---|
8320 | 85284 | Y | both match |
8320 | omit | A | address only |
| omit | 85284 | Z | ZIP only |
8321 | 49855 | N | neither matches |
| omit | omit | 0 | no AVS data |
Omitting both is worth testing on its own: 0 is not a pass, it is the
absence of a check, and a merchant policy may treat it differently from
Y.
An AVS or CVV mismatch can decline the payment
On a cardholder-initiated charge — use_type: ONE_TIME_FUTURE — the
merchant's AVS policy is applied. A mismatch can decline the
transaction. Both avs_mismatch and cvv_mismatch exist as decline
codes, and your integration must handle them.
So do not build on the assumption that a mismatch is advisory. The outcome depends on the merchant's configured policy, which means the same PAN and the same amount can approve for one merchant and fail for another. Read the result at runtime:
state—CAPTUREDorFAILED, as for any other outcome.decline_code—avs_mismatchorcvv_mismatchwhen the policy rejected the verification result.
Testing checklist
- One approval: matching address and ZIP, the network's
99xCVV. - One CVV decline:
111, everything else valid. - One AVS mismatch:
8321with49855, against a merchant whose policy rejectsN. - One no-data case: omit address and ZIP, expect
0.
Run these through the flow on test cards, and check the required set in certification scenarios.