Skip to main content
Cresora Commerce
Testing & Sandbox

AVS and CVV

Drive AVS and CVV results in sandbox from the values typed on the hosted page.

AVS and CVV results are driven by what the cardholder types on the hosted payment page — the security code, the street address, and the ZIP. None of it is sent to the Cresora API, so these scenarios can only be exercised through a hosted page session.

CVV

999 approves. 111 declines. Both are first-party verified round-trips:

CVVHTTPstateResult field
999200CAPTUREDcv_response_code M
111200FAILEDdecline_code generic_decline

The declining value is the same on every network. The approving value belongs to the 99x family and differs per network — always pair a PAN with the code on its own row:

NetworkPANApproving CVV
Visa4012000098765439999
MasterCard5146315000000055998
Discover6011000993026909996
Amex3714496353923769997
ℹNote

CVV triggers fire only on CVV-present flows — that is, the hosted page, where the cardholder types the code. A charge against a stored token does not re-verify CVV and cannot exercise these scenarios at all.

AVS

Verified on Visa in sandbox. The address line and the ZIP each match or do not, independently, and the pair selects the AVS result:

AddressZIPAVSMeaning
832085284Yboth match
8320omitAaddress only
omit85284ZZIP only
832149855Nneither matches
omitomit0no AVS data

Omitting both is worth testing on its own: 0 is not a pass, it is the absence of a check, and a merchant policy may treat it differently from Y.

An AVS or CVV mismatch can decline the payment

ℹNote

On a cardholder-initiated charge — use_type: ONE_TIME_FUTURE — the merchant's AVS policy is applied. A mismatch can decline the transaction. Both avs_mismatch and cvv_mismatch exist as decline codes, and your integration must handle them.

So do not build on the assumption that a mismatch is advisory. The outcome depends on the merchant's configured policy, which means the same PAN and the same amount can approve for one merchant and fail for another. Read the result at runtime:

  • state — CAPTURED or FAILED, as for any other outcome.
  • decline_code — avs_mismatch or cvv_mismatch when the policy rejected the verification result.

Testing checklist

  • One approval: matching address and ZIP, the network's 99x CVV.
  • One CVV decline: 111, everything else valid.
  • One AVS mismatch: 8321 with 49855, against a merchant whose policy rejects N.
  • One no-data case: omit address and ZIP, expect 0.

Run these through the flow on test cards, and check the required set in certification scenarios.