Skip to main content
Cresora Commerce
Testing & Sandbox

Test cards

The four canonical sandbox PANs, and how to run an approval and a decline.

Sandbox card testing uses four PANs — one per network — entered on the hosted payment page. The PAN chooses which network processes the transaction. The amount chooses whether it approves or declines.

The four canonical cards

All expire 12/28. Use the CVV on the same row: each network has its own approving value.

NetworkPANCVV
Visa4012000098765439999
MasterCard5146315000000055998
Discover6011000993026909996
Amex3714496353923769997
ℹNote

Never send a PAN to the Cresora API. There is no card object on any request body and a raw PAN is rejected with 400. Card data is typed into the hosted page only.

Run an approval end to end

1. Create the session

curl
curl -X POST https://api.sandbox.cresoracommerce.ai/api/v1/hpp/sessions \
  -H "Authorization: Bearer $CRESORA_API_KEY" \
  -H "Idempotency-Key: $(uuidgen)" \
  -H "Content-Type: application/json" \
  -d '{"merchant_id": "<uuid>", "amount": "10.00", "currency": "USD"}'

The response carries the page to open:

{
  "hpp_url": "<open this URL in a browser>"
}

2. Enter the values on the page

Open hpp_url, then type PAN 4012000098765439, expiry 12/28, CVV 999. Submit.

3. Read the outcome

Poll the session's status or handle the completion webhook for your subscription. An approval looks like this:

{
  "state": "CAPTURED"
}

Run a decline end to end

Change one thing: the amount. Repeat the steps above with an amount of 0.20, a fresh Idempotency-Key, and the same card. The result is still HTTP 200:

{
  "state": "FAILED",
  "decline_code": "<code returned for this scenario>"
}

Card amount triggers

AmountVendor scenarioKind
$10.00approved—
$0.01refer to issuerCALL
$0.05pick up cardhard, retain
$0.07lost cardfraud, hard
$0.20do not honordecline
ℹNote

This is a partial list. These rows are the canonical certification scenarios; the complete amount-to-outcome sheet is vendor-owned and larger. Test against the rows you need to certify.

Discriminating on the outcome

Two fields carry the result — a decline is HTTP 200 with state: FAILED plus a decline_code; an approval is state: CAPTURED. A decline is a business outcome, so the transport is a normal 200. Branch on state; report or route on decline_code.

ℹNote

Do not hard-code an amount-to-decline_code mapping from this page. The trigger amount selects the vendor scenario; read the decline_code your integration actually receives at runtime and branch on that.

Next: AVS and CVV for address and security-code results, and certification scenarios for the list you must cover before going live.