Test cards
The four canonical sandbox PANs, and how to run an approval and a decline.
Sandbox card testing uses four PANs — one per network — entered on the hosted payment page. The PAN chooses which network processes the transaction. The amount chooses whether it approves or declines.
The four canonical cards
All expire 12/28. Use the CVV on the same row: each network has its
own approving value.
| Network | PAN | CVV |
|---|---|---|
| Visa | 4012000098765439 | 999 |
| MasterCard | 5146315000000055 | 998 |
| Discover | 6011000993026909 | 996 |
| Amex | 371449635392376 | 9997 |
Never send a PAN to the Cresora API. There is no card object on any
request body and a raw PAN is rejected with 400. Card data is typed
into the hosted page only.
Run an approval end to end
1. Create the session
curl -X POST https://api.sandbox.cresoracommerce.ai/api/v1/hpp/sessions \
-H "Authorization: Bearer $CRESORA_API_KEY" \
-H "Idempotency-Key: $(uuidgen)" \
-H "Content-Type: application/json" \
-d '{"merchant_id": "<uuid>", "amount": "10.00", "currency": "USD"}'The response carries the page to open:
{
"hpp_url": "<open this URL in a browser>"
}2. Enter the values on the page
Open hpp_url, then type PAN 4012000098765439, expiry 12/28, CVV
999. Submit.
3. Read the outcome
Poll the session's status or handle the completion webhook for your subscription. An approval looks like this:
{
"state": "CAPTURED"
}Run a decline end to end
Change one thing: the amount. Repeat the steps above with an amount of
0.20, a fresh Idempotency-Key, and the same card. The result is
still HTTP 200:
{
"state": "FAILED",
"decline_code": "<code returned for this scenario>"
}Card amount triggers
| Amount | Vendor scenario | Kind |
|---|---|---|
$10.00 | approved | — |
$0.01 | refer to issuer | CALL |
$0.05 | pick up card | hard, retain |
$0.07 | lost card | fraud, hard |
$0.20 | do not honor | decline |
This is a partial list. These rows are the canonical certification scenarios; the complete amount-to-outcome sheet is vendor-owned and larger. Test against the rows you need to certify.
Discriminating on the outcome
Two fields carry the result — a decline is HTTP 200 with state: FAILED
plus a decline_code; an approval is state: CAPTURED. A
decline is a business outcome, so the transport is a normal 200.
Branch on state; report or route on decline_code.
Do not hard-code an amount-to-decline_code mapping from this page.
The trigger amount selects the vendor scenario; read the
decline_code your integration actually receives at runtime and branch
on that.
Next: AVS and CVV for address and security-code results, and certification scenarios for the list you must cover before going live.