Test Data
This page is the reference for the test cards and test values that the Basis Theory sandbox recognizes in a TEST tenant. Use them to simulate specific success and error scenarios for each feature.
For how to design a testing strategy across the platform (unit, integration, and end-to-end), see the Platform Testing guide.
Test Data
Card Numbers
The card and card_number token types accept any card numbers and are not restricted to a particular set of card numbers, even for tenants only used for testing purposes. However, every provider in a payment flow runs its own sandbox with its own test data, so a card that works in one will not necessarily work in another. If you exchange card tokens with any external systems (using reactors, the proxy, or your PSP), those systems have their own test card requirements that you should follow to ensure the integration works as expected. For a full picture of how to validate each leg of the chain, see Platform Testing.
BIN Details Test Cards
Your Test Tenant can be configured to return fake data for the BIN Details enrichment and can be requested in the Tenant's Quota Page.
When fake responses are enabled the following will occur:
- If a card does not have a static value below, on every request a random set of BIN details following the
enhanceddata structure. - If a card does have a static value below, on every request the BIN details will be the same.
The following card numbers ranges have static BIN Details:
| Card Number Begin | Card Number End | Type | Card Brand | Segment | Test Card Example | Issuer Country |
|---|---|---|---|---|---|---|
4242424242424242 | 4242424242424242 | CREDIT | VISA | Commercial | 4242424242424242 | Bermuda |
4242430000000017 | 4242430000000017 | CREDIT | VISA | Consumer | 4242430000000017 | United States |
5555555555550000 | 5555555555560000 | CREDIT | MASTERCARD | Commercial | 5555555555554444 | Türkiye |
2720394612465072 | 2720394612465072 | CREDIT | MASTERCARD | Commercial | 2720394612465072 | United States |
378282246310000 | 378282246310010 | CREDIT | AMEX | Consumer | 378282246310005 | Faroe Islands |
4000056655665550 | 4000056655665550 | CREDIT | VISA | Business | 4000056655665556 | Chile |
6200000000000000 | 6200000000000000 | CREDIT | UNIONPAY | 6200000000000005 | Svalbard & Jan Mayen Islands | |
6011010000000000 | 6011010000000005 | DEBIT | DISCOVER | Commercial | 6011010000000003 | Bermuda |
6011981111111113 | 6011981111111113 | DEBIT | DISCOVER | Commercial | 6011981111111113 | United States |
3566002020360504 | 3566002020360506 | DEBIT | JCB | Commercial | 3566002020360505 | Bermuda |
3530111333300000 | 3530111333300000 | DEBIT | JCB | Commercial | 3530111333300000 | United States |
378282246310011 | 378282246310020 | DEBIT | VISA | Commercial | 378282246310013 | Bermuda |
4242420000000018 | 4242420000000018 | DEBIT | VISA | Consumer | 4242420000000018 | United States |
4005550000081018 | 4005550000081020 | DEBIT | VISA | Commercial | 4005550000081019 | Bermuda |
5112000400000000 | 5112000400000001 | DEBIT | MASTERCARD | Commercial | 5112000400000000 | Bermuda |
5112010000000003 | 5112010100000002 | DEBIT | MASTERCARD | Commercial | 5112010000000003 | Bermuda |
5200828282828210 | 5200828282828210 | DEBIT | MASTERCARD | Commercial | 5200828282828210 | United States |
6011000990139420 | 6011000990139430 | CREDIT | DISCOVER | Commercial | 6011000990139424 | Bermuda |
6011000995500000 | 6011000995500000 | CREDIT | DISCOVER | Commercial | 6011000995500000 | United States |
5589092000000000006 | 5589092000000000006 | DEBIT | MASTERCARD | Commercial | 5589092000000000006 | United States |
5589620000000000007 | 5589620000000000007 | DEBIT | MASTERCARD | Commercial | 5589620000000000007 | United States |
Partial and Empty BIN Details
In production, not every card returns complete BIN details. Cards from regional or less common networks, or BINs that aren't yet covered, frequently tokenize successfully but come back with some enrichment fields empty — or with no bin_details at all. Your integration has to keep working when funding, brand, or issuer_country are missing. See Handling Incomplete Data for guidance on treating these fields as optional.
The following Test-Tenant card numbers reproduce that behavior on demand, so you can write CI tests that prove your fallback logic works without mocking our API or waiting for a real partial-data card in production. Each one tokenizes successfully but deliberately omits one or more enrichment fields. Like the static table above, these only return this deterministic data when your Test Tenant's BIN Details enrichment is set to fake — otherwise a random, complete enhanced response is returned.
| Test Card | card.brand | card.funding | card.issuer_country | enrichments.bin_details | Simulates |
|---|---|---|---|---|---|
4900000000000011 | visa | absent | Bermuda | Returned | Missing funding (debit/credit unknown) |
4900000000000029 | visa | credit | absent | Returned | Missing issuer country |
9000000000000019 | absent | credit | Bermuda | Returned | Missing brand |
9000000000000027 | absent | absent | absent | Returned | Missing brand, funding, and issuer country |
4900000000000003 | visa | absent | absent | absent | No bin_details object on a successful token |
The most instructive case is 4900000000000003, where the entire enrichments.bin_details object is absent even though tokenization succeeds — mirroring a regional BIN whose network is known but whose enrichment data is unavailable:
{
"id": "<TOKEN_ID>",
"type": "card",
"card": {
"bin": "49000000",
"last4": "0003",
"expiration_month": 12,
"expiration_year": 2025,
"brand": "visa"
},
"enrichments": {}
// enrichments.bin_details is absent — your code must not assume it is present
}
3DS Test Cards
The following test card numbers can be used to test various 3D Secure scenarios.
| Card Number | Card Brand | 3DS Scenario | Is Luhn Valid |
|---|---|---|---|
5204247750001471 | MASTERCARD | Successful Frictionless Authentication | Yes |
6011601160116011 | DISCOVER | Successful Frictionless Authentication | Yes |
340000000004001 | AMEX | Successful Frictionless Authentication | Yes |
4000020000000000 | VISA | Successful Challenge Authentication | Yes |
370000000000002 | AMEX | Successful Challenge Authentication | Yes |
3566002020360505 | JCB | Successful Challenge Authentication | Yes |
3566006663297692 | JCB | Successful Challenge Authentication | Yes |
4005562231212123 | VISA | Successful Challenge Authentication - Method not Required | Yes |
4761369980320253 | VISA | Successful Mandated Challenge Authentication | Yes |
5200000000001104 | MASTERCARD | Successful Mandated Challenge Authentication | Yes |
4000000000000341 | VISA | Successful Out-of-Band Challenge Authentication | Yes |
4005571701111111 | VISA | Attempted Challenge Authentication | Yes |
4111111111111111 | VISA | Authentication Attempted | Yes |
5424180011113336 | MASTERCARD | Authentication Attempted | Yes |
4264281511112228 | VISA | Authentication Failed | Yes |
5424180000000171 | MASTERCARD | Authentication Failed | Yes |
5405001111111165 | MASTERCARD | Authentication Unavailable | Yes |
5405001111111116 | MASTERCARD | Authentication Rejected | Yes |
4055011111111111 | VISA | Failed Challenge Authentication | Yes |
5427660064241339 | MASTERCARD | Failed Challenge Authentication | Yes |
6011361011110004 | DISCOVER | Failed Out of Band Challenge Authentication | Yes |
6011361000008888 | DISCOVER | Unavailable Challenge Authentication | Yes |
6011361000001115 | DISCOVER | Rejected Challenge Authentication | Yes |
4264281500003339 | VISA | 3DS Directory Server Error | Yes |
5424180011110001 | MASTERCARD | 3DS Directory Server Error | Yes |
4264281500001119 | VISA | Internal 3DS Server Error | Yes |
4200000000000002 | VISA | Successful Frictionless Authentication | No |
4200000000000004 | VISA | Successful Challenge Authentication | No |
4200000000000014 | VISA | Successful Challenge Authentication - Method not Required | No |
4200000000000015 | VISA | Successful Mandated Challenge Authentication | No |
4200000000000016 | VISA | Successful Out-of-Band Challenge Authentication | No |
4200000000000008 | VISA | Attempted Challenge Authentication | No |
4200000000000003 | VISA | Authentication Attempted | No |
4200000000000005 | VISA | Authentication Failed | No |
4200000000000006 | VISA | Authentication Unavailable | No |
4200000000000007 | VISA | Authentication Rejected | No |
4200000000000009 | VISA | Failed Challenge Authentication | No |
4200000000000017 | VISA | Failed Out of Band Challenge Authentication | No |
4200000000000010 | VISA | Unavailable Challenge Authentication | No |
4200000000000011 | VISA | Rejected Challenge Authentication | No |
4200000000000012 | VISA | 3DS Directory Server Error | No |
4200000000000013 | VISA | Internal 3DS Server Error | No |
Account Updater Test Cards
The following test card numbers can be used to test various Account Updater scenarios.
| PAN | Exp. Month | Exp. Year | Card Brand | Result Code | Update Details |
|---|---|---|---|---|---|
4111111111111111 | 12 | 2023 | VISA | UPD_PAN | 4166676667666746 |
4012888888881881 | 12 | 2023 | VISA | UPD_PAN | 4212345678910006, 12/2026 |
5555555555554444 | 12 | 2023 | MASTERCARD | UPD_PAN | 5454545454545454 |
5105105105105100 | 12 | 2023 | MASTERCARD | UPD_PAN | 5233580618829955, 12/2026 |
6011111111111117 | 12 | 2023 | DISCOVER | UPD_PAN | 6011000990139424 |
6011601160116611 | 12 | 2023 | DISCOVER | UPD_PAN | 6445644564456445, 12/2026 |
378282246310005 | 12 | 2023 | AMEX | UPD_PAN | 375155165213132 |
371449635398431 | 12 | 2023 | AMEX | UPD_PAN | 348835199015504, 12/2026 |
4539097887163333 | 12 | 2023 | VISA | UPD_EXP_DATE | 12/2026 |
5325191087030619 | 12 | 2023 | MASTERCARD | UPD_EXP_DATE | 12/2026 |
6011690151507086 | 12 | 2023 | DISCOVER | UPD_EXP_DATE | 12/2026 |
373555735376156 | 12 | 2023 | AMEX | UPD_EXP_DATE | 12/2026 |
6011760519541711 | 12 | 2023 | DISCOVER | UPD_BRAND_CONV | N/A |
6011490740263725 | 12 | 2023 | DISCOVER | UPD_CORRECTED | N/A |
4711358892785746 | 12 | 2023 | VISA | NO_UPDATE | N/A |
5412000000001009 | 12 | 2023 | MASTERCARD | NO_UPDATE | N/A |
4929980395567582 | 12 | 2023 | VISA | WRN_CONTACT_CARDHOLDER | N/A |
6011444770992901 | 12 | 2023 | DISCOVER | WRN_CONTACT_CARDHOLDER | N/A |
4929544240318920 | 12 | 2023 | VISA | WRN_ISSUER_NOT_ENROLLED | N/A |
5580422612666704 | 12 | 2023 | MASTERCARD | WRN_ISSUER_NOT_ENROLLED | N/A |
4916725297925395 | 12 | 2023 | VISA | WRN_ISSUER_NO_DATA | N/A |
5157204564548129 | 12 | 2023 | MASTERCARD | WRN_ISSUER_NO_DATA | N/A |
4035501000000008 | 12 | 2023 | VISA | WRN_OPT_OUT | N/A |
5461310156953048 | 12 | 2023 | MASTERCARD | WRN_CLOSED_ACCOUNT | N/A |
6011168802268945 | 12 | 2023 | DISCOVER | WRN_CLOSED_ACCOUNT | N/A |
370488998077498 | 12 | 2023 | AMEX | WRN_CLOSED_ACCOUNT | N/A |
122000000000003 | 12 | 2023 | N/A | WRN_UNSUPPORTED_NETWORK | N/A |
4035501428146300 | 12 | 2023 | VISA | ERR_INVALID_PAN | N/A |
5555341244441115 | 12 | 2023 | MASTERCARD | ERR_INVALID_PAN | N/A |
6011829379808385 | 12 | 2023 | DISCOVER | ERR_INVALID_PAN | N/A |
378025849667382 | 12 | 2023 | AMEX | ERR_INVALID_PAN | N/A |
4111111145551142 | 12 | 2023 | VISA | ERR_INVALID_EXP_DATE | N/A |
5577000055770004 | 12 | 2023 | MASTERCARD | ERR_INVALID_EXP_DATE | N/A |
6011648103759866 | 12 | 2023 | DISCOVER | ERR_INVALID_EXP_DATE | N/A |
378734493671000 | 12 | 2023 | AMEX | ERR_INVALID_EXP_DATE | N/A |
4111112014267661 | 12 | 2023 | VISA | ERR_INVALID_CONFIG | N/A |
5555444433331111 | 12 | 2023 | MASTERCARD | ERR_INVALID_CONFIG | N/A |
370000000000002 | 12 | 2023 | AMEX | ERR_INVALID_CONFIG | N/A |
6011178332216017 | 12 | 2023 | DISCOVER | ERR_UNDEFINED | N/A |
Network Tokens Test Cards
The following test card numbers can be used to test various Network Token scenarios.
| PAN | Card Brand | Response | Error Title |
|---|---|---|---|
4000000000000002 | Visa | Success | [Not Applicable] |
4000000000000085 | Visa | Success | [Not Applicable] |
4000000000000093 | Visa | Success | [Not Applicable] |
5100000000000008 | Mastercard | Success | [Not Applicable] |
5100000000000065 | Mastercard | Success | [Not Applicable] |
5100000000000073 | Mastercard | Success | [Not Applicable] |
6011000000000004 | Discover | Success | [Not Applicable] |
370000000000002 | American Express | Success | [Not Applicable] |
370000000000069 | American Express | Success | [Not Applicable] |
370000000000077 | American Express | Success | [Not Applicable] |
4012888888881881 | Visa | Provision Data Expired | PROVISION_DATA_EXPIRED |
5105105105105100 | Mastercard | Provision Data Expired | PROVISION_DATA_EXPIRED |
6011601160116611 | Discover | Provision Data Expired | PROVISION_DATA_EXPIRED |
371449635398431 | American Express | Provision Data Expired | PROVISION_DATA_EXPIRED |
4330251207506660 | Visa | Card Verification Failed | CARD_VERIFICATION_FAILED |
5461310156953048 | Mastercard | Card Verification Failed | CARD_VERIFICATION_FAILED |
6011168802268945 | Discover | Card Verification Failed | CARD_VERIFICATION_FAILED |
370488998077498 | American Express | Card Verification Failed | CARD_VERIFICATION_FAILED |
4539097887163333 | Visa | Card Not Eligible | CARD_NOT_ELIGIBLE |
5325191087030619 | Mastercard | Card Not Eligible | CARD_NOT_ELIGIBLE |
6011690151507086 | Discover | Card Not Eligible | CARD_NOT_ELIGIBLE |
373555735376156 | American Express | Card Not Eligible | CARD_NOT_ELIGIBLE |
4929980395567582 | Visa | Card Not Allowed | CARD_NOT_ALLOWED |
5580422612666704 | Mastercard | Card Not Allowed | CARD_NOT_ALLOWED |
6011444770992901 | Discover | Card Not Allowed | CARD_NOT_ALLOWED |
378025849667382 | American Express | Card Not Allowed | CARD_NOT_ALLOWED |
4929544240318920 | Visa | Card Declined | CARD_DECLINED |
5157204564548129 | Mastercard | Card Declined | CARD_DECLINED |
6011760519541711 | Discover | Card Declined | CARD_DECLINED |
348322853530243 | American Express | Card Declined | CARD_DECLINED |
4916725297925395 | Visa | Provision Not Allowed | PROVISION_NOT_ALLOWED |
5336475987107024 | Mastercard | Provision Not Allowed | PROVISION_NOT_ALLOWED |
6011490740263725 | Discover | Provision Not Allowed | PROVISION_NOT_ALLOWED |
375155165213132 | American Express | Provision Not Allowed | PROVISION_NOT_ALLOWED |
4711358892785746 | Visa | Card Eligibility Error | CARD_ELIGIBILITY_ERROR |
5233580618829955 | Mastercard | Card Eligibility Error | CARD_ELIGIBILITY_ERROR |
6011000990139424 | Discover | Card Eligibility Error | CARD_ELIGIBILITY_ERROR |
348835199015504 | American Express | Card Eligibility Error | CARD_ELIGIBILITY_ERROR |
5555555555554444 | Mastercard | Issuer Declined | ISSUER_DECLINED |
Agentic Payments Test Cards
The following test card numbers can be used to test various Agentic Payments scenarios.
The matrix is deliberately small. Each card exercises one materially different integration or recovery behavior, and any card number not listed follows its brand's happy path. Tokenize the card in your test tenant first, then use the resulting token as source.token_id.
Because both rails see the same card number, one card can produce different outcomes per rail. That is what makes partial rail success testable with a single payment method.
Visa
| Card Number | Payment method rails | Verification | Scenario |
|---|---|---|---|
4242424242424242 | agentic-token enabled, spt enabled | Full ceremony to active | Visa happy path |
4929980395567582 | agentic-token enabled, spt enabled | submit_otp returns 400 INVALID_OTP | Verification failure |
4000000000000002 | agentic-token enabled, spt error (CARD_REJECTED) | Full ceremony to active | Partial rail success. Retrying the spt rail is rejected again |
4000000000000119 | agentic-token enabled, spt error | Full ceremony to active | Recoverable provisioning failure. Retrying the spt rail succeeds |
4000000000000341 | agentic-token enabled, spt enabled | Full ceremony to active | Credential issuance failure. A spt mint returns 422 PROVIDER_CREDENTIALS_FAILED and releases the reservation |
4000000000009995 | agentic-token enabled, spt enabled | Full ceremony to active | Indeterminate credential outcome. An spt mint returns 409 CREDENTIAL_OUTCOME_UNKNOWN and consumes the requested allowance capacity |
| Any other Visa number | agentic-token enabled, spt enabled | Full ceremony to active | Default |
Mastercard
| Card Number | Payment method rails | Verification | Scenario |
|---|---|---|---|
5555555555554444 | agentic-token enabled, spt enabled | Hosted redirect to active | Mastercard happy path |
5186160000000001 | agentic-token error (CARD_REJECTED), spt enabled | Not applicable | Permanent network rejection. The spt rail still works |
5186160000000003 | agentic-token enabled, spt enabled | complete returns 422 PROVIDER_VERIFICATION_FAILED | Verification failure, with brand behavior differing from Visa's |
| Any other Mastercard number | agentic-token enabled, spt enabled | Hosted redirect to active | Default |
The agentic-token rail follows the card's network: Visa numbers provision vic and Mastercard numbers provision agentpay. Every card also provisions the spt rail, and the Stripe outcomes are keyed on the card number rather than the brand: 4000000000000002 declines permanently, 4000000000000119 fails once and succeeds on retry, 4000000000000341 provisions but conclusively fails to mint, 4000000000009995 simulates a lost mint response, and every other number succeeds.
Mock Credentials
Mock credentials are deterministic so repeated runs see stable values.
| Format | Value |
|---|---|
card | A Luhn-valid virtual card number, 4000001000004242 for the 4242 Visa card and 5100001000004446 for the 4444 Mastercard, falling back to 4000001000000000 and 5100001000000006 for other cards. Expiration comes from the tokenized card; the security code is derived deterministically |
network-token | The same virtual number as the payment_token, with a deterministic cryptogram. Visa returns ECI 07 and Mastercard returns ECI 06; cryptogram.type reads CARD_APPLICATION_CRYPTOGRAM_SHORT_FORM on both |
identifier | A Stripe token identifier prefixed spt_mock_ |
mpp | The same network or Stripe data, packaged for the challenge you supplied |
Credential expiry follows each network's real rule rather than a uniform test value. Mastercard supplies no cryptogram expiry — its short-form cryptogram is single-use and bound to the transaction — so cryptogram.expires_at falls back to the allowance's expires_at, in the mock exactly as in production. Visa's cryptogram expiry is network-supplied, and the mock returns a short synthetic window in its place, so do not calibrate "how long is a credential usable" against the Visa mock's value. Use any cryptogram immediately on both networks.
Mock credentials are suitable for integration tests. They are not provider certification evidence.
Deprecated Agentic Commerce Test Cards
These cards apply to the deprecated Agents, Enrollments, and Instructions model only.
Visa Test Cards
Enrollment Success
| Card Number | Verification | Description |
|---|---|---|
4242424242424242 | OTP challenge | Standard flow — requires OTP verification and passkey creation. |
4000000000000002 | OTP challenge | Standard flow — requires OTP verification and passkey creation. |
4000020000000000 | OTP challenge | Alternate card for testing multiple enrollments. |
4000056655665556 | Auto-approved | The issuer approves without a challenge — verification returns approved with no OTP and no passkey step. |
4711358892785746 | OTP challenge | Standard flow — requires OTP verification. |
| Any other Visa PAN | OTP challenge | Default behavior for unrecognized Visa cards. |
Verification Failures
| Card Number | Verification | Description |
|---|---|---|
4929980395567582 | Invalid OTP | OTP submission always returns an INVALID_OTP error. |
4916725297925395 | Max attempts exceeded | OTP submission returns a MAX_ATTEMPTS_EXCEEDED error. |
Partial Failures (Retryable)
| Card Number | Error | Description |
|---|---|---|
4000000000003063 | PROVIDER_ENROLLMENT_FAILED (422) | Card registers with the network but fails a subsequent provider step. Returns enrollment with failed status and card display data. Retryable via POST /enrollments/:id/retry. |
4000000000003071 | PROVIDER_ENROLLMENT_FAILED (422) | Card fails during token provisioning. Returns enrollment with failed status. Retryable via POST /enrollments/:id/retry. |
Enrollment Failures
| Card Number | Error | Description |
|---|---|---|
4330251207506660 | CARD_REJECTED (422) | Card fails network verification during enrollment. |
4539097887163333 | CARD_REJECTED (422) | Card is not eligible for agentic commerce enrollment. |
4929544240318920 | CARD_REJECTED (422) | Card is declined by the issuer during enrollment. |
Mastercard Test Cards
Enrollment Success
| Card Number | Verification | Description |
|---|---|---|
5555555555554444 | Popup challenge | Standard flow — requires Mastercard popup authentication. |
5200828282828210 | Auto-approved | Enrollment is automatically approved — no popup required. |
2223003122003222 | Popup challenge | Mastercard 2-series card — requires popup authentication. |
5425233430109903 | Popup challenge | Standard flow — requires Mastercard popup authentication. |
5204740009900014 | Passkey bypass | Verification returns approved without the popup ceremony. |
| Any other Mastercard PAN | Popup challenge | Default behavior for unrecognized Mastercard cards. |
Verification Failures
| Card Number | Verification | Description |
|---|---|---|
5186160000000003 | Invalid challenge | Completing the ceremony returns PROVIDER_VERIFICATION_FAILED (422). |
5186160000000004 | Max attempts exceeded | Completing the ceremony returns MAX_ATTEMPTS_EXCEEDED (400). |
Enrollment Failures
| Card Number | Error | Description |
|---|---|---|
5105105105105100 | CARD_REJECTED (422) | Card is not eligible for agentic commerce enrollment. |
5186160000000001 | CARD_REJECTED (422) | Card fails network verification during enrollment. |
5186160000000002 | CARD_REJECTED (422) | Card is declined by the issuer during enrollment. |
Bank Verification Test Cards
The following test bank account numbers can be used to test various Bank Verification scenarios.
| Routing Number | Account Number | Status |
|---|---|---|
021000020 | 00000 | disabled |
021000021 | 00001 | enabled |
021000021 | 00002 | inconclusive |