A CVV is three digits on Visa, Mastercard, Discover, and most other cards, and four digits on American Express. A length test on that field checks one thing: does the form take exactly that many digits, stop at the limit, and block submission when the input is short? The rule set is small. Most failures come from paste, autofill, and coercion, not from the length limit itself.

CVV Length Test: How to Verify CVV Length for Online Transactions

What the field should accept

  • Exactly 3 digits when the brand is unknown or is a non-Amex card.
  • Exactly 4 digits when the card is American Express.
  • Digits only. No letters, spaces, hyphens, or slashes.
  • No leading or trailing whitespace.
  • Submission blocked until the digit count matches the expected length.

Card brands and their expected lengths

The brand decides the number, so a fixed three-digit cap will reject real customers.

cvv length test api

  • Visa: 3
  • Mastercard: 3
  • Discover: 3
  • American Express: 4
  • Diners Club: 3 on current cards
  • UnionPay: 3

A few regional non-Amex cards also print four digits. If you sell across markets, tie the limit to the detected brand instead of hardcoding one value.

cvv length test api

Building the test cases

I run these in order, because each one isolates a different layer of the stack.

read more

  1. Type the minimum valid count and submit. Confirm the form proceeds.
  2. Type one digit less and submit. Confirm an inline error appears, not a silent failure.
  3. Type one digit more. Confirm the field truncates or blocks the keystroke. A fifth digit landing in a three-digit field is a bug.
  4. Paste a 4-digit string into a 3-digit field. Confirm truncation or rejection, never a stored 1234.
  5. Paste a spaced string such as 1 2 3. Confirm the value normalizes to digits only.
  6. Paste letters and symbols. Confirm rejection with a visible message.
  7. Autofill from a saved card. Confirm the field populates at the right length.
  8. Repeat on iOS and Android with the numeric input mode set. Confirm the digit keypad appears and letters are not reachable by default.

Edge cases that break length validation

  • Leading zeros. A code like 007 becomes 7 if a backend treats it as an integer. Run the length check on a string.
  • Non-ASCII digits. Full-width and Arabic-Indic numerals can pass a loose digit test while the processor rejects them. Normalize to ASCII before validating.
  • maxlength alone. The attribute controls typing but not JavaScript-set values or every paste path. Always validate again on submit.
  • Hidden characters. Copying from an email or a spreadsheet can drag in a newline. Trim and strip before counting.

Never store the value

PCI DSS forbids retaining the card verification value after authorization in any form, including encrypted storage. Your test should also confirm the field is not written to logs, error trackers, session replays, or analytics payloads. If a test data set uses real card numbers, stop and switch to the processor's test PANs. The check is about whether the input behaves, not about the code itself.

A five minute manual checklist

  1. The field takes digits only.
  2. The maximum length matches the brand rule.
  3. A short value blocks submission with a clear message.
  4. Paste and autofill behave the same as typing.
  5. Nothing writes the value anywhere it should not go.