Test card number generator and checker
These are test numbers. They satisfy the Luhn checksum and nothing else; no account is behind them and every real payment gateway will decline them. They exist so you can exercise a checkout form without a live card.
Runs in your browser · nothing is sent anywhere
Generates card numbers that pass the Luhn checksum and carry a real brand prefix, which is exactly what a checkout form’s client-side validation checks, and checks a number you paste against the same arithmetic. Generated numbers are test numbers: no account is behind them and every real gateway declines them.
How to use the test card number generator and checker
What makes a card number look valid to a form is two things: a recognised prefix and a correct Luhn check digit. The prefix identifies the brand. 4 for Visa, 51–55 and 2221–2720 for Mastercard, 34 and 37 for American Express, and the last digit is a checksum over the rest. A form’s client-side validation checks both and nothing else, because it cannot check anything else without talking to the network. Generating a number and checking one are therefore the same arithmetic run in opposite directions, which is why they sit on one page.
The Luhn algorithm exists to catch typing mistakes, not fraud. It was designed in the 1950s to detect the two errors humans actually make: a single wrong digit, and two adjacent digits swapped. It catches every single-digit error and almost every transposition, the exception being 09 swapped to 90, and it does it with arithmetic simple enough to have been done by a mechanical device.
What it emphatically does not do is tell you a card is real. Any number ending in the right check digit passes, and roughly one number in ten does by chance. Passing means "nobody mistyped this", not "this card exists": only the issuer can answer the second question, and only through an authorisation request. That is also why generated numbers are harmless — one reaching a real gateway is declined at the network as an invalid account, every time.
Length is the detail people forget, and it varies by brand inside the 12 to 19 digits the standard allows: American Express is 15, Diners Club 14, most others 16. A 16-digit number starting 34 is not a valid Amex card regardless of its checksum, which is why the checker tests length against the brand and not merely against the standard’s range. A generated number takes the length its own prefix implies instead of defaulting to 16, and the expiry and CVV follow the same rule — four digits of CVV for American Express, three for everything else, a real difference that catches out forms with a hard-coded three-digit field.
For testing against a specific gateway, prefer that gateway’s own published numbers; Stripe’s 4242 4242 4242 4242, and the ranges every provider documents. Those are wired into the sandbox to produce specific outcomes: a successful charge, a decline, an expired card, a fraud block. Random Luhn-valid numbers exercise your form’s validation; the published ones exercise your error handling, and you need both.
One practical note about the checker: nothing you paste leaves your browser. That is worth caring about, because a validator that posts the number to a server is a card number in someone else’s logs.
What people use it for
- Exercising a checkout form’s validation without a live card
- Checking that a form accepts a four-digit American Express CVV
- Filling a test database with structurally valid card numbers
- Demonstrating a payment flow in a screenshot without a real card on it
- Finding the mistyped digit in a number read out over the phone
- Confirming a 15-digit number starting 34 really is an Amex before debugging further
Questions
No. They pass the Luhn checksum and carry a real brand prefix, which is all a form checks. No account exists behind them.
No. It is declined at the network as an invalid account. The checksum is not an authorisation.
No. It means no digit was mistyped. Roughly one random number in ten passes by chance. Only the issuer knows whether a card exists.
Every single wrong digit, and almost every transposition of adjacent digits. The exception is 09 swapped to 90.
They are the Issuer Identification Number: 4 for Visa, 51–55 and 2221–2720 for Mastercard, 34 and 37 for American Express.
It varies by brand: Amex is 15, Diners 14, most others 16. A 16-digit number starting 34 is not a valid Amex card whatever its checksum says.
Because it really has one. Forms with a hard-coded three-digit field fail on Amex, which is worth testing.
No. That needs an authorisation request to the issuer, which no web page can make.
Both. These exercise your form validation; the published ones trigger specific outcomes like declines and expiries.
An expired date fails a form’s date check before the number is ever read, which is not what you are testing. Type a past date by hand to exercise that path.
They are unallocated digit strings that satisfy a checksum, which is why payment providers publish their own openly. Attempting to pay with a number you are not entitled to use is fraud whatever its source.
No. Numbers are generated in your browser and a number you paste is checked there too. Neither is transmitted.