Playground API
DocsStatsBlogStudio
Documentation Tree
Technical BlogFeature Deep Dives
  • Introduction
  • Quickstart
    5 min
  • How It Works
  • Recipes & Cookbooks
  • Platform Comparisons
  • Real-World Showcase
  • Interactive Studio
    Studio
  • GraphiQL IDE
    IDE
  • Session Quotas & Activity
  • Network Chaos Simulator
  • Atomic Sandbox Reset
  • Overview & Models
    Hub
  • Users Resource
  • Posts Resource
  • Comments Resource
  • Todos Resource
  • Custom Collections
    Custom
  • Multipart File Uploads
    Upload
  • Dynamic SVG Avatars
    SVG
  • Image Thumbnails
    CDN
  • Relational Filtering
  • Full-Text Search
  • Dynamic Sorting
  • Offset Pagination
  • Cursor Pagination
    Scroll
  • CSV & Excel Export & Import
    IO
  • Custom Collections
    CRUD
  • Overview & Architecture
    Hub
  • JWT Auth Flow
  • Refresh Token Rotation
    Mutex
  • RBAC Permission Matrix
    Roles
  • Expiry Simulation
  • Clock Skew Drift
  • Password Recovery Loop
  • Dual-Mode Sandboxing
  • GraphiQL IDE
    IDE
  • Relational Queries
  • Stateful Mutations
  • Realtime Subscriptions
  • Overview & Flowcharts
    Hub
  • Hosted Checkout
    Stripe
  • Payment Intents API
  • 3DS Challenge Modal
    Modal
  • Customers Vault
  • Charges & Refunds
  • Test Cards Catalog
  • Overview & Channels
    Hub
  • Virtual Email Mailbox
    Mailtrap
  • Virtual SMS Terminal
    Phone
  • In-App Notifications
  • Message Dispatcher
  • Realtime Studio
    Studio
  • Native WebSocket (/ws)
  • Socket.io Gateway
  • Presence & Echo Bot
  • Server-Sent Events (SSE)
    SSE
  • Analytics Telemetry
  • Webhook Subscriptions
  • HMAC SHA-256 Signatures
  • Delivery Logs
  • Manual Retry Simulator
  • Network Latency Delay
  • HTTP Status Codes
  • Rate-Limit Simulator
    429
  • Flaky Network & Jitter
    Chaos
  • Session Quotas & Activity
  • JSON Snapshots
    JSON
  • Headless CI/CD Testing
    CI
  • Mobile QR Code Sync
  • System Metrics & Health
  • Atomic Sandbox Reset
  • Official TypeScript SDK
  • Multi-Language Generators
  • DevTools Extension
  • OpenAPI 3.1 Spec
    JSON
  • Postman Collection v2.1
  • Bruno Collection
  • Insomnia Workspace
  • TypeScript .d.ts
    .d.ts
  • AI Prompt Rules
    Rules
  • Context Index (llms.txt)
  • Full Schema (llms-full.txt)
  • Manifest (product.json)
  • All Feature Articles
    Blog
  • React CRUD Without Backend
    Deep Dive
  • Why Static APIs Fail
  • Mocking Stateful Auth
  • WebSockets & SSE Guide
Technical Blog
Articles

In-depth articles explaining stateful mock APIs, WebSockets, payments, and frontend resilience.

Read Articles
PreviousCharges & Refunds
NextOverview & Channels
Mock Commerce & Billing

Deterministic Test Cards Catalog

Simulate every real-world checkout event deterministically. Playground API includes 14+ magic test card numbers, dynamic expiry validations, AVS postal address verification, and dynamic CVC security checks—zero real money charged.

Jump to Cards CatalogDynamic AVS & CVC RulesPayment Intents API
Selected Test Instrument
Visa

TEST MODE

4242 4242 4242 4242
Outcome: Immediate Success
Cardholder
ALEXANDER TESTER
Expires
12/28
Click card to flip • Ready to run

Charge Test Card (Live Gateway Execution)

POST
response.json
1
{
2
// Click "Send" above to execute this request against the live server.
3
}

Deterministic Card Catalog

14 official test card credentials mapped to specific payment gateway outcomes.

Card NumberBrandOutcomeHTTP & Error CodeDescription & Handler AdviceActions
4242 4242 4242 4242VisaImmediate Success200
Universal successful charge. Emulates valid card with sufficient liquidity and clean issuer risk score.
Advice: Fulfill order, send customer receipt, dispatch payment_intent.succeeded webhook.
5555 5555 5555 4444MastercardImmediate Success200
Mastercard format successful payment. Validates multi-network bin routing and BIN range matching.
Advice: Fulfill order, trigger inventory decrement.
3782 822463 10005AmexImmediate Success200
American Express 15-digit card number. Emulates 4-digit CID validation.
Advice: Fulfill order, record American Express processor reference.
4000 0000 0000 0341Visa3DS Challenge Required200authentication_required
Requires customer strong authentication (SCA / 3DS 2.2 challenge). Returns redirect / iframe action.
Advice: Invoke stripe.confirmCardPayment() or display challenge modal for OTP / biometric confirmation.
4000 0000 0000 0317Visa3DS Frictionless Approval200
SCA exempt or frictionless authorization. Issuer performs silent risk analysis without prompting user.
Advice: Payment succeeds immediately with 3DS cryptographic liability shift cryptogram.
4000 0000 0000 0002VisaCard Declined402card_declined
General hard decline from issuing bank without specific reason disclosed.
Advice: Prompt customer to contact their card issuer or choose an alternate payment instrument.
4000 0000 0000 0127VisaInsufficient Funds402insufficient_funds
Cardholder account balance or available credit line is insufficient for the requested amount.
Advice: Prompt user to retry with an alternate card or top up account balance.
4000 0000 0000 0069VisaExpired Card402expired_card
Card has passed its valid expiration date.
Advice: Highlight expiration date field in checkout UI and request updated card details.
4000 0000 0000 0119VisaIncorrect Security Code402incorrect_cvc
Security code (CVV/CVC) failed issuer cryptographic check.
Advice: Clear CVC input field and prompt customer to re-enter 3-digit or 4-digit code.
4000 0000 0000 0128VisaAVS Postal Mismatch402postal_code_invalid
Address Verification System (AVS) rejected the zip/postal code provided with billing address.
Advice: Request customer verify postal code matches credit card monthly statement address.
4000 0000 0000 0005VisaHigh Fraud Risk Blocked402fraudulent
Machine learning fraud detection rule blocked charge due to velocity, proxy, or stolen telemetry.
Advice: Do not automatically retry. Flag customer account for compliance/risk review.
4000 0000 0000 0036VisaLost / Stolen Card402stolen_card
Card has been officially reported as lost or stolen by the primary account holder.
Advice: Immediate reject. Halt order processing and do not reveal card status to suspicious agent.
4000 0000 0000 0013VisaVelocity Rate Limit429velocity_limit_exceeded
Card has exceeded frequency limits for consecutive transactions in a short window.
Advice: Implement exponential backoff. Suggest user wait 15 minutes before retrying.
4000 0000 0000 0110VisaIssuer System Glitch500processing_error
Gateway connection dropped or card network interchange switch timed out.
Advice: Safely retry request with identical Idempotency-Key header.

Dynamic Verification & Heuristic Overrides

In addition to magic card numbers, the engine evaluates field-level metadata in real time without requiring test card swapping.

Dynamic Date Expiry

Supply any exp_year prior to the current calendar year (or current year with a past month), and the engine returns expired_card automatically.

exp_month: 01, exp_year: 2020

Magic CVC 000

Keep your normal success card (4242...) but pass cvc: "000". The gateway will simulate a security code mismatch (incorrect_cvc).

cvc: "000" → 402 incorrect_cvc

Magic Postal 99999

Pass postal code "99999" in billing address details to simulate an Address Verification System (AVS) mismatch (postal_code_invalid).

postal_code: "99999" → 402 AVS

Integration Handling Recipes

How to structure frontend and backend exception handling for decline codes in your application.

Frontend Decline Mapping (React / Next.js)

typescript
1
// Map payment error codes to user-friendly form messages
2
export function mapPaymentError(error: { code?: string; message: string }): string {
3
switch (error.code) {
4
case 'card_declined':
5
return 'Your card was declined by your bank. Please try another card.';
6
case 'insufficient_funds':
7
return 'Insufficient funds. Please check your balance or use another card.';
8
case 'expired_card':
9
return 'Your card has expired. Please check the expiration date.';
10
case 'incorrect_cvc':
11
return 'The CVC security code is incorrect. Check the back of your card.';
12
case 'postal_code_invalid':
13
return 'The postal code does not match your billing address.';
14
case 'authentication_required':
15
return '3D Secure authorization required. Opening bank challenge...';
16
case 'velocity_limit_exceeded':
17
return 'Too many payment attempts. Please wait a few minutes.';
18
default:
19
return error.message || 'Payment could not be completed. Please try again.';
20
}
21
}

Backend Intent Confirmation (Node.js / Express)

javascript
1
import axios from 'axios';
2
3
// Confirm Payment Intent with Idempotency Key
4
export async function confirmIntent(intentId, paymentMethod, idempotencyKey) {
5
try {
6
const response = await axios.post(
7
https://playground.nileslabs.com/api/v1/payments/intents/${intentId}/confirm`,
8
{ payment_method: paymentMethod },
9
{ headers: { 'Idempotency-Key': idempotencyKey } }
10
);
11
12
if (response.data.status === 'requires_action') {
13
// Return client secret to frontend for 3DS challenge
14
return { requiresAction: true, clientSecret: response.data.client_secret };
15
}
16
17
return { success: true, payment: response.data };
18
} catch (err) {
19
const errorDetails = err.response?.data?.error || {};
20
console.error('Payment confirmation error:', errorDetails.code);
21
throw errorDetails;
22
}
23
}