Decline guide · incorrect_cvc
Stripe incorrect_cvc: what it means and how to fix it.
incorrect_cvc means the security code on the back of the card didn't match, so the bank refused the payment. Usually it's a typo, and the customer is still on your checkout page. The fix is a clear message and a second try.
Mostly a typo, sometimes not.
Card rules don't let anyone store the security code, so renewals on a saved card usually don't send one. You'll see this code mostly when a customer is typing their card in.
| Where you see it | What it means for you |
|---|---|
| CheckoutA new payment | The customer is still there. Say which field was wrong, keep the rest of the form filled in, and they can fix it in seconds. |
| Updating a cardBilling page or portal | Same fix. If it fails again, the customer may be reading the wrong number: on most cards it's 3 digits on the back, on American Express it's 4 digits on the front. |
| Many in a rowDifferent cards, minutes apart | Not typos. A run of wrong codes on many different cards can be card testing: someone trying stolen card numbers on your form. Look at the payments together, and read Stripe's own guidance on card testing. |
You may also see invalid_cvc. The fix is the same: the customer checks the code and enters it again.
Let them try again.
Three steps for a real customer, and one for a burst of failures.
- Show a plain message next to the card form: the security code didn't match, please check it and try again. Don't clear what they already typed.
- If they left after the failure, send one email with a link back to the order or a payment link. Keep the order on hold, not cancelled.
- If the same card fails twice more, suggest another card. Repeating the same wrong code won't change the answer.
A burst of incorrect_cvc on different cards is a warning sign, not lost sales. Don't email those "customers". Look at the payments in your Dashboard and at your fraud settings.
ActionHi ‹first name›,
Your payment for ‹order or plan› didn't go through because the card's security code didn't match. That's usually just a typo.
You can try again here: ‹payment link›. The code is the 3 digits on the back of most cards, or 4 on the front of an American Express.
Thanks,
‹your name›
Want to see how often it happens to you? Run the free check on your Stripe payments export →
Recover lost revenue.
The Failed-Payment Recovery Kit: a download on Whop, yours right after paying. No subscription, no account with us.
- Dunning email templates to send after a failed payment
- A Stripe settings checklist
- A recovery playbook
One-time purchase · Files, not software