# Sandbox testing

> Use sandbox test cards to validate card payment flows, 3DS scenarios, failure responses, subscriptions, token payments, and wallet payments.

Use the following test cards in the sandbox to validate your payment flows. Test cards are for sandbox use only. Do not use them in production, and do not replace them with real cardholder data.

<note>

`Response` shows the typical response used to validate success or failure branches. Actual API responses still depend on the current sandbox configuration.

</note>

## Card payment test cards

Use these card numbers to validate one-time payments, 3DS authentication flows, exemption scenarios, failure responses, subscription payments, and token payments.

<tip>

The 3DS test scenario describes the authentication flow or exemption path simulated by the sandbox test card. `Challenge flow` and `Frictionless flow` are 3DS authentication flows. `Exemption` describes an exemption scenario. These labels are not fixed properties of the card itself, and they do not mean every transaction from the same country or region will trigger the same result.

</tip>

| Card number | Country | Card brand | 3DS test scenario | Response | Subscription | Save payment method |
| --- | --- | --- | --- | --- | --- | --- |
| `4000020951595032` | 🇺🇸 `US` | Visa | Challenge flow | Success | Yes | Yes |
| `4761344136141390` | 🇸🇬 `SG` | Visa | Exemption | Success | Yes | Yes |
| `4000319872807223` | 🇺🇸 `US` | Visa | Frictionless flow | Success | No | Yes |
| `4000128449498204` | 🇺🇸 `US` | Visa | Frictionless flow | Do not honor | No | Yes |
| `4021937195658141` | 🇬🇧 `GB` | Visa | Frictionless flow | Insufficient funds | No | No |
| `4000164166749263` | 🇮🇳 `IN` | Visa | Frictionless flow | Suspected fraud | No | No |
| `2221008123677736` | 🇺🇸 `US` | Mastercard | Challenge flow | Success | Yes | No |
| `5333302221254276` | 🇹🇷 `TR` | Mastercard | Exemption | Success | No | No |
| `5333418445863914` | 🇲🇽 `MX` | Mastercard | Frictionless flow | Success | No | No |
| `5109486948867999` | 🇺🇸 `US` | Mastercard | Frictionless flow | Restricted Card | No | No |
| `4998170000000015` | 🇧🇷 `BR` | Visa | Challenge flow | Success | No | No |
| `4998170000000023` | 🇧🇷 `BR` | Visa | Challenge flow | Suspected fraud | No | No |

## Apple Pay sandbox testing

Before testing Apple Pay in the sandbox, complete the following preparation:

1. **Domain verification**: If you show the Apple Pay button on your own pages through the Web SDK or the Direct API, the test domain must first pass Apple domain verification, either through your own Apple Developer account or registered by Onerway; see [Apple Pay setup](/payments/online-payments/payment-methods/apple-pay#setup). The Onerway-hosted checkout page does not need this step.
2. **Sandbox tester account**: Create a sandbox tester account in App Store Connect. Sign out of iCloud on the test device, then sign in with the tester account.
3. **Device country and region**: Set the test device's country and region to one that the Apple Pay sandbox supports and that matches the card network of the test card; Wallet in the China mainland region supports UnionPay test cards only.

Test cards are provided by Apple and replaced in batches, so use the latest cards on the [Apple Pay sandbox testing](https://developer.apple.com/apple-pay/sandbox-testing/) page and add them manually in the Wallet app on the test device.

## Google Pay test cards

Before testing Google Pay, join the [Google Pay test card suite group](https://groups.google.com/g/googlepay-test-mode-stub-data) with your Google account. Once joined, Google Pay on that account automatically presents a set of test cards, so there is no need to add cards manually.

## Suggested test scenarios

- Use test cards with an expected `Success` response to validate payment creation and payment confirmation.
- Verify that your server receives payment webhooks: verify each notification with the `X-Rh-Signature` header per [request signing](/payments/get-started/request-signing), then return the acknowledgement response so the notification is not redelivered.
- Use test cards with an expected failure response to validate error display, retry handling, and order status rollback.
- Use cards that support subscriptions to validate subscription payments.
- Use cards that support saving payment methods to validate save payment method flows and later token payments.
- Use the Apple Pay and Google Pay test cards to validate wallet payment flows.
