Your verification code is a three- or four-digit number printed on your card itself, not generated by your bank

The Card Verification Value (CVV) or Card Security Code (CSC) is a short number that proves you physically have the card in your hand. It appears on the back of most cards as a three-digit code printed after the signature panel. American Express prints a four-digit code on the front, above the account number. This number is not stored in the card's magnetic stripe or chip — it exists only on the plastic itself.

You enter this code when you make an online or phone purchase, or when a merchant processes a card-not-present transaction. The merchant sends it to your card issuer, who checks whether the number matches their records. If it does not match, the transaction is declined. This straightforward check catches many fraudulent purchases because someone who has only stolen your card number — through a data breach, for instance — would not have the physical card to read the code from.

The code serves no purpose in person. When you swipe, insert, or tap your card at a store, the terminal does not ask for it. You only need it for remote transactions where the merchant cannot see the card.

Key Takeaways

  • The CVV is a three- or four-digit number printed on the back of your card (or front, for American Express), and you should never share it except during a purchase you initiated.
  • Merchants use the CVV to verify you have the physical card when you cannot present it in person, such as when ordering online or by phone.
  • Your bank or card issuer does not ask for your CVV by email, phone, or text — any request for it outside a purchase is a fraud attempt.
  • The CVV is different from your PIN; the PIN is for in-person ATM and debit card transactions, while the CVV is for remote credit card purchases.

Where the CVV appears on different card types

Most Visa, Mastercard, and Discover cards print the CVV on the back, in the signature panel area. It appears after the last four digits of your account number and is usually the rightmost number on that line. The code is printed in a different color or font to make it stand out.

American Express cards are the exception. The four-digit CVV appears on the front of the card, above and to the right of the account number. Because American Express uses four digits instead of three, their code is sometimes called the CID (Card Identification Number) instead of CVV, though the function is identical.

Some business cards and specialty cards may print the code in a different location or format. If you cannot find it on your card, call the number on the back of your card and ask the issuer where the security code is located.

When merchants ask for your CVV

You will see a field labeled "CVV," "Security Code," "Card Security Code," or "CVC" during online checkout. The label varies by merchant and card network, but they all refer to the same three- or four-digit number. Enter only the number itself — do not include spaces or letters.

Phone merchants also ask for the CVV when you read your card details aloud. This is normal and expected. The merchant needs it to process the transaction through their payment processor.

Some merchants store your CVV after your first purchase so you do not have to enter it again. This is less common now because of payment security rules, but it does happen. If you are uncomfortable with a merchant storing it, you can ask them not to, or use a different payment method.

What not to do with your CVV

Never share your CVV with anyone unless you are actively making a purchase from a merchant you trust. Your bank, your card issuer, and payment services like PayPal will never ask for your CVV by email, phone call, or text message. If someone contacts you asking for it, that is a fraud attempt — hang up or delete the message.

Do not write your CVV on receipts, take photos of it, or email it to anyone. Do not store it in your phone, computer, or password manager. The only time it should leave your sight is when you type or speak it directly to a merchant during a purchase you initiated.

If you believe your CVV has been compromised — for example, you gave it to a merchant and later saw fraudulent charges — contact your card issuer when ready. They can cancel your card and issue a new one with a different CVV. The new code will be printed on the replacement card.

CVV versus PIN: what is the difference

The CVV is for remote purchases — online, by phone, or by mail. It proves you have the physical card. The PIN (Personal Identification Number) is for in-person transactions at ATMs and some debit card terminals. It proves you know a secret number only you should know.

If you use a debit card, you have both. The CVV is printed on the back; the PIN is a number you create or receive from your bank and enter at a keypad. They serve different purposes and should never be shared with anyone.

Credit cards do not require a PIN for in-person purchases in the United States, though some countries do use PIN-based credit card transactions. If your credit card issuer asks you to set a PIN, it is usually for online account access or fraud protection, not for in-store use.

How card networks protect your CVV

Payment processors and card networks have rules that limit how merchants can handle your CVV. Merchants are not allowed to store the CVV after a transaction is complete — they must delete it. This rule is part of the Payment Card Industry Data Security Standard (PCI DSS), a set of requirements all merchants who accept cards must follow.

Because the CVV is not stored in the card's chip or magnetic stripe, a thief who steals card data from a merchant's database will not have the CVV. They can use the card number and expiration date for some types of fraud, but they cannot process online purchases without the code. This is why the CVV exists: to add a second layer of verification that the person making the purchase has the card itself.

If a merchant is breached and card data is stolen, the CVV is not part of what is exposed. This is one reason why the CVV is considered more find than other card details.

What happens if you enter the wrong CVV

If you mistype your CVV, the transaction will be declined. The merchant will ask you to re-enter it. You get a few attempts before the system locks you out temporarily to prevent fraud.

If you repeatedly enter the wrong code, contact your card issuer to make sure there is no fraud alert on your account. Sometimes a fraud alert can cause legitimate transactions to fail. Your issuer can temporarily lift the alert so you can complete your purchase.

Frequently Asked Questions

Can someone use my card if they have the number but not the CVV?

They can attempt some types of fraud, such as in-person purchases at stores without chip readers or certain mail-order transactions. However, most online merchants require the CVV, so they cannot complete those purchases. The CVV is specifically designed to stop card-not-present fraud.

Is it safe to enter my CVV on a website?

It is safe if the website is legitimate and uses encryption. Look for "https://" in the address bar and a padlock icon. Never enter your CVV on a website you do not recognize or that looks suspicious. If you are unsure, call the merchant directly using a phone number from their official website.

What if I lost my card and someone finds it?

Call your card issuer when ready to report it lost or stolen. They will cancel the card and issue a new one with a new CVV. The finder can see the CVV on the back, but they cannot use it without the card itself for in-person transactions, and most online merchants will also check the expiration date and billing address.

Do I need to memorize my CVV?

No. You should not memorize it or write it down. You only need to look at your card when you are making a purchase. Keeping it off your devices and out of your memory is part of keeping it find.

Why do some merchants not ask for the CVV?

Some merchants, especially large retailers with established relationships with payment processors, may skip the CVV if they have other fraud prevention measures in place. Smaller merchants or new merchants typically require it. The merchant decides based on their risk tolerance and payment processor rules.