Why payment UAT is different
User acceptance testing (UAT) for a payment chain is the test campaign that validates, before go-live, how every link a transaction passes through behaves. A regression here does a different kind of damage than in ordinary software: it loses sales or wrongly charges a customer, often without any error showing on screen. UAT must therefore cover the happy path, then the long tail of declines, timeouts, cancellations, and 3DS cases, and then continue after go-live as ongoing monitoring.
sk_test_ / pk_test_). A real card is never used in the sandbox, and a test card is never used in production. Mixing up the two environments is the most common integration error, and the most expensive.Test cards and scenarios
Test cards are dummy PANs, supplied by PSPs and card networks, that trigger a specific behavior in the sandbox (approval, a decline for a given reason, a 3DS challenge, and so on). Any CVV and any future expiry date will do. The campaign consists of deliberately triggering each case to check that the merchant’s code responds correctly.
| Test number | Network | Simulated behavior |
|---|---|---|
| 4242 4242 4242 4242 | Visa | Payment approved (happy path) |
| 5555 5555 5555 4444 | Mastercard | Payment approved |
| 3782 822463 10005 | American Express | Payment approved (15-digit format) |
| 4000 0000 0000 0002 | Visa | Generic decline (do not honor) |
| 4000 0000 0000 9995 | Visa | Declined for insufficient funds |
| 4000 0000 0000 3220 | Visa | Triggers a 3-D Secure 2 challenge |
- Happy path: authorization approved, capture, payment received.
- Declines: replay each code (05, 14, 41, 51, 54, 65/1A…) and check the message and the retry strategy.
- 3DS2: frictionless and challenge flows, including abandonment and failed authentication.
- Partial capture and cancellation: pre-authorization, capture for a lower amount, reversal/void before clearing.
- Refunds: full and partial, with a reconciliation check.
- Degraded modes: issuer timeout, PSP unavailable, double submission (idempotency), replayed webhook.
// Send the SAME idempotency key twice: the PSP must
// return the same transaction without creating a second debit.
const idempotencyKey = "order-2026-07-11-000482"
async function pay() {
return fetch("/v1/charges", {
method: "POST",
headers: {
"Authorization": "Bearer sk_test_XXXX",
"Idempotency-Key": idempotencyKey,
"Content-Type": "application/json",
},
body: JSON.stringify({ amount: 4280, currency: "EUR", source: "tok_test" }),
}).then((r) => r.json())
}
const a = await pay()
const b = await pay()
console.assert(a.id === b.id, "Idempotency broken: possible double debit")Certification: proving compliance with the network
For an integrator, being certified means having passed a formal process, run with the acquirer, the card network, or an accredited body, that confirms the implementation meets the specifications and behaves correctly on an official test platform. Tests run in the sandbox are not enough to get access to a live network; certification comes on top of them. In France, card acceptance also requires CB certification from Cartes Bancaires, France’s domestic card scheme, in addition to the international Visa and Mastercard approvals.
Monitoring: acceptance testing never stops
Monitoring a payment chain means continuously tracking its metrics after go-live. A degradation does not always produce a technical error. A change at the issuer, an expired certificate, or an overly strict fraud rule can make the payment success rate drop without any error message appearing. Monitoring combines alerts with synthetic transactions: test payments run in production at regular intervals to check that the chain responds.
| Indicator | What it reveals | Warning sign |
|---|---|---|
| Authorization rate | Overall acceptance health | Sudden drop or drift on a BIN or issuer |
| DE39 code distribution | Type of decline (soft vs. hard) | Rise in 05, 65/1A, 91 |
| 3DS2 success rate | Authentication friction | Frictionless rate collapsing, challenge abandonment |
| End-to-end latency | Payment chain performance | Response times creeping up, timeouts |
| Fraud / chargeback rate | Risk exposure | Nearing scheme thresholds (Visa VAMP, Mastercard EFM) |
| Availability (uptime) | Technical resilience | 5xx errors, undelivered webhooks |