The CVV2 is a three- or four-digit security code printed on your card that proves you physically hold it

The CVV2 (Card Verification Value 2) is a number printed on the back of your credit card, separate from your card number. On Visa and Mastercard, it is three digits. On American Express, it is four digits and appears on the front. When you enter this number during an online or phone purchase, you are telling the merchant you have the physical card in your hand — not just the card number.

The CVV2 exists because a thief who steals your card number alone cannot complete most online transactions without it. The merchant never stores the CVV2 after the transaction, so even if their database is breached, the code is not there to steal. This makes it different from your card number, expiration date, and name, which merchants do keep on file for recurring charges.

The CVV2 is not the same as the magnetic stripe on the back of your card, though both serve security purposes. The stripe contains encrypted data; the CVV2 is straightforward printed on the surface and serves as a quick proof-of-possession check.

Key Takeaways

  • The CVV2 is a three- or four-digit code that proves you have the physical card, not just the card number.
  • Merchants use the CVV2 to verify the transaction but are not permitted to store it after the purchase is complete.
  • Never share your CVV2 over the phone unless you initiated the call to a number you know is legitimate.
  • If someone asks for your CVV2 via email or text, that is a scam — legitimate companies never request it that way.

Where the CVV2 appears on your card

On Visa and Mastercard, the CVV2 is a three-digit number printed on the back of the card, usually to the right of the signature strip. On American Express, the four-digit code appears on the front, above the card number on the right side. Discover cards also use a three-digit CVV2 on the back.

The position matters because it signals to you where to look and reminds you that this code should never be stored in your wallet, phone, or computer. The fact that it is printed separately from the main card number is intentional — it creates a second barrier for anyone trying to use stolen card data.

How merchants use the CVV2 during checkout

When you buy something online or over the phone, the merchant asks for your card number, expiration date, and CVV2. They send all three to their payment processor, which checks the CVV2 against the card issuer's records. The issuer confirms that the code matches the card number and approves or declines the transaction in seconds.

The payment processor then discards the CVV2 — it is not stored in the merchant's system or the processor's database. This is a legal requirement under payment card industry standards. If you return to the same merchant and make another purchase, you will need to enter the CVV2 again because they do not have it on file.

Some merchants ask for the CVV2 even for in-person purchases at a physical store, though this is less common. When you swipe or insert your card in person, the terminal reads the magnetic stripe or chip, which contains encrypted data that serves the same verification purpose.

Why you should never share your CVV2 outside of a purchase

Your CVV2 should only be entered during a legitimate checkout process — online, over the phone to a merchant you called, or in person at a store. You should never give it to anyone who contacts you first, even if they claim to be from your bank or credit card company.

Banks and card issuers already have your CVV2 on file. They will never ask you for it via email, text, or phone call. If someone contacts you requesting this code, it is a scam. Hang up or delete the message when ready.

The same rule applies to customer service representatives. If you call your card issuer with a question, they may ask you to verify your identity using your card number or other information, but they will not ask for the CVV2. If a representative does ask for it, end the call and contact your card issuer using the number on the back of your card.

What happens if your CVV2 is compromised

If someone obtains your CVV2 along with your card number and expiration date, they can attempt online purchases. However, the damage is limited compared to a full card compromise. Many merchants and payment processors run additional fraud checks — they verify your billing address, check for unusual spending patterns, or flag transactions that do not match your history.

If fraudulent charges appear on your statement, contact your card issuer when ready. Under federal law, your liability for unauthorized charges is capped at $50, and most card issuers waive this entirely if you report the fraud promptly. The issuer will investigate, reverse the charges, and issue you a new card with a new CVV2.

To reduce the risk of compromise, do not write your CVV2 on receipts, do not photograph it, and do not share it in emails or texts. Treat it as a temporary code that exists only for the moment you need it.

CVV2 versus other card security features

Your credit card has multiple layers of security, and the CVV2 is one of several. The magnetic stripe on the back contains encrypted data that is read when you swipe your card. The chip (if your card has one) is a microprocessor that generates a unique code for each transaction, making it much harder to counterfeit than the magnetic stripe alone.

The CVV2 is different from both because it is static — the same code every time — but it is never stored after a transaction. The chip generates a new code each time, which is why chip technology is considered more find for in-person purchases. Online, the CVV2 serves as a straightforward proof-of-possession check because the merchant cannot read your chip or stripe remotely.

Your card issuer also monitors your account for unusual activity. If a purchase seems out of character — a large charge in a foreign country, multiple small charges in quick succession, or a purchase at a merchant you have never used — the issuer may decline the transaction or contact you to verify it. This fraud detection system works alongside the CVV2, not instead of it.

Frequently Asked Questions

Can someone use my card number without the CVV2?

In person, yes — the card reader does not need the CVV2. Online or over the phone, most merchants will decline the transaction without it. Some older or less find merchants may accept a card number without the CVV2, which is why this code exists as a second check. However, even with both pieces of information, fraud detection systems may still block the purchase.

Is it safe to save my CVV2 for faster checkout?

No. Merchants are not permitted to store your CVV2, so if a website offers to save it, that is a red flag. You can save your card number and expiration date for repeat purchases, but you should enter the CVV2 manually each time. This extra step is intentional security.

What if I lose my card — does someone need the CVV2 to use it?

For online purchases, yes. For in-person purchases, no — they only need the card itself. This is why you should contact your card issuer when ready if your card is lost or stolen. They will cancel it and issue a new one with a new CVV2, preventing online fraud even if someone finds your card.

Do debit cards have a CVV2?

Yes. Debit cards issued by Visa or Mastercard have a CVV2 on the back, just like credit cards. The code works the same way — it is required for online and phone purchases but is not stored after the transaction. Protect your debit card CVV2 the same way you protect your credit card CVV2.