Is it possible to verify CVC, ZIP code, and Address 1 on Stripe.createToken()?
Asked Answered
S

2

8

So my system consists of a backend and a frontend. We're doing Stripe integration.

I'm implementing Stripe checkout form on frontend to simply PCI compliance process, and I want Stripe to verify everything, including CVV / Address line 1/ ZIP before returning a token, which I use to send to the backend for further actions.

Here's how I create a token, very simple (I'm using React and Stripe Elements):

const {token, error} = await this.props.stripe.createToken(card)

The issue is a token is always returned successfully even when I fill in wrong cvc/expiry date/address 1/postal code. And I see these fields in the response:

address_line1_check: "unchecked"
address_zip_check: "unchecked"
cvc_check: "unchecked"

My question is:

Is it possible to verify CVC, ZIP code, and Address 1 before actually issuing a token?

Here is how the form looks like:

enter image description here

Feel free to enlighten me because I'm very new to online payment standards. :D

Secund answered 3/4, 2018 at 18:39 Comment(1)
You have to do something with the token to have those verified. (eg. attach it to a customer, create a charge, etc.) the only way to get that out ahead of time is to use Checkout, since it does that $0/1 auth against the bank automagically.Squiggle
C
5

I know it's an old post but recently I was faced with the same Issue. It turned out that stripe does not check for cvc/zip etc when you try to create the stripe token/source using stripe.js

However CVC etc. is checked when you try to create the customer object using this card token/source, or try to attach this token/source to the exiting customer.

Also see the accepted answer in this thread Verify CVC code before creating charge

Thanks!

Conscientious answered 5/9, 2018 at 19:14 Comment(1)
Just to expand on this...this is because the banks have to do the check. Not stripeIroning
H
1

Finally, I found this is not set by code but in the account dashboard. You can add rules to allow/block a payment in Radar -> Rules segment. When you add a rule says "Block if CVC verification fails", then all payment with wrong CVC will blocked by stripe. And notice what rules in main account and connected account need to set rules up separately.

Hypozeugma answered 7/12, 2018 at 1:50 Comment(0)

© 2022 - 2024 — McMap. All rights reserved.