Even if the CVV of the credit card is wrong, a token can be generated, is this correct behavior?

Yes, that is correct. The tokenization of a card isn’t a full validation. It’s a light format validation of the information. Only when the token is used to make a payment will it be validated with the information the bank has. :slightly_smiling_face: