EMV QR code

Also called: EMVCo QR, EMV MPM, merchant-presented QR

Definition

An EMV QR code is a payment QR code that follows the EMVCo specification, a tag-length-value format that many national schemes use to encode a merchant, currency and amount.

What the EMV QR specification covers

The EMV QR code specification from EMVCo defines how payment data is laid out inside an ordinary QR code. It comes in two modes. In Merchant-Presented Mode (MPM) the merchant displays a code and the customer scans it with a banking or wallet app. In Consumer-Presented Mode (CPM) the customer’s app shows a code and the merchant scans it at the till.

The specification does not create a payment network. It is a shared data format, so a national scheme or a card network can add its own account details while keeping the rest of the payload the same. That is why Pix in Brazil, PromptPay in Thailand, SGQR in Singapore, DuitNow in Malaysia, QRIS in Indonesia, VietQR in Vietnam and Bharat QR in India all look structurally alike.

How the payload is structured

An MPM payload is a string of data objects, each written as a two-digit ID, a two-digit length and the value. For example, 5303840 means ID 53 (transaction currency), length 03, value 840 (US dollars in ISO 4217 numeric form). Objects follow one another with no separators, and some IDs are templates that contain their own nested objects in the same format.

The payload must begin with ID 00 and end with ID 63, a checksum. The checksum is a CRC-16/CCITT-FALSE value written as four hexadecimal characters, calculated over everything before it including the characters 6304. A scanner that computes a different checksum rejects the code, which catches most typing or copying errors.

  • 00: payload format indicator, always 01
  • 01: point of initiation, 11 for static or 12 for dynamic
  • 26–51: merchant account information templates
  • 52: merchant category code (MCC)
  • 53: currency (ISO 4217 numeric) and 54: amount
  • 58: country code, 59: merchant name, 60: city
  • 62: additional data such as a bill or reference number; 63: CRC

Static and dynamic codes

A static EMV QR code (point of initiation 11) is printed once and reused, and the customer types the amount. A dynamic code (point of initiation 12) is generated for a single transaction and usually carries the amount and a reference, so the customer only confirms. Printed counter stickers are typically static, while codes on a checkout screen or invoice are typically dynamic.

Frequently asked questions

What is the difference between MPM and CPM QR payments?

In Merchant-Presented Mode the customer scans a code shown by the merchant. In Consumer-Presented Mode the merchant scans a code shown on the customer’s phone.

Can any QR code app read an EMV payment QR code?

Any QR reader can decode the text, but only a payment app that supports the scheme named inside the code can turn it into a payment.

What does the 6304 at the end of a payment QR string mean?

It is the start of the checksum object: ID 63, length 04, followed by four hexadecimal characters of CRC-16 calculated over the whole payload.

Sources and standards

All terms