How a UPI QR code works
A UPI QR code holds a payment link that begins with upi://pay. When a UPI app scans it, the app reads the payee’s virtual payment address (the UPI ID), the payee name and any amount or note, then asks the payer to confirm with their UPI PIN. The money moves between bank accounts through UPI, the real-time payment system operated by the National Payments Corporation of India (NPCI).
Because the format is shared, a code created for one bank or app works with any other UPI app. A person-to-person code usually carries only the UPI ID and name, while a merchant code may add a merchant category code and a transaction reference.
Fields in the upi://pay link
The link is a set of query parameters. A minimal example is upi://pay?pa=shop@examplebank&pn=Example%20Store&cu=INR. Adding am=250.00 fixes the amount, and adding tn sets a note that appears in the payer’s app. Spaces and special characters in the name or note must be percent-encoded.
- pa: payee address (UPI ID), required
- pn: payee name
- am: amount, in rupees with up to two decimals
- cu: currency, INR
- tn: transaction note
- mc and tr: merchant category code and transaction reference, used by merchants
Static codes, dynamic codes and safety
A static UPI QR code without an amount can be printed and reused, and the payer enters the amount each time. A dynamic code includes the amount and a reference for one order. Scanning a UPI code can only send money from the payer; it cannot pull money in, so a message that says “scan this code to receive a refund” is a common scam pattern.