UPI
42.0 What this chapter gives you#
- You will be able to explain why NPCI never holds a rupee of Meera’s forty and yet determines where every one of them goes.
- You will be able to say what happens between Ravi’s speaker announcing forty rupees and his bank actually being made whole, and name the risk his bank carries in the meantime.
- You will be able to explain why UPI carries 85.5 per cent of India’s digital payment volume and only 9.5 per cent of its value, and why that is the same shape as CHAPS and Faster Payments in Britain.
- You will be able to describe single-click two-factor authentication and say why removing the OTP round trip is what made a forty-rupee payment worth making.
- You will be able to tell a customer which twelve-digit number to write down when a payment goes wrong, and what the Reserve Bank of India’s turnaround-time circular entitles them to without asking.
- You will be able to distinguish a failed payment from a payment that succeeded to the wrong person, and give the different remedy for each.
- You will be able to explain deemed status, and why a payment sitting pending for hours is neither a success nor a failure.
- You will be able to read a UPI QR code as a
upi://pay?deep link and say which parameters make it static and which make it dynamic. - You will be able to say what zero merchant discount rate is, what the amendment of 6 August 2026 changed, and why nobody should model UPI economics as though free acceptance were a law of nature.
- You will be able to design a UPI integration that survives the API rate limits, the abolition of person-to-person collect, and the fact that every number in the specification moves.
There is a country where roughly two thirds of a billion payments happen every day, where the tea seller with a plastic stool and a kettle takes forty rupees by phone without paying a fee for the privilege, and where the whole thing runs on a piece of national infrastructure owned by a not-for-profit company that no single bank controls. That country is India, and the thing is the Unified Payments Interface. It is the highest-volume retail payment system on earth, and it is worth understanding properly, because almost everything written about it is either breathless or wrong.
The plain version#
Imagine a very old-fashioned telephone exchange. Every house in town has a wire running to one building in the middle. Inside that building sits an operator with a board full of sockets. When you pick up your phone you do not dial a number, you say a name: “the baker on the high street, please.” The operator knows which socket belongs to the baker, plugs your wire into his, and the two of you are connected. You never had to know which socket he was on. You never had to know that his wire runs down Mill Lane and under the canal. You said a name and the operator did the rest.
UPI is that operator, for money.
In India, every bank account has a long number and a branch code, exactly as a British account has a sort code and an account number. Nobody enjoys typing those. So UPI lets you register a short nickname that points at your account. The nickname looks like an email address: meera@okhdfcbank, ravi@ybl, stalls9971@paytm. It is called a virtual payment address. When somebody wants to pay you, they type the nickname, or they scan a square barcode that contains the nickname, and the operator in the middle looks it up and connects the two banks.
The operator is a company called NPCI, the National Payments Corporation of India. It sits between every bank in the country. It does not hold your money. It holds the address book and it passes the messages.
Now the worked example, with real numbers.
Meera stops at Ravi’s tea stall on her way to work. Two glasses of chai, forty rupees, which is about thirty-five pence. Ravi has no card machine. He has a laminated square of paper taped to the counter with a black-and-white pattern printed on it. Meera opens her payments app, points the camera at the square, and the app fills in Ravi’s nickname automatically. She types 40. The app shows her a name: RAVI KUMAR. That name did not come from the square of paper. It came back from Ravi’s bank, a quarter of a second ago, as a check that she is paying who she thinks she is paying. She taps to confirm and types a four-digit PIN.
What happens next takes about a second and a half. Her app sends a message to her bank. Her bank sends it to NPCI. NPCI asks Ravi’s bank to confirm the address is real. Meera’s bank checks her PIN, checks she has forty rupees, and takes forty rupees off her balance. NPCI then tells Ravi’s bank to put forty rupees on his balance. Ravi’s bank does it and says so. A small speaker sitting next to Ravi’s kettle, the kind every stallholder in India now owns, says out loud in Hindi: “Forty rupees received.” Meera is already walking away.
Here is the part that surprises people. No money has actually moved between the two banks. Meera’s bank is forty rupees richer. Ravi’s bank is forty rupees poorer, because it credited Ravi out of its own pocket. Both banks made a note of it. Later that day, at one of ten scheduled moments, NPCI adds up every single thing that happened between every pair of banks, works out who owes whom on balance, and tells the Reserve Bank of India to shift the net amounts between the banks’ accounts. Meera’s forty rupees never travels on its own. It is swept up into one enormous sum with millions of other payments and settled in a lump.
Think of it as a group of friends who share a taxi every week and keep a tally on the fridge rather than passing coins about each time. At the end of the week one person hands over one note and the tally goes back to zero.
The scale of that tally is what makes UPI worth a chapter. In July 2026, the most recent full month at the time of writing, UPI processed 23,658.35 million transactions, which is 23.66 billion, worth ₹29,87,880.49 crore, which is about ₹29.9 lakh crore or roughly 29.9 trillion rupees. 741 banks were live on the system that month. Divide the volume by thirty-one days and you get about 763 million payments a day. Divide that by 86,400 seconds and you get roughly 8,800 payments every second, averaged flat across the whole day and night, which means the peaks are a great deal higher than that.
Divide the value by the volume and you get the number that explains everything: the average UPI payment in July 2026 was worth ₹1,263, about eleven pounds. This is not a system for buying flats. It is a system for buying chai, and vegetables, and a bus ticket, and topping up a phone, hundreds of millions of times an hour.
Every one of those payments gets a receipt number. It is usually twelve digits long, and it is the single most useful thing a customer can know, because when a payment goes wrong the receipt number is the only thing that lets a bank find it. More on that shortly.
Where the plain version stops being true#
The operator does not move money, and “instant” describes only what the customer sees. The telephone-exchange picture makes it sound as though NPCI holds a great pot of rupees and shifts them about. It does not. NPCI is a switch: it routes messages, applies rules, keeps score, and produces settlement files. The actual money moves between banks’ current accounts held at the Reserve Bank of India, and it moves in batches, not per payment. UPI is a deferred net settlement system dressed in real-time clothing. Since 3 November 2025, NPCI has run ten settlement cycles a day for authorised transactions, between 09:00 and 21:00 at two-hour intervals, plus two separate cycles a day for disputes, so that a chargeback can no longer delay a payments cycle. Between the moment Ravi’s phone speaks and the moment his bank is actually made whole, his bank is carrying credit risk on Meera’s bank. That risk is small per payment and enormous in aggregate, which is why NPCI caps how far into the red any member may go before it must top up, and why the number of daily cycles has crept upwards over the years. The customer experience is instant. The interbank plumbing is not, and any practitioner who confuses the two will size their liquidity wrong.
The app is not a bank, and the nickname hides less than it appears to. Meera’s app may be PhonePe or Google Pay or Paytm. None of those is a bank. They are third-party application providers, and they ride on the licence of a sponsor bank called a payment service provider bank. Money never sits with the app; the app is a user interface and a fraud-scoring engine bolted onto somebody else’s banking licence. That is a deliberate design choice and it is the single biggest reason UPI got good so fast, but it means that when an app has an outage, the correct question is which sponsor bank is down. As for the nickname: it hides the account number from the payer, which is the point, because a stolen account number plus branch code is a useful thing for a fraudster and a stolen ravi@ybl is not. It does not hide anything from NPCI, which resolves it, or from Ravi’s bank, which owns it. And the resolution deliberately leaks something back the other way: the payee’s registered name is returned to the payer before confirmation. That is an anti-fraud feature, and it is also a small, permanent, unavoidable disclosure of who owns a given address.
Volume is not value, and UPI is not where India’s money is. This is the correction that most commentary gets wrong. According to the Reserve Bank of India’s half-yearly Payment Systems Report covering the second half of 2025, UPI accounted for 85.5 per cent of India’s digital payment transactions by volume but only 9.5 per cent by value. RTGS, the high-value real-time gross settlement system, accounted for 0.1 per cent of volume and 68.6 per cent of value. NEFT took 3.6 per cent of volume and 14.9 per cent of value. The shape is identical to the United Kingdom’s, where CHAPS carries a tiny fraction of the payments and the large majority of the sterling value. UPI is the everyday rail. It is not the wholesale rail, it was never designed to be, and a person who says “India moves its money on UPI” is describing counts, not sums.
Free to the customer is not the same as free, and the law changed in August 2026. Since 1 January 2020, merchant discount rate on bank-account UPI and on RuPay debit has been set at zero by statute, through Section 10A of the Payment and Settlement Systems Act 2007 and Section 269SU of the Income-tax Act 1961, both inserted by the Finance (No. 2) Act 2019. Zero MDR is why Ravi accepts UPI: a card machine would have cost him a rental and a percentage, and a QR sticker costs him the price of the lamination. But zero MDR is a subsidised outcome, not a costless one. NPCI charges member banks a switching fee, banks carry the infrastructure, and the government has run an incentive scheme to compensate the ecosystem for the foregone revenue. On 6 August 2026 the Lok Sabha passed the Taxation and Other Laws (Amendment) Bill, 2026, which amends Section 10A of the Payment and Settlement Systems Act to give the central government the power to permit charges on UPI and other notified electronic modes. At the time of writing no charge has been notified and small-value payments are widely expected to stay free, but the statutory bar that made zero MDR permanent has been removed. Anyone modelling UPI economics past 2026 should treat the current position as a policy choice rather than a law of nature. Note also that three flows already sit outside the zero-MDR perimeter today: RuPay credit card on UPI above ₹2,000, prepaid-instrument-on-UPI, and credit line on UPI.
The technical version#
What NPCI is, and what it is not#
The National Payments Corporation of India was incorporated in 2008 as a not-for-profit company, promoted by the Reserve Bank of India and the Indian Banks’ Association, and it operates India’s retail payment systems under authorisation from the RBI under the Payment and Settlement Systems Act, 2007. Its registered office is at 1001A, The Capital, B Wing, Bandra Kurla Complex, Mumbai 400 051, and its corporate identity number, U74990MH2008NPL189067, encodes the “not-for-profit public limited” status that shapes everything about how it behaves. It runs IMPS, NACH, RuPay, NETC FASTag, the National Financial Switch, AePS, BHIM and UPI, and it has two subsidiaries of note: NPCI International Payments Limited, which exports the stack, and NPCI Bharat BillPay.
The relevant comparison for a British reader is Pay.UK rather than Visa. NPCI is the scheme operator and the switch. It is not a bank, it is not a settlement agent, and it does not take a percentage of the transaction. It levies a switching fee on member banks, and NPCI’s own circulars refer to rebate arrangements on that fee through the URCS back-office system, which is where reconciliation, adjustments and chargebacks are handled.
UPI went live as a pilot on 11 April 2016, launched by Dr Raghuram G. Rajan, then Governor of the Reserve Bank of India, in Mumbai, with 21 banks. As at March 2026 there were 703 banks live, and as at July 2026, 741.
The participant stack#
A single UPI payment involves more legal entities than most people expect. The roles, in NPCI’s own vocabulary, are these.
The UPI app is the interface the customer touches. The payer PSP is the payment service provider bank whose licence that app rides on; if the app is a bank’s own app, the two are the same entity, and if the app is a third-party application provider such as PhonePe, Google Pay or Paytm, the PSP is a sponsor bank. Axis Bank and Yes Bank are the two largest sponsors by volume. The remitter bank is the bank that actually holds the payer’s account and performs the debit. The payee PSP is the equivalent on the receiving side, and the beneficiary bank holds the account that gets credited. For merchant payments there is also an acquiring bank and, very often, a payment aggregator sitting between the merchant and the acquirer.
The separation of the app layer from the account layer is the architectural decision that made UPI what it is. A company with no banking licence, no branch network and no balance sheet can build a payments app, compete purely on user experience, and reach every bank account in India on day one. That is why the market is so concentrated in the app layer and so fragmented in the bank layer: as at recent months PhonePe and Google Pay between them have run roughly four fifths of UPI volume, against an NPCI rule capping any single third-party application provider at 30 per cent. NPCI first announced that cap in November 2020 and has extended the compliance deadline three times; the current deadline is 31 December 2026, accurate at the time of writing. Whether it is enforced is one of the genuinely open questions in Indian payments.
Addressing: the VPA, the UPI number and the mapper#
The virtual payment address takes the form handle@psp. The left side is chosen by the customer or generated by the app; the right side identifies the PSP, so @okhdfcbank, @oksbi, @ybl, @paytm, @axl. The address is not a bank account. It is a pointer, resolved by NPCI’s central mapper to a specific account at a specific bank. One customer may have several addresses pointing at the same account, or several accounts behind one address with one nominated as default.
Three other addressing forms exist. A UPI Number is a numeric alias, typically the customer’s mobile number, mapped to an account through NPCI’s mapper; NPCI’s circular series on the Numeric UPI ID continues into FY 2026-27. A payer may also address a payment to a raw account number plus IFSC, which is how UPI absorbs the older IMPS use case. And a payment may be addressed by QR code, which is simply an encoded address plus optional parameters, covered below.
Before any money moves, the payer’s app performs an address validation. The resolved registered beneficiary name is returned and displayed. This is mandatory, it is the reason UPI’s mis-payment rate is as low as it is, and it is the reason a UPI address cannot be treated as private.
Authentication: device binding, the Common Library, and single-click two-factor#
Indian regulation requires two-factor authentication on electronic payments. Card payments satisfy this with a card plus an OTP, which costs a round trip through a mobile network and is where a large share of card failures come from. UPI satisfies it without any round trip at all, and this is the second architectural decision that made the system work.
At registration, the app sends an outbound SMS from the handset to bind the device to the customer’s mobile number as registered with the bank. That establishes the device as the first factor, something the customer has. The UPI PIN, four or six digits, is the second factor, something the customer knows. Because the device is already bound, no OTP is needed at payment time. NPCI calls the result single-click two-factor authentication, and it is worth pausing on how much latency and failure that removes.
The PIN is never seen by the app or by the PSP. It is captured inside NPCI’s Common Library, a component embedded in every UPI app, which encrypts the keystrokes into a credential block under NPCI’s public key. The block travels through the app, the PSP and the switch as opaque ciphertext and is decrypted and verified only at the remitter bank, inside a hardware security module. A compromised app cannot harvest PINs. A compromised PSP cannot replay them.
The PIN itself is set using a second-channel credential: historically the last six digits and expiry date of the customer’s debit card, and more recently Aadhaar-based verification, which removed the requirement to hold a debit card at all and opened UPI to the very large population of Jan Dhan account holders who never had one. NPCI’s circulars on user onboarding cover this route.
The two legs: debit and credit#
A UPI push payment is two legs and a switch. Both legs are synchronous request-response messages over the UPI API, an XML message set carried over mutually authenticated TLS with digital signatures on the payload. The messages a practitioner meets are named in matched pairs: ReqPay and RespPay for the payment itself, ReqValAdd and RespValAdd for address validation, ReqAuthDetails and RespAuthDetails for the credential and authorisation exchange with the remitter bank, ReqChkTxn and RespChkTxn for status enquiry, ReqBalEnq for balance, ReqListAccount for account discovery, ReqMandate for e-mandates and ReqComplaint for disputes.
The sequence for Meera paying Ravi is as follows.
The app resolves ravi@ybl with ReqValAdd, which the switch routes to the payee PSP; the response carries the registered name, which the app displays. The customer enters the amount and the PIN; the Common Library produces the credential block. The app issues ReqPay to the payer PSP carrying a transaction ID of up to 35 characters generated by the initiating PSP, the amount, both addresses, a purpose code, and, for merchant payments, a merchant category code. The payer PSP signs and forwards it to the UPI switch.
The switch performs the debit leg: it presents the credential block and the debit instruction to the remitter bank, which validates the PIN in its HSM, applies its own velocity and value limits, checks the balance, debits the account and responds. Only on a successful debit does the switch perform the credit leg, presenting the credit instruction to the beneficiary bank, which credits the payee’s account and responds. The switch then returns RespPay to both PSPs, and both customer apps show the outcome.
Three failure shapes matter, and they are the source of most customer distress.
If the debit fails, nothing has happened and the customer sees a decline. Common response codes are 00 for success, Z9 for insufficient balance, ZM for an incorrect UPI PIN and ZA for a transaction declined by the customer; the authoritative list lives in NPCI’s API and technical specification and runs to several hundred entries across issuer, acquirer and switch categories.
If the debit succeeds and the credit fails cleanly, the switch initiates a reversal and the money returns, usually within minutes.
If the debit succeeds and the credit times out without a definitive answer, the transaction enters an indeterminate state. NPCI’s rules define deemed approval and deemed debit handling for exactly this case, with dedicated circulars on the subject in FY 2025-26 and FY 2026-27, and the position is resolved in the next reconciliation cycle through the URCS back office. This is the state in which the customer’s money has genuinely left their account and has genuinely not arrived, and it is the state the next section is about.
A collect or pull payment inverts the first half of the flow. The payee’s PSP issues ReqPay in collect mode; the switch delivers a pending request to the payer’s PSP, which notifies the payer; the payer approves with a UPI PIN inside an expiry window set by the requester; the debit and credit legs then run exactly as above. Collect is how a merchant’s website asks a customer’s app for money without a redirect, and it is how UPI handles subscription first-payments and IPO applications.
Collect is also, historically, UPI’s worst fraud surface, because a request for money looks superficially like an offer of money to an inexperienced user. Fraudsters exploited that relentlessly. NPCI’s response was progressive restriction and then abolition: the person-to-person collect limit was reduced to ₹2,000, and from 1 October 2025 NPCI discontinued person-to-person collect requests on UPI entirely. Merchant collect remains available to verified merchants. If you are designing a UPI integration today, plan for a world in which pull only exists in the merchant direction.
Settlement#
Settlement is deferred and net. NPCI accumulates every authorised transaction, computes each member’s multilateral net position, and produces a settlement file. Members hold current accounts with the Reserve Bank of India, and the net positions are posted against those accounts. NPCI operates net debit caps and collateral requirements so that no member can accumulate an unfunded net debit position beyond a prescribed limit.
The cycle structure changed on 3 November 2025. Before that date, authorised transactions and disputes shared the same cycles. From that date, authorised settlement runs in ten cycles a day between 09:00 and 21:00 at two-hourly intervals, and disputes run in two separate cycles, one covering midnight to 16:00 and one covering 16:00 to midnight. RTGS posting timelines were unchanged. The purpose is to stop a large chargeback batch from delaying a payments cycle, and to make each cycle’s arithmetic cleaner for members’ treasury teams. This is accurate at the time of writing; settlement cycle structures change, and a practitioner should read NPCI’s current circular rather than a book.
For a British reader the mental map is: UPI’s customer experience resembles Faster Payments, its settlement model resembles Faster Payments’ deferred net settlement rather than CHAPS’ real-time gross settlement, and its addressing and app layer occupy the space that Open Banking occupies in the United Kingdom. The difference is that in India those layers are one system with one rule book, whereas in the United Kingdom the rail, the addressing and the API layer are three separate things governed by three separate regimes.
| UPI (India) | Faster Payments (UK) | Bacs (UK) | |
|---|---|---|---|
| Operator | NPCI | Pay.UK | Pay.UK |
| Customer experience | Seconds, 24/7 | Seconds, 24/7 | Three working day cycle |
| Settlement model | Deferred net | Deferred net | Deferred net |
| Addressing | VPA, UPI number, QR, account plus IFSC | Sort code and account number, Paym | Sort code and account number |
| Per-transaction ceiling | ₹1 lakh default, higher for listed categories | GBP 1 million | Set by scheme and sponsor |
| Recurring | UPI AutoPay e-mandate | Standing order | Direct Debit |
Identifiers, and what to do when money vanishes#
Every UPI transaction carries at least two identifiers, and confusing them wastes hours.
The UPI transaction ID is generated by the initiating PSP and may be up to 35 characters. It is the app’s handle on the transaction. It is excellent for talking to the app’s support team and close to useless for talking to a bank.
The Retrieval Reference Number, twelve digits, is generated by the switch and carried through both legs. Consumer apps display it under labels including “UPI Ref No”, “UPI transaction reference” and, most commonly, UTR, for unique transaction reference. Strictly, UTR is the term the Indian banking system uses for the reference on a NEFT or RTGS credit and RRN is the term for a switched retail transaction, but in ordinary Indian usage the twelve-digit number on a UPI receipt is called the UTR by customers, banks and NPCI’s own support material alike. It is the number that both the remitter bank and the beneficiary bank can search on. It is the number to write down.
Now the procedure, because this is the part a customer actually needs.
Money leaves the account and does not arrive. First, distinguish two cases, because they have completely different remedies. If the payment failed — the app showed an error, a pending state or a timeout — this is a system failure and the rules are on the customer’s side. If the payment succeeded but went to the wrong person — the customer typed the wrong address, or was defrauded — this is not a system failure, there is no automatic reversal, and the remedy is a fraud report to the bank and to the National Cyber Crime Reporting Portal, plus, in practice, the beneficiary’s consent.
For the failure case, the governing rule is the Reserve Bank of India’s circular RBI/2019-20/67 of 20 September 2019, “Harmonisation of Turn Around Time (TAT) and customer compensation for failed transactions using authorised Payment Systems”. Its two UPI rows are precise. Where the account is debited but the beneficiary account is not credited on a funds transfer, the beneficiary bank must auto-reverse latest on T+1 day, and beyond that the customer is entitled to ₹100 per day of delay. Where the account is debited but transaction confirmation is not received at a merchant location, auto-reversal is within T+5 days, with the same ₹100 per day beyond it. The compensation is not discretionary and does not require the customer to ask.
The escalation ladder, in order, is: raise the complaint inside the app, because UPI carries a native dispute mechanism and apps are required to expose it; if unresolved, go to the PSP bank; if still unresolved after thirty days, escalate to NPCI through the UPI Help portal at upihelp.npci.org.in; and beyond that to the Reserve Bank - Integrated Ombudsman Scheme through the RBI’s complaint management system. At every rung, the first thing anybody will ask for is the twelve-digit reference.
There is one more state worth knowing. A transaction may sit in deemed status, where the switch never received a definitive answer from one leg. To a customer it looks identical to a failure. Internally it is not a failure at all; it is an unresolved fact, and it is settled by reconciliation rather than by reversal. NPCI’s response-code extensions for deemed debit on mandate execution, issued as an addendum to circular OC-128 in FY 2026-27, exist because this state kept producing wrong customer outcomes on AutoPay. If a customer’s payment sits pending for hours rather than seconds, deemed status is usually why.
QR codes#
A UPI QR code is not a special data format. It is a text string, encoded as a standard QR symbol, containing a UPI deep link of the form upi://pay? followed by URL query parameters. The parameters a practitioner meets are pa for the payee address, pn for the payee name, am for amount, cu for currency, always INR, tr for a transaction reference, tn for a note, mc for the merchant category code, mode and sign for signed intent. A static merchant QR omits am, so the customer types the amount; a dynamic QR, generated per bill by a till or a printer, includes both am and tr, which is what allows automatic reconciliation against an invoice.
The same string, invoked on a handset rather than printed, is an intent: tapping a upi://pay? link on an Android device offers the user their installed UPI apps and hands the parameters straight across. That is the mechanism behind every “Pay by UPI” button on an Indian checkout page, and it is why a UPI merchant integration requires no card fields, no 3-D Secure and no redirect.
NPCI publishes brand guidelines for merchant QR, with a circular series on mandatory BHIM UPI merchant QR branding running to an addendum in FY 2026-27, and separately supports EMVCo-compliant QR for interoperability with card schemes and for international acceptance. Circular OC No. 236 of FY 2026-27 covers enhancement of international mobile application payment acceptance through UPI QR in India, which is the mechanism that lets a visitor’s foreign wallet scan an Indian merchant’s sticker.
The economics of the QR are the whole story of UPI’s merchant reach. A card terminal costs a merchant a device, a rental, a telephone or data line and a percentage of every sale. A UPI QR costs the price of printing. The Reserve Bank of India’s Annual Report for 2024-25 recorded UPI QR codes rising 91.5 per cent to 65.8 crore, that is 658 million, against a point-of-sale terminal estate roughly two orders of magnitude smaller. There is no version of the card model that reaches a tea stall. There is an obvious version of the sticker model that does.
Collect requests, mandates and UPI AutoPay#
UPI AutoPay, launched in 2020, is the recurring-payments layer. It is a genuine e-mandate rather than a stored credential: the customer authorises a mandate once, with additional factor of authentication, and the mandate is registered against their account at the remitter bank with a Unique Mandate Number. Subsequent executions do not require the PIN.
The parameters a practitioner needs are these. The customer receives a pre-debit notification at least 24 hours before any execution, so that funds can be arranged; NPCI waives the pre-debit notification only for auto-replenishment of NETC FASTag and RuPay NCMC balances. The additional factor of authentication limit — the ceiling below which no per-execution authentication is needed — was raised from ₹15,000 to ₹1,00,000 for credit card bill payment, mutual fund and insurance use cases. The customer can modify, revoke, pause and unpause a mandate from within any UPI app, and that control must be exposed in the app rather than buried with the merchant, which is a materially stronger consumer position than a card-on-file subscription.
Frequency options run from one-time through daily, weekly, fortnightly, monthly, bi-monthly, quarterly, half-yearly, yearly and as-presented, which is why AutoPay swallowed use cases as varied as OTT subscriptions, insurance premiums, SIP mutual fund instalments, loan EMIs and utility bills.
One operational constraint matters for anyone building on AutoPay. From 1 August 2025, NPCI began rate-limiting UPI APIs to protect the switch at peak. Balance enquiries are capped at 50 per app per day, non-customer-initiated API calls are restricted during peak hours, and peak hours are defined as 10:00 to 13:00 and 17:00 to 21:30. Mandate executions are pushed into off-peak windows. If your batch of mandate executions is scheduled for eleven in the morning, it will not run when you expect it to.
Limits#
NPCI sets ceilings; member banks set their own limits within them, and often lower. The default per-transaction and per-day ceiling for ordinary person-to-person and person-to-merchant use is ₹1,00,000, with banks free to impose tighter caps, and many impose a first-24-hour cap on a newly linked account and a cap on the number of transactions per day.
Higher ceilings apply to specific merchant categories, and the governing document is NPCI circular NPCI/UPI/2025-26/OC/185B dated 28 August 2025, an addendum to OC 185A, with a compliance date of 15 September 2025. The enhanced limits apply only to merchants classified as Verified Merchant and compliant with NPCI’s merchant onboarding circulars. Person-to-person limits were explicitly left unchanged.
| Category | Merchant category code | Per transaction | Cumulative, 24 hours |
|---|---|---|---|
| Capital markets | 6211 | ₹5 lakh | ₹10 lakh |
| Insurance | 5960 | ₹5 lakh | ₹10 lakh |
| Government e-Marketplace, EMD payments | 9311 | ₹5 lakh | ₹10 lakh |
| Travel | 4722 | ₹5 lakh | ₹10 lakh |
| Credit card bill payments | 5413 | ₹5 lakh | ₹6 lakh |
| Collections | 7322 | ₹5 lakh | ₹10 lakh |
| Business or merchant, including pre-approved payments | Payer MCC not 0000, purpose code 20 or 15 | ₹5 lakh | not applicable |
| Jewellery | 5944 | ₹2 lakh | ₹6 lakh |
| FX-Retail via BBPS | 6012 | ₹5 lakh | ₹5 lakh |
| Digital account opening, term deposits | 7410 | ₹5 lakh | ₹5 lakh |
| Digital account opening, initial funding | 7409 | ₹2 lakh | ₹2 lakh |
Two adjacent products carry their own ceilings. UPI Lite is an on-device wallet designed for payments below ₹1,000, processed without a UPI PIN and without a round trip to the bank’s core banking system; it exists to take load off issuers’ cores and to keep passbooks uncluttered, and the balance behaves like cash in that losing the device without disabling the wallet means going to the bank for a refund. UPI Circle, which lets a primary user delegate spending authority to a secondary user or to a trusted device, carries limits of ₹5,000 per transaction per device, ₹15,000 per month per device, ₹2,000 in the first 24 hours after linking, and a maximum of five linked secondary devices or software agents, per NPCI’s published product page at the time of writing.
All of these figures are accurate at the time of writing and all of them have moved before. Read the current circular.
Why it reached these volumes#
It is tempting to attribute UPI’s scale to India’s population, but population explains the ceiling, not the trajectory. Several deliberate design choices did the work, and they are transferable.
Interoperability was mandatory from the first day. Any app could pay any bank account. There was never a period in which a merchant had to accept four different wallets, and there was never a network effect that a single incumbent could capture. Compare the closed-wallet era that immediately preceded it, in which a customer holding one wallet simply could not pay a merchant who accepted another.
The app layer was separated from the licensed layer. Firms with no balance sheet could compete on user experience alone. That created ferocious product competition without creating prudential risk, because customer money never rested outside a bank.
Authentication was made cheap. Device binding plus PIN removed the OTP round trip, which removes both latency and a large class of failures. A payment that completes in under two seconds gets used for a forty-rupee purchase. A payment that takes twenty seconds and fails one time in twenty does not.
Addressing was abstracted. The VPA removed both the friction of typing an account number and the risk of publishing one. The mandatory name-return closed most of the mis-payment gap that abstraction would otherwise have opened.
Merchant acceptance was made nearly free, at both ends. Zero MDR removed the merchant’s financial reason to refuse, and the printed QR removed the merchant’s capital cost to accept. Those two together are why acceptance reached the informal economy, which no card scheme has ever managed anywhere.
The prerequisites were already in place. Bank accounts from the Jan Dhan financial inclusion programme, identity from Aadhaar, and mobile connectivity at some of the lowest data prices in the world gave UPI an addressable base it did not have to create. Demonetisation in November 2016, seven months after launch, provided an accelerant that no product plan could have arranged.
The specification kept moving. UPI 2.0 in August 2018 added linked overdraft accounts, one-time mandates, invoice-in-the-inbox and signed intent and QR. Later layers added AutoPay, UPI Lite, UPI 123Pay for feature phones, RuPay credit card on UPI, credit line on UPI, UPI Circle and IPO applications on UPI. Each layer reused the same switch, the same addressing and the same authentication, which is why each shipped in months rather than years.
UPI 123Pay deserves a specific mention because it is the clearest evidence that the design was about reach rather than about smartphones. It offers feature-phone users four routes: calling an interactive voice response number, an app running on the feature phone itself, a missed-call-based flow, and proximity sound-based payments. None of these requires a data connection in the ordinary sense.
The results, in NPCI and government figures published on 30 April 2026 to mark ten years of the system: annual volume grew from 2 crore transactions in FY 2016-17 to 24,161.69 crore in FY 2025-26, an increase of roughly twelve thousand times; annual value in FY 2025-26 exceeded ₹314 lakh crore; the daily average through 2025 was about 60 crore transactions, rising past 66 crore; person-to-merchant payments made up 63 per cent of volume while person-to-person made up 71 per cent of value; and 86 per cent of merchant payments were below ₹500. The International Monetary Fund, in a June 2025 report, recognised UPI as the world’s largest real-time payment system by transaction volume, at roughly 49 per cent of global real-time payment volume.
The honest caveats#
Concentration is real. Two apps run about four fifths of the volume, the rule says 30 per cent, and the deadline has moved three times. An outage at one of those apps, or at one of the two dominant sponsor banks, degrades payments for a very large fraction of the country at once. NPCI publishes uptime and downtime statistics per member precisely because this is the live risk.
Economics are unresolved. Zero MDR made acceptance universal and left the ecosystem dependent on a government incentive scheme that has consistently funded only a fraction of industry cost. The August 2026 amendment to Section 10A is the first legislative acknowledgement that this cannot continue indefinitely. Whatever emerges will be a compromise between the merchant reach that free acceptance bought and the revenue that maintaining the rail requires.
Fraud has migrated rather than disappeared. The collect request was closed off; social engineering, mule accounts and fake customer-support numbers were not. NPCI’s FY 2026-27 circular OC No. 234 on safeguarding user information in UPI, and the revision of turnaround times for fraud and wrong-credit chargebacks in URCS, are the current front line.
And the system is not finished. Circulars in the current financial year cover a limit management member portal, on-device biometric authentication with an enhanced transaction ceiling, numeric UPI IDs, and international QR acceptance. Anything in this chapter with a number attached should be checked against NPCI’s circular list before it is relied upon in production. That is not a weakness of the writing. It is the nature of a rail that is still being built at the same time as it carries eight thousand payments a second.
42.98 Common wrong ideas#
Wrong: UPI is an instant payment system end to end. Right: the customer experience is instant and the interbank plumbing is deferred net settlement, in ten cycles a day between 09:00 and 21:00 since 3 November 2025, and a practitioner who confuses the two will size their liquidity wrong.
Wrong: NPCI holds the money and shifts it between banks. Right: NPCI is a switch that routes messages, applies rules, keeps score and produces settlement files; the money moves across banks’ current accounts at the Reserve Bank of India.
Wrong: India moves its money on UPI. Right: UPI is 85.5 per cent of digital payment volume and 9.5 per cent of value, while RTGS is 0.1 per cent of volume and 68.6 per cent of value; that claim describes counts, not sums.
Wrong: PhonePe, Google Pay and Paytm are banks. Right: they are third-party application providers riding on a sponsor payment service provider bank’s licence, which is why the right question during an outage is which sponsor bank is down.
Wrong: a virtual payment address keeps the account holder anonymous. Right: it hides the account number from the payer, and nothing at all from NPCI or the payee’s bank, and the registered name is deliberately returned to the payer before confirmation.
Wrong: UPI is free. Right: zero merchant discount rate is a statutory policy subsidised by member banks, NPCI switching fees and a government incentive scheme, three flows already sit outside the perimeter, and the statutory bar was removed on 6 August 2026.
Wrong: the transaction ID shown in the app is the reference to quote when chasing a payment. Right: the up-to-35-character transaction ID is the app’s handle; the twelve-digit retrieval reference number, commonly called the UTR, is the number both banks can search on.
Wrong: if money leaves the account and does not arrive, the customer must chase it and hope. Right: auto-reversal is due latest on T+1 for a funds transfer and within T+5 at a merchant location, with ₹100 per day of delay beyond that, and the compensation is not discretionary.
Wrong: a collect request is a normal way to ask an individual for money. Right: person-to-person collect was progressively restricted and then discontinued entirely from 1 October 2025, because a request for money looks like an offer of money to an inexperienced user.
Wrong: mandate executions and API calls can be scheduled whenever it suits the merchant. Right: since 1 August 2025 NPCI rate-limits UPI APIs, caps balance enquiries at fifty per app per day, and pushes non-customer-initiated calls out of the peak windows of 10:00 to 13:00 and 17:00 to 21:30.
42.99 Chapter summary in 20 lines#
- UPI is India’s retail payment switch, operated by NPCI, a not-for-profit company promoted by the Reserve Bank of India and the Indian Banks’ Association, live since 11 April 2016.
- NPCI holds no money: it keeps the address book, routes the messages, applies the rules and produces the settlement files.
- A payment is addressed by virtual payment address, UPI number, QR code or raw account number plus IFSC, and the address is resolved to an account by NPCI’s central mapper.
- Before any debit, the payee’s registered name is returned and displayed, which is why mis-payment is rare and why a UPI address cannot be treated as private.
- Two-factor authentication is satisfied by a bound device plus a PIN, with no OTP round trip, which NPCI calls single-click two-factor authentication.
- The PIN is encrypted inside NPCI’s Common Library and decrypted only in the remitter bank’s hardware security module, so neither the app nor the PSP ever sees it.
- A push payment is two synchronous legs: the switch performs the debit at the remitter bank and only on success performs the credit at the beneficiary bank.
- Failures come in three shapes: a clean decline, a credit failure that reverses within minutes, and a timeout that leaves the transaction in deemed status until reconciliation resolves it.
- Settlement is deferred and net across members’ current accounts at the Reserve Bank of India, in ten cycles a day between 09:00 and 21:00 since 3 November 2025, with two separate cycles for disputes.
- Between the customer’s instant result and settlement the beneficiary bank carries credit risk on the remitter bank, which is why NPCI runs net debit caps and collateral requirements.
- The app layer was separated from the licensed layer, so firms with no balance sheet compete on user experience while customer money never rests outside a bank.
- That separation also produced extreme concentration: two apps run about four fifths of volume against a 30 per cent cap whose deadline has moved three times and now stands at 31 December 2026.
- In July 2026 UPI carried 23.66 billion transactions worth about ₹29.9 lakh crore across 741 banks, roughly 763 million payments a day.
- The average payment was ₹1,263, about eleven pounds, which is the number that explains everything: this is a rail for chai and vegetables, not for flats.
- Zero merchant discount rate, statutory since 1 January 2020, is why a tea stall accepts a laminated sticker that cost the price of printing rather than a terminal with a rental and a percentage.
- On 6 August 2026 the Lok Sabha passed an amendment removing the statutory bar on charging, so the free-to-use position is now a policy choice rather than a law of nature.
- When money vanishes, the twelve-digit reference is the only thing that lets a bank find it, and the escalation ladder runs app, PSP bank, NPCI’s UPI Help portal, then the Reserve Bank Integrated Ombudsman Scheme.
- UPI AutoPay is a genuine e-mandate with pre-debit notification, customer-side control and frequency options from daily to as-presented, subject to peak-hour rate limits.
- The scale came from mandatory interoperability, cheap authentication, abstracted addressing, near-free acceptance at both ends, an existing base of accounts, identity and cheap data, and a specification that never stopped moving.
- The unresolved problems are concentration, the economics of zero MDR, and fraud that migrated to social engineering rather than disappearing, which is why every figure here should be checked against NPCI’s current circular before production use.
Sources: NPCI (UPI product statistics for July 2026, About UPI, UPI AutoPay, UPI Lite, UPI Circle, UPI 123PAY, UPI circular list, and circular NPCI/UPI/2025-26/OC/185B of 28 August 2025); Reserve Bank of India (circular RBI/2019-20/67 of 20 September 2019 on turn around time and customer compensation, Annual Report 2024-25, and the half-yearly Payment Systems Report covering H2 2025); Press Information Bureau releases of 30 April 2026 and on zero MDR; the Payment and Settlement Systems Act 2007 as amended, and reporting on the Taxation and Other Laws (Amendment) Bill, 2026 passed by the Lok Sabha on 6 August 2026.