A shop’s QR code does not usually require the customer and shopkeeper to use the same payment app. They can transact because their services connect to a shared payment system: the Unified Payments Interface, or UPI.
Developed by the National Payments Corporation of India, UPI enables instant transfers and operates around the clock. In its familiar bank-account form, money moves between accounts rather than needing to be loaded into a separate shopping wallet first. NPCI’s customer FAQ explains the basic system. Other supported funding arrangements exist, so “UPI” should not be used as a synonym for one bank account or one app.
The app is not the entire payment system
A payment app provides the interface for choosing a recipient, checking an amount and viewing transactions. BHIM, for example, is an application that uses UPI; it is not another name for the whole network. Its official product guide describes account linking, QR payments and transaction history.
Behind the screen are other participants. NPCI distinguishes the sending account holder and their bank, the beneficiary and their bank, and payment-service-provider banks that enable access to the system. This division of roles explains why a payment problem is not necessarily caused by the company whose app icon is on the phone. NPCI’s ecosystem glossary sets out these responsibilities.
What happens when you scan a QR code?
In a typical bank-account payment, the app reads payment details from the code. The customer checks the displayed recipient and amount, then authorises the transaction using the supported authentication method. The payment request travels through the participating institutions, and the app returns a status.
For an illustrative ₹250 shop purchase, the important checks are straightforward: does the displayed recipient match the intended shop, is the amount ₹250, and does the transaction history show the expected result? This is an example of reading a payment screen, not a claim that every app uses identical steps. A QR code is an instruction-bearing tool; its appearance alone does not establish that the intended person will receive the money.
Receiving money should not require a payment authorisation
A common scam reverses the meaning of a transaction: someone promises a refund or reward, then asks the recipient to scan a code and enter a UPI PIN. NPCI’s fraud warning explains that this scan-and-authorise sequence is for making a payment, not receiving one.
Never disclose a PIN or OTP to a caller or supposed support agent. Use help channels inside the genuine app or through your bank, rather than contact details supplied in an unsolicited message. Before approving anything, read what the screen says will happen to your money—not what another person claims it means.
Why do some payments work without a fresh PIN?
Not every supported UPI transaction follows the standard PIN-entry flow. UPI Lite supports low-value payments without entering a PIN for each payment. UPI AutoPay uses a mandate for recurring payments. A previously approved mandate is different from a stranger asking for authorisation to “send” a refund.
Eligibility, available authentication methods and transaction limits depend on the service and current rules. Check the terms shown by your app and bank; a single limit quoted online may not apply to every payment type.
What if money is debited but the payment is unclear?
Check the transaction record and bank account before assuming success or paying again. Save the transaction reference and raise the issue through the app or bank. NPCI’s customer FAQ provides grievance routes, but a pending, failed or disputed transaction should not be described as guaranteed to resolve instantly.
The useful distinction is between convenience and certainty. UPI removes much of the friction of everyday transfers; it does not remove the need to verify the recipient, understand an authorisation or follow up when the recorded outcome is unclear.



In 30 Seconds



