Skip to content
This repository was archived by the owner on May 16, 2026. It is now read-only.
This repository was archived by the owner on May 16, 2026. It is now read-only.

Merchant payments (and potentially avoid issues seen with major payment apps) #38

Description

@reeteshranjan

Is your feature request related to a problem? Please describe.

  1. Merchant payments: UPI deep linking specification, implemented by this package, is for merchant payments by design though individual to individual payments are supported by several apps on an ad-hoc basis. Work on this feature will add merchant payment support.
  2. Security warning/errors on major apps: Discussion with Bank of Baroda UPI team reveals that several major payment apps are looking to avoid fraud on UPI by doing a strict check on authenticity of payments. This makes these issues appear more related to the lack of merchant signature in current version of the package. This is further seen in the following snippet from the UPI deep linking specification which is about how a UPI payment app should verify a UPI deep linking request (the ones made through this package)

Screenshot 2021-07-09 at 5 14 47 PM

Describe the solution you'd like

  1. Mechanism in which users can create merchant signature themselves:
    1. Provide an API that would generate the UPI transaction request in the format specified in point 3 in section 1.3 of UPI deep linking specification towards signing by a package user app using their merchant private key.
    2. Provide an API that would accept the UPI transaction data and the signature created and will perform the UPI transaction
  2. Provide an API that implements signing using the algorithm described in point 3 in section 1.3 (RSA512 and SHA256) for users that are OK with providing their private key and then performs the UPI transaction.

The API changes/additions should retain backward compatibility for non-merchant payments.

Describe alternatives you've considered

This aspect of the UPI deep linking specification has no alternatives.

Any example solutions

This feature is research based and is an attempt to implement part of the UPI deep linking specification not yet implemented. There is no example solution known.

Additional context

None

Activity

  1. pinned this issue on Jul 23, 2021
  2. reeteshranjan commented on Aug 26, 2021

    @reeteshranjan
    CollaboratorAuthor

    Expecting to close the work on this in September. Merchant bank account setup, required for the work, has been delayed for various reasons.

  3. vshanthamoorthi commented on Sep 9, 2021

    @vshanthamoorthi

    hi @reeteshranjan, looking for this feature as currently transfer is flagged as possible fraud transaction. so please let me know if some help needed.

  4. reeteshranjan commented on Sep 13, 2021

    @reeteshranjan
    CollaboratorAuthor

    hi @reeteshranjan, looking for this feature as currently transfer is flagged as possible fraud transaction. so please let me know if some help needed.

    Thanks for the offer to help!

    As of now my work on getting a merchant bank account setup is delayed. If you have one (a commercial current account with UPI keys setup), and you wish to provide details for me to be able to develop and test the functionality, please do so.

    I am expecting to move my own merchant bank account setup to move this week; but nothing sure as of now.

  5. vshanthamoorthi commented on Sep 13, 2021

    @vshanthamoorthi
  6. Chanelle25meyer commented on Sep 15, 2021

    @Chanelle25meyer

    I have commercial bank accounts and UPI is setup for the same through gpay. does this work? if yes, let me know at vshanthamoorthi at gmail.com
    …
    On Mon, Sep 13, 2021 at 2:31 PM Reetesh Ranjan @.***> wrote: hi @reeteshranjan https://github.com/reeteshranjan, looking for this feature as currently transfer is flagged as possible fraud transaction. so please let me know if some help needed. Thanks for the offer to help! As of now my work on getting a merchant bank account setup is delayed. If you have one (a commercial current account with UPI keys setup), and you wish to provide details for me to be able to develop and test the functionality, please do so. I am expecting to move my own merchant bank account setup to move this week; but nothing sure as of now. — You are receiving this because you are subscribed to this thread. Reply to this email directly, view it on GitHub <#38 (comment)>, or unsubscribe https://github.com/notifications/unsubscribe-auth/AJPYSRZNF5AII37KFHARMJLUBW4XPANCNFSM5ACUAYOA . Triage notifications on the go with GitHub Mobile for iOS https://apps.apple.com/app/apple-store/id1477376905?ct=notification-email&mt=8&pt=524675 or Android https://play.google.com/store/apps/details?id=com.github.android&referrer=utm_campaign%3Dnotification-email%26utm_medium%3Demail%26utm_source%3Dgithub.

  7. reeteshranjan commented on Sep 15, 2021

    @reeteshranjan
    CollaboratorAuthor

    I have commercial bank accounts and UPI is setup for the same through gpay. does this work? if yes, let me know at vshanthamoorthi at gmail.com
    …
    On Mon, Sep 13, 2021 at 2:31 PM Reetesh Ranjan @.***> wrote: hi @reeteshranjan https://github.com/reeteshranjan, looking for this feature as currently transfer is flagged as possible fraud transaction. so please let me know if some help needed. Thanks for the offer to help! As of now my work on getting a merchant bank account setup is delayed. If you have one (a commercial current account with UPI keys setup), and you wish to provide details for me to be able to develop and test the functionality, please do so. I am expecting to move my own merchant bank account setup to move this week; but nothing sure as of now. — You are receiving this because you are subscribed to this thread. Reply to this email directly, view it on GitHub <#38 (comment)>, or unsubscribe https://github.com/notifications/unsubscribe-auth/AJPYSRZNF5AII37KFHARMJLUBW4XPANCNFSM5ACUAYOA . Triage notifications on the go with GitHub Mobile for iOS https://apps.apple.com/app/apple-store/id1477376905?ct=notification-email&mt=8&pt=524675 or Android https://play.google.com/store/apps/details?id=com.github.android&referrer=utm_campaign%3Dnotification-email%26utm_medium%3Demail%26utm_source%3Dgithub.

    Sorry, that does not help. It's not about linking your account to UPI. It's about creating merchant public and private keys, and installing the public key in the NPCI network through your bank.

  8. vshanthamoorthi commented on Oct 9, 2021

    @vshanthamoorthi

    @reeteshranjan ,

    how is this feature support going?

    I try to understand the key generation and installation NPCI network. PNB bank people does not aware of key installation and i also could not find any ways to generation of Keys.

    So You should guide us as well with which bank support this so that it will be easy to use this. thanks in advance for your help.

  9. reeteshranjan commented on Oct 11, 2021

    @reeteshranjan
    CollaboratorAuthor

    @reeteshranjan ,

    how is this feature support going?

    I try to understand the key generation and installation NPCI network. PNB bank people does not aware of key installation and i also could not find any ways to generation of Keys.

    So You should guide us as well with which bank support this so that it will be easy to use this. thanks in advance for your help.

    Did not get the chance to move the work on this. Looking to get the work on the bank part going in next 2-3 weeks as of now.

    As you figured out, it's not straightforward; but all we need is the right setup with one bank account. So far I have managed to talk with BOB and ICICI. ICICI team was very well informed and they were aggressive, and I was hoping I could get that going and complete the work on this feature with a merchant account with them. However; for business-specific reasons, the account with ICICI was not opened. In next 2-3 weeks, I'll be looking to work with few other banks I have scouted. With the huge number of banks having their UPI presence, I am trying to pick few based on how good their UPI payment apps are.

  10. 47 remaining items

  11. reeteshranjan commented on Apr 8, 2024

    @reeteshranjan
    CollaboratorAuthor

    It was a circle back. iSPIRT pointed me to Sanjay Jain, whom I met at IITACB event, and he gave me his card to get any help. I have reached out to him, and he said he'll see what he can do. I have pinged back every few weeks to him; but have not heard back anything.

  12. pratikjadhav12 commented on May 6, 2024

    @pratikjadhav12

    any updates bro

  13. sureshramanujam commented on Jul 11, 2024

    @sureshramanujam

    Is your feature request related to a problem? Please describe.

    1. Merchant payments: UPI deep linking specification, implemented by this package, is for merchant payments by design though individual to individual payments are supported by several apps on an ad-hoc basis. Work on this feature will add merchant payment support.
    2. Security warning/errors on major apps: Discussion with Bank of Baroda UPI team reveals that several major payment apps are looking to avoid fraud on UPI by doing a strict check on authenticity of payments. This makes these issues appear more related to the lack of merchant signature in current version of the package. This is further seen in the following snippet from the UPI deep linking specification which is about how a UPI payment app should verify a UPI deep linking request (the ones made through this package)

    Screenshot 2021-07-09 at 5 14 47 PM

    Describe the solution you'd like

    1. Mechanism in which users can create merchant signature themselves:

      1. Provide an API that would generate the UPI transaction request in the format specified in point 3 in section 1.3 of UPI deep linking specification towards signing by a package user app using their merchant private key.
      2. Provide an API that would accept the UPI transaction data and the signature created and will perform the UPI transaction
    2. Provide an API that implements signing using the algorithm described in point 3 in section 1.3 (RSA512 and SHA256) for users that are OK with providing their private key and then performs the UPI transaction.

    The API changes/additions should retain backward compatibility for non-merchant payments.

    Describe alternatives you've considered

    This aspect of the UPI deep linking specification has no alternatives.

    Any example solutions

    This feature is research based and is an attempt to implement part of the UPI deep linking specification not yet implemented. There is no example solution known.

    Additional context

    None

    @reeteshranjan : If this was the case then when using upi_india plugin I wonder how the payments happened about 3-4 months back in 2024? I believe these mandates are introduced by NPCI from the year 2017.

  14. reeteshranjan commented on Sep 9, 2024

    @reeteshranjan
    CollaboratorAuthor

    Could anyone post a screen capture of what happens when Phone Pe opens and what error it displays? A screenshot of the error displayed by PhonePe should work, too.

    I have got some more connects and currently I am working with one of my juniors in Phone Pe to understand/proceed further. Payment apps like Phone Pe get some SDK from NPCI that implements their part of the UPI transaction with banks. So error that PhonePe shows will help understanding the overall flow better.

    My junior in PhonePe knows several folks in NPCI, so this investigation would help him narrow down whom in NPCI to connect for our specific issue.

    @sureshramanujam @marutichintan @drenther @itsmesubham @pratikjadhav12 @kspoojary @tata-pay @efficientaman @nillastudios @Chanelle25meyer @vshanthamoorthi @bvivek77 @chetanjrao @pepsighan @itss-sid @venky9885 @Thathwagnu @rvharjinderbains @dhirajkadam27 @sravan1432 @ajesh123 @suyogbargule @vinayvishnu725 @bashadev21 @adityasreebysani @jatinyadav25 @mangeshsvk @manojsinghal2003 @yashwp @lzzy12 @AnandMG02 @prince-vishal @viveknimkarde @ngaurav @senthil88

  15. sureshramanujam commented on Sep 9, 2024

    @sureshramanujam
  16. reeteshranjan commented on Sep 9, 2024

    @reeteshranjan
    CollaboratorAuthor

    Hi Reetesh, I can explain why things are not happening. After a few months of search, asking etc., I finally found that this won't happen l, just because all UPI payments done to merchants by any UPI app are only treated as C2M payments (Customer to Merchant). For any C2M payments the Merchant must be registered to accept ONLINE payments. No UPI app is authorised to make any merchant as ONLINE. For example, if a merchant is registered as verified merchant on Google Pay Business, then GPay Business will issue a Merchant ID. Even in this case, GPay can only mark such registered merchants as OFFLINE. Meaning, customers can pay to these merchants only either by scanning their QR Code or pay to their phone number or pay to their VPA issued by GPay Business. The only solution to overcome this problem is to use a payment gateway. Payment Gateways are PSPs (Payment Service Providers) registered as Developers with NPCI. Only PSPS have the authorisation to mark mark merchants as ONLINE. This, INTENT payments can now be done to such merchants who are specifically marked as ONLINE (accepts OFFLINE also). Thanks, Suresh Ramanujam.
    …
    On Mon, Sep 9, 2024, 12:11 Reetesh Ranjan @.> wrote: Could anyone post a screen capture of what happens when Phone Pe opens and what error it displays? I have got some more connects and currently I am working with one of my juniors in Phone Pe to understand/proceed further. Payment apps like Phone Pe get some SDK from NPCI that implements their part of the UPI transaction with banks. So error that PhonePe shows will help understanding the overall flow better. — Reply to this email directly, view it on GitHub <#38 (comment)>, or unsubscribe https://github.com/notifications/unsubscribe-auth/AAZHDMW45T2FDU5K3EVUAADZVU7LLAVCNFSM5ACUAYOKU5DIOJSWCZC7NNSXTN2JONZXKZKDN5WW2ZLOOQ5TEMZTG4ZDKNJTG4YA . You are receiving this because you commented.Message ID: @.>

    Hi Suresh, could you please list your source of info here? So we all can benefit?

    I asked that because I see some sort of going off from the spec we are implementing, which handles merchant payments and gives us a way to behave as merchants etc. while invoking a UPI transaction; but without being a PSP, Payment app or a bank.

  17. amriteshfrommac commented on Nov 2, 2024

    @amriteshfrommac

    Hey @reeteshranjan, I am working on a project that requires UPI deep-linking in app and I am getting the same issue with all the UPI apps but able to pay successfully through bank UPI id to a non-merchant user. I don't know the reason for this, perhaps this signing of intent is required only for third party UPI apps like (Gpay, Paytm, etc.). Would this be of any help in researching about this issue?

  18. langziyong commented on Mar 18, 2025

    @langziyong

    Hi Reetesh, I can explain why things are not happening. After a few months of search, asking etc., I finally found that this won't happen l, just because all UPI payments done to merchants by any UPI app are only treated as C2M payments (Customer to Merchant). For any C2M payments the Merchant must be registered to accept ONLINE payments. No UPI app is authorised to make any merchant as ONLINE. For example, if a merchant is registered as verified merchant on Google Pay Business, then GPay Business will issue a Merchant ID. Even in this case, GPay can only mark such registered merchants as OFFLINE. Meaning, customers can pay to these merchants only either by scanning their QR Code or pay to their phone number or pay to their VPA issued by GPay Business. The only solution to overcome this problem is to use a payment gateway. Payment Gateways are PSPs (Payment Service Providers) registered as Developers with NPCI. Only PSPS have the authorisation to mark mark merchants as ONLINE. This, INTENT payments can now be done to such merchants who are specifically marked as ONLINE (accepts OFFLINE also). Thanks, Suresh Ramanujam.
    …
    On Mon, Sep 9, 2024, 12:11 Reetesh Ranjan @.> wrote: Could anyone post a screen capture of what happens when Phone Pe opens and what error it displays? I have got some more connects and currently I am working with one of my juniors in Phone Pe to understand/proceed further. Payment apps like Phone Pe get some SDK from NPCI that implements their part of the UPI transaction with banks. So error that PhonePe shows will help understanding the overall flow better. — Reply to this email directly, view it on GitHub <#38 (comment)>, or unsubscribe https://github.com/notifications/unsubscribe-auth/AAZHDMW45T2FDU5K3EVUAADZVU7LLAVCNFSM5ACUAYOKU5DIOJSWCZC7NNSXTN2JONZXKZKDN5WW2ZLOOQ5TEMZTG4ZDKNJTG4YA . You are receiving this because you commented.Message ID: _@**.**_>

    @reeteshranjan There is no way, neither MQR nor personal VPA can bypass the URL protocol wake-up method. This is a restriction order issued by NPCI, and PhonePE, GPay, and PayTM have all responded. But not long ago, I found that another protocol of PayTM supports wake-up support. I will analyze it here for you

    paytmmp://cash_wallet?pa=test@upi&pn=&tn=353FW2M4NG5K1&am=100.00&cu=INR&mc=4468&url=&mode=02&purpose=00&orgid=159002&sign=dD1OyTQs4NIUQBVN==&featuretype=money_transfer

    @SilurianYang Hello, is there any way to wake up the phonepe now?

  19. discretemicros commented on Apr 29, 2025

    @discretemicros

    Hi @reeteshranjan I am using upi_pay for my app, for all the UPI apps Bhim, paytm etc. the response from bank after successfully providing the password for UPI is aways a failure (Error: Payment Failed as per UPI risk policy to keep your account safe, don't worry the money is not deducted).

    For Bhim (Error: The request type is not supported)

    Version: upi_pay: ^1.1.0

    Am is missing something.

  20. vishal24102002 commented on Aug 24, 2025

    @vishal24102002

    i got the same issue and looked for solution but unable to get anything related to the issue

  21. reeteshranjan commented on Aug 25, 2025

    @reeteshranjan
    CollaboratorAuthor

    A Yahoo! colleague of mine, Sarath, has recently joined NPCI as an architect. Going to bug him on this one.

  22. vishal24102002 commented on Aug 26, 2025

    @vishal24102002

    Thanks for your help on this.Really looking forward to it

  23. kumaraguru1735 commented on Sep 7, 2025

    @kumaraguru1735

    Can We create Signature and pass at the end of the upi intent like below to make work
    https://stackoverflow.com/questions/75171822/how-to-create-sign-parameter-value-in-upi-deeplink-uri

  24. kumaraguru1735 commented on Sep 7, 2025

    @kumaraguru1735

    I am building app on jetpack compose, for now my logic is below
    for gpay I will share qrcode generated using upi intent
    for paytm I use direct intent with dummy signature

    // for other app need to work out how to implement original signature
    // this is the only working method as of now

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions