Who is being paid
The address money is sent to — handle@bank. Nothing is verified against a bank; check it against your own app.
NPCI marks this mandatory in the link spec, so fill it in even though most apps now display the bank-registered name instead. Up to 50 characters.
Carried into the payer's statement, which is what lets you reconcile it later.
Your QR code
Enter a UPI ID above and the code appears here. Nothing is sent anywhere — the QR is built in this browser.
Want the QR on the invoice itself? Add your UPI ID to an invoice and it is printed on the PDF with the invoice total already filled in.
What is actually inside the code
NPCI’s UPI Linking Specification defines the whole thing as a URL: upi://pay?param=value¶m=value. Encoding that string as a QR is all a “UPI QR generator” does. The parameters worth knowing:
| Tag | What it is |
|---|---|
pa | Payee VPA. Mandatory. This is the address the money goes to. |
pn | Payee name. Mandatory in the spec, but since June 2025 apps display the bank-registered name instead of this one. |
am | Amount. Optional for a static QR, mandatory for a dynamic one. Its presence locks the amount — see below. |
mam | Minimum amount, where the amount field is left editable. |
cu | Currency. The spec says only INR is supported. There is no multi-currency UPI QR. |
tn | Transaction note. What the payer sees and what lands in their statement. |
tr | Transaction reference — order or bill ID. Mandatory for merchant transactions and dynamic URLs, and the only field echoed back to a merchant system. |
mc | Merchant category code. Assigned by the acquiring bank at onboarding — typing one in does not make a personal VPA a merchant account. |
mode, sign, orgid | Transaction mode, a Base-64 signature over the whole intent string, and the originating organisation. The signature is produced with a payment service provider’s private key, so no browser tool can generate one. |
Static or dynamic: the counter-QR trap
The specification puts the distinction plainly: a small shop can print a static code with just the payee address and name, and the customer types the amount after scanning. A dynamic code is generated per bill and carries the amount and a reference.
The mistake is printing a code with am baked into it and sticking it on a counter. The spec says: “If ‘am’ is not present then field is editable.” The converse is what bites — when it is present, the field is not editable, so a QR generated for one ₹500 sale charges every later customer ₹500 too.
That is why the tool above keeps the amount off by default, and why a UPI QR printed on an invoice is the right place for a fixed amount: it belongs to one bill.
Encoding, and why it matters
Everything in a value has to be percent-encoded to RFC 3986. The specification calls out spaces specifically: they must be %20, not a bare %. An unencoded ampersand or hash in a business name is worse than cosmetic — it terminates the parameter, and the payer’s app then shows the wrong payee or no amount at all. “Smith & Sons (Pvt) Ltd” is exactly the sort of name that breaks a naive generator. The link builder here escapes the sub-delimiters that encodeURIComponent leaves alone, which is why the string shown beside the code looks over-escaped: it is correct rather than pretty.
Where the limits bite
- Scanning a saved image caps at ₹2,000. NPCI circular OC 76A treats “QR share & pay” differently from scanning a physical code, capping it at ₹2,000 for peer-to-peer and for non-verified offline merchants. WhatsApping a QR and expecting a five-figure payment does not work.
- Small-merchant VPAs have inward limits. Circular OC 192 sets ₹10,000 per transaction, ₹25,000 per day and ₹1,00,000 per month for P2PM merchant addresses. Sustained breaches are a signal to the bank to reclassify the account.
- Collect requests are going away for merchants. UPI Collect has been discontinued for peer-to-merchant flows on Android and desktop, with carve-outs for mandates and market flows. Intent on mobile and a QR on desktop are the routes that remain, which is a reason to put a QR on the invoice rather than send a collect request.
Three different QR codes, constantly confused
- A UPI QR — the
upi://paylink above. A payment convenience. Anyone can generate one. - The GST dynamic QR — required on B2C invoices for businesses over the notified turnover. Circular 146/02/2021-GST requires it to carry the supplier’s GSTIN, UPI ID, bank account and IFSC, the invoice number and date, the total invoice value and the GST amount with its breakup. A
upi://paystring cannot carry any of that, so a UPI QR does not satisfy it. - The IRN QR — required by Rule 46(r) on an e-invoice. It carries the Invoice Reference Number and is generated by the Invoice Registration Portal when the invoice is registered. More on when e-invoicing applies.
RBI’s 2020 interoperability circular left UPI QR and Bharat QR in place and barred new proprietary QR codes, so those are the two a payer’s app is guaranteed to understand.
Putting one on an invoice
The invoice generator on this site does that automatically: enter a UPI ID in the payment section and the PDF carries a QR for the exact invoice total, with the invoice number as the payment note so the credit can be matched back. Make an invoice with a payment QR.
Before you print anything with a QR on it, scan it once with your own UPI app and check that the payee and the amount are what you expect. That is thirty seconds against the cost of a run of invoices pointing at a mistyped VPA.
More invoice formats and free tools
GST invoice format
Every particular Rule 46 requires on a tax invoice, and what happens when one is missing.
GST invoice generator
Make a GST tax invoice with the CGST/SGST or IGST split worked out. No account, no invoice limit.
Proforma invoice format
An offer, not a tax invoice: no GST payable and no input tax credit against it.
Quotation format
Quote a price with a validity date, and know when a quotation becomes a contract.
Delivery challan format
Rule 55: moving goods without a supply, in triplicate, with the right markings.
GST calculator
Add GST to an amount, or pull the GST back out of a GST-inclusive one.
Amount in words
A rupee figure written out in the Indian system, with paise, ready for a cheque or an invoice.
Frequently asked questions
- Is the UPI QR on my invoice the same as the GST dynamic QR code?
- No, and they are not interchangeable. Circular 146/02/2021-GST requires the GST dynamic QR to contain the supplier’s GSTIN, the supplier’s UPI ID, the payee bank account and IFSC, the invoice number and date, the total invoice value and the GST amount with its breakup. A upi://pay link carries none of that. There is also a third code — the QR required by Rule 46(r) on an e-invoice, which carries the IRN and is generated by the Invoice Registration Portal, not by you.
- Should I put an amount in a QR I print and stick on the counter?
- No. The NPCI specification is explicit: “If ‘am’ is not present then field is editable.” Encode an amount and the amount is locked, so the ₹500 you set for one customer becomes ₹500 for everyone who ever scans it. Leave the amount off a reusable QR and let the payer type it; set an amount only on a one-off request against a particular bill.
- Why does the payer’s app show a different name from the one I entered?
- Since 30 June 2025, NPCI requires UPI apps to display only the beneficiary name fetched from the bank’s core banking system through the Validate Address API. Names from QR codes, contact lists and user nicknames may no longer be shown. The pn value you encode is a hint to the app, not what the payer sees on the confirmation screen — so it cannot be used to present yourself as someone else, which is the point.
- Someone scanned my QR from a screenshot and it capped at ₹2,000. Why?
- That is “QR share & pay”, and NPCI circular OC 76A of 12 March 2024 caps it at ₹2,000 for peer-to-peer transfers and for payments to non-verified offline merchants. Scanning a saved image is treated differently from scanning a physical code. For larger amounts the payer should scan the printed code directly, or you should be onboarded as a verified merchant.
- Is there a limit on what I can receive?
- On a small-merchant (P2PM) VPA, yes: NPCI circular OC 192 sets maximum inward credits of ₹10,000 per transaction, ₹25,000 cumulatively per day and ₹1,00,000 cumulatively per month. Exceeding the monthly figure repeatedly is a signal to your bank to reclassify you as a full merchant. Higher per-transaction limits — up to ₹5 lakh in vetted categories since 15 September 2025 — apply only to merchants the bank has specifically enabled.
- The spec says mode and sign are mandatory. Is an unsigned QR invalid?
- It is incomplete rather than invalid. The signature is produced with a private key held by a payment service provider, so nothing that runs in a browser can create one. In practice a missing signature causes the payer’s app to warn that the source of the intent could not be verified and to require a passcode; the payment still goes through. Bank-issued merchant QRs carry the signature, which is one real difference between them and a self-generated code.
- Does anything leave my browser?
- No. The link is assembled and the QR is encoded on your device by JavaScript already on the page. Your VPA, the amount and the note are never sent anywhere, and the PNG is drawn locally.