Understanding the Role of PSP and TPAP in UPI
Every time you scan a QR code or send money through a UPI app, at least two distinct entities work behind the scenes to make that transaction happen. One is a bank. The other is the app itself. But the technical relationship between these two is often misunderstood. NPCI, the organization that operates UPI, classifies participants into specific roles. The two most important are PSP (Payment Service Provider) and TPAP (Third Party Application Provider). Understanding what each one does, and where the boundary sits between them, helps you make sense of how your money actually moves.
What Is a PSP in UPI?
A PSP, or Payment Service Provider, is a bank that is a direct member of the UPI platform operated by NPCI. PSP banks connect to UPI's central switching infrastructure and are responsible for processing transactions. When you use any UPI app, there is always a PSP bank sitting underneath that app, handling the actual movement of funds between accounts.
Not every bank qualifies as a PSP. To become one, a bank must integrate directly with NPCI's UPI system, maintain the technical infrastructure for processing UPI messages, and comply with NPCI's operational and security requirements. As of 2026, major PSP banks include SBI, ICICI Bank, Axis Bank, Yes Bank, and HDFC Bank.
The PSP bank is the entity that actually talks to UPI's servers. It issues the UPI handle (the part after the @ in your VPA), routes the payment instruction, and settles the funds. If you have a VPA like yourname@okaxis, Axis Bank is the PSP. If it is yourname@ybl, Yes Bank is the PSP.
What Is a TPAP in UPI?
A TPAP, or Third Party Application Provider, is the company that builds and operates the UPI app you interact with on your phone. TPAPs do not connect directly to UPI's infrastructure. Instead, they partner with a PSP bank, which handles all the heavy lifting of transaction processing on their behalf.
Google Pay, PhonePe, Paytm (for its third-party UPI service), CRED, and many other apps are all TPAPs. They design the user interface, manage customer onboarding, and provide value-added features like bill splitting or transaction history. But when a payment instruction leaves the app, it goes to the PSP bank, which routes it through UPI.
NPCI requires every TPAP to operate under a formal agreement with at least one PSP bank. The TPAP cannot process payments independently. This is a deliberate design choice: it ensures that a regulated bank always sits in the transaction chain, maintaining oversight and accountability.
PSP vs TPAP: Key Differences
While both PSPs and TPAPs are essential to the UPI ecosystem, their responsibilities are fundamentally different. The table below breaks down the distinction.
| Parameter | PSP (Payment Service Provider) | TPAP (Third Party App Provider) |
|---|---|---|
| Entity type | Bank (regulated by RBI) | Technology company or fintech |
| UPI membership | Direct member of UPI/NPCI | Not a direct member, operates via PSP |
| Transaction processing | Handles routing, settlement, and fund transfer | Sends payment instructions to PSP |
| UPI handle | Issues the @handle (e.g., @ybl, @okaxis) | Uses the PSP's handle for its users |
| Customer data | Holds account and transaction records | Holds app-level user data |
| Regulatory oversight | Directly regulated by RBI and NPCI | Governed by NPCI guidelines via PSP agreement |
| Example | Yes Bank, Axis Bank, ICICI Bank | Google Pay, PhonePe, CRED |
How PSP and TPAP Work Together During a Transaction
When you initiate a payment on a TPAP app, here is what happens step by step:
1. You open the TPAP app (say PhonePe) and enter the amount and recipient.
2. PhonePe sends the payment instruction to its PSP bank (Yes Bank).
3. Yes Bank validates the instruction and forwards it to NPCI's UPI switch.
4. NPCI routes the instruction to the recipient's bank (the remitter's PSP or the beneficiary's bank).
5. The recipient's bank debits/credits the account and sends a response back through the same chain.
6. The confirmation reaches your PhonePe app, and you see the success screen.
The entire process takes 2 to 3 seconds. But in that window, the payment instruction passes through at least three regulated entities: your TPAP's PSP bank, NPCI, and the recipient's bank. This layered architecture is what makes UPI both fast and secure.
Why NPCI Requires This Separation
NPCI designed UPI with a deliberate separation between the app layer (TPAP) and the banking layer (PSP) for several reasons. First, it ensures that every transaction passes through a regulated bank, which means RBI's oversight extends to every UPI payment regardless of which app initiates it.
Second, it lowers the barrier for new apps to enter the market. A fintech startup does not need a banking licence to launch a UPI app. It simply partners with an existing PSP bank. This has driven the explosion of UPI apps in India, from payment-focused apps to shopping apps, investment platforms, and credit products that all integrate UPI.
Third, the separation protects user data. The PSP bank holds sensitive banking information, while the TPAP only accesses what is needed to display transaction status and history. If a TPAP suffers a data breach, the core banking data remains with the PSP.
What This Means for You as a User
Most UPI users never think about whether they are interacting with a PSP or a TPAP. And in day-to-day use, you do not need to. But there are practical situations where this knowledge matters.
If a UPI transaction fails, the PSP bank is ultimately responsible for the settlement and reversal. Raising a complaint with just the TPAP may not resolve a stuck payment. You can also escalate directly to the PSP bank or use NPCI's dispute resolution mechanism.
When choosing a UPI app, the PSP bank behind it affects the reliability and speed of your transactions. Some PSP banks have better uptime and faster processing. Checking which PSP bank powers your favourite app can help you understand occasional slowdowns or failures during peak hours.
Stashfin's UPI Money Transfer feature lets you scan and pay, send money to a mobile number or UPI ID, or move funds to your own bank account. All transfers run on direct bank-to-bank UPI rails through a licensed PSP partner, so your payments are processed with the same regulated infrastructure that powers every major UPI app in the country.
Key Takeaways
A PSP (Payment Service Provider) is a bank that connects directly to UPI's infrastructure and processes transactions.
A TPAP (Third Party Application Provider) is the app you use, which partners with a PSP bank to offer UPI services.
TPAPs cannot process payments independently. They must operate under a PSP bank's licence.
The PSP bank issues your UPI handle (the @suffix in your VPA).
This separation ensures every UPI transaction passes through a regulated bank, regardless of the app.
If a transaction fails, the PSP bank is responsible for settlement and reversal, not just the TPAP.