Back

Published July 15, 2026

Understanding UPI Signed Intent and QR

A signed QR or Intent carries a digital signature that proves a payment request has not been tampered with. Here is exactly how this protects you from a specific class of UPI fraud.

Stashfin

Stashfin

Jul 15, 2026

Understanding UPI Signed Intent and QR

Not every UPI QR code or payment request carries the same level of verifiable trust. NPCI introduced signed Intent and signed QR as a way to cryptographically prove a specific payment request came from who it claims to, and understanding this distinction helps explain one of the less visible but genuinely important layers of UPI's fraud protection.

Download Stashfin App

What a Digital Signature Actually Adds Here

A signed QR code or Intent request includes a cryptographic signature generated using the merchant's or biller's verified credentials, which your UPI app can check against NPCI's records to confirm the request genuinely originates from the entity it claims to represent, rather than a tampered or spoofed code designed to redirect your payment elsewhere.

Why This Specifically Matters for Fraud Prevention

A classic UPI scam involves swapping a legitimate merchant's QR code with a fraudulent one, redirecting payments to a scammer's account while looking visually identical to the genuine code. A signed QR closes this specific gap, since a tampered or substituted code will fail the signature verification check, and a properly updated UPI app can flag or reject it rather than processing the payment blindly.

Additional Read: How to Prevent UPI Fraud on Your Account

How This Differs From an Ordinary Unsigned QR Code

Aspect Unsigned QR Code Signed QR Code
Verification No cryptographic check of the encoded VPA's authenticity App can verify the signature against NPCI's records
Tampering risk A substituted code can redirect payment without detection A tampered code fails signature verification and can be flagged
Typical use case Common among smaller, less formally onboarded merchants Increasingly required for verified, registered merchant integrations

A signed request is particularly relevant for something like a credit card bill payment tool, since verifying the request genuinely comes from your actual card issuer, rather than a spoofed lookalike, protects against exactly the kind of redirection fraud a signed Intent is designed to prevent.

What This Means for You as a Payer

Most of this verification happens automatically and invisibly inside your UPI app, without requiring any extra action from you. The practical takeaway is simply that keeping your UPI app updated matters, since older app versions may not support the latest signature verification checks NPCI introduces over time.

Why Not Every QR Code Is Signed Yet

Rolling out signed QR requires merchants and billers to be onboarded through a verification process that issues them the credentials needed to generate a properly signed code, which takes time to reach every existing merchant, particularly smaller vendors who set up a basic static QR code before this feature became available. Adoption is expanding, but it is not yet universal across every UPI-accepting business.

How This Connects to the Broader Fight Against QR Tampering

Signed QR is one specific technical countermeasure within a broader set of protections against QR code fraud, alongside user education about checking a merchant's displayed name before paying and physically inspecting a printed QR code for signs of being stuck over the original. As signed QR adoption spreads across more merchants, this particular fraud vector should become progressively harder to exploit, though the other layers of protection remain just as necessary in the meantime.

What a Simple Habit Check Adds on Top of Signed QR

Even as signed verification spreads, it remains worth pausing to read the merchant name your UPI app displays before authorizing a payment, since this single habit catches a wider range of mismatches than signature checking alone can cover, including cases where a legitimate but wrong biller was accidentally selected rather than one involving deliberate tampering. Building this quick read-before-you-pay habit costs a payer only a second or two per transaction, yet it closes gaps that no purely technical safeguard, signed or otherwise, is designed to catch on its own.

How Merchants Benefit From Adopting Signed QR

Beyond protecting the paying customer, a merchant who moves to a signed QR code also protects their own revenue, since a substituted, unsigned code redirecting customer payments to a scammer's account represents a direct loss of income the merchant may not notice until reconciling sales figures against actual bank credits. This dual benefit, protecting both sides of the transaction simultaneously, is part of why NPCI has actively encouraged registered merchants to move toward signed verification as their onboarding infrastructure allows.

Stashfin's UPI service lets you scan and pay to any mobile number or UPI ID, or move money to your own bank account, directly through bank-to-bank UPI rails, built with the latest NPCI security standards including signed verification where applicable.

Key Takeaways

  • A signed QR code or Intent request includes a cryptographic signature verifying it genuinely comes from the merchant or biller it claims to represent.

  • This specifically protects against a classic scam involving a substituted, fraudulent QR code redirecting payments elsewhere.

  • A tampered signed QR fails signature verification and can be flagged by an updated UPI app, unlike an unsigned code.

  • Most of this verification happens automatically inside your UPI app without requiring extra action from you.

  • Adoption of signed QR is still expanding rather than universal, since it requires merchants to be onboarded through a verification process.

Frequently asked questions

Common questions about this topic.

It is a QR code carrying a cryptographic signature that your UPI app can verify against NPCI's records to confirm it genuinely comes from the claimed merchant.

Quick Actions

Manage your investments

Personal Loan

Instant Approval | 100% Digital | Minimal Documentation* | 0% rate of interest upto 30 days.

Payments

Send money instantly to anyone, pay bills, and make merchant payments with Stashfin's secure UPI service.

Corporate Bonds

Diversify your portfolio & compound your income with investment-grade bonds

Insurance

Ensure safety in true form with affordable, high-impact insurance plans

Calculators

Fund your emergency with minimal documentation and instant disbursal.

Loan App

Fund your emergency with minimal documentation and instant disbursal.