A QR code is not a payment method
A payment QR code is a two-dimensional image whose modules encode a string of characters that a phone can read. A QR code is an initiation channel, separate from the payment instrument that carries out the transaction. It holds a payee address, sometimes an amount, and nothing else. The payer’s rights, the cost, the settlement time, and the fraud exposure all depend on the underlying rail the code points to. When negotiating an acceptance contract, that rail is what you are negotiating, and the code sets none of its terms.
- A QR code on top of an instant credit transfer. QRIS (Indonesia), Pix QR (Brazil), UPI QR (India), VietQR (Vietnam), Thai QR Payment (Thailand): the payment is an irrevocable credit transfer. No chargebacks, no preauthorization, final credit within seconds.
- A QR code on top of a card. SGQR aggregates international card schemes, and TR Karekod covers both cards and FAST credit transfers: the payment remains a card transaction, with interchange, scheme rules, and a dispute cycle.
- A QR code on top of a wallet. Alipay, WeChat Pay, GCash: the payment debits an e-money balance, with counterparty risk on the issuer and payout times set by contract.
- A QR code on top of mobile money. GIMACPAY in the CEMAC zone (Central Africa), TANQR in Tanzania: the balance is safeguarded e-money, and turning it into bank money requires a cash-out.
The distinction also explains why QR codes spread in markets where card acceptance had remained limited. QR acceptance needs no terminal. A laminated stand is enough, so the upfront cost of accepting payments drops to zero. In Indonesia, 32.71 million merchants were already enrolled on QRIS in 2024 (Bank Indonesia), a scale no POS terminal fleet reaches in an emerging market. In Bolivia, 88.4% of QR payments are under 500 bolivianos and 49.7% are under 50 bolivianos (Banco Central de Bolivia, Informe de Vigilancia del Sistema de Pagos 2025). There, QR codes handle small tickets that cards could not process at a cost acceptable to merchants.
EMV QRCPS: the standard beneath the standards
The EMV QRCPS specification defines the structure of the data encoded in a payment QR code, and the two ways the code can be presented. Almost every national QR standard in this guide claims EMVCo compliance, including QRIS, Thai QR Payment, QR Ph, DuitNow QR, LANKAQR, KHQR, and Pix QR. The reference document is the EMV® QR Code Specification for Payment Systems (EMV QRCPS), published by EMVCo in two separate volumes, both at version 1.1, dated November 27, 2020 (EMVCo, public specifications).
| Merchant-Presented Mode (MPM) | Consumer-Presented Mode (CPM) | |
|---|---|---|
| Who displays the code | The merchant | The customer, on their phone screen |
| Who scans | The customer, with their app | The merchant, with an optical scanner or camera |
| Merchant equipment | None (a sticker) or a screen | A 2D scanner or a camera-equipped register |
| Content encoding | Text, positional TLV in the clear | Base64-encoded BER-TLV; application template with a cryptogram |
| Type of token | Payee address, reusable | Single-use, short-lived payment token |
| Typical use case | Micro-merchants, markets, bills, mobile e-commerce | High-throughput checkouts, transit, chain retail |
| Dependence on the customer’s connection | High: the customer must be online | Low: the code can be generated in advance, offline |
MPM dominates deployments worldwide because it shifts the equipment cost from the merchant to the customer, who already owns a phone. Its structure is a positional TLV. Each data object is a sequence of identifier (2 digits) + length (2 digits) + value, strung together with no separator. The content can be read in the clear from the image alone, with no key and nothing to decrypt. An MPM QR code holds no secret and is not authenticated. Anyone can copy one exactly or swap in a different one, and nothing in the format prevents it.
000201 tag 00: Payload Format Indicator, value "01"
010212 tag 01: Point of Initiation Method
11 = STATIC (reusable)
12 = DYNAMIC (single use)
26XX.... tags 02 to 51: Merchant Account Information
one template per scheme or per national
standard; this is where the payee's real
address lives (alias, VPA, Pix key,
account number, wallet identifier)
52045812 tag 52: Merchant Category Code (MCC, ISO 18245)
5303360 tag 53: transaction currency (ISO 4217 numeric)
540512500 tag 54: amount (absent on a static QR)
5502011 tag 55: tip / convenience fee indicator
5802ID tag 58: country (ISO 3166-1 alpha-2)
5913WARUNG BU SRI tag 59: merchant name (25 characters max)
6008SURABAYA tag 60: merchant city (15 characters max)
62XX.... tag 62: Additional Data Field Template
01 bill number
03 store label
05 reference label (reconciliation) <<< KEY
07 terminal label
6304A1B2 tag 63: CRC-16/CCITT-FALSE over the WHOLE payload,
"6304" included, value excludedCPM is built differently. The customer’s phone generates a Base64-encoded BER-TLV, whose application template carries the application identifier, the account data, and a cryptogram. It is the EMV logic of a contactless card, carried over into an image. The cryptogram authenticates the transaction, which no MPM code can do, and the merchant does the scanning, so it needs a scanner. CPM therefore takes hold where throughput matters and checkout equipment already exists, such as supermarket registers and transit, rather than where acceptance has to stay free to deploy.
Static and dynamic: two products, not two settings
Tag 01 of the payload, the Point of Initiation Method, takes only two values, which mark two different uses of the same format. A static QR code, value 11, is a printed address with no amount and no reference. It can be reused indefinitely and costs nothing to distribute. A dynamic QR code, value 12, is generated by the register for a single transaction. It carries the amount, the currency, and the reference, and it expires.
| Dimension | Static QR (tag 01 = 11) | Dynamic QR (tag 01 = 12) |
|---|---|---|
| Amount | Entered by the customer, a source of errors and underpayment fraud | Set by the register, cannot be changed |
| Order reference | Usually missing | Carried in tag 62-05, inserted by the POS system |
| Accounting reconciliation | Manual, by amount and time | Automatic, one to one |
| Deployment cost | Next to nothing: printing, a stand, a sticker | Integration with the register or terminal, plus a screen or printer |
| Physical risk | Sticker swapping (QR swap) | None: the code exists for only a few seconds |
| Payment confirmation | Notification in the merchant app, checked by eye | Feedback to the register: the POS knows the payment went through |
| Use case | Market stalls, taxis, tradespeople, tips, donations, bills | Chain retail, restaurants, e-commerce, transit |
This split has a design consequence that is often missed. A dynamic QR code is a separate product from a static one, aimed at a different type of merchant, not an upgraded version of the same product. Countries where adoption took off started with static codes, precisely because they cost nothing and need no equipment. Only then did they connect dynamic codes to chain retailers’ registers. The reverse order, dynamic first, is a fairly reliable sign of a failed rollout. It limits acceptance to merchants that already have a register that can be integrated, which is the part of the market cards were already serving.
National QR standards around the world
A national QR standard always fits the same definition: a single code displayed by the merchant, readable by every licensed app in the country. What varies is the settlement rail underneath, the authority that sets the standard, and how strictly it is enforced. The table below covers the live standards in the main markets. Every figure comes with its source and year.
| Standard | Country | Operator | Since | Settlement rail |
|---|---|---|---|---|
| QRIS (Quick Response Code Indonesian Standard) | Indonesia | Bank Indonesia with ASPI | 2019 | Credit transfer / e-money, interoperable |
| Thai QR Payment (Standardised Thai QR Code) | Thailand | Bank of Thailand / National ITMX | 2018 | PromptPay (instant) |
| QR Ph | Philippines | Bangko Sentral ng Pilipinas with PPMI | 2019 | InstaPay (instant) |
| DuitNow QR | Malaysia | PayNet | 2019 | DuitNow (instant) + UnionPay acceptance |
| SGQR | Singapore | MAS / IMDA through the Singapore Payments Council | 2018 | Multi-scheme: PayNow, NETS, card schemes |
| UPI QR | India | National Payments Corporation of India | 2016 | UPI (instant) |
| Pix QR | Brazil | Banco Central do Brasil | 2020 | Pix / SPI (instant) |
| VietQR | Vietnam | NAPAS | 2021 | NAPAS 247 (instant), address = bank account |
| KHQR | Cambodia | National Bank of Cambodia, on Bakong | 2020 | Bakong (dual-currency: riel / US dollar) |
| LANKAQR | Sri Lanka | Central Bank of Sri Lanka / LankaClear | 2018 | Domestic interbank |
| MMQR | Myanmar | Central Bank of Myanmar | 2025 | Switch linking 11 wallets |
| tarusQR | Brunei | ndpx, under the Brunei Darussalam Central Bank | 2025 | Interbank and wallets |
| JPQR | Japan | Payments Japan Association, backed by METI | 2019 | Multi-provider, one code per merchant |
| Taiwan Pay (台灣Pay) | Taiwan | Financial Information Service Co. | 2017 | Direct debit from the bank account |
| TR Karekod | Turkey | BKM | 2020 | Card and FAST instant credit transfer |
| QR Platba | Czechia | Česká bankovní asociace | 2012 | Credit transfer order |
| IPS pokaži / IPS skeniraj | Serbia | Narodna banka Srbije | 2020 | IPS NBS (instant) |
| qvik | Hungary | Magyar Nemzeti Bank / GIRO Zrt. | 2024 | AFR (instant) |
| RoPay | Romania | TRANSFOND S.A. | 2025 | Plăți instant |
| Transferencias 3.0 / PCT | Argentina | Banco Central de la República Argentina, COELSA clearing | 2020-2021 | Credit transfer (not card) |
| QR Simple | Bolivia | Banco Central de Bolivia with ASFI | 2019 | Interbank, including cooperatives and credit unions |
| CoDi | Mexico | Banco de México | 2019 | SPEI (instant) |
| GhQR | Ghana | GhIPSS | 2020 | Interbank and mobile money |
| TANQR | Tanzania | Bank of Tanzania | 2022 | TIPS (instant) |
| GIMACPAY | CEMAC zone (6 countries) | GIMAC, under the aegis of the BEAC | 2020 | Card, mobile money, and transfers on a single rail |
| Bangla QR | Bangladesh | Bangladesh Bank, on the NPSB platform | 2020 | Domestic interbank |
| Fonepay | Nepal | Fonepay Payment Service Ltd (F1Soft group) | 2020 | Private network turned de facto standard |
| ELQR | Kyrgyzstan | National Bank of the Kyrgyz Republic | 2022 | National instant payment rail |
| Fiji QR Code Scheme | Fiji | Reserve Bank of Fiji | – | Domestic interbank |
| QMP (Qatar Mobile Payment) | Qatar | Qatar Central Bank | – | Interoperable instant mobile switch |
| 聚易用 Simple Pay | Macao | Autoridade Monetária de Macau | – | Aggregates local QR payment instruments |
Who sets the standard: three governance models
The governance of a national QR standard comes down to who publishes the specification and decides whether it is mandatory. No national QR standard grew out of the market on its own. In every country, an authority made the call, and who that authority is predicts the adoption rate fairly well, along with fee levels and how stable the system will be over ten years. Three setups cover most cases.
What QR acceptance really costs
The cost of accepting a QR payment is the fee charged to the merchant, the merchant discount rate (MDR), plus the operating costs that come with the channel. QR is often sold as the free channel, but the actual rate cards say otherwise. How the fee is set varies widely by country, under five regimes. Indonesia has a regulated, published rate, India a legal ban on any fee, and Saudi Arabia a regulatory cap on the underlying card rail. Hungary chose zero fees mandated by the central bank, while Brazil and most other markets leave the price to be negotiated freely with the provider.
| Merchant category | QRIS MDR |
|---|---|
| Micro business (UMI), transaction ≤ Rp500,000 | 0 % |
| Micro business (UMI), above Rp500,000 | 0,3 % |
| Small, medium, and large businesses | 0,7 % |
| Education | 0,6 % |
| Public retail fuel stations | 0,4 % |
| Public services, government agencies, social programs | 0 % |
- Indonesia: the rate card above, with a cap of Rp10 million per transaction. Providers can add their own daily or monthly limits based on their risk assessment (Bank Indonesia).
- India: fees are prohibited by law. Since January 1, 2020, Section 10A of the Payment and Settlement Systems Act, 2007 and Section 269SU of the Income-tax Act, 1961 have barred any charge to either payer or payee on UPI and RuPay debit payments. The direct result: on UPI, acceptance is not a profit center, and the business model shifts to lending, product distribution, and data.
- Saudi Arabia: regulation caps the merchant fee on the mada card rail at 0.80%, with a ceiling of about SAR 40 per transaction (SAMA). That cap, not the QR channel, drives the economics of local acceptance.
- Hungary: qvik charges no fees to either merchant or customer, by regulatory design (Magyar Nemzeti Bank). It is a direct and openly declared attack on card interchange.
- Mexico: CoDi is completely free on both sides. It still has not taken off, because zero fees make up neither for its absence from banking apps nor for the lack of any incentive for merchants.
- Brazil: Pix is free for consumers by decision of Banco Central do Brasil, but on the merchant side, each participating institution sets its own price, not the central bank. Pricing varies more between Brazilian providers than between countries, so the comparison that matters happens within the market.
Cross-border links: the bilateral web and what comes next
Cross-border QR acceptance lets a traveler pay a foreign merchant with their usual payment app. Today it relies mostly on a web of bilateral agreements between central banks, not on a global standard. The traveler pays by scanning the host country’s national QR code with their usual domestic app. The merchant keeps its code, contract, and equipment. It receives a domestic credit, in its own currency, into its usual account.
The documented web of links is dense. Live links include Thailand–Cambodia (2020), Thailand–Vietnam (2021), Thailand–Malaysia (2021), Thailand–Singapore (2021), and Thailand–Indonesia (2022). They also include Malaysia–Singapore (2023), Malaysia–Indonesia (2023), Cambodia–Laos (2023), Cambodia–Vietnam (2023), Indonesia–Singapore (2023), Malaysia–Cambodia (2024), and Laos–Thailand (2024). In all, 29 QR and P2P links within ASEAN or with outside partners were counted as of December 2025 (regional sources, 2025–2026). Cambodia, with KHQR, has the densest network for its size, with links to Thailand, Laos, Vietnam, Malaysia, China, Singapore, and India.
- Outside ASEAN, India exports its QR code. UPI acceptance is live in Bhutan (2021, the first country in the world to accept UPI for merchant payments), the UAE through NeoPay (2022), Singapore, Nepal, Sri Lanka, Mauritius (2024), and Qatar through QNB (2024). The Nepal corridor, opened in February 2024, carried 134,701 transactions worth Rs 321 million in five months (Fonepay / NPCI International).
- Japan came late but moved fast. JPQR Global, launched on July 5, 2025, at the Expo 2025 Osaka, Kansai site, links JPQR with KHQR, then with QRIS from August 17, 2025.
- Laos built the UnionPay specifications into its national standard in late 2024 to capture Chinese tourist spending. It is the classic case of a small market opening up out of economic necessity.
- A competing private route exists: Alipay+ (Ant International, since 2020). It claims more than 2 billion accounts reachable through some 50 partner wallets, more than 150 million merchants, and more than 220 markets covered (alipayplus.com, checked in 2026). For a merchant, that means one integration instead of N bilateral agreements, at the cost of depending on a private intermediary.
- The Philippines and Myanmar remain outside the ASEAN QR network, with immediate operational consequences for anyone doing business in those markets.
What breaks in production
Operational incidents in QR acceptance are failures that keep a payment from going through or keep the funds from being identified. They recur with great regularity from one country to the next. They have less to do with cryptography than with the physical and accounting setup around the code. The table below lists them, with the root cause and the fix for each.
| Symptom | Root cause | What to do |
|---|---|---|
| No app can read the QR code | CRC (tag 63) miscalculated; the classic mistake is leaving “6304” out of the calculation | Test the payload with at least three different issuers’ apps, not just one |
| The code scans, but the payment is declined | Currency (tag 53) or country (tag 58) does not match the payee account | Check that the generator maps currencies to numeric ISO 4217 codes (not alphabetic ones) |
| Merchant name cut off on the customer’s screen | Tag 59 is limited to 25 characters, tag 60 to 15 | Pick a short display name that the customer will recognize, or they will abandon the payment |
| Half of all payments fail to reconcile | Tag 62-05 is missing, not carried by the rail, or not returned in the settlement file | Make it a contract requirement and test it end to end, from QR code to statement |
| The merchant receives the wrong amount | Static QR: the customer enters the amount | Switch to dynamic codes once the average ticket justifies it; until then, check every notification |
| The merchant receives nothing even though the customer paid | A fraudster swapped the sticker (QR swap) | Sealed stand or code under glass, a daily visual check, and mandatory daily reconciliation |
| Fake payments accepted at the register | The cashier relies on the customer’s screen | Confirm only on the notification the merchant receives, or on a soundbox audio alert |
| Refund sent to the wrong person | The refund is an outgoing credit transfer, keyed in by hand for lack of a reliable alias | Only allow refunds triggered from the original transaction, never keyed in manually |
One last architectural choice determines long-term dependence. A standard encodes either a bank account or a wallet ID. VietQR encodes a bank account. That choice explains why Vietnam did not become dependent on a dominant wallet, unlike Indonesia or the Philippines. Taiwan Pay and QR Platba made the same choice. When a standard encodes a wallet ID, the ecosystem consolidates around two or three dominant players, and merchants gradually lose the ability to play one provider off against another.
Getting connected: who to talk to and what to demand
For a merchant, connecting to a national QR standard means obtaining an acceptance ID that the country’s licensed apps recognize. In nearly all these markets, direct access to the standard is limited to licensed institutions: banks, payment institutions, and e-money issuers. A merchant or foreign provider cannot get an ID from the central bank. It has to go through a participant. The first job in any project, before any technical question, is therefore to identify which entities are allowed to onboard a merchant in the target country.
- Identify the settlement rail before anything else: instant credit transfer, card, e-money, or mobile money. Everything else follows from that.
- Establish who is allowed to onboard a merchant: get the list of licensed participants published by the central bank or the operator, and check that the prospective partner is still on it.
- Get the applicable pricing: regulated and public (Indonesia), banned by law (India), capped (Saudi Arabia), or unregulated (most markets). The answer changes the negotiation completely.
- Test tag 62-05 end to end: QR generation, notification, settlement file, bank statement. Until the reference shows up at the last step, you cannot reconcile.
- Check how voids and refunds work: on an irrevocable rail, a refund is not a reversal but an outgoing credit transfer, with its own compliance checks and timing.
- Check the target market’s cross-border status: whether inbound QR payments are accepted, which origin countries are covered, and who bears the FX risk.
- Keep a register of every static code issued from day one, with store, date, and distribution channel. You cannot rebuild that inventory after the fact.