Subscription Hub — UPI AutoPay Flow

What is UPI AutoPay?

UPI AutoPay is NPCI's mandate framework for recurring payments over UPI. It lets a customer authorize a merchant to debit their linked bank account, via UPI, on a recurring schedule — using the same UPI apps (any UPI-enabled banking or third-party app) customers already use for everyday payments.

Stages of the UPI AutoPay flow

1. Registration

  1. The customer initiates a subscription and chooses "UPI AutoPay" as the payment method.
  2. The customer provides their UPI ID (VPA), or scans a QR code / uses an intent flow, depending on the integration.
  3. Before authorizing, the customer is shown the mandate terms in their UPI app: merchant name, debit amount (fixed or a variable-amount ceiling), frequency, and mandate validity (start date and end date, up to a maximum of one year, renewable).
  4. The customer authenticates the mandate using their UPI PIN inside their UPI app.
  5. On successful authentication, NPCI confirms the mandate and is marked active, returning a mandate reference for all future operations.

The entire registration experience happens inside the customer's own UPI app, which most customers find more familiar and trustworthy since it mirrors how they already authorize UPI payments.

2. Pre-debit notification

  • As with card SI, the customer must be notified ahead of every scheduled debit , merchant can sends this notification using the Subscription Hub via SMS, email stating the amount and date.

    Notification is sent at least 24 hours before execution, consistent with the RBI/NPCI recurring-payment framework.

3. Execution and the additional-factor-of-authentication (AFA) rule

  • For recurring debits up to a defined per-transaction threshold, execution happens silently , I.e. no PIN entry or app action needed from the customer, since the mandate itself was PIN-authenticated at registration.
  • For recurring debits above that threshold, NPCI's framework requires the customer to complete an additional authentication step (typically approving the specific debit in their UPI app, or entering their UPI PIN again) before the transaction can go through. Merchants offering high-value recurring billing over UPI should design their customer communication to account for this extra step.
  • Execution requests are sent to NPCI, and status updates flow back to Subscription Hub, which reflects the state to the merchant.

4. Handling pending, failed, and delayed responses

  • If a debit fails (insufficient balance, customer declined the AFA step, bank-side decline), the mandate execution can be retried on a later date.

    Upto 3 retries on a PDN is supported

  • The mandate itself remains active across a failed cycle unless explicitly revoked

5. Mandate Cancellation

  • Customers can revoke a UPI AutoPay mandate directly from their UPI app at any time, independent of the merchant.
  • Merchants can also trigger revocation from their end (subject to customer consent for modifications), through the Dashboard or API.
  • A revoked mandate cannot be reactivated — the customer must register a new one.

Customer experience, step by step

StepWho actsWhat the customer sees
  1. Start subscription
CustomerChooses plan/amount and selects "UPI AutoPay"
  1. Enter UPI ID / scan QR
CustomerFamiliar UPI collect/intent screen
  1. Review mandate in UPI app
CustomerMerchant name, amount, frequency, validity shown natively in-app
  1. Authenticate with UPI PIN
CustomerStandard UPI PIN entry
  1. Mandate confirmed
SystemConfirmation in-app and on merchant site; mandate reference generated
  1. Pre-debit reminder
System → CustomerIn-app notification and/or SMS a day before each debit
  1. Auto-debit (below threshold)
SystemSilent debit, no customer action
7a. Auto-debit (above threshold)CustomerPrompted to approve the specific debit in-app
  1. Manage mandate
CustomerCan pause, modify, or revoke from their UPI app or merchant portal

Key statuses to track

  • INITIATED — registration started, awaiting UPI PIN authentication
  • ACTIVE — mandate authenticated and live
  • PENDING — a debit has been triggered and is awaiting confirmation from NPCI/bank
  • PAUSED — temporarily suspended
  • FAILED — a specific execution attempt failed
  • REVOKED — mandate permanently cancelled

Card SI vs. UPI AutoPay, at a glance

Card Standing InstructionUPI AutoPay
Authentication at registrationOTP / 3D-Secure via issuer or networkUPI PIN, inside the customer's UPI app
Where the customer manages itMerchant portal or bank net bankingMerchant portal or their UPI app
High-value debit handlingGoverned by card network/issuer rulesAdditional in-app authentication above threshold


Did this page help you?