Subscription Hub — UPI AutoPay Flow
What is UPI AutoPay?
UPI AutoPay is NPCI's mandate framework for recurring payments over UPI. It lets a customer authorize a merchant to debit their linked bank account, via UPI, on a recurring schedule — using the same UPI apps (any UPI-enabled banking or third-party app) customers already use for everyday payments.
Stages of the UPI AutoPay flow
1. Registration
- The customer initiates a subscription and chooses "UPI AutoPay" as the payment method.
- The customer provides their UPI ID (VPA), or scans a QR code / uses an intent flow, depending on the integration.
- Before authorizing, the customer is shown the mandate terms in their UPI app: merchant name, debit amount (fixed or a variable-amount ceiling), frequency, and mandate validity (start date and end date, up to a maximum of one year, renewable).
- The customer authenticates the mandate using their UPI PIN inside their UPI app.
- On successful authentication, NPCI confirms the mandate and is marked active, returning a mandate reference for all future operations.
The entire registration experience happens inside the customer's own UPI app, which most customers find more familiar and trustworthy since it mirrors how they already authorize UPI payments.
2. Pre-debit notification
- As with card SI, the customer must be notified ahead of every scheduled debit , merchant can sends this notification using the Subscription Hub via SMS, email stating the amount and date.
Notification is sent at least 24 hours before execution, consistent with the RBI/NPCI recurring-payment framework.
3. Execution and the additional-factor-of-authentication (AFA) rule
- For recurring debits up to a defined per-transaction threshold, execution happens silently , I.e. no PIN entry or app action needed from the customer, since the mandate itself was PIN-authenticated at registration.
- For recurring debits above that threshold, NPCI's framework requires the customer to complete an additional authentication step (typically approving the specific debit in their UPI app, or entering their UPI PIN again) before the transaction can go through. Merchants offering high-value recurring billing over UPI should design their customer communication to account for this extra step.
- Execution requests are sent to NPCI, and status updates flow back to Subscription Hub, which reflects the state to the merchant.
4. Handling pending, failed, and delayed responses
- If a debit fails (insufficient balance, customer declined the AFA step, bank-side decline), the mandate execution can be retried on a later date.
Upto 3 retries on a PDN is supported
- The mandate itself remains active across a failed cycle unless explicitly revoked
5. Mandate Cancellation
- Customers can revoke a UPI AutoPay mandate directly from their UPI app at any time, independent of the merchant.
- Merchants can also trigger revocation from their end (subject to customer consent for modifications), through the Dashboard or API.
- A revoked mandate cannot be reactivated — the customer must register a new one.
Customer experience, step by step
| Step | Who acts | What the customer sees |
|---|---|---|
| Customer | Chooses plan/amount and selects "UPI AutoPay" |
| Customer | Familiar UPI collect/intent screen |
| Customer | Merchant name, amount, frequency, validity shown natively in-app |
| Customer | Standard UPI PIN entry |
| System | Confirmation in-app and on merchant site; mandate reference generated |
| System → Customer | In-app notification and/or SMS a day before each debit |
| System | Silent debit, no customer action |
| 7a. Auto-debit (above threshold) | Customer | Prompted to approve the specific debit in-app |
| Customer | Can pause, modify, or revoke from their UPI app or merchant portal |
Key statuses to track
INITIATED— registration started, awaiting UPI PIN authenticationACTIVE— mandate authenticated and livePENDING— a debit has been triggered and is awaiting confirmation from NPCI/bankPAUSED— temporarily suspendedFAILED— a specific execution attempt failedREVOKED— mandate permanently cancelled
Card SI vs. UPI AutoPay, at a glance
| Card Standing Instruction | UPI AutoPay | |
|---|---|---|
| Authentication at registration | OTP / 3D-Secure via issuer or network | UPI PIN, inside the customer's UPI app |
| Where the customer manages it | Merchant portal or bank net banking | Merchant portal or their UPI app |
| High-value debit handling | Governed by card network/issuer rules | Additional in-app authentication above threshold |
Updated about 2 months ago
Did this page help you?

