UPI QR security: verify before you pay
Treat a QR as a readable payment instruction, not a trusted identity. Review the recipient and amount in your UPI app before you authorize anything.
Check the destination, not just the label
A name printed beside a QR can be typed by anyone. The name entered in QR Bench is also user-supplied. Compare the account information resolved by your app with the intended recipient; if it differs, stop and verify through a known contact channel.
For a physical payment stand, look for a replacement sticker or other tampering. When you generate a new image, scan it yourself before distributing copies.
Keep credentials out of the form
QR Bench never needs a UPI PIN, OTP, card number or banking password. Do not put those values into the note field. A note is part of the QR payload and can be read by anyone who decodes the image.
Do not mistake a request to send money for evidence that you will receive money. Read the action shown by the trusted payment app before authorizing.
Understand the privacy boundary
The generator sends no form details over the network and stores no payment history. Downloading, printing or sharing a QR creates another copy of its payload outside the website’s control. A shared device, browser extension, screenshot or print queue can expose that copy.
Choose Clear details after use on a shared computer. Remove downloaded images when you no longer need them. See the privacy page for the distinction between local form processing and ordinary hosting logs.
If something looks wrong
Stop the payment flow. Recheck the recipient address from the original banking app or contact the intended payee through a channel you already trust. If money has already moved, use your bank or payment app’s official support and dispute process. QR Bench has no access to transfers and cannot reverse them.
Official sources
- NPCI: UPI frequently asked questions (official reference)
- Google Pay: UPI payment-request fields (official reference)
The workflow describes QR Bench. Payment app behavior, acceptance and limits are controlled by the app, bank and network.