UPI Payment Request Links May Face Restrictions: What the Proposed Change Could Mean for Users
A familiar Unified Payments Interface feature that allows merchants or individuals to send payment requests could face new restrictions as payment authorities examine ways to curb digital fraud. The facility, commonly called a “collect request” or “pull transaction,” asks the recipient to approve a payment by entering a UPI PIN.
According to the report, the National Payments Corporation of India is considering restrictions on certain pull-payment transactions because fraudsters have been misusing payment requests to deceive users. However, the report also says that discussions with banks are continuing and that the proposal has not yet been finalised.
Users should therefore treat the reported change as a possible security measure, not as a confirmed closure of every UPI collect-payment facility.
What is a UPI pull transaction?
In a pull transaction, the person or business expecting payment initiates the process. A payment request appears in the customer’s UPI application, showing details such as the recipient’s name and the requested amount.
The customer must review the request and enter a UPI PIN to authorise the transfer. Money is debited only after approval.
This feature is used in several situations. A merchant may send a collect request after an online purchase, or an individual may request payment from a friend. The convenience of this method has also created an opportunity for fraudsters to send deceptive requests.
How is a push payment different?
A push payment begins with the person sending money. The user scans a QR code, selects a saved contact or enters a UPI ID before specifying the amount and authorising the transaction.
The basic difference is straightforward:
| Payment Type | Who Starts the Transaction? | What the Customer Does |
|---|---|---|
| Push payment | The person sending money | Scans a QR code or enters a UPI ID and pays |
| Pull payment | The person requesting money | Sends a collect request that the customer approves |
Ordinary push payments are not described as being part of the reported proposal. Users should still be able to initiate transfers by scanning a verified QR code or entering the correct UPI ID.
Why are collect requests being examined?
Cybercriminals frequently exploit confusion over how a UPI PIN works. They may contact a victim with a false promise of a refund, reward, cashback, online sale payment or financial assistance. The fraudster then sends a collect request and tells the victim to enter a PIN to “receive” money.
That instruction is false. A UPI PIN is normally required to authorise money leaving an account, not to receive an ordinary payment.
Someone selling a product online may be told that a buyer has transferred money and that the payment needs to be “accepted” by entering a PIN. In reality, the seller may be approving a debit request. Restrictions on such transactions could reduce this type of fraud.
Will every payment request be discontinued?
The cited report says the matter is under consideration and is not yet a final decision. It mentions a possible deadline of October 31, but users should wait for a formal NPCI or bank notification before treating that date as confirmed.
There is also an important distinction between person-to-person collect requests, merchant payment requests and UPI AutoPay mandates. These services do not necessarily operate under identical rules.
Earlier restrictions focused on recipient-initiated person-to-person collect requests. Reports in 2025 said that NPCI instructed banks and payment applications to stop P2P collect requests from October 1, 2025, as an anti-fraud measure. That does not automatically establish that every merchant collect link or recurring mandate will now be discontinued.
What could change for customers?
If wider restrictions are introduced, customers may need to initiate more payments themselves. Instead of approving a request sent by a merchant or individual, the user could be asked to scan a verified QR code, enter a UPI ID or use the payment option inside the merchant’s official application.
This may add an extra step, but it would give the payer greater control over how the transaction begins. Users would still need to verify the recipient’s name and amount before entering their PIN.
The original report suggests that recurring payments for electricity, mobile services, LPG bills and streaming subscriptions could be affected. That claim requires caution. UPI AutoPay uses an approved mandate framework and should not be assumed to end merely because some collect requests are restricted. Any impact on mandates would depend on the final scope of an official order.
Essential UPI safety rules
Customers can reduce the risk of fraud by following a few basic precautions:
- Never enter a UPI PIN to receive an ordinary payment.
- Read the amount and recipient’s name before approving a request.
- Reject collect requests from unfamiliar people or businesses.
- Do not scan a QR code sent for processing a refund.
- Never share an OTP, UPI PIN or screen-sharing access.
- Use only an official bank or recognised payment application.
- Contact the bank immediately after an unauthorised transaction.
The proposed restriction could strengthen UPI security, but its final scope remains unclear. Until NPCI or participating banks issue formal instructions, users should not assume that all payment links, merchant requests or automatic mandates are being discontinued.