Skip to content
The Product Guys
All teardowns
PhonePeUser Psychology5 min read

Paying a stranger by scanning a sticker

UPI turned payment into an action with no account numbers in it.

The surface
The everyday UPI payment: opening the scanner, reading a merchant QR code, entering an amount, authorising with a UPI PIN, and the confirmation both parties get.
What the user wants
I want to pay the vegetable seller the exact amount without cash, in under ten seconds, standing in the street.
01

The scanner as the home action

The app puts a scan and pay action in the most prominent position, so the common case is one tap from opening the app.

Optimise the dominant path

Most payments in this context are to a physical merchant with a printed code, and everything else in the app is rarer. Giving the dominant case the largest target makes the app feel fast regardless of how much else it contains. Feature richness is survivable only if the main path stays one tap.

02

The QR code as the address

A merchant is identified by a printed code encoding a UPI ID, so the payer never handles an account number or bank branch code.

Hide the plumbing

Account numbers are long, checkable only by retyping, and the source of most payment anxiety. Replacing them with a scan removes both the effort and the fear of sending money to the wrong place. The underlying interbank system is unchanged, and the felt experience is completely different.

03

Name confirmation before the amount

After scanning, the payee's registered name is shown before the amount is entered and again before authorisation.

Confirmation before irreversibility

UPI transfers settle immediately and cannot be pulled back, so the interface has to place the check before the action rather than offer an undo. Showing a human readable name is a check the payer can actually perform, unlike verifying digits. It is the single most important element on the screen.

04

The UPI PIN

Authorisation uses a separate PIN entered in a secure screen provided by the payment infrastructure rather than by the app, and it is required for every debit.

Trust through consistency

The same PIN screen appears across different apps and banks, so users learn one ritual and recognise it everywhere. A consistent security moment is easier to trust and harder to imitate convincingly. Standardising it at the infrastructure layer rather than the app layer was the decision that made this work.

05

The audible confirmation

Merchants commonly use a speaker device that announces the received amount aloud, and the payer sees an immediate success screen.

Closing the loop for both parties

In a street transaction the merchant cannot inspect the payer's phone, and a claimed payment used to be unverifiable without waiting. An audible confirmation the merchant hears independently settles the transaction socially as well as technically. The interaction ends the way a cash handover does, which is why it replaced cash.

Trust standardised below the app

1Scan a printed codeThe address is a sticker, so themerchant needs no hardware.2The payee name is shownBefore any amount is typed. This isthe moment a wrong payment is caught.3Enter the amountAfter the name, deliberately, so thecheck is not skipped in a hurry.4PIN, held by the bankThe app never sees it, which is whyevery app is equally safe here.5An audible confirmationDesigned for a shopkeeper who cannotlook at a screen for every sale.
The sequence is identical whichever app is scanning, because it is specified by the payment rail rather than by the product. That single decision let dozens of apps compete on speed and design while none of them could compete by being slightly less careful.

What not to copy

  • Instant and irreversible is a fraud designer's ideal combination, and UPI scams built on inducing a payment or a collect request have been a persistent problem in India. Interfaces that make paying effortless have to invest equally in making a suspicious request feel wrong, and that side lags.
  • Collect requests, where another party initiates a pull that the user approves, are the weakest part of the model. The approval screen looks similar to a payment screen while the money flows the other way, and that ambiguity is exactly what is exploited.
  • Rewards, scratch cards and cashback gamification attached to ordinary payments train frequency for its own sake and push users toward the app's other products. Celebrating a grocery payment with a prize animation is engagement design applied to something that did not need it.
  • The apps have grown into insurance, lending and investing surfaces that sit beside the payment flow. A user who came to scan a code is being sold financial products at a moment of habitual, low attention tapping.

The takeaway

Standardising the trust moment at the infrastructure layer let every app compete on speed without competing on safety. That is a platform decision doing more work than any interface could.

Finished the teardown? Bank it and the day counts toward your run.

Where the principles come from

  • The Design of Everyday Things, Don Norman
  • Influence: The Psychology of Persuasion, Robert B. Cialdini
  • Error Prevention, Nielsen Norman Group

Written from public behaviour of the product, not from inside it. Interfaces change often, so treat the flow described here as of the time of writing and check the live product before quoting it.