UPI Integration Guide: PSP, TPAP and NPCI Rules

UPI Integration Guide: PSP, TPAP and NPCI Rules

TL;DR

  • UPI integration connects your app to NPCI’s rails through a licensed PSP bank. Your role decides your timeline, not your tech stack.
  • Merchants integrate in weeks through a payment aggregator. Becoming a TPAP takes five to nine months because NPCI approval and certification sit in the path.
  • NPCI now rate-limits the APIs you will lean on. Balance checks are capped at 50 per app per user daily, and status checks at three attempts with 90-second gaps.
  • Two rules dominate 2026 planning: the 30% TPAP volume cap due December 31, and RBI’s two-factor authentication directions already in force since April 1.
  • EngineerBabu builds UPI integration flows for lenders, wallets, and marketplaces, including sponsor bank coordination, certification support, and reconciliation logic.

UPI integration connects your application to India’s Unified Payments Interface through three parties. NPCI operates the switch and writes the rules. A PSP bank holds the license and issues the handle. A TPAP is the app the user actually touches.

Where you sit in that chain decides everything else. It sets your approval timeline, your compliance burden, and what your product is legally allowed to do.

Most teams scope this as a two-week API job. Then they discover a sponsor bank agreement, an NPCI certification cycle, and a CERT-In security audit standing between them and go-live.

The scale explains the scrutiny. UPI processed 23.2 billion transactions worth ₹29.9 trillion in May 2026 alone, an all-time high according to NPCI data (IBEF). Rails carrying roughly 740 million payments a day do not hand out access casually.

Who Does What: NPCI, PSP, and TPAP

Four entities touch every UPI transaction. Confusing them is the single most common mistake in early architecture decisions.

Entity What it is What it controls
NPCI The umbrella body operating the UPI switch Circulars, certification, routing, dispute rules
PSP bank A bank with NPCI membership UPI handles, UPI PIN, device binding, API access
TPAP A non-bank app provider riding a PSP license User experience, onboarding, app-side features
Issuer or remitter bank Where the customer’s money sits Debit authorization, balance, account status

A TPAP never talks to NPCI directly for transactions. It calls its sponsor PSP bank, which calls the NPCI switch, which routes to the beneficiary side. Every API contract you write sits against the PSP, not against NPCI.

That dependency is why serious TPAPs run multi-bank setups. PhonePe and Google Pay both operate across several sponsor banks so one bank outage does not take the whole app down.

Planning that redundancy early is easier than retrofitting it, and a solid bank API integration checklist saves weeks of discovery.

Which UPI Integration Path Fits Your Product

There are three realistic routes. Picking the wrong one adds months.

Path Who it suits Typical timeline Approval needed
Merchant via payment aggregator Ecommerce, SaaS, D2C collecting payments 2 to 4 weeks None beyond PA onboarding
UPI plugin or in-app SDK Apps wanting checkout inside the app 4 to 8 weeks PA and PSP coordination
Full TPAP Products where UPI is the core feature 5 to 9 months NPCI approval plus PSP sponsorship

If you only need to collect money, you are a merchant. You do not need a UPI integration in the regulatory sense. You need a payment aggregator, an RBI-licensed entity that handles settlement and compliance for you.

You need the TPAP route only when UPI is the product. Wallet apps, neobanks, and super apps fall here, and each needs full KYC at onboarding. Choosing KYC and identity verification software before you start building saves painful rework at the sponsor bank review.

NPCI Rules That Shape Your Build

These are not policy footnotes. Each one changes code you would otherwise write differently.

  • The 30% Volume Cap

NPCI limits any single TPAP to 30% of total UPI transaction volume, measured on a rolling three-month basis. The compliance deadline for TPAPs already over the line is December 31, 2026, after a two-year extension granted in 2024.

Apps approaching the threshold must throttle or stop new user onboarding. If your growth model assumes unlimited acquisition, model that ceiling now.

  • API Rate Limits

NPCI’s guidelines on UPI and API usage took effect on August 1, 2025, and they directly constrain app design.

API Limit
Balance enquiry 50 per app, per customer, per day
List of accounts linked to a mobile number 25 per app, per customer, per day
Transaction status check 3 attempts, with 90-second gaps
Autopay mandate execution Non-peak windows only

Peak hours are defined as 10:00 to 13:00 and 17:00 to 21:30. Any polling loop you write must respect these ceilings, because non-compliance invites API restrictions and onboarding suspension.

  • Authentication and Compliance

RBI’s Authentication Mechanisms for Digital Payment Transactions Directions, 2025 became enforceable on April 1, 2026. Every digital payment now needs two distinct authentication factors, and for non-card-present transactions, one factor must be dynamically created per transaction.

Data localization applies on top. Payment data must be stored on servers inside India, which affects your hosting design before you write a line of code. Running your broader fintech compliance checklist alongside the build keeps audit findings from arriving late.

  • Transaction Limits by Category

Category Per-transaction ceiling
Standard P2P and P2M ₹1,00,000
Capital markets, insurance, collections ₹2,00,000
IPO and RBI Retail Direct ₹5,00,000
Hospitals, education, tax payments ₹5,00,000
UPI Lite ₹1,000 per payment
UPI 123Pay ₹10,000

Banks can set lower limits than NPCI allows. Never hardcode these values, since they change through circulars more often than most teams expect.

UPI Integration Step by Step

  • Sign a Sponsor PSP Bank

Nothing starts before this. Shortlist PSP banks on switch uptime, technical decline rates, and how many TPAPs they already support. Ask for their transaction success rate during peak evening hours, not their annual average.

Negotiate the handle, the API specification version, and the sandbox access timeline in the same agreement. Budget four to eight weeks for due diligence, since the bank reviews your KYC process, your data handling, and your promoter background before signing anything.

  • Build Registration and Device Binding

This is where most UPI integration projects first slip. Registration requires an outbound SMS from the user’s device to hard-bind the phone number to that specific handset.

Dual-SIM phones, SMS permission denials, and low-cost devices break this flow constantly. Instrument every drop-off point, because a 20% registration failure rate is common in first builds and entirely fixable.

UPI PIN setup follows, using debit card details or Aadhaar OTP depending on the issuing bank.

  • Wire the Payment Flows

Four flows cover almost every product: intent, collect, QR, and autopay mandates. Intent hands off to a UPI app and returns. Collect pushes a request to the payer and waits, which means long timeouts and careful state handling.

Build an abstraction layer over the PSP specification instead of coding against one bank’s quirks. Disciplined API Development here is what lets you add a second sponsor bank later without rewriting your payment core.

  • Handle Reconciliation and Disputes

Settlement files arrive daily, and they will not match your database on day one. Build a reconciliation job that flags mismatches automatically instead of relying on manual checks.

RBI’s turnaround time rules require auto-reversal of failed debits within the prescribed window, with customer compensation when you miss it. NPCI also requires in-app dispute raising, so users must be able to file a complaint without calling support.

Design a transaction state machine early: initiated, pending, deemed success, reversed, settled.

  • Certify, Audit, and Go Live in Phases

Certification runs in the NPCI sandbox against mandated test cases covering every flow and error code. A CERT-In empanelled security audit runs in parallel, and remediation usually adds two to three weeks.

Go-live is phased. NPCI typically approves a limited user cohort first, then lifts the cap once your decline rates and complaint volumes look clean. Treat that window seriously and work through a full app launch checklist before you request expansion.

Where AI Earns Its Place

UPI settles in seconds, which leaves no room for manual review between authorization and money movement. Risk scoring has to happen inline.

Models built through ML Development can score device, velocity, and beneficiary signals within the transaction window, flagging mule accounts before funds leave. Teams using AI Development for support automation also cut ticket load sharply, since most UPI complaints are status questions a system already knows the answer to.

Keep the fraud model separate from the payment path. A slow model should degrade to a rules fallback, never block a legitimate payment.

What Breaks in Production

  • Treating pending as failed. UPI has deemed-success states. Marking them failed creates double debits and angry users.
  • Aggressive status polling. The three-check rule is enforced. Polling loops written before August 2025 now breach it.
  • Storing the VPA as user identity. Handles change when users switch apps. Key off your own user ID instead.
  • Single sponsor bank dependency. One PSP outage takes down 100% of your volume.
  • Under-provisioned infrastructure. Festival traffic multiplies volume within hours, so pick from the best cloud for mobile apps with autoscaling and India-region data residency in place.

Technical declines deserve their own dashboard. They are usually a bank-side problem, but users blame your app every time.

Final Thoughts

A UPI integration is a regulatory project wearing an engineering costume. The code is manageable. The approvals, certification, and reconciliation logic are what decide your launch date.

Scope your role first, because merchant, plugin, and TPAP paths share almost nothing beyond the acronym. Then build for the rules already published rather than the ones you remember from 2023.

Teams launching a first version usually get there faster through focused MVP Development, shipping one flow cleanly before adding mandates and QR.

An experienced Mobile App Development partner will map sponsor bank timelines into the project plan instead of discovering them in month three.

FAQs

  • What is UPI integration?

UPI integration is the process of connecting an app to India’s Unified Payments Interface. It runs through a PSP bank that holds NPCI membership, either directly as a TPAP or indirectly through a payment aggregator.

  • What is the difference between a PSP and a TPAP?

A PSP is a bank with NPCI membership that issues UPI handles and manages the UPI PIN. A TPAP is a non-bank app provider that offers UPI services to users under that bank’s license.

  • How long does UPI integration take?

Merchant integration through an aggregator takes two to four weeks. Full TPAP integration takes five to nine months, since sponsor bank due diligence, NPCI certification, and a security audit all sit in the critical path.

  • Do I need NPCI approval to accept UPI payments?

No. Merchants accepting payments work through an RBI-licensed payment aggregator and need no direct NPCI approval. You need NPCI approval only when becoming a TPAP offering UPI services in your own app.

  • What are the current NPCI API limits?

Balance enquiries are capped at 50 per app per customer daily, account list requests at 25, and transaction status checks at three attempts spaced 90 seconds apart. Autopay mandates execute only during non-peak windows.

  • What happens if a UPI transaction fails but money is debited?

The remitter bank must auto-reverse the debit within RBI’s prescribed turnaround time. Miss that window and the bank owes the customer compensation, so your reconciliation job needs to surface these cases within hours.