RBI's New Two-Factor Authentication Rule for UPI Payments: What It Means If You Sell Online
Starting April 1, 2026, every digital payment made in India, UPI included, has to clear two separate authentication checks instead of one. The Reserve Bank of India calls this the Authentication Mechanisms for Digital Payment Transactions Directions, 2025, and it quietly rewired how banks, payment apps, and payment aggregators verify that the person paying is really who they say they are. If you run a small business, sell services online, or collect payments through a payment gateway, this rule touches you even if nobody sent you a memo about it. I run UroPay, a UPI collection tool for small sellers in India, and I spend a fair amount of time reading RBI circulars so my users do not have to. Here is what actually changed, who has to do the work of complying, and where a direct UPI setup like UroPay sits relative to a traditional payment aggregator under the new rule.
What the RBI's April 2026 authentication rule actually says
The directions were issued on September 25, 2025, and became enforceable on April 1, 2026, giving banks and payment companies roughly six months to get ready, according to KPMG's summary of the rule. The core requirement is simple to state: every domestic digital payment transaction now needs at least two distinct authentication factors, and at least one of those factors has to be dynamic, meaning it is generated fresh for that specific transaction rather than reused.
The rule covers UPI, credit and debit cards, mobile wallets, and net banking, per Bajaj Finserv's explainer on the April 2026 changes. A single SMS-based OTP, on its own, no longer counts as sufficient authentication for most transaction types. It can still be one of the two factors, just not the only one.
For UPI specifically, the second factor is usually already built into how the app works: device binding (the UPI app is registered to one specific phone and SIM) combined with the UPI PIN or a biometric unlock counts as two factors. Most UPI apps were already doing this before the rule existed, which is part of why the changeover has been relatively quiet for ordinary users making everyday payments. Cards are a bigger adjustment, since a lot of card-not-present transactions have historically leaned on OTP alone.
One detail worth flagging for anyone running an online business: the RBI also allows risk-based authentication, so a small, routine payment from a device your bank already recognizes may sail through with less visible friction than a large payment from an unfamiliar device or location. The security work is happening in the background either way. The government's own reporting to Parliament on UPI security measures confirms this layered approach is now official policy, not just an app-level convenience feature.
Why RBI moved away from OTP-only verification
OTP fatigue was a genuine, well-documented problem. SIM swap fraud, where a criminal convinces a mobile carrier to move a victim's number onto a new SIM, let attackers intercept OTPs directly. Phishing pages that mimic a bank's checkout screen collected OTPs in real time. Malware sitting quietly on a phone read incoming SMS messages and forwarded the code before the owner even noticed. Bajaj Finserv's breakdown of the rule change lists phishing, SIM swaps, malware, and social engineering as the four attack patterns that made single-factor OTP verification a weak link in a payment system processing this much money.
And it really is a lot of money. UPI closed FY 2025-26 with 24,161.69 crore transactions worth ₹314.23 lakh crore, up from 18,586.60 crore transactions worth ₹260.56 lakh crore the year before, per the Ministry of Finance's written reply in the Lok Sabha, reported by PIB in July 2026. Close to 55.49 crore people now have a UPI account. I don't think anyone who has fielded a panicked call from a relative who lost money to a fake "your KYC has expired" SMS will be surprised RBI finally acted on this. At that scale, a fraud pattern that works on even a tiny fraction of transactions adds up to real losses, and RBI's own reasoning for the new rule centers on cutting that exposure before it grows further.
There is also an accountability shift buried in the fine print. Institutions that have not implemented compliant authentication by the deadline can be held directly liable for compensating fraud victims, rather than pushing the loss onto the customer or the merchant by default. That changes the incentive structure for banks and payment companies to actually invest in better authentication rather than treating fraud losses as a cost of doing business.
None of this changes how a customer pays you through a Payment Link or Payment Button on UroPay. The customer still opens their own UPI app and authenticates with their own PIN or biometric, exactly as they always have. What changed is what happens on the bank and UPI app side of that transaction, which is where the compliance burden actually sits.
How the new rule lands differently on payment aggregators vs direct UPI collection
This is the section I get asked about most on WhatsApp, so it is worth slowing down here. A payment aggregator, in RBI's language, is an intermediary that sits between your customer and your bank account. It receives the payment first, holds it briefly, deducts its commission, and then settles the remainder to you, typically the next business day. Because the aggregator is the entity actually processing the transaction, it is the one that has to prove its checkout flow meets the new two-factor standard across every payment method it supports.
Practically, that means a small business using a payment aggregator now has homework. It is reasonable to ask your payment gateway provider for written confirmation that their checkout is compliant with the new authentication directions, and to check whether your merchant agreement says anything about who is liable if a transaction is later disputed as improperly authenticated. Medianama's explainer on the RBI's Master Direction for Payment Aggregators lays out how much of this compliance weight has shifted onto the aggregator layer since the 2020 guidelines were first issued, and the 2025 authentication directions add another layer on top of that.
There is also the onboarding side. Payment aggregators are required to complete KYC before you can go live, and for most merchants that means a PAN card, business registration proof, a bank account in the business's name, and government ID for the authorized signatory, according to Razorpay's own guide to payment gateway KYC onboarding. RBI does allow simplified checks for merchants under a ₹40 lakh turnover threshold, but simplified is still not the same as none. If you are a freelancer, a student running a side project, or someone selling online without formal business registration, this is often where the friction actually shows up, well before you ever think about transaction fees.
A direct UPI collection tool works differently because it is not an intermediary at all. With UroPay, the customer's money moves straight from their UPI app to your UPI ID. Nothing passes through a pooled account, nothing sits with a third party awaiting settlement, and there is no aggregator checkout flow that has to separately satisfy the authentication directions, because UroPay never touches the transaction itself. UroPay's part of the job is reading the UPI credit SMS your bank already sends you and matching it to the right order. That is a fundamentally different, and much lighter, compliance position than running a payment aggregator's checkout stack.
UroPay vs a traditional aggregator under the new rules
| UroPay | Traditional Payment Aggregator | |
|---|---|---|
| Commission | ₹0 (flat monthly subscription) | Typically around 2% per transaction |
| KYC to start | None | PAN, business proof, bank details, signatory ID |
| Who processes the payment | Customer pays your UPI ID directly | Aggregator holds funds, then settles to you |
| Settlement | Instant, direct to your account | Usually T+1 to your bank account |
| Who owns AFA compliance for the checkout | Your bank / the customer's UPI app | The aggregator |
| Best suited for | Freelancers, creators, unregistered or informal sellers, low-to-mid volume | Registered businesses needing card, net banking, or wallet options too |
| Chargeback handling | None needed, funds go directly to your account | Aggregator mediates disputes |
This is not a claim that one model is universally better. If you need to accept credit cards, EMI, or net banking alongside UPI, or you are already running a registered business with a compliance team, an aggregator's broader payment stack and dispute-handling infrastructure earns its cost. UroPay is built for the seller who mainly needs UPI, wants to keep every rupee, and does not want a KYC process standing between them and their first sale. That is also why UroPay's own pricing page is upfront that UroPay does not itself act as a payment aggregator or hold UPI accounts on anyone's behalf.
A worked cost example: flat fee vs 2% aggregator commission
I would rather show the rupee amounts than argue about percentages, since 2% sounds tiny until you watch it leave your account every single day. UroPay runs three plans: Free at ₹0/month for up to 5 transactions, Growth at ₹100/month for up to 50 transactions, and Unlimited at ₹1,000/month with no transaction cap, all listed on the pricing page. Compare that to an aggregator charging a commonly cited rate of around 2% per transaction.
On the Growth plan, ₹100/month becomes cheaper than a 2% commission once your monthly UPI collections cross roughly ₹5,000 (2% of ₹5,000 is ₹100). Sell ₹20,000 worth of online courses, coaching sessions, or products in a month and a 2% aggregator would take ₹400 off the top; UroPay's Growth plan still costs ₹100, as long as you stay within 50 transactions.
On the Unlimited plan, the break-even point sits around ₹50,000 in monthly UPI collections (2% of ₹50,000 is ₹1,000), and above that, every additional rupee of sales is fully yours regardless of how many transactions it took to get there. A seller doing ₹1,00,000 a month would hand over roughly ₹2,000 to a 2% aggregator; on UroPay's Unlimited plan, it is still ₹1,000 flat.
This is an illustrative comparison based on a 2% blended rate, and actual aggregator pricing varies by provider, category, and payment method, so it is worth checking your own gateway's fee schedule against the numbers on UroPay's pricing page before deciding.
Step-by-step: setting up direct UPI collection with UroPay
Getting started takes a few minutes, not a few days of document uploads.
- Sign up. Go to the UroPay dashboard and create an account with your email and UPI ID. No business registration, PAN, or GST number required.
- Pick a plan. Free works for testing the waters with up to 5 transactions a month; Growth and Unlimited suit anyone selling regularly. Compare them on the pricing page.
- Create a Payment Link or Payment Button. Set an amount (or let customers enter their own), add a description, and generate the link or embeddable button.
- Share it or embed it. Drop the Payment Link into an Instagram bio, a WhatsApp message, or an email, or add the Payment Button to your website or blog with a short embed snippet.
- Install the companion app (optional but recommended). The UroPay Companion App for Android reads the UPI credit SMS the moment it arrives and confirms the order automatically. Skip the app and customers can still confirm by entering their UPI reference number, and you will get a notification either way.
- Track everything from the dashboard. Real-time order and payment history is available at app.uropay.me, so you always know what has been paid and what is pending.
If you later outgrow UPI-only collection and need cards, net banking, or full merchant-grade bank settlement, UroCentro, UroPay's partnership product with the RBI-licensed aggregator Decentro, is the upgrade path, with its own KYC process and a 1.75%+GST commission.
Quick takeaways
- RBI's Authentication Mechanisms for Digital Payment Transactions Directions, 2025 took effect April 1, 2026, and requires two distinct authentication factors, with at least one dynamic, for domestic digital payments including UPI.
- A single SMS OTP is no longer sufficient authentication on its own for most transaction types; it can still be one of two factors.
- Payment aggregators carry the compliance weight of proving their checkout flow meets the new standard, since they are the intermediary processing the transaction.
- Direct UPI tools like UroPay are not intermediaries, so the authentication work happens at the bank and UPI app layer, exactly where it already happened before the rule changed.
- UPI closed FY 2025-26 with 24,161.69 crore transactions worth ₹314.23 lakh crore, and roughly 55.49 crore users are onboarded as of June 2026.
- A flat-fee model like UroPay's Growth (₹100/month) or Unlimited (₹1,000/month) plan breaks even against a 2% aggregator fee at roughly ₹5,000 and ₹50,000 in monthly collections.
- UPI has carried zero MDR since January 2020, so the fee difference between UroPay and an aggregator comes down to the aggregator's own commission, not any government-mandated charge.
Conclusion
RBI's new authentication rule is a genuine security upgrade, and it deserved to happen given how much money now moves through UPI every month. What it also does, almost as a side effect, is highlight a difference that already existed between payment aggregators and direct UPI collection tools. An aggregator processes your payment, which means it inherits the job of proving that process meets the new authentication bar. A tool like UroPay never processes the payment at all, since your customer pays your UPI ID directly and UroPay just reads the confirmation. If you are a freelancer, tutor, small shop owner, or anyone selling online without a registered business behind you, that distinction is worth understanding before you pick a payment tool, not after a compliance question catches you off guard. Take a look at how UroPay's Payment Buttons and Payment Links work, check the pricing page against your own sales volume, and reach out to me directly at gaurav@uropay.me if you have questions specific to your business.
Frequently asked questions
Does RBI's new authentication rule affect UPI payments I collect through Payment Links or Payment Buttons?The rule governs how your customer's bank and UPI app authenticate the transaction, which was already a two-factor process (device binding plus UPI PIN or biometric) for most UPI apps. As a seller collecting payments through a Payment Link or Payment Button, you do not need to make any changes on your end.
Is a single UPI PIN entry still enough to authorize a payment after April 1, 2026?Yes, because UPI transactions already combine device binding with the PIN or biometric, which counts as two distinct factors under the new directions. The rule mainly targeted single-factor OTP flows on cards, wallets, and net banking that had not been layering in a second factor.
Do I need to ask my payment aggregator for proof of compliance with the new rule?It is a reasonable question to ask, since payment aggregators are the entity responsible for meeting the authentication standard across their checkout flow. Reviewing your merchant agreement for how liability is handled in a disputed or fraud-related transaction is worth doing at the same time.
Why does UroPay not require KYC when payment aggregators do?UroPay is not a payment aggregator and does not hold UPI accounts on anyone's behalf; the customer's payment goes directly to your own UPI ID. Since UroPay is not an intermediary handling funds, it is not subject to the same RBI Payment Aggregator KYC requirements that apply to entities like Razorpay, Cashfree, or PayU.
What happens if I outgrow UPI-only collection and need cards or net banking too?That is what UroCentro is for. It is UroPay's partnership product with Decentro, an RBI-licensed payment aggregator, offering full KYC onboarding, T+1 bank settlement, and a broader payment method mix at 1.75%+GST commission.
I would like to hear from you: has your existing payment gateway told you anything about how it is handling the new authentication rule, or did this catch you by surprise like it did a lot of small sellers I talk to? Drop a comment, or message me directly, and share this with anyone you know who runs an online shop or freelance business and might be wondering the same thing.
References
- KPMG India, "Reserve Bank of India (RBI): Authentication Mechanisms for Digital Payment Transactions Directions, 2025" — https://kpmg.com/in/en/insights/2025/12/reserve-bank-of-india-rbi-authentication-mechanisms-for-digital-payment-transactions-directions-2025.html
- Bajaj Finserv, "RBI's New Digital Payment Rules from April 1: What Changes for UPI, Cards and e-Wallets" — https://www.bajajfinserv.in/rbi-new-digital-payment-rules-april-2026
- Press Information Bureau, Ministry of Finance, "Nearly 55.49 Crore Users Onboarded on UPI as in June 2026" (July 20, 2026) — https://www.pib.gov.in/PressReleasePage.aspx?PRID=2286608®=48&lang=1
- Medianama, "Explained: RBI's Master Direction For Payment Aggregators" — https://www.medianama.com/2025/09/223-explained-rbi-master-direction-payment-aggregators/
- Razorpay, "Payment Gateway KYC Onboarding Guide India (2026)" — https://razorpay.com/blog/payment-gateway-kyc-onboarding-india/
- Deccan Herald, "No MDR Will Be Charged on UPI Transactions: FinMin" — https://www.deccanherald.com/business/no-mdr-will-be-charged-on-upi-transactions-finmin-3582565






