QR Code Payments: How They Work and How to Use Them
How QR code payments actually work in 2026: transaction flow, static vs dynamic codes, how to accept them, and the quishing risks nobody warns you about.
A QR code payment is a contactless transaction where a customer scans a merchant's QR code with a phone camera or payment app, confirms the amount, and sends money directly from a linked wallet, bank account, or card. The scan tells the app which merchant to pay and, for dynamic codes, exactly how much. Global QR payment volume passed $3 trillion in 2025 and is projected to exceed $8 trillion by 2029, according to Juniper Research.
Somewhere in Shenzhen a fruit vendor takes seventy-eight scan-to-pay transactions before lunch. Zero card readers, zero cash drawer, zero small change to hunt for. Meanwhile in a coffee shop in Austin, a barista is still fumbling with a chip reader that refuses to talk to a customer's phone. Same century, very different payment stack.
QR code payments closed most of that gap in about a decade, and the last two years have been especially loud in North America and Europe as PayPal, Venmo, Cash App, and every mid-size POS provider added scan-to-pay support. This guide breaks down how a QR code payment actually moves money from a buyer's account to yours, the three main types of QR payment flows (and which one you probably want), how to accept them in a real business without a payment engineer on staff, and the security gap most guides skim over. If you print a QR anywhere near a checkout counter, this is worth reading before, not after.
Table of Contents
- What Is a QR Code Payment?
- How QR Code Payments Actually Work
- The Three Flavors: MPM, CPM, and P2P
- Static vs Dynamic Payment QR Codes
- Where QR Code Payments Are Winning
- How to Accept QR Code Payments for Your Business
- Popular QR Payment Apps Compared
- Security: The Quishing Problem You Cannot Ignore
- Fees, Settlement, and the Small Print
- Frequently Asked Questions
What Is a QR Code Payment?
A QR code payment is a contactless mobile transaction where the payer scans a merchant's QR code with a smartphone camera or payment app, and the encoded data tells the app who to pay and, optionally, how much. No card is swiped, no NFC terminal is tapped, and no cash changes hands.
The code itself is not the money. It is instructions. Depending on the format, those instructions carry a merchant ID, an account handle, a currency, an amount, an invoice reference, and sometimes a signed integrity check. Once the payer's app decodes that string, it takes over the rest: authenticates the user, calls the payment processor, and pushes funds through whichever rails the app is wired into. Card networks, ACH, real-time payments, wallet balances, they all sit behind the scan.
That decoupling is the whole point. A merchant does not need a terminal certified to Visa's specifications, a card acquirer, or a leased line. The merchant only needs a way to display a code and a way to receive settled funds. The infrastructure lives inside the payer's app. That is why QR payments scaled first in markets where card terminals were expensive and later in markets where card terminals were fine but tipping, splitting, and peer-to-peer transfer were annoying.
How QR Code Payments Actually Work
Here is the whole flow in six steps, stripped of jargon:
- The merchant generates a payment QR code. It encodes either a merchant identifier (for a fixed store) or a full transaction (for a specific bill).
- The customer opens a payment app or their camera. Most modern phones detect the payment URI natively and hand it to the right app.
- The app decodes the string and displays the transaction details. Merchant name, amount if pre-filled, currency, and any memo.
- The customer confirms and authenticates. Face ID, fingerprint, PIN, or biometric-plus-PIN depending on the app.
- The app calls the payment processor. The processor validates the request, checks funds, applies any fraud rules, and pushes the money.
- Both sides get confirmation. Merchant sees the payment land in real time (or T+1 depending on the rails); customer sees a receipt in the app.
The whole thing usually takes fifteen to thirty seconds, most of which is the human deciding to hit "pay." The actual routing is often faster than a chip card handshake.
An important nuance: nothing about a QR code makes the payment "instant" or "safe" on its own. The rails behind the code do. A QR that points to a UPI request in India settles in seconds because UPI itself does. A QR that opens a PayPal invoice on a US business account clears at PayPal's normal pace. The scan just replaces the address bar.
The Three Flavors: MPM, CPM, and P2P
Not all payment QR codes work the same way. If you plan to accept them, this distinction matters more than any other.
Merchant-Presented Mode (MPM). The merchant displays the code, the customer scans. This is what you see on a coffee shop counter, a parking meter, or a table tent. It's the cheapest to deploy because the merchant only needs a printed sticker or a screen. It's also the model most vulnerable to sticker-over-sticker fraud, which we cover in the security section.
Consumer-Presented Mode (CPM). The customer's app displays a rotating QR code that encodes their wallet or virtual card, and the merchant scans it with a scanner or their POS. Amazon Go, Walmart Pay, and most transit gates use this pattern. It's better for high-throughput checkouts and safer against tampering, because the code is generated fresh on the customer's device.
Peer-to-Peer (P2P). No merchant category at all. Two individuals scan each other's QRs to move money. Venmo, Cash App, WeChat Pay red packets, UPI person-to-person requests. This is the fastest-growing bucket in the US because the friction of getting someone's phone number or bank info just vanishes.
A single business often uses all three: MPM at the register, CPM for the drive-through, P2P for the tip jar. The QR pattern looks the same to a human. The intent baked in is very different.
Static vs Dynamic Payment QR Codes
A dynamic QR code encodes a short URL that the merchant controls. The destination page (or transaction record) can be updated any time without reprinting the code. A static QR code, by contrast, encodes the destination data directly and cannot be changed once printed.
For payments, this is not a stylistic preference. It changes what your code can actually do.
A static payment QR points to a fixed handle, like paypal.me/yourshop. The customer scans, lands on the payer form, and types the amount themselves. It costs you nothing per code, and a single sticker at the register can serve every transaction for years. The catch: no per-transaction amount, no reconciliation reference, no way to send the customer to a different account seasonally without re-printing.
A dynamic payment QR either encodes a full one-time transaction (with amount, invoice ID, and expiry) or points to a short link you can re-target. Dynamic codes let you print once and reuse forever, swap the destination if you change processors, and match every scan back to a specific bill. Our deep dive on dynamic vs static QR codes walks through the encoding differences if you want the technical version.
If you're placing codes on printed collateral, product packaging, or in-store signage that will live longer than one campaign, dynamic is the only choice that survives the first pricing change. If you're generating a fresh code for each bill anyway (like an invoice PDF), static-per-bill is fine because you never reuse it.
Where QR Code Payments Are Winning
QR pay is not evenly distributed. It shows up hardest in a handful of use cases where the alternatives are worse:
- Table checkout. Diners scan the code on the receipt, tip and split from their own phones, and walk out. Toast, Square, and Stripe all built table QR flows in 2024-2025. Servers get their tables back thirty percent faster in the pilots that publish numbers. Our QR codes for restaurants piece unpacks the restaurant angle in more depth.
- Peer-to-peer transfers. Splitting a bar tab used to require asking for a Venmo handle. Now the person paying just holds up a QR. In markets like India and Brazil, P2P scan-pay is already the default way to pay a friend.
- Parking and street payments. Meters, garages, and toll booths increasingly point to a scan-to-pay page instead of asking for a card in the rain. The trade-off is real quishing risk, which we cover below.
- Vending and self-service. Vending machines without card readers add a QR sticker on the door. The scan opens a payment page tied to the machine ID, so the operator knows exactly which unit dispensed which drink.
- Charity and tips. Buskers, food-truck cooks, and stand-up comics have leaned on payment QRs since 2020 because the alternative was cash-only. A single strip on a bucket now takes Venmo, Cash App, and PayPal at the same time.
- B2B invoicing. Invoice PDFs increasingly ship with a dynamic QR that opens a pre-filled payment portal. Accounts payable teams scan from the paper copy and skip the "type the invoice number into the vendor portal" step entirely.
- Charity events and fundraisers. Print a QR on the pledge card, point it at your donation processor, watch conversion double. This is the pattern behind a lot of the 2025 giving-season growth stories.
- Retail returns and reorders. Amazon and a few large retailers put a return QR on the shipping label. Scan opens the returns flow pre-populated with the right order. Same trick works for reorder codes on consumable products.
The common thread: every one of these use cases replaces either a physical terminal or a step where the customer has to type something. Anywhere that description fits, a scan usually wins.
How to Accept QR Code Payments for Your Business
If you can accept a debit card, you can accept a QR payment. The setup is friendlier than most guides make it sound.
Step 1: Pick a payment processor that supports QR
Any of Stripe, Square, PayPal Business, SumUp, Helcim, and most regional banks now offer scan-to-pay endpoints. Pick based on where your money already sits and what your card fees look like. Do not open a new merchant account just for QR support unless your current processor charges premium fees for it.
Step 2: Generate a payment link or checkout URL
In your processor's dashboard, create a hosted checkout link, an invoice link, or a persistent payment page. This is the URL your QR code will point to. If you want the amount pre-filled (a "$8 latte" QR at the register), include the amount as a query parameter, which most processors support.
Step 3: Turn the URL into a dynamic QR code
Shorten and brand the URL with a QR-friendly link generator so the code stays scannable and the destination stays editable. You can create a dynamic QR from any URL for free at U2L AI's QR code generator, no login needed. Pick colors, add a logo, and download the SVG or PNG. Our step-by-step walkthrough on how to create a dynamic QR code has the full flow if you want a deeper look.
Step 4: Test the scan before you print anything
Scan the code with the actual devices your customers will use (iPhone camera, Android camera, Google Pay, Venmo, PayPal apps). Confirm the destination loads, the amount is correct, and the payment method options match what you expect. Test on cellular data, not just Wi-Fi.
Step 5: Place the code where customers will actually see it
Register, table tent, receipt, drive-through window, invoice PDF, product packaging. Give the code a clear call-to-action nearby ("Scan to pay - opens Venmo, Cash App, or your bank"). Guests almost never scan a bare QR with no context.
Step 6: Reconcile scans against payments weekly
Dynamic QR codes track every scan, and your processor tracks every payment. The gap between the two is your friction rate. If a hundred people scan and only sixty pay, something in the middle of your checkout is broken - usually a slow-loading page or an unclear amount field. Fix it.
Two footnotes worth adding. First, if your business needs one QR per bill rather than one QR per counter, use a QR API (Stripe, Square, and U2L AI all offer these) so codes generate automatically inside your invoice or POS flow. Second, if you're running multiple codes across locations, tag each one so your analytics separates "counter A" from "counter B" scans. This is where dynamic really pays off.
Popular QR Payment Apps Compared
Every app supports slightly different flows. Here is what actually matters for a merchant deciding where to point their QR:
| Payment app | Merchant QR (MPM) | Consumer QR (CPM) | P2P scan | Best for |
|---|---|---|---|---|
| PayPal Business | Yes | Yes | Yes | Small business selling online + in person |
| Venmo | Yes (via PayPal parent) | Yes | Yes | US peer-to-peer, tipping, freelancers |
| Cash App | Yes | Yes | Yes | US P2P, buskers, service tips |
| Stripe | Yes (Payment Links) | Limited | No | Businesses that already run Stripe checkout |
| Square | Yes | Yes | No | Bricks-and-mortar retail and food service |
| WeChat Pay | Yes | Yes | Yes | Reaching Chinese customers |
| Alipay | Yes | Yes | Yes | Reaching Chinese customers |
| UPI (India) | Yes | Yes | Yes | Any business serving India |
| Zelle | No | No | Yes | US bank-to-bank P2P only |
There is no single "best" answer. In the US, most independent merchants combine PayPal Business (broad reach) with one bank-linked option for peer-to-peer. In Southeast Asia, one UPI-compatible code covers ninety percent of the population. Look at where your customers already pay, not where the app blogs tell you they should.
Security: The Quishing Problem You Cannot Ignore
QR codes cannot carry viruses. They are static image data. The problem is what the code points to.
Quishing (QR phishing) rose from less than one percent of phishing attacks in 2021 to about twelve percent by end of 2025, and the first half of 2026 saw another sharp jump as attackers targeted parking meters, restaurant menus, and tourist destinations. The typical attack: a scammer prints a sticker with a lookalike QR, slaps it over the real one, and waits. Anyone who scans it lands on a fake checkout page that harvests card details or wallet credentials.
Three practical defenses for merchants:
- Use tamper-evident placement. Laminate the code, place it behind glass, print it directly on your receipt, or emboss it on a fixed surface. Cheap peel-off stickers are the attacker's dream.
- Add a branded short domain. A code that opens
pay.yourbrand.co/menuis inspectable in the preview screen. A code that opens a random string is not. Custom short domains do this for you, and U2L AI supports them (see u2l.ai/features for the full list). - Point the code at a page you control, not the raw processor URL. If the processor changes URLs or gets phished itself, you can retarget your dynamic QR without reprinting anything.
For customers, our full guide on how to check if a link is safe walks through the pre-scan verification steps, and the QR code security piece covers the quishing landscape in depth. The short version: preview the URL after scanning but before entering any payment detail, and refuse to type your card number into any page that does not clearly belong to a payment brand you recognize.
Fees, Settlement, and the Small Print
QR payments do not float in a fee-free zone. What you pay depends entirely on which rails sit behind the code.
Card-network-backed QR flows (Stripe, Square, most PayPal QR transactions) charge you the standard card processing fee, roughly 2.6% plus a small per-transaction cent in the US, plus any hardware or software fees. Wallet-to-wallet QR flows (Venmo P2P, Cash App friends-and-family) are usually free between individuals but charge one to three percent for merchant or "business" tags. Bank-rail QR flows (UPI in India, PIX in Brazil) are near-zero cost for the merchant by design, which is why they exploded.
Settlement timing varies too. Real-time rails (UPI, PIX, FedNow-backed QR) land funds in seconds. Card-backed QR settles on your processor's normal card cycle, usually one to two business days. Wallet-based QR (Venmo, Cash App) can hold funds inside the wallet until you transfer them to a bank, which is instant for a small fee or free with a delay.
None of this is a reason to skip QR. It is a reason to price it into your margins the same way you price card fees, and to pick the rail that fits your cash-flow reality, not the one with the best marketing.
Frequently Asked Questions
How does a QR code payment work in simple terms?
The merchant displays a QR code that encodes their payment handle or a specific transaction. The customer scans it with a payment app or phone camera, confirms the amount and authenticates, and the app moves the money through whichever rail it is connected to. No card reader is involved; the payment infrastructure lives inside the payer's app.
Are QR code payments safe?
The technology is safe when used correctly. The risk is quishing, where an attacker replaces a legitimate code with a lookalike that points to a fake payment page. Protect yourself by verifying the URL after scanning, using tamper-evident placement as a merchant, and pointing your QR at a branded short link you control rather than a raw processor URL. Our QR code security guide covers this in detail.
Do I need a special app to pay by QR code?
Usually not. Modern iPhone and Android cameras detect payment URIs automatically and hand them to the right installed app. For some region-specific rails (WeChat Pay, Alipay, UPI) you need the corresponding app installed. Card-backed QR flows work in any browser.
What is the difference between a static and dynamic payment QR code?
A static code encodes the destination directly and cannot be updated after printing. A dynamic code points to a short URL you control, so you can change the destination, pre-fill amounts, and track every scan. For any use case beyond a one-off invoice, dynamic is the right default.
Can I accept QR payments without a merchant account?
You can accept peer-to-peer QR payments through PayPal, Venmo, or Cash App using a personal or business profile, no traditional merchant account required. For higher volumes, discounted fees, and better reporting, a proper processor like Stripe or Square is usually worth it. Fees still apply either way.
How much do QR code payments cost the business?
It depends on the rail. Card-backed QR runs 2-3% plus per-transaction fees, wallet P2P is typically free between individuals and 1-3% for merchant use, and bank-rail QR (UPI, PIX) is often near zero. Pick based on your customer mix and settlement needs, not the rail with the loudest marketing.
Can dynamic QR codes track how many people scanned but did not pay?
Yes, when you route the QR through a short link. The link platform logs every scan; your processor logs every completed payment. The gap between the two is your abandonment rate, and it usually points to a slow page or an unclear amount screen. This is one of the main reasons to run QR payments through a proper short-link layer.
What happens if my payment processor goes down?
This is the strongest argument for dynamic codes. If your processor is offline or changes URLs, you update the short link destination once and every printed code retargets automatically. Static QR codes hard-coded to a processor URL become useless if that URL breaks.
QR code payments are not a shiny future thing anymore. They are a core rail in most of the world and a growing one in every remaining market, and the businesses that print a code today without thinking about dynamic control, tamper-evident placement, and scan-to-pay analytics will spend the next year reprinting collateral. Point every payment code you deploy at a link you control, track the scans, and treat the QR itself as the packaging, not the payment. Create a free dynamic QR code at u2l.ai, or sign up for a free U2L AI account to manage payment codes, short links, and scan analytics from one dashboard.