QR code payments in Indonesia uses QRIS (Quick Response Code Indonesian Standard), an Indonesian QR code standard developed by Bank Indonesia (BI) and Indonesian Payment System Association for cashless payments in Indonesia.
Features
Channel Code | QRIS |
Display Name | QRIS |
Currency | IDR |
Country | ID |
Type | QR CODE |
Min Amount | 1 |
Max Amount | 10,000,000.00 |
User Approval Flow | PRESENT TO CUSTOMER |
Reusable Payment Code | ✓ |
Save | - |
Merchant Initiated Transaction | - |
Auth & Capture | - |
Partial Capture | - |
Desktop Support | - |
Mobile Support | - |
Custom Payment Code | - |
Display Merchant Name | MERCHANT |
Customize Display Name | - |
Set Expiry | ✓ |
Payment Request Expiry (hours) | 48 |
Payment Token Validity (years) | - |
Payment Processing Time (hours) | INSTANT |
Settlement Time | T+1 BUSINESS DAYS |
Installments | - |
Refund | ✓ |
Partial Refund | ✓ |
Multiple Partial Refund | ✓ |
Refund Validity (days) | 7* |
Payment Link | ✓ |
Fund Flow | AGGREGATOR |
Payment flow
.png?sv=2026-02-06&spr=https&st=2026-07-22T19%3A10%3A37Z&se=2026-07-22T19%3A22%3A37Z&sr=c&sp=r&sig=OESfAim1fV6%2BHr5A07n0fshjrWMsusFpjGht7EOhUec%3D)
On the checkout page, select QRIS as payment method
A QR code will appear on the screen
Open your mobile banking or e-wallet app, then find the Scan QR Code feature
Point your phone camera at the QR code
Make sure the payment amount and merchant is correct
Confirm payment
Limitations
The QRIS refund process is limited to the following issuers:
Issuer | Refund full amount & within 24 hours of payment completion | Refund full amount & after 24 hours of payment completion | Partial refund |
|---|---|---|---|
DANA | ✅ | ✅ | ✅ |
ShopeePay | ✅ | ✅ | ✅ |
OVO | ✅ | ✅ | ✅ |
Gopay | ✅ | ✅ | ✅ |
CIMB | ❌ | ✅ | ✅ |
Permata | ✅ | ✅ | ✅ |
Jenius / SMBC | ✅ | ✅ | ✅ |
BSI | ✅ | ✅ | ✅ |
Chargebacks
What is a QR Dispute?
A QR Dispute occurs when a customer challenges a payment made via QR code on online purchase or physical stores through their bank or e-wallet (the Issuer). Generally, customers can initiate a dispute within 90 days of the transaction.
Common QR Disputes
Disputes typically fall into these categories:
Billing Errors: Transaction failed / incomplete, but the funds were still deducted
Duplicate Processing: The customer was charged twice for a single purchase. For example an end user scanned a code that was no longer in use and so the store owner/merchant made the end user pay afresh.
Fraud: Customer claims the transaction was unauthorized or they were tricked by a fake QR code.
Unprocessed Credit: Merchant failed to issue a refund for a returned item
Fulfillment Issues: Goods/services were not received or did not match the description
Mismatch Refund: Refund amount does not match the original amount of the transaction.
The merchant needs to contact the end users and clarifies regarding the QR dispute reason
The Dispute Workflow

When a dispute is raised, the information flows as follows:
End-User contacts their QR Issuer (Bank/E-wallet).
QR Issuer notifies the QR Acquiring Partner
QR Acquiring Partner notifies Xendit.
Xendit alerts the Merchant to provide evidence or accept the dispute.
Prevention Checklist
To minimize the risk of disputes and fraud, follow these best practices:
Verify Success: Only release goods/services once you receive a "Success" notification or SMS alert. It is the merchant’s responsibility to confirm the genuineness of the QR code being used.
Physical Security: Regularly inspect physical QR codes for tampering or "sticker" overlays.
Maintain Records: Save all transaction proofs (e.g. screenshots), invoices, receipts, and communication logs.
Hygiene: Immediately remove/deactivate QR codes that are no longer in use to prevent double billing error dispute
Responsiveness: Resolve customer inquiries and process necessary refunds promptly to prevent them from escalating to their bank.
QR Dispute Timeline

Stage | Description | Window |
|---|---|---|
Retrieval | Acquiring Partner informs Xendit; Merchant must provide evidence. | T+90 days from transaction date |
Dispute | If the initial evidence is rejected, the merchant may re-submit evidence. | T+30 days from Retrieval Information |
Understanding QR Fraud Types
The documented types of fraud (so far) are listed below:
Cyber fraud: Fraud attempt by replicate or counterfeit QR Code data such as
Quishing (QR Phishing): Malicious QR codes sent by phishing email / text that direct users to fake sites to steal login or payment credentials
QRLjacking: Tricking users into scanning a "Quick Response Login" code to take over their account session.
Friendly Fraud / Returned Fraud: A legitimate customer makes a purchase but later claims they don't recognize it to get their money back.
Internal/Employee fraud. An employee replaced the original QR code with their own personal code to divert funds. Commonly happened in in-store payments