India recurring paymentsPublic preview
Learn how to update an integration to support RBI e-mandates for cards and UPI.
Caution
While the regulation refers to “recurring” payments, networks treat any off-session (that is, merchant-initiated) transaction as in scope, and so do we.
The Reserve Bank of India (RBI) issued a directive (amended subsequently in December 2020 and March 2021) that introduces additional security measures for recurring payments on India issued cards and other payment methods such as UPI. These measures include:
- Payment providers need to register customers and create an e-mandate through a one-time process, using additional factor authentication (AFA) such as 3D Secure (3DS) for cards or UPI PIN for UPI.
- Customers must be alerted at least 24 hours before charges take place and given the ability to opt out of transactions.
- Recurring transactions over 15,000 INR (or equivalent in other currencies) must go through AFA each time.
If you’re an India-based Stripe user or an international (non-IN) Stripe user, your business is impacted if you have customers who use India cards or UPI for:
- Off-session payments
- Subscriptions or Invoices where the
collection_is set tomethod charge_automatically
Note
For UPI-specific recurring payment details including mandate customization options, see Recurring payments (UPI AutoPay).
How payments work with an e-mandate
Stripe has worked with a partner platform to support registering e-mandates and issuing pre-debit notifications to customers. This applies to both card payments and UPI payments.
Note
We don’t currently offer the use of e-mandates to Stripe users in Mexico.
Depending on how you’ve integrated with Stripe, you might need to send Stripe additional information to set up a mandate. The customer must go through AFA (3DS for cards, or UPI PIN for UPI) to register the mandate.
Subsequent off-session payments or auto-debits for a Subscription undergo a significant change. Customers need to receive a pre-debit notification at least 24 hours before the actual payment with the exact debit amount mentioned. The pre-debit notification contains information about the payment and an option to cancel the mandate. For card payments, if the payment amount is above 15,000 INR or the mandate’s maximum amount, the pre-debit notification contains a link to perform AFA (3DS) to authorize the payment. UPI currently doesn’t support recurring transactions of greater than 15,000 INR in value.
For card payments, because Stripe is integrating with a partner platform, Stripe waits 26 hours before charging the customer after receiving a payment request (Stripe adds a buffer for possible downstream issues, which necessitates the 26-hour advance notification). This means that Stripe delays collecting card payments by 26 hours. For UPI payments, Stripe sends the pre-debit notification and charges the customer 1 day later.
Without a mandate for an off-session payment, the payment will be declined.
Integration
The RBI regulations impact Subscriptions that use collection_ to charge India issued cards or UPI.
Note
Stripe doesn’t support e-mandates for India recurring payments with PaymentIntents or SetupIntents. To manage mandates for recurring payments, use Subscriptions, as described below.
Subscription creation
When creating a new Subscription with the API,
- If you have a default payment method set, the Subscription uses the latest SetupIntent on the payment method, and attempts to find a corresponding mandate.
- If no mandate is in place, Stripe automatically attempts to create one even if you don’t pass in the relevant parameters in mandate_options. The customer then needs to authenticate the payment.
To learn how to create a new Subscription, see Build a subscriptions integration.
Subscription Revenue Recovery
Stripe provides a number of automated recovery features to help collect payments that might’ve been unsuccessful. If you want to handle these payment failures on your own, refer to Build your own handling for recurring charge failures for guidance. Otherwise, some recommendations are listed below.
Note
Payments from India issued cards are attempted only once. This behavior is independent of your payment retry settings. If the payment from an India issued card fails, your Subscription and Invoice status will still be updated based on what you configured in your Subscriptions and emails settings for “If all retries for a payment fail”.
3D Secure emails
If a mandate doesn’t exist on the default payment method during Subscription renewals or updates, Stripe attempts to create a new one. To register the mandate, the customer needs to complete AFA (3DS). Enable the Subscriptions and emails settings to Send a Stripe-hosted link for customers to confirm their payments when required so that customers can be brought back on-session to complete authentication if required.
Note
Stripe doesn’t attempt to create a new mandate if the current mandate used by the Subscription is inactive.
Manage failed payments
We recommend enabling notifications to your customers if their Subscription payments fail and their Subscription is paused. Stripe can send emails to customers to update failed payment methods if you enable it in the Subscriptions and emails settings.
Mandate creation
If you rely on Stripe to automatically create the mandate, the mandate details are returned in the Invoice’s underlying PaymentIntent and corresponding Charge, or the SetupIntent if you’re creating the Subscription with a trial.
Stripe doesn’t return a card mandate ID if any of the following are true:
- A card isn’t an India issued card.
- The currency for the mandate isn’t supported by either the issuer or for the Stripe account’s country.
- The India issued card is neither Visa nor Mastercard. Stripe only supports mandates for these two card brands.
Stripe supports INR mandates for all businesses. The following currencies are supported only for international (non-IN) businesses:
- AUD
- USD
- EUR
- GBP
- SGD
- CAD
- CHF
- SEK
- AED
- JPY
- NOK
- MYR
- HKD
There are over 100 issuing banks in India and the process of fully adapting to the new requirements is expected to take some time. An issuer might not support e-mandates for a particular currency yet. If so, Stripe doesn’t return a mandate ID.
If your customer initiates a subscription with Adaptive Pricing, and mandates support the selected currency, Stripe automatically creates an e-mandate in that currency.
Mandate status and troubleshooting
If Stripe can’t create a mandate, you can suggest using a different payment method (such as a different card or UPI), or you can offer alternative options such as setting collection_method as send_ for the subscription instead.
Also, a previously active mandate can become inactive, for instance if the customer cancels it. In that case, the mandate becomes inactive and Stripe sends a mandate. event.
For more information on receiving webhooks, see Steps to receive webhooks.
Subscription updates
The pre-debit notification that the bank sends tells the customer, at minimum, about the name of the business, the transaction amount, the date or time of the debit, the reference number of the mandate, and the reason for debit. Make sure that your mandate details match what you’re actually debiting the customer for to avoid confusion or declines.
If you depend on Stripe to automatically create mandates for your Subscription and want to update a Subscription, we recommend that you bring the customer back on-session to cancel the original Subscription. Doing so creates a new subscription in the following scenarios, and creates a new mandate that reflects the Subscription details accurately:
- Changes to the billing interval of a Subscription
- Upgrades to a Subscription where the customer wants to avoid having to authorize the payment each renewal. For context, Stripe creates the mandate with
amount_by default. A customer can still be charged more than the maximum amount withtype=maximum amount_. However, the customer must authorize payments for amounts more than thetype=maximum mandate_or 15,000 INR (whichever is less).options[amount]
Examples:
- If you have
amount_,type=maximum amount=100000, the customer would need to authenticate for amounts over 1,000 INR. - If you have
amount=2000000, the customer would need to authenticate for amounts over 15,000 INR.
Pre-debit notification
When the off-session PaymentIntent is confirmed, the bank sends the customer the pre-debit notification. The PaymentIntent transitions to a processing state for the entire duration of the pre-debit notification period (26 hours) and can’t be canceled.
{ "object": "payment_intent", ... "processing": { "card": { "customer_notification": { "approval_requested": true, "completes_at": 1677307005 } }, "type": "card" }, ... "status": "processing", ... }
If processing.card.customer_notification.approval_requested is true, the customer needs to authenticate the payment using the pre-debit notification sent to them by the bank.
The processing.card.customer_notification.completes_at attribute specifies the time that Stripe attempts to charge the payment method. If successfully processing the payment requires customer approval, they need to authenticate the payment by the specified time.
Error and decline codes
We return error codes for the following scenarios:
| Error code | Description |
|---|---|
payment_ | Attempting a recurring payment using an inactive mandate returns this code. You can prevent this by checking the mandate status before attempting to charge. |
india_ | Attempting a recurring payment using a canceled mandate returns this code. This can happen when we only learn that a mandate has been canceled at this point. |
processing_ | Discovery of a (usually transient) processing error returns this code. |
In the context of e-mandates, certain decline codes have potentially more specific explanations than in general scenarios:
| Decline code | Description |
|---|---|
transaction_ | Attempting a subsequent payment when the customer has paused permissions to auto-debit, or doesn’t authenticate the payment when it’s required returns this code. |
Testing
You can use these test card numbers to simulate different card mandate scenarios.
In a sandbox, it takes approximately 15 minutes for an off-session PaymentIntent to transition out of the processing state. The on-session PaymentIntent for an initial payment never enters the processing state.
| Number | Scenario |
|---|---|
| Simulates successful mandate setup and renewals. | |
| Simulates a customer receiving a pre-debit notification for either canceling or pausing an off-session payment for a mandate of any amount. | |
| Simulates the issuing bank’s failure to send a pre-debit notification to the customer during off-session payment for a mandate of any amount. | |
| Simulates a customer canceling a mandate of any amount. |
Limitations
Keep in mind the following limitations:
- Stripe attempts to automatically create mandates only on Subscriptions created after October 1, 2021. If you have a Subscription created before then, cancel and create a new Subscription to make sure a mandate is created.
- You can’t create a mandate using the Charges and Sources APIs.
- For Subscriptions with a non-INR currency, mandates are only registered if an India payment method is attached to the Customer at the time of subscription creation. If you create a non-INR subscription without a payment method and later add an India card, no mandate is created. To ensure proper mandate creation, attach an India payment method before creating the subscription.
- You can’t pass an existing mandate to a Subscription.
- You can’t cancel or update a mandate.
- UPI currently doesn’t support recurring transactions of greater than 15,000 INR in value.