One standard per country, not one for the region
The first thing to understand is that there is no single Southeast Asian QR code. Each country built its own national standard, usually led by the central bank, and each one works differently in detail. Indonesia's QRIS is owned and regulated by Bank Indonesia, was launched in August 2019 and became mandatory at the end of that year, so any payment service provider offering QR payments there must use it. Thailand's PromptPay is operated under the Bank of Thailand, with Thai QR Payment as the merchant-facing QR service. Malaysia's DuitNow QR is run by PayNet. Vietnam has VietQR, and Singapore consolidated a large number of competing stickers into a common scheme. For a merchant selling into several of these markets, that means several integrations, which is exactly why most cross-border merchants go through a provider rather than direct to each scheme.
- Expect one national standard per market rather than a single regional QR code.
- Go through a provider or acquirer rather than integrating each national scheme yourself.
- Check whether the standard is mandatory, because in some markets it is the only compliant option.
- Treat wallet brand names and national QR standards as two different layers of the same stack.
QRIS: how Indonesia made a single code work for every wallet
Before QRIS, a merchant in Indonesia might display five stickers, one per wallet, and a customer could only pay with the wallet that matched the sticker. QRIS inverted that. Any licensed payment service provider, whether a bank or an e-money operator such as DANA, OVO, GoPay, ShopeePay or LinkAja, can scan any QRIS code, so a merchant needs one code and one account. The standard was developed with the industry, is based on international EMVCo specifications, and participating providers and switching institutions must be approved by Bank Indonesia. There are two merchant-presented variants. A static code is printed, contains no amount, and the customer types the amount themselves, which suits micro and small merchants. A dynamic code is generated by a device or system for a specific transaction, contains the amount, and suits higher-volume merchants. There is also a consumer-presented mode where the customer shows a barcode and the merchant scans it, used where speed matters.
- One QRIS code reaches every participating wallet and bank app, so you do not need one sticker per wallet.
- Use static codes for fixed-amount or counter service, and dynamic codes for anything with a computed total.
- Open the merchant account with a Bank Indonesia licensed provider rather than with a wallet directly.
- Check whether your provider supports online display of a QRIS code, not only printed stickers.
PromptPay, Thai QR Payment and MyPromptQR
Thailand's PromptPay is the account-to-account rail operated under the Bank of Thailand, and it lets a payer send money using a simple identifier such as a phone number or national ID rather than an account number. On top of it sits Thai QR Payment, the QR service that lets a customer scan with a mobile banking app, and MyPromptQR, a customer-presented variant built on the ISO 20022 standard that carries business data with the payment and suits larger merchants. One practical difference from Indonesia: because PromptPay is account-to-account, the money lands in a bank account rather than in a wallet balance. For a merchant, the integration question is whether your provider gives you dynamic QR generation with a reference you can reconcile against, because a plain static QR tells you money arrived but not which order it belongs to.
- Ask your provider for dynamic QR generation with an order reference, not just a static code.
- Remember PromptPay settles to a bank account, which affects where and how you reconcile.
- Consider MyPromptQR if you need to carry invoice or order data with the payment.
- Check the availability of wallet brands alongside PromptPay, since Thai shoppers use both.
VietQR, DuitNow QR and what Singapore does instead
Vietnam's VietQR is the national QR standard, built to be interoperable across banks and wallets, and it is the layer that connects Vietnamese banks to cross-border linkages. In Malaysia, DuitNow QR is operated by PayNet and lets a customer pay from any participating bank or e-wallet by scanning one code, with the merchant signing up through a bank or acquirer rather than directly. PayNet also runs a separate online banking and wallets channel for web checkout, which is the product most e-commerce merchants actually integrate. Singapore took a different path: rather than one national account-to-account QR for everything, it consolidated many competing QR stickers into a common scheme and layered instant bank transfer on top, so cards, wallets and bank transfer all sit side by side at checkout. In practice that means a Singapore checkout is usually multi-method, while an Indonesian one can often lead with a single QRIS code.
- In Malaysia, integrate the online banking and wallets channel for web checkout rather than only printed QR.
- In Vietnam, treat VietQR as the bank layer and MoMo or ZaloPay as the wallet layer.
- In Singapore, expect to offer cards and bank transfer alongside QR rather than leading with QR alone.
- Confirm settlement timing per scheme, because they do not all credit merchants on the same cycle.
Static vs dynamic QR, and why online checkout needs dynamic
The distinction sounds technical and is actually commercial. A static QR is fixed, usually printed, and carries no amount; the customer enters the amount, confirms, and both parties get a notification. It is cheap, works without a terminal, and is ideal for a market stall or a fixed-price service. But it cannot tell you which order a payment belongs to, it cannot expire, and it invites the wrong amount. A dynamic QR is generated per transaction, carries the amount and usually a reference, and can expire. For any online checkout, and for any business where orders must be matched to payments automatically, dynamic is not a nice-to-have, it is the requirement. This is also where reconciliation begins: the reference you put into the dynamic QR is the key your finance team will match against the settlement report, so make sure your provider returns it in both the notification and the report.
- Use dynamic QR for every online checkout, because static codes cannot carry an order reference.
- Set an expiry on dynamic codes so abandoned carts do not leave payable codes floating.
- Put a meaningful order reference into the QR and confirm it comes back in the settlement report.
- Keep static codes for fixed-price counter service where reconciliation is manual and volumes are small.
Reconciliation and the arrival of cross-border QR
Reconciling QR payments means matching a notification, an order and a settlement line. Insist that your provider gives you all three with a common reference, and check that the settlement report includes the scheme reference, the amount, the collection or confirmation date and the fee. Then automate the match and route only exceptions to a person. The second thing to plan for is that these standards are starting to talk to each other. The Bank of Thailand has built cross-border QR linkages with Malaysia, Vietnam, Indonesia, Cambodia, Singapore and others under the ASEAN payment connectivity agenda, so a visitor can scan a local code with their home banking app, with settlement handled through appointed dealers in local currency. Depending on the corridor, an existing domestic code can already accept a foreign wallet. Ask your provider which inbound corridors are live, because it is incremental revenue you may already be able to take.
- Require the scheme reference in the webhook, the admin panel and the settlement report.
- Automate three-way matching between order, notification and settlement line, and review exceptions daily.
- Ask which inbound cross-border QR corridors are live for your market, since your existing code may already accept them.
- Reconcile on the scheme's confirmation schedule, not on your card-settlement habit.
Questions merchants ask
Is QRIS a wallet?
No. QRIS is Indonesia's national QR standard, owned and regulated by Bank Indonesia. Wallets such as DANA, OVO, GoPay and ShopeePay, and mobile banking apps, all read the same code. That is why a merchant only needs one QRIS code instead of one sticker per wallet. The practical benefit is that one code replaces the pile of wallet stickers a merchant used to display.
What is the difference between a static and a dynamic QR code?
A static code is printed, carries no amount, and the customer types the amount, which suits small fixed-price merchants. A dynamic code is generated for one transaction, carries the amount and usually a reference, and can expire. Any online checkout needs dynamic codes so payments can be matched to orders. Choose dynamic whenever orders must be matched to payments without a person reading a bank statement.
Do I need to integrate every wallet in Indonesia?
No. Because QRIS is mandatory and interoperable, a single code issued through a licensed provider can be scanned by any participating wallet or bank app. If you want wallet-specific features such as in-app payments or promotions, you integrate those separately, but basic acceptance needs one code. Integrate wallets directly only when you need in-app payments, promotions or wallet-specific features.
Can a foreign merchant get a QRIS or DuitNow QR code?
Usually yes, through a provider or acquirer that is licensed in that market and willing to board a foreign-registered entity, rather than by contracting with the scheme operator directly. Confirm eligibility for your registration country and your product category, and check which legal entity will contract with you and which one will settle the money to you.
Can one QR code accept payments from foreign tourists?
Increasingly yes, depending on the corridor. Several central banks in the region have linked their national QR systems, so a visitor can scan a local code with their home banking app and settlement is handled in local currency. Ask your provider which inbound corridors are live for your market. Coverage changes as central banks add corridors, so re-check with your provider twice a year.
How do I reconcile QR payments against orders?
Use a common reference. Put an order reference into a dynamic QR, make sure the provider returns it in both the payment notification and the settlement report, then automate three-way matching between order, notification and settlement line. Only amount mismatches and late payments should need a person. Reconcile on the scheme's confirmation schedule rather than on the rhythm you use for card settlements.