Skip to article
Degrees of SatoshiFollow the connections.
Degrees of Satoshi/ Encyclopedia

Encyclopedia Bitcoin basics · Entry 178

Bitcoin payment requests and QR codes: what a scan actually tells you

Theme
Bitcoin basics
Sources
3 cited records
Reading time
About 3 minutes
Automated verification
Substantive update
In this article

At a glance

Key facts

Key facts for Bitcoin payment requests and QR codes: what a scan actually tells you
FactDetailSource
Amount unitThe URI amount field uses decimal BTC[1]
AuthorizationA URI must not trigger payment without authorization[1]
IdentityA label is not recipient authentication[1][3]
01

Read the decoded request

A request can provide an on-chain destination, a human-readable label and a message. Modern instructions can also describe a Lightning invoice or offer. The application decides which supported route to present; do not assume every scanned Bitcoin request necessarily means an on-chain payment.

BIP-321 permits a URI without a normal on-chain address when it supplies another payment instruction. A wallet that cannot handle a required feature should not silently make a different payment.

02

A small decimal can still be misread

An illustrative amount of 0.0005 BTC equals 50,000 satoshis. The URI uses decimal BTC even if the wallet screen prefers sats. Its amount must not include a thousands-separating comma. Compare the normalized amount the wallet displays with the invoice you intend to pay.

A label such as a shop name is merely supplied text. A malicious request can carry a convincing name alongside an attacker’s destination.

03

Check both the request and the signing screen

Obtain the request from the intended recipient and inspect its contents after scanning. For a hardware wallet, compare supported transaction details on the device with the intended payment. The device confirms the transaction it will sign, not the truth of the request’s business story.

If a code is unreadable or unsupported, ask for a compatible request. Editing unfamiliar parameters by hand risks changing amount or payment semantics.

Direct answers

Questions people ask

Is a QR code safer than copying an address?

It can reduce typing errors, but the code can still encode a substituted destination or misleading amount. Both methods require you to check the decoded request against an authenticated source.

Does scanning the code send the bitcoin?

Scanning usually imports instructions. BIP-321 requires user authorization before acting on a payment URI; the wallet should let you inspect and approve the payment rather than treating the scan as proof of consent.

Inspect the evidence

The answer and key facts have stable claim links. These records retain the scope and qualification when reused.

A Bitcoin payment QR code is an encoding of text, often a payment URI containing a destination, amount and optional instructions. Scanning helps transfer those fields; it does not prove who created the request or that payment has happened. Review the wallet’s decoded request before approval. BIP-321 updates the older BIP-21 URI scheme, but actual support depends on the wallet.

Educational explanation. Product-specific behavior is scoped to the cited documentation, checked 2026-10-02.

Scope: Bitcoin · data through 2026-10-02. Verification: verified · 2026-10-02T19:29:20.637Z.

Link to this claim
Amount unit: The URI amount field uses decimal BTC

Scope: Bitcoin · data through 2026-10-02. Verification: verified · 2026-10-02T19:29:20.637Z.

Link to this claim
Authorization: A URI must not trigger payment without authorization

Scope: Bitcoin · data through 2026-10-02. Verification: verified · 2026-10-02T19:29:20.637Z.

Link to this claim
Identity: A label is not recipient authentication

Scope: Bitcoin · data through 2026-10-02. Verification: verified · 2026-10-02T19:29:20.637Z.

Link to this claim
Revision history
  1. — First publication after primary-source research and separate automated verification.

On the Send and check a Bitcoin payment path · Learn next: How to send Bitcoin: review the destination, amount and fee

Source register

Sources and references

Retrieval dates and locators are recorded individually.
  1. URI SchemeBitcoin Improvement Proposals

    Successor payment URI scheme and wallet-dependent payment instructions.

    Locator: General rules for handling (important!); General Format; Query Keys; Transfer amount; Forward compatibility; Backward compatibility · Version / scope: Pinned BIPs revision · Retrieved: 2026-10-02T18:53:54.108ZOpen source
  2. URI SchemeBitcoin Improvement Proposals

    Historical Bitcoin payment URI fields, amount units and required-parameter handling.

    Locator: Superseded by BIP 321; Specification; Rationale; Forward compatibility · Version / scope: Pinned BIPs revision · Retrieved: 2026-10-02T18:53:53.954ZOpen source
  3. Trezor’s Trusted DisplayTrezor

    Manufacturer explanation of device display checks and the limits of a host-computer screen.

    Locator: Trusted display article: on-device verification steps and limits of what the device verifies · Retrieved: 2026-10-02T18:53:56.900ZOpen source
How this article was made

Research and drafting use AI assistance. A separate automated review checks claims against primary sources; no external expert or named human review is implied. Publication, substantive editing, source retrieval and verification are recorded separately. This version was independently checked by an automated reviewer on 2 October 2026.

Editorial method and corrections

Degrees of Satoshi editorial project. “Bitcoin payment requests and QR codes: what a scan actually tells you.” Published 2026-10-02; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/bitcoin-payment-requests-qr-codes/