# Bitcoin payment requests and QR codes: what a scan actually tells you

A Bitcoin payment QR code is an encoding of text, often a payment URI containing a destination, amount and optional instructions. Scanning helps transfer those fields; it does not prove who created the request or that payment has happened. Review the wallet’s decoded request before approval. BIP-321 updates the older BIP-21 URI scheme, but actual support depends on the wallet.

Evidence: [URI Scheme](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0321.mediawiki); [URI Scheme](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0021.mediawiki); [Trezor’s Trusted Display](https://trezor.io/guides/trezor-devices/trezor-fundamentals/trezor-s-trusted-display-verify-every-address-on-your-device)

Canonical: https://degreesofsatoshi.com/encyclopedia/bitcoin-payment-requests-qr-codes/
Published: 2026-10-02
Substantively modified: 2026-10-02
Independently verified by an automated reviewer: 2026-10-02T19:29:20.637Z
Data current through: 2026-10-02

AI-assisted research and drafting with a separate automated source-verification pass; no external expert or named human review is implied.

## Key facts

- **Amount unit:** The URI amount field uses decimal BTC ([URI Scheme](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0321.mediawiki))
- **Authorization:** A URI must not trigger payment without authorization ([URI Scheme](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0321.mediawiki))
- **Identity:** A label is not recipient authentication ([URI Scheme](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0321.mediawiki); [Trezor’s Trusted Display](https://trezor.io/guides/trezor-devices/trezor-fundamentals/trezor-s-trusted-display-verify-every-address-on-your-device))

## Read the decoded request

A request can provide an on-chain destination, a human-readable label and a message. Modern instructions can also describe a Lightning invoice or offer. The application decides which supported route to present; do not assume every scanned Bitcoin request necessarily means an on-chain payment.

BIP-321 permits a URI without a normal on-chain address when it supplies another payment instruction. A wallet that cannot handle a required feature should not silently make a different payment.

Evidence: [URI Scheme](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0321.mediawiki)

## A small decimal can still be misread

An illustrative amount of 0.0005 BTC equals 50,000 satoshis. The URI uses decimal BTC even if the wallet screen prefers sats. Its amount must not include a thousands-separating comma. Compare the normalized amount the wallet displays with the invoice you intend to pay.

A label such as a shop name is merely supplied text. A malicious request can carry a convincing name alongside an attacker’s destination.

Evidence: [URI Scheme](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0321.mediawiki)

## Check both the request and the signing screen

Obtain the request from the intended recipient and inspect its contents after scanning. For a hardware wallet, compare supported transaction details on the device with the intended payment. The device confirms the transaction it will sign, not the truth of the request’s business story.

If a code is unreadable or unsupported, ask for a compatible request. Editing unfamiliar parameters by hand risks changing amount or payment semantics.

Evidence: [URI Scheme](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0321.mediawiki); [Trezor’s Trusted Display](https://trezor.io/guides/trezor-devices/trezor-fundamentals/trezor-s-trusted-display-verify-every-address-on-your-device)

## Questions

### Is a QR code safer than copying an address?

It can reduce typing errors, but the code can still encode a substituted destination or misleading amount. Both methods require you to check the decoded request against an authenticated source.

Evidence: [URI Scheme](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0321.mediawiki); [Trezor’s Trusted Display](https://trezor.io/guides/trezor-devices/trezor-fundamentals/trezor-s-trusted-display-verify-every-address-on-your-device)

### Does scanning the code send the bitcoin?

Scanning usually imports instructions. BIP-321 requires user authorization before acting on a payment URI; the wallet should let you inspect and approve the payment rather than treating the scan as proof of consent.

Evidence: [URI Scheme](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0321.mediawiki)

## Claims and scope

### bitcoin-payment-requests-qr-codes-quick-answer

A Bitcoin payment QR code is an encoding of text, often a payment URI containing a destination, amount and optional instructions. Scanning helps transfer those fields; it does not prove who created the request or that payment has happened. Review the wallet’s decoded request before approval. BIP-321 updates the older BIP-21 URI scheme, but actual support depends on the wallet.

Educational explanation. Product-specific behavior is scoped to the cited documentation, checked 2026-10-02.

Scope: {"collection":"bitcoin","dataAsOf":"2026-10-02","blockHeight":null}

### bitcoin-payment-requests-qr-codes-fact-amount-unit

Amount unit: The URI amount field uses decimal BTC

Scope: {"collection":"bitcoin","dataAsOf":"2026-10-02","blockHeight":null}

### bitcoin-payment-requests-qr-codes-fact-authorization

Authorization: A URI must not trigger payment without authorization

Scope: {"collection":"bitcoin","dataAsOf":"2026-10-02","blockHeight":null}

### bitcoin-payment-requests-qr-codes-fact-identity

Identity: A label is not recipient authentication

Scope: {"collection":"bitcoin","dataAsOf":"2026-10-02","blockHeight":null}

## Sources

- [URI Scheme](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0321.mediawiki) — Bitcoin Improvement Proposals. Successor payment URI scheme and wallet-dependent payment instructions. Locator: General rules for handling (important!); General Format; Query Keys; Transfer amount; Forward compatibility; Backward compatibility. Retrieved: 2026-10-02T18:53:54.108Z.
- [URI Scheme](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0021.mediawiki) — Bitcoin Improvement Proposals. Historical Bitcoin payment URI fields, amount units and required-parameter handling. Locator: Superseded by BIP 321; Specification; Rationale; Forward compatibility. Retrieved: 2026-10-02T18:53:53.954Z.
- [Trezor’s Trusted Display](https://trezor.io/guides/trezor-devices/trezor-fundamentals/trezor-s-trusted-display-verify-every-address-on-your-device) — Trezor. Manufacturer explanation of device display checks and the limits of a host-computer screen. Locator: Trusted display article: on-device verification steps and limits of what the device verifies. Retrieved: 2026-10-02T18:53:56.900Z.

## Revision history

- 2026-10-02: First publication after primary-source research and separate automated verification.

## Cite this entry

Degrees of Satoshi editorial project. “Bitcoin payment requests and QR codes: what a scan actually tells you.” Published 2026-10-02; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/bitcoin-payment-requests-qr-codes/
