Request to Pay: How Open Banking's Pull Payment Model Challenges Card Networks
Request to Pay lets merchants send payment requests directly to customer banks. How this pull payment model threatens card dominance.
Every card payment begins with a merchant pulling funds from a customer's account through a chain of intermediaries: acquirer, card network, issuer. The customer never explicitly authorizes each transaction in real time. Request to Pay (RtP) inverts this model. The merchant sends a structured payment request directly to the customer's bank, the customer reviews it and authorizes payment from their own banking app, and funds move instantly via account-to-account rails. No card network in the middle. No interchange fee. No chargeback window.
RtP is not a payment method. It is a messaging layer that triggers a payment. That distinction matters: it means RtP can sit on top of any instant payment system, from the UK's Faster Payments to SEPA Instant Credit Transfer to Brazil's PIX. And it is starting to gain traction at exactly the moment when merchants are looking for alternatives to card fees that average 2.36% per credit transaction.
How Request to Pay Works
A Request to Pay flow has four steps. First, the merchant (or biller) creates a payment request containing the amount, reference, and due date. Second, the request is routed through an RtP service provider to the customer's bank. Third, the customer receives a notification in their banking app, reviews the details, and either approves, declines, or requests a modification. Fourth, upon approval, the customer's bank initiates a push payment to the merchant's account via the underlying real-time payment rail.
The critical difference from card payments: the customer's bank initiates the fund transfer, not the merchant. This is a push payment triggered by a pull request. The merchant asks; the customer decides. Contrast this with a direct debit, where the merchant pulls funds from the customer's account based on a standing mandate, or a card payment, where the merchant submits an authorization request through the card network.
Push vs. pull vs. request: A wire transfer is a pure push (payer initiates). A card payment is a pure pull (merchant initiates via acquirer). Request to Pay is a hybrid: the payee initiates the request, but the payer authorizes the actual fund movement. This gives merchants the convenience of initiating while giving consumers explicit control.
RtP Implementations Around the World
UK: Pay.UK Request to Pay
Pay.UK developed the UK's Request to Pay framework with input from over 400 organizations. The framework launched in May 2020, with Mastercard becoming the first enrolled RtP Service Provider in July 2020. It operates as a messaging overlay on top of the Faster Payments system, meaning it does not move money itself but triggers instant payments through existing rails.
The UK framework is intentionally flexible: customers can pay the full amount, request to pay a partial amount, ask for more time, decline the request, or communicate directly with the biller. This flexibility makes it attractive as a direct debit alternative for recurring bills. A 2023 industry survey found that 87% of leading global banks view RtP as a viable alternative to direct debits, and 71% expect it to reduce merchant dependency on payment cards.
Broader adoption signals are encouraging: the UK's open banking ecosystem surpassed 16.5 million user connections by December 2025 (up 36% year-over-year), and open banking payments grew 53%, reaching 7.9% of all Faster Payments volume.
Europe: SEPA Request to Pay
The European Payments Council (EPC) has developed the SEPA Request to Pay (SRTP) scheme, with the first rulebook published in November 2020 and the scheme going live in June 2021. Version 4.0 of the SRTP rulebook entered into force on 5 October 2025, focusing on simplifying entry barriers and stabilizing the scheme. Homologation waves for participants are running through 2026, with Spain and Italy confirming their intention to launch SRTP services for public administration.
Adoption remains early: by late 2024, only three applicants had been successfully homologated and listed in the EPC's Register of Participants. The EPC Directory Service is scheduled to open to SRTP scheme participants at the end of September 2026, enabling cross-border request-to-pay messaging across the 36-country SEPA zone. When combined with SEPA Instant Credit Transfer, the full cycle from request to settlement can complete in under 10 seconds.
India: UPI Collect Requests
India's Unified Payments Interface implemented the request-to-pay concept through its "collect request" feature from launch in 2016. A merchant or individual could send a collect request to any UPI ID (Virtual Payment Address), and the recipient would review and authorize payment by entering their UPI PIN. UPI processed over 241 billion transactions in FY 2025-26, with a value exceeding $3.7 trillion, making it the world's largest real-time payment platform.
However, collect requests also became a vector for social engineering fraud: attackers sent fake collect requests impersonating legitimate businesses. In February 2026, NPCI mandated the Intent flow (QR scan or deep link) as the default for mobile-native transactions, restricting manual VPA-based collect requests. Collect survives for desktop web, IPO applications, and verified merchant use cases. This highlights a key challenge: when anyone can send a payment request, authentication and trust become critical.
Brazil: PIX Cobrança
Brazil's PIX instant payment system implements request-to-pay through Cobrança (Portuguese for "charge"). Merchants generate dynamic QR codes containing payment amount, description, and expiration date. Customers scan and authorize payment from their banking app. PIX processed nearly 80 billion transactions in 2025 and commands roughly 40% of Brazil's e-commerce payment volume, with projections reaching 51% by 2027.
In June 2025, the Central Bank of Brazil launched PIX Automático, enabling recurring authorized payments: subscriptions, utility bills, and rent payments triggered automatically based on prior customer authorization. Active enrollments grew at an average 177% per month in the first year. This directly competes with card-on-file recurring payments and traditional direct debits.
RtP Implementations Compared
| System | Region | Launch | Settlement Rail | Status (2026) |
|---|---|---|---|---|
| Pay.UK RtP | United Kingdom | 2020 | Faster Payments | Live, growing adoption |
| SEPA RtP (SRTP) | 36 SEPA countries | 2021 | SEPA Instant Credit Transfer | Onboarding participants |
| UPI Collect | India | 2016 | UPI / IMPS | Restricted to verified merchants |
| PIX Cobrança | Brazil | 2020 | PIX (BCB) | Widely adopted |
| PayTo | Australia | 2022 | New Payments Platform | Live, bank rollout ongoing |
The Merchant Value Proposition
For merchants, the economics of Request to Pay are compelling. Card payments carry layered fees: interchange (paid to issuer), scheme fees (paid to Visa or Mastercard), and acquirer processing fees. Combined, these average 1.79% plus $0.08 per in-person transaction and 2.31% plus $0.25 per online transaction in the US. For a business processing $10 million annually in card payments, that translates to $179,000 to $231,000 in fees.
Account-to-account payments via RtP eliminate the interchange layer entirely. The underlying real-time payment rails typically cost a flat fee per transaction: ACH in the US runs $0.25 to $1.00 per transaction regardless of amount. FedNow charges $0.045 per credit transfer. The US RTP network charges just $0.01 per Request for Payment message. The UK's Faster Payments costs banks roughly £0.05 per transaction. For high-value transactions, the savings are dramatic: on a $5,000 invoice, a merchant saves over $85 compared to card processing.
Fee Comparison: Cards vs. A2A vs. RtP
| Payment Method | Merchant Cost (typical) | Settlement Speed | Chargeback Risk |
|---|---|---|---|
| Visa/Mastercard credit | 1.5% to 3.5% + per-txn fee | T+1 to T+2 | Yes (up to 120 days) |
| Visa/Mastercard debit | 0.5% to 1.5% + per-txn fee | T+1 to T+2 | Yes |
| ACH (US) | $0.25 to $1.00 flat | Same-day or T+1 | Limited (60-day window) |
| FedNow (US) | $0.045 per credit transfer | Instant | No (irrevocable) |
| Faster Payments (UK) | ~£0.05 flat | Instant | No (irrevocable) |
| SEPA Instant (EU) | €0.002 to €0.20 flat | Instant (under 10s) | No (irrevocable) |
| PIX (Brazil) | Free for individuals, ~0.22% for merchants | Instant | No (irrevocable) |
| UPI (India) | Free (zero MDR) | Instant | No (irrevocable) |
No chargebacks is a feature, not a bug: A2A payments settled via RtP are irrevocable: the customer explicitly authorized the payment from their bank. This eliminates chargeback fraud and the associated dispute costs that burden merchants globally. But it also means consumers lose the buyer-protection guarantees they get with card payments, which creates a significant adoption barrier.
Why Consumer Adoption Remains Difficult
Despite clear merchant benefits, consumer adoption of RtP-based payments faces structural headwinds. These are not technical problems: they are incentive problems.
- Rewards programs: credit cards offer 1% to 5% cashback or points. A2A payments offer nothing. For consumers, switching means paying more for the same purchase.
- Buyer protection: card networks provide dispute resolution and fraud liability limits. RtP payments, once authorized, are final. Consumers bear the risk of authorized push payment (APP) fraud.
- UX unfamiliarity: a survey of UK consumers found that familiarity with the term "Pay by Bank" fell from 55% to 38% between 2024 and 2025, even as open banking payment volumes grew 53% year-over-year. The product is growing, but consumers do not recognize it.
- Credit access: card payments offer float and installment plans. RtP debits the account immediately. For consumers who rely on credit lines, instant payment is less attractive.
- Trust deficit: UPI's experience with collect-request fraud shows that when anyone can send a payment request, social engineering attacks follow. Building verified-sender infrastructure is essential but slow.
The willingness-usage gap is striking: 46% of US consumers say they are willing to use open banking for at least one purchase type, but only 11% have actually done so. A2A represents roughly 2% of all UK transaction value for consumer purchases and about 7% of UK e-commerce. Card and digital wallet satisfaction scores remain 50% to 100% higher than A2A payment scores.
Bank readiness is another constraint. UK banks earn approximately 10% of personal current account revenue from interchange; digital banks like Revolut and Monzo derive over 30%. An estimated £1 billion in UK interchange revenue is at stake if A2A displaces cards significantly. Few banks have launched RtP services, and the feature does not yet appear on the short-term roadmaps of many institutions.
How Card Networks Are Responding
Visa and Mastercard are not ignoring the threat. Their strategy: if you cannot beat A2A, own the infrastructure.
Visa acquired Tink, a Swedish open banking platform connected to over 3,400 banks, for €1.8 billion ($2.15 billion) in 2021. In June 2025, Visa launched Visa A2A in the UK, using open banking rails through Pay.UK's Faster Payments. The play: offer scheme-like dispute protections and biometric authentication on top of A2A rails, making "Pay by Bank" feel as safe as a card payment to consumers. Initial partners include Nationwide, TSB, and Checkout.com.
Mastercard acquired Finicity for $825 million in 2020 and Aiia in Europe in 2021, building open banking capabilities across both US and European markets. Mastercard has since partnered with JPMorgan Chase and Worldpay in the US to scale A2A, positioning itself as a trust and security layer for bank-to-bank payments.
In 2025, more than 75% of payment executives globally identified debit and prepaid cards as the products most exposed to disruption from A2A payments. The consumer A2A payments market is projected to grow from $1.7 trillion in 2024 to $5.7 trillion by 2029, according to Juniper Research. Card networks know that inserting themselves into A2A flows, even at lower margins, is better than being disintermediated entirely.
The Visa retreat: In August 2025, Visa exited US open banking entirely, driven by regulatory reversal at the CFPB and rising costs as large banks began charging fintechs for data access. Visa is now concentrating its A2A and open banking investments in Europe and Latin America, where regulatory frameworks are more favorable.
Payment Requests in Crypto: BIP-70 and BOLT12
The concept of a payee-initiated payment request is not unique to open banking. Bitcoin has experimented with similar models, with mixed results.
BIP-70: The First Attempt
BIP-70, proposed by Gavin Andresen and Mike Hearn in 2013, defined a Payment Protocol where merchants could send signed payment requests to customers. The three-step flow worked like this: a customer clicked a BIP-21 URI containing an r parameter, the wallet fetched signed payment details from the merchant via SSL, and the transaction was sent with the merchant acknowledging receipt. The request contained a destination address, amount, memo, and an X.509 certificate proving the merchant's identity.
BIP-70 failed. Its reliance on X.509 certificates (the same PKI infrastructure used by HTTPS) created complexity and centralization concerns. The 2014 Heartbleed vulnerability exposed the risks of pulling OpenSSL into wallet software. Bitcoin Core allowed building without BIP-70 in 2018, disabled it by default in v0.19.0, and fully removed it shortly after. Almost all wallets and merchants that once supported it have since dropped it.
BOLT12 Offers: A Better Model
BOLT12 offers, proposed by Rusty Russell in 2019 and officially merged into the Lightning specification in September 2024, represent a fundamentally different approach to payment requests on the Lightning Network. An offer is a static, reusable identifier that a merchant publishes. When a customer wants to pay, their wallet sends an invoice_request message to the merchant via onion-routed messages. The merchant responds with a specific Lightning invoice, and the customer pays it.
This mirrors the RtP flow: the payee publishes an identifier, the payer requests details, and then authorizes payment. Unlike BIP-70, BOLT12 does not rely on external certificate authorities. Identity verification happens through the Lightning Network itself, using blinded paths for receiver privacy. BOLT12 is implemented in Core Lightning, LDK, and Eclair, with broader adoption progressing across wallets like Phoenix, Strike, and Alby Hub.
Crypto-Native Payment Requests and Spark
The request-to-pay model maps naturally to self-custodial crypto wallets. When a merchant sends a payment request to a customer's wallet, the customer reviews the amount and recipient, then authorizes a transfer from their own keys. No intermediary pulls funds. No card network sits between buyer and seller. The payment is final the moment the customer signs.
Spark implements this pattern natively. A merchant or service provider can generate a payment request, the customer's Spark wallet displays the details, and the customer authorizes an instant transfer. Settlement is immediate, fees are minimal, and the customer retains self-custody throughout. Unlike traditional RtP implementations that depend on bank participation and regulatory mandates, Spark's payment requests work across any wallet that supports the protocol, with no geographic restrictions or scheme enrollment required.
For developers exploring how request-to-pay flows work in a self-custodial context, the Spark SDK documentation covers payment request creation and wallet integration. Wallets like General Bread demonstrate how this model works for end users: merchants request payment, customers approve from their self-custodial wallet, and settlement happens instantly on Spark.
What Comes Next for Request to Pay
The trajectory is clear: RtP will grow, but slowly, and card networks will not disappear. Several dynamics will shape the next few years.
Regulatory mandates are accelerating infrastructure. The EU's Instant Payments Regulation, effective October 2025, requires all eurozone banks to support instant credit transfers. This creates the settlement layer that SRTP needs to function at scale. Similarly, the UK's UK Payments Initiative, announced in June 2026, pushes banks toward standardized open banking payment flows and commercial variable recurring payments.
Variable Recurring Payments (VRP), a form of authorized recurring A2A payment, are launching commercially in the UK through 2025-2026. VRPs combine the convenience of direct debit (automatic recurring charges) with the consumer control of RtP (explicit authorization with spend limits). This may be the wedge that drives mainstream A2A adoption for subscriptions and utilities.
Cross-border interoperability remains the open frontier. Today, most RtP systems are domestic. International PIX, expected in 2027, aims to connect Brazil's instant payment system with other countries. The EPC's SRTP scheme covers the SEPA zone but does not extend beyond it. Crypto payment protocols like BOLT12 and Spark are borderless by default, which gives them an advantage for international commerce that traditional RtP schemes will take years to match.
For a deeper look at how account-to-account payments are reshaping the broader payments landscape, see our research on the A2A payments revolution and our overview of real-time payment systems worldwide.
This article is for educational purposes only. It does not constitute financial or investment advice. Payment systems and protocols involve regulatory, technical, and financial considerations. Always do your own research and understand the tradeoffs before adopting any payment method.

