Who does what in an AePS transaction
The Aadhaar Enabled Payment System lets a customer withdraw cash, check a balance or get a mini statement at a business correspondent's counter with their Aadhaar number and biometrics. NPCI runs the network, and every transaction is bank-led.
| Role | Who it is | What it answers for |
|---|---|---|
| Customer's bank | The bank holding the customer's account | Debiting the account, and its own limits |
| Acquiring bank | The bank whose network the counter belongs to | Due diligence of the touchpoint operators in its network |
| BC or aggregator | The company holding the acquiring bank's contract | Onboarding operators and running the channel under the bank's rules |
| Your platform | The software your network uses | Onboarding screens, authentication, wallets, commission and reports |
| Operator | The retailer at the counter | Serving the customer with their own KYC and a registered RD device |
| UIDAI | The Aadhaar authority | Authenticating the customer's biometrics |
A software platform sits between the operator and the acquiring side. It doesn't replace the bank, and the bank's rules decide what the platform must record.
Ways to offer AEPS with Payonclick India
| Route | What it means | Status |
|---|---|---|
| White-label platform | AEPS inside your own branded portal and Android app, connected to your acquiring bank or aggregator contract | Available |
| Custom development | The AEPS module added to your existing software | Scoped per project |
| Payonclick partner AEPS API | Call Payonclick's AEPS from your servers | Not offered |
| Distributor account | Onboard retailers who offer AEPS on the Payonclick app | Available on payonclick.in |
What the AEPS module includes
The module runs AEPS for Payonclick retailers today, on the web portal and in the Android app.
Four transaction types
Cash withdrawal, balance enquiry, mini statement and Aadhaar Pay.
Merchant onboarding
An OTP step, then the merchant's biometric eKYC, with the bank eKYC status tracked separately so you can see exactly where a merchant is stuck.
Daily authentication
Each merchant authenticates biometrically once a day before transacting, tracked per user, per service and per day.
Step-up OTP
A cash withdrawal or Aadhaar Pay above ₹5,000 also needs an OTP sent to the customer's Aadhaar-linked mobile. The OTP travels inside the biometric request, with a 30-second resend cooldown.
Authentication modes
Fingerprint or iris for transactions. Face authentication is accepted only for daily authentication, and the server rejects it for a transaction.
RD device registry
16 registered RD device models, including Mantra, Morpho and Startek devices, from one registry shared by the web portal and the app.
Pending transactions, wallets and reconciliation
- Ledger-backed wallet credit. A successful withdrawal credits the merchant's AEPS wallet, with separate ledger entries for the charge and the commission, each under a unique reference.
- Pending resolution. A transaction without a final answer is resolved through the provider's status API. The update is a compare-and-swap with a unique ledger reference, so two checks can't credit the same withdrawal twice. A manual status check is also available.
- Nightly reconciliation. AEPS, Micro ATM and UPI cash withdrawal transactions go into a reconciliation upload every night.
- Settlement. Merchants move money from the AEPS wallet to the main wallet, or to their verified bank account by IMPS.
Operator due diligence from 1 January 2026
RBI's directions on due diligence of AePS touchpoint operators (RBI/2025-26/63, dated 27 June 2025) apply from 1 January 2026. According to a summary by Mondaq, acquiring banks must:
- complete KYC of every touchpoint operator, including sub-agents
- redo KYC after three consecutive months of inactivity
- make sure the APIs are used only for AePS
- monitor operators by risk, including location, volume and velocity
These duties sit with the acquiring bank, which passes them down to its BCs and their platforms. The module records each merchant's own eKYC and daily authentication, and the Android app asks for location permission for daily authentication. Dormancy re-KYC and velocity monitoring are set to your acquiring bank's requirements during the build.
Every operator must onboard and authenticate with their own Aadhaar. Never let a distributor or a staff member complete eKYC or daily authentication on a retailer's behalf.
Limits you will meet
- Rolling 30-day recommendation. NPCI's circular 087 recommends that banks limit AePS cash withdrawals and Aadhaar Pay together to ₹50,000 over a rolling 30 days. Declines for this reason use response code 61.
- Bank limits. The customer's bank can apply its own, lower limits.
- Step-up authentication. NPCI's AePS circulars page lists a 2026-27 circular on step-up authentication for cash withdrawal and Aadhaar Pay. Industry summaries report an Aadhaar OTP above ₹5,000 with a deadline of 15 July 2026; read the circular itself before you rely on the detail. The module already asks for an OTP above ₹5,000.
Getting started
Line up your AEPS partner
Sign with an acquiring bank or an AEPS aggregator that allows your model, including sub-agents if you plan a network.
Scope the build
We map your partner's onboarding, authentication and reconciliation requirements onto the module.
Build and brand
Your admin panel, retailer portal and Android app, with RD device and biometric integration.
Test and go live
Acceptance testing with your partner's credentials, then admin training and launch.