upi-auto-verify
v1.0.0
Published
Instant UPI payment verification via Gmail IMAP — auto-detect payments, generate QR codes, prevent replay attacks. Works with FamPay, GPay, PhonePe, Paytm & any UPI app.
Maintainers
Readme
upi-auto-verify
The #1 Node.js package for instant UPI payment verification via Gmail. Auto-detect payments from FamPay, Google Pay (GPay), PhonePe, Paytm and any UPI app — no manual UTR entry needed.
Why upi-auto-verify?
Building a payment gateway, Telegram bot, Discord bot, e-commerce site, or SaaS platform in India? You need a reliable way to verify UPI payments in real-time. upi-auto-verify connects to your Gmail inbox via IMAP and automatically:
- ✅ Detects incoming UPI payments by amount (e.g. ₹25.01 unique decimal)
- ✅ Extracts UTR / Transaction ID from payment confirmation emails
- ✅ Prevents replay attacks with built-in duplicate detection
- ✅ Generates UPI QR codes with custom amounts and UPI IDs
- ✅ Works with any UPI app — FamPay, GPay, PhonePe, Paytm, BHIM, etc.
- ✅ Database-optional — use Supabase auto-logging or bring your own MongoDB/Postgres/MySQL
Features
| Feature | Description | |---|---| | 🔍 Dynamic Amount Verification | Match payments by unique decimal amounts (e.g. ₹25.01) — no UTR needed | | 🔢 Manual UTR/TxnID Verification | Fallback to verify with 12-digit UPI reference number | | ⏱️ 15-Minute Expiry Check | Auto-ignores old emails to prevent stale payment claims | | 🛡️ Replay Attack Protection | Built-in Supabase logging prevents double-verification | | 📱 QR Code Generator | Generate UPI payment QR codes as base64 images | | 🗄️ Database Flexible | Works with MongoDB, PostgreSQL, MySQL, SQLite, Supabase, or no DB at all | | 🤖 Bot Friendly | Perfect for Telegram bots, Discord bots, WhatsApp bots | | 🌐 Universal | Works in any Node.js environment — Express, Fastify, Next.js, CLI tools |
Installation
npm install upi-auto-verifyyarn add upi-auto-verifypnpm add upi-auto-verifyQuick Start
1. Generate a UPI QR Code
import { IflexVaultVerifier } from 'upi-auto-verify';
const verifier = new IflexVaultVerifier({
gmail: '[email protected]',
gmailAppPassword: 'your_16_char_app_password'
});
// Generate UPI QR Code and Payment Link
const qr = await verifier.generateQr({
upiId: 'iflexvault@fam',
amount: '25.01',
name: 'iFlexVault Store'
});
console.log(qr.qr_image); // Base64 image → embed in <img src="..." />
console.log(qr.upi_uri); // upi://pay?pa=iflexvault@fam&pn=...
console.log(qr.upi_id); // iflexvault@fam
console.log(qr.amount); // 25.012. Verify a UPI Payment (Database-Free)
// Automatically searches Gmail for a ₹25.01 payment in the last 15 minutes
const result = await verifier.verifyPayment({
amount: '25.01'
});
if (result.verified) {
console.log(`✅ Payment verified! ₹${result.amount} from ${result.sender_name}`);
console.log(`UTR: ${result.utr}`);
console.log(`Time: ${result.payment_time_ist}`);
} else {
console.log(`❌ ${result.message}: ${result.details}`);
}3. Verify with UTR Number (Manual Fallback)
const result = await verifier.verifyPayment({
amount: '25.01',
utr: '123456789012' // 12-digit UPI reference number
});4. Verify with Supabase Auto-Logging
const verifier = new IflexVaultVerifier({
gmail: '[email protected]',
gmailAppPassword: 'your_app_password',
supabaseUrl: 'https://your-project.supabase.co',
supabaseServiceRoleKey: 'your-service-role-key'
});
// Now every verification is logged & duplicate UTRs are blocked automatically
const result = await verifier.verifyPayment({ amount: '25.01' });How It Works
- You call
verifyPayment({ amount })with a unique decimal amount (e.g. ₹25.01) - The package connects to Gmail via secure IMAP (TLS encrypted)
- Searches your inbox for emails containing the amount
- Parses UPI confirmation emails from any bank/UPI app
- Extracts sender name, UTR number, transaction ID, and timestamp
- Returns a structured result — verified or not, with full details
- (Optional) Logs everything to Supabase and blocks duplicate UTRs
Use Cases
Telegram Bot Payment Verification
import { IflexVaultVerifier } from 'upi-auto-verify';
const verifier = new IflexVaultVerifier({
gmail: process.env.GMAIL,
gmailAppPassword: process.env.GMAIL_APP_PASSWORD
});
// In your Telegram bot handler
bot.on('payment', async (ctx) => {
const amount = ctx.message.text; // e.g. "25.01"
const result = await verifier.verifyPayment({ amount });
if (result.verified) {
ctx.reply(`✅ Payment of ₹${result.amount} verified from ${result.sender_name}`);
} else {
ctx.reply(`❌ Payment not found. Please try again.`);
}
});Express.js API Endpoint
import express from 'express';
import { IflexVaultVerifier } from 'upi-auto-verify';
const app = express();
const verifier = new IflexVaultVerifier({
gmail: process.env.GMAIL,
gmailAppPassword: process.env.GMAIL_APP_PASSWORD
});
app.post('/api/verify-payment', async (req, res) => {
const { amount, utr } = req.body;
const result = await verifier.verifyPayment({ amount, utr });
res.json(result);
});
app.listen(3000);Discord Bot Integration
import { IflexVaultVerifier } from 'upi-auto-verify';
const verifier = new IflexVaultVerifier({
gmail: process.env.GMAIL,
gmailAppPassword: process.env.GMAIL_APP_PASSWORD
});
// After user sends payment screenshot
async function verifyDiscordPayment(amount) {
const result = await verifier.verifyPayment({ amount });
if (result.verified) {
return `✅ Verified: ₹${result.amount} from ${result.sender_name} (UTR: ${result.utr})`;
}
return `❌ Payment not found in inbox`;
}API Reference
IflexVaultVerifier(config)
| Parameter | Type | Required | Description |
|---|---|---|---|
| gmail | string | ✅ | Your Gmail address |
| gmailAppPassword | string | ✅ | 16-character Gmail App Password (no spaces) |
| supabaseUrl | string | ❌ | Supabase project URL for auto-logging |
| supabaseServiceRoleKey | string | ❌ | Supabase service role key |
verifier.generateQr(params)
| Parameter | Type | Required | Description |
|---|---|---|---|
| upiId | string | ✅ | UPI VPA (e.g. iflexvault@fam) |
| amount | number \| string | ✅ | Payment amount |
| name | string | ✅ | Merchant / receiver name |
| userId | string | ❌ | User ID for Supabase logging |
Returns: { qr_image, upi_uri, upi_id, amount, name, created_at_ist }
verifier.verifyPayment(params)
| Parameter | Type | Required | Description |
|---|---|---|---|
| amount | number \| string | ✅ | Expected payment amount |
| utr | string | ❌ | 12-digit UPI Reference Number |
| txnid | string | ❌ | Transaction ID |
| userId | string | ❌ | User ID for Supabase logging |
Returns:
{
verified: boolean;
transaction_id?: string;
amount?: number;
utr?: string | null;
sender_name?: string;
payment_time_ist?: string;
message?: string;
details?: string;
}How to Get Gmail App Password
For security, Google requires an App Password (not your regular password) for IMAP access:
- Go to Google Account Settings
- Navigate to Security → Enable 2-Step Verification
- Search "App passwords" in the search bar
- Create a new App Password (name it "UPI Auto Verify")
- Copy the 16-character code (remove spaces) and use it in your config
⚠️ Never commit your App Password to Git! Use environment variables or a
.envfile.
Database Setup (Optional)
If you want replay attack protection and transaction logging, connect Supabase:
- Create a free account at supabase.com
- Create a new project
- Create an
api_logstable:
CREATE TABLE api_logs (
id UUID DEFAULT gen_random_uuid() PRIMARY KEY,
user_id TEXT,
endpoint TEXT,
status INTEGER,
utr TEXT,
txn_id TEXT,
amount NUMERIC,
created_at TIMESTAMPTZ DEFAULT NOW()
);- Get your Project URL and Service Role Key from Settings → API
- Pass them to the constructor
Supported UPI Apps
This package works with all UPI apps that send email confirmations:
| UPI App | Supported | |---|---| | FamPay | ✅ | | Google Pay (GPay) | ✅ | | PhonePe | ✅ | | Paytm | ✅ | | BHIM | ✅ | | Amazon Pay | ✅ | | WhatsApp Pay | ✅ | | Any bank UPI | ✅ |
FAQ
Q: Does this work without Supabase? A: Yes! Supabase is completely optional. You can use it with any database (MongoDB, Postgres, MySQL) or no database at all.
Q: Which Gmail accounts are supported? A: Any Gmail account with IMAP enabled and an App Password created.
Q: Is it secure? A: Yes. All connections use TLS encryption. App Passwords have limited access (only IMAP). No passwords are stored.
Q: Can I use this in production? A: Absolutely. It's designed for production use with built-in error handling, logging, and duplicate detection.
Q: How fast is payment detection? A: Near-instant. It searches Gmail IMAP in real-time. Typical response time is 2-5 seconds.
Backward Compatibility
If you were previously using fampay-verify, the old FamPayVerifier class name still works:
import { FamPayVerifier } from 'upi-auto-verify'; // still works!Contributing
Contributions are welcome! Feel free to open issues and pull requests.
License
MIT License - see LICENSE for details.
Contact
- Website: iflexvault.pro
- Telegram: t.me/iflexvault
- GitHub: github.com/iflexvault
