Skip to content
Writing and playbooks

11 Aug 2026 · 6 min read

Set Up Invoice-Specific PayNow QR Payments for Xero

A Codex runbook for building a controlled Xero payment page from a provider-issued PayNow QR, with field validation, tests, deployment checks, and real banking-app verification.

PayNowXeroPaymentsCodex

Start from the official provider-issued QR

A receiving proxy must not be inferred from a business UEN alone. The implementation starts by decoding the official QR issued by the bank or payment provider and treating its proxy type, proxy value, merchant metadata, and payment settings as authoritative.

The original QR remains preserved byte-for-byte as a private fallback asset. Live payment addresses, customer information, credentials, domains, and provider-issued assets should not enter a public repository without explicit approval.

Change only the invoice transaction fields

The dynamic QR should retain the provider-issued merchant profile while setting the point-of-initiation method, fixed invoice amount, invoice number reference, editable-amount indicator where required, and a recalculated CRC-16/CCITT-FALSE checksum.

Currency, amount, reference, and merchant configuration are validated before rendering. Public URL parameters must not be allowed to replace the merchant proxy or intended recipient.

Preserve a clear manual-payment path

The page should include a provider-approved fallback with the complete payment address and the provider's instructions. It should use plain PayNow text unless an authorised brand asset is supplied.

Automated tests should cover the decoded merchant profile, proxy type, amount, reference, checksum, and preservation hash of the source QR so later changes do not silently alter the receiving identity.

Verify deployment and a real banking-app scan

Netlify and VPS deployment are alternative routes. Either route should use a reversible release, verify the build and tests, confirm HTTPS and service health, and retain a rollback path.

A controlled low-value scan in a Singapore banking app is required before rollout. The app must resolve the expected recipient and show the intended amount and invoice reference.

Keep payment evidence and Xero authority separate

Rendering a QR does not prove that money was received. Bank evidence and accounting reconciliation remain the source of truth, and the page must not claim payment success.

The proposed Xero custom payment URL should be shown for review before configuration changes. Creating payments, altering invoices, or changing branding-theme payment services requires explicit approval for the exact action. The living Gist contains the complete agent prompt and prerequisite controls.

Share and save

Living source

This post is the stable site version. The source gist may be updated as the working pattern develops.

Read the complete PayNow and Xero runbookOpen the canonical implementation repository