印度的 Agentic UPI:拆解 NPCI 的统一 Agent 协议

·阅读约11分钟·Evergreen Tools Team

大多数「Agent 支付」的故事发生在钱包与信用卡体系里。2026 年 9 月 1 日,路透社报道了另一条更重的路径:印度国家支付公司(NPCI)正在准备一套框架,让 AI Agent 无需为每一笔交易单独审批,就能发起小额 UPI 支付。若成真,UPI——按 2025 年 IMF 报告为全球交易量最大的零售快速支付系统——将成为全球首批国家级 Agent 支付基础设施之一。

"金钱与卡片"

"Agent 支付进入国家级通道"

一、报道说了什么,又没说死什么

据路透社援引三位知情人士,NPCI 计划为商户提供可直接集成的基础设施,让用户为 AI Agent 设定基于规则的指令:何时付、付多少。系统将内建消费限额、审计轨迹与身份核验,NPCI 还计划加入责任框架,但未披露细节。必须强调:NPCI 没有正式确认这套协议,路透社的报道也依赖未具名信源,且任何上线都需印度储备银行(RBI)批准。把它当作「正在成形的方向」,而不是「已发布的标准」。

# 1) Machine-executable spend policy for an autonomous agent.
POLICY = {
    "agent_id": "agent-42",
    "currency": "INR",
    "per_txn_cap": 500,
    "daily_cap": 2000,
    "monthly_cap": 10000,
    "merchant_allow": ["grocery.example", "cabs.example"],
    "window": ("06:00", "23:00"),
}

def allowed(txn: dict, spent: dict, now_hhmm: str) -> bool:
    if txn["currency"] != POLICY["currency"]:
        return False
    if txn["merchant"] not in POLICY["merchant_allow"]:
        return False
    if not (POLICY["window"][0] <= now_hhmm <= POLICY["window"][1]):
        return False
    if txn["amount"] > POLICY["per_txn_cap"]:
        return False
    return spent["day"] + txn["amount"] <= POLICY["daily_cap"]

二、它建在两块已有积木上

这套被外界称为「统一 Agent 协议」(UAP)的机制,并非凭空而来。它建在两个已经存在的 UPI 功能上:UPI Circle 允许主账户持有人把支付权限委托给次级用户(包括 AI Agent);Reserve Pay 让客户为多次扣款提前锁定资金,目前上限约为 10,000 卢比(约 105 美元),最长 90 天。把这两者形式化、统一化,就是 NPCI 想让 Agent 处理日常采购(日用、订阅、打车)的方式。

// 2) Idempotency: a retried payment must never double-charge.
const ledger = new Map();  // in production: durable store with unique index

async function payOnce(idempotencyKey, doPay) {
  if (ledger.has(idempotencyKey)) {
    return ledger.get(idempotencyKey);      // return the original result
  }
  const result = await doPay();
  ledger.set(idempotencyKey, result);
  return result;
}

// callers pass a stable key derived from intent, not from the attempt
await payOnce("agent42:" + intentId + ":" + cartHash, () => upi.debit(amount));

三、规模为什么重要

按 NPCI 自己发布的统计,2026 年 8 月 UPI 处理了 245.09 亿笔交易(24,508.96 million),金额约 29.82 万亿卢比,覆盖 752 家银行。一个月约 245 亿笔支付,运行的是一套大半个国家都依赖的基础设施。Agent 支付在美国、欧洲、新加坡已有公司级框架,而一旦在 UPI 上落地,印度将成为少数拥有国家级 Agent 支付基础设施的国家之一。

// 3) Delegation model, mirroring UPI Circle + Reserve Pay semantics.
const delegation = {
  principal: "user-1001",
  agent: "agent-42",
  rail: "reserve-pay",          // funds blocked upfront
  reserve: { amount: 10000, days: 90 },
  subLimits: { perTxn: 500, daily: 2000 },
  onExhaust: "deny-and-notify", // never silently exceed
};

function debit(delegation, amount) {
  if (amount > delegation.subLimits.perTxn) throw new Error("per-txn cap");
  if (delegation.reserve.amount < amount) throw new Error("reserve empty");
  delegation.reserve.amount -= amount;      // stays inside the block
}

四、真正的难题是身份与责任

Agent 支付会撕裂传统「授权/未授权」的二分法。客户可能确实授权了 Agent,但 Agent 误读了指令、选了欺骗性商户,或买下了不可退的商品。此时谁负责?UPI 联合发明人、NPCI 前 CTO Rajendran N. 的建议是:把 Agent 支付作为一个独立渠道引入,拥有自己的信任、风险与运营框架,以隔离生态中的问题。这其实是在说:别把 Agent 塞进人类通道,而要给它一套单独的、可审计的身份体系。

# 4) Audit trail bound to the triggering conversation turn.
import json, time, hashlib

def record_payment(trace_id, turn_id, txn, decision):
    entry = {
        "ts": time.time(),
        "trace_id": trace_id,
        "turn_id": turn_id,          # the user message that caused this
        "txn": txn,
        "decision": decision,        # allowed / denied / escalated
    }
    entry["digest"] = hashlib.sha256(
        json.dumps(entry, sort_keys=True).encode()
    ).hexdigest()
    with open("payments.audit.jsonl", "a") as f:
        f.write(json.dumps(entry) + chr(10))
    return entry

五、竞争格局已经拥挤

2026 年 6 月,Pine Labs 发布了 P3P,被称为印度首个基于 UPI 的 Agent 支付协议,且已在生产环境运行;此前 2025 年 Razorpay、NPCI 与 OpenAI 做过用 ChatGPT 驱动 UPI 支付的试点;2026 年 2 月,Mastercard 与 Axis Bank、RBL Bank 在印度 AI 影响力峰会上演示了印度首笔经认证的 Agent 交易;Razorpay 也在 3 月推出了面向商户的 Agent Studio。Agentic AI 是 2026 年孟买全球金融科技节(9 月 8 至 11 日)的三大核心技术支柱之一。

// 5) Separate credentials: spending vs refunding/withdrawing.
const creds = {
  pay: { scope: "upi:debit", uses: "agent-initiated purchases only" },
  refund: { scope: "upi:credit", uses: "human-approved reversals only" },
};

function authorize(action, agent) {
  if (action.startsWith("refund") || action.startsWith("withdraw")) {
    if (!agent.humanApproved) throw new Error("human approval required");
    return creds.refund;
  }
  return creds.pay;   // the agent can spend, never claw funds back
}

六、开发者现在该准备什么

即使协议尚未定稿,准备工作是明确的。第一,把「Agent 身份」当成一等公民:每个 Agent 有独立、可撤销的标识。第二,规则要机器可执行:上限、白名单商户、时间窗、单笔与累计封顶,全部写成结构化策略。第三,幂等键必备,避免重试造成重复扣款。第四,保留完整审计轨迹,与触发支付的对话绑定。第五,把退款与提现凭据与支付凭据分离。下面的代码示例给出一个面向 Agent 支付的策略校验器与幂等落账骨架。

"全球网络"

"245 亿笔交易的规模"

"加密与结算"

"身份与责任才是难点"

📌 常见问题 FAQ

NPCI 的统一 Agent 协议是什么?

一套正在成形、尚未正式确认的框架,意在让 AI Agent 无需逐笔审批即可发起小额 UPI 支付,并内建消费限额、审计轨迹与身份核验。报道来自路透社(2026 年 9 月 1 日),且任何上线都需 RBI 批准。

它建在哪些已有功能上?

UPI Circle(主用户把支付权限委托给次级用户,包括 Agent)与 Reserve Pay(提前锁定资金供多次扣款,目前上限约 10,000 卢比、最长 90 天)。

UPI 的规模有多大?

按 NPCI 统计,2026 年 8 月处理了 245.09 亿笔交易,金额约 29.82 万亿卢比,覆盖 752 家银行。

为什么责任划分是难点?

传统「授权/未授权」二分法无法覆盖「用户授权了 Agent,但 Agent 误读指令或选错商户」的情形,因此需要独立的信任、风险与责任框架。

开发者现在可以准备什么?

把 Agent 身份作为一等公民、把消费规则写成机器可执行的策略、使用幂等键防重复扣款、保留与对话绑定的审计轨迹,并分离支付与退款凭据。