Standards/swish-qr
Swish QR
Overview
Swish is Sweden's national mobile payment system, founded in 2012 by six of Sweden's largest banks as a joint venture, and ranks as one of the most successful bank-backed mobile payment platforms in the world by per-capita adoption — 8+ million users in a country of ~10 million (~86 % of the population, February 2025) [1, se-cro]. The Swish QR code feature launched in 2017, encoding payment details (Swish number, amount, message, editable-field flags) as text inside a standard qr-code symbol — using a Swish-proprietary text format rather than EMVCo TLV [2, 3]. By 2025 Swish processed ~1.1 billion transactions per year (May 2025 was the first single month past 100 M); the 2024 split was 484 M P2P (44 %) / 604 M commerce (56 %) worth SEK 309 B P2P + SEK 251 B commerce, with 345,000+ connected businesses end-2024 SE. Settlement migrated to RIX-INST (Riksbank's central-bank instant payment platform) in February 2024, replacing the previous Bankgirot-operated rail [se-cro, 4].
History
Founding (December 2012): Six competing Swedish banks formed Swish AB and launched the service as a person-to-person mobile payment system [1, se-cro]:
- Danske Bank
- Handelsbanken
- Länsförsäkringar
- Nordea
- SEB
- Swedbank
The proposition was simple: send money to anyone whose mobile phone number you know, instantly, free, via your existing bank's app. No new account, no card, no codes.
Evolution timeline [se-cro, 1]:
- 2012 — Swish launched, person-to-person only.
- 2014 — Organisations / businesses can receive payments.
- 2017 — Swish QR code launched. E-commerce / web-based sales support added.
- 2019 — Founding member of EMPSA (European Mobile Payments Systems Association).
- February 2024 — Migration from Bankgirot's BiR (Betalningar i realtid) to Riksbank's RIX-INST instant payment platform. Settlement now in central-bank money — eliminates bankruptcy-risk of clearing-bank failures [4].
- November 2024 — NCT-INST mandate (Nordic Payments Council) requires all RIX-INST participants to accept instant payments SE.
- 2024 — Zimpler partnership announced for merchant integration SE.
Bank participation has expanded well beyond the six founders; additional Swedish banks (Skandia, Sparbanken Syd, ICA Banken, etc.) joined over time SE.
Technical specification
Unlike most national QR payment standards, Swish does not use EMVCo TLV. Its QR code carries a Swish-proprietary text payload with semicolon-separated fields [3, 5].
Swish QR text format [3]:
C<swish-number>;<amount>;<message>;<editable-fields-bitmask>
Where:
C— leading character identifying a Swish payment QR (Type C — the dominant format).<swish-number>— recipient's Swish-registered mobile phone number (Swedish format, no country prefix needed for domestic).<amount>— integer in base 10. Some implementations multiply by 100 for cents.<message>— free-text payment note.<editable-fields-bitmask>— bitstring controlling which fields the payer can override:0b001(1) — PHONE_EDITABLE0b010(2) — AMOUNT_EDITABLE0b100(4) — MESSAGE_EDITABLE0b111(7) — all editable0b000(0) — all locked
Swish QR Types as documented by lindskogen/swish-qr-format [6]:
| Type | Description |
|---|---|
| Type A | Basic payment to a Swish number (number only) |
| Type B | Payment with a specified amount |
| Type C | Payment with customisable message and editable-field bitmask (the dominant production format) |
| Type D | Base64-encoded format (undocumented) |
The Swish QR text format is proprietary and unpublished by Swish AB — lindskogen/swish-qr-format is the result of reverse-engineering production QR codes [6].
Underlying symbology: standard qr-code (ISO/IEC 18004), no Swish-specific QR modifications.
Settlement (post-February 2024) [4, se-cro]:
- Inter-bank routing handled by Swish AB.
- Settlement via RIX-INST, the Riksbank's instant payment platform (based on TIPS — TARGET Instant Payment Settlement).
- 24/7/365 availability.
- Central-bank-money settlement (no clearing-bank credit risk).
- ISO 20022 messaging on the underlying rail.
Use cases
Swish is essentially universal across Swedish payment contexts; the QR code feature has been instrumental at the small-merchant and informal-vendor end:
- Person-to-person transfers — the original 2012 use case; instant, free SE.
- Small retail / POS — almost every café, restaurant, supermarket displays a Swish QR or accepts via Swish number entry SE.
- Flea markets and informal vendors — Swish QR (and pre-QR, the Swish-number-entry method) replaced cash at outdoor markets and farmers' stands SE.
- Charity donations — donation collection at events, churches; the simplicity is the point SE.
- E-commerce checkout — since 2017, Swish QR is a standard online-checkout option for Swedish customers [se-cro, 1].
- Invoice payment requests — Swish "payment request links" can be shared digitally SE.
- Corporate billing — real-time payment visibility for businesses, refund tools, reporting SE.
Statistics (2024) SE:
- 1.1 billion transactions
- ~SEK 600 billion in transaction value (~€55 billion)
- ~450 million P2P transactions
- ~650 million business payments
- 3+ million daily transactions
- ~70 % of small Swedish businesses accept Swish
- ~80 % adult population uses Swish
Adjacent technologies in Swedish banking apps:
- OCR scanning for paper invoices — a separate OCR-number reference printed on Swedish invoices, scanned by the same banking app that handles Swish. Not a QR code but the same camera workflow. Universal in Swedbank, SEB and other Swedish bank apps SE.
Implementations
The proprietary text format is small and trivial to generate — the implementation work is in QR rendering, not the payload — so there are few high-star Swish QR libraries despite Swish's massive adoption. The bigger work happens inside Swedish bank apps via Swish AB's gated API.
Open-source libraries:
- JavaScript — gillstrom/swish-qr — 25★, last active 2015. Node.js module that generates Swish QR codes [7]. Has not been updated since the early days of Swish QR.
- JavaScript — lindskogen/swish-qr-format — 4★. Documents the reverse-engineered Swish QR format including all four type variants (A/B/C/D) [6]. More valuable as reference docs than as a runtime library.
Bank app integrations (canonical production deployments) SE:
- Swedbank Private (Swedbank)
- SEB
- Handelsbanken
- Nordea Mobile (Nordea)
- Länsförsäkringar
Plus other Swedish bank apps. Every Swedish bank app supports both scanning a Swish QR and generating one for receiving.
BankID dependency: Swish authentication is gated through BankID, Sweden's national digital identification system, which provides strong customer authentication for every payment confirmation SE.
Merchant SDKs:
- Direct Swish for Business API (Swish AB).
- Zimpler (recent partnership) — merchant onboarding and payment-flow tooling SE.
Comparison
vs. blik (Poland) — Closest peer: both founded by a consortium of six competing national banks (Swish: 2012; BLIK: 2015) in non-Eurozone countries with their own national currency (SEK / PLN), both achieved near-universal adoption (~80 % SE / ~45 % PL of population), both QR-supported but with a primary non-QR interaction (Swish: phone number entry; BLIK: 6-digit code). The bank-consortium founding pattern is the structural commonality — competing-banks-collaborating is how you reach critical mass for national mobile payments without state mandate [pl-cro, se-cro].
vs. twint (Switzerland) — Also a bank-consortium mobile payment system; both Swiss and Swedish models reflect their respective economies' bank concentration and willingness to collaborate on shared standards. TWINT has ~60 bank-specific app versions; Swish has one Swish app + per-bank integrations. Both are near-universal in their home markets [ch-cro, se-cro].
vs. EMVCo MPM family (sgqr, duitnow-qr, promptpay-qr, pix) — Swish's text format is the outlier among major national QR payment standards in not using EMVCo TLV. This is a 2017 design choice that reflects Swish QR's role as a domestic-only convenience overlay on an already-dominant phone-number payment scheme, rather than a from-scratch national QR standard. The trade-off: simpler payload, but no cross-border interoperability with EMVCo-based systems without a translation bridge [3, se-cro].
vs. epc-qr (European SEPA standard) — Sweden is non-Eurozone (SEK), so EPC QR's SEPA Credit Transfer mechanism isn't directly applicable. Swedish bank apps support OCR scanning for paper invoices (a barcode-style reference, not a QR), filling the invoice-payment niche EPC QR occupies in eurozone countries SE.
Fun facts
Swish achieved ~80 % of the Swedish adult population in just over a decade — among the highest adoption rates of any national payment system globally [se-cro, 1]. The combination of small homogeneous population, high banking penetration, smartphone ubiquity, BankID's strong authentication foundation, and bank-consortium founding gave Swish an unusual launch advantage.
The February 2024 migration to RIX-INST moved Swish's underlying settlement from a commercial-bank-operated rail (Bankgirot's BiR) to the central-bank's instant payment platform (Riksbank's RIX-INST, based on TIPS) [4, se-cro]. This is one of the most consequential payment-system architectural changes in recent Swedish history — eliminating commercial-bank-credit risk from instant payments and bringing Swish into alignment with the European TIPS infrastructure that backs SEPA Instant Credit Transfer.
Sweden is the most cash-averse country in Europe — 367.4 card payments per capita (highest in the EU) and approaching near-cashless status SE. Swish's QR is one of the small set of digital-payment touchpoints that filled the role cash used to fill: paying the kid for shoveling snow, paying the farmer at the stand, paying for the second-hand bicycle at the flea market. The cash-replacement use cases gave Swish QR a different cultural meaning than EMVCo MPM QRs have in countries where cash never fully receded.
The Swish QR text format is officially undocumented — Swish AB doesn't publish the spec [6]. The lindskogen/swish-qr-format repository is the result of community reverse-engineering production QRs. The closed-spec posture is unusual for a national payment system; most peers (Pix, PromptPay, SGQR, DuitNow) publish detailed open specs.
Status
Active and infrastructurally significant. Most recent metrics SE:
- ~8 million users (~80 % of Swedish adult population)
- 1.1 billion transactions / year (2024)
- ~SEK 600 billion annual value (~€55 billion)
- ~70 % small-business acceptance
- 3+ million daily transactions
- Settlement: RIX-INST (Riksbank central-bank infrastructure since Feb 2024)
Migration to T2 (European) RTGS platform under discussion for the parent RIX-RTGS system, with expected ~5-year transition; this would further integrate Swedish payment infrastructure with European standards while Sweden remains non-Eurozone SE.
EMPSA founding membership positions Swish for possible European mobile payment expansion, though no concrete cross-border rollout plan has been announced as of 2025 SE. No deprecation planned; Swish is canonical Swedish payment infrastructure.
Sources
- Swish (payment) — Wikipedia
- Swish — official
- Swish — GitHub topic
- Swish payments moved to RIX-INST — Riksbank press notice 2024
- mvallim/emv-qrcode — general EMV QR reference
- lindskogen/swish-qr-format — reverse-engineered format docs
- gillstrom/swish-qr — JS encoder
- Swish transactions in Sweden — Statista
- SE-sweden.md
- PL-poland.md
Deployments
Found in the following country reports (grep across reports/countries/):
- SE — SE-sweden.md