Background Mobile

How to Make an App Like Alipay

fintech/
September 15, 2026
How to Make an App Like Alipay

How to Make an App Like Alipay

Alipay processes billions of transactions for more than a billion users, and it does far more than move money. It is a payments rail, a digital wallet, a lifestyle super app, a credit engine, and a merchant platform all bundled into one interface. That combination is exactly why so many founders, banks, and retail groups want to build something similar for their own market.

This guide walks through what Alipay actually is under the hood, the features you need, the technology stack that supports them, the regulatory work you cannot skip, and what the build realistically costs.

What Makes Alipay Different From a Standard Payment App

Most payment apps do one job: they move money from a customer to a merchant. Alipay treats payments as the entry point to an ecosystem.

Wallet-first architecture. Users top up a stored-value balance, link bank cards, or borrow through integrated credit products. The wallet is the account, not a thin layer over a card network.

QR codes as the universal rail. Instead of relying on expensive point-of-sale hardware, Alipay scaled on printed and dynamic QR codes. A street vendor and a department store use the same mechanism.

Mini programs. Third parties build lightweight apps that run inside Alipay. Users order food, book travel, pay utility bills, and buy insurance without ever leaving the app.

Risk scoring at the core. Alipay's fraud and credit systems evaluate transactions in milliseconds, which is what allows instant approvals and low friction.

Merchant tooling. Settlement dashboards, refunds, marketing coupons, and loyalty programs keep businesses inside the ecosystem.

If you only build a peer-to-peer transfer app, you have built a feature. If you build the ecosystem, you have built a platform.

Step 1: Define Your Market and Business Model

Before a line of code is written, decide what problem you are solving and how money flows back to you.

Pick a wedge. Alipay started with escrow for Taobao purchases. It solved a trust problem in online shopping, then expanded. Your app needs a similar beachhead: remittances for a specific corridor, cashless payments for informal retail, payroll for gig workers, or campus payments.

Choose revenue streams. Common options include merchant discount rates on transactions, withdrawal or top-up fees, float income on stored balances, subscription tiers for business accounts, lending margins, and advertising or commission from partner services.

Understand unit economics. Payments are a volume business with thin margins. Model your cost per transaction including interchange, network fees, KYC verification, SMS OTP, cloud, and customer support before promising free transfers.

Step 2: Handle Licensing and Compliance Early

This is the step that kills more payment startups than any technical problem.

Licensing. Depending on your jurisdiction you may need an e-money institution license, a payment services provider license, a money transmitter license per state or region, or a partnership with a licensed sponsor bank. Licensing timelines run from a few months to over two years.

KYC and AML. You need identity verification, document scanning, liveness detection, sanctions and PEP screening, transaction monitoring, and suspicious activity reporting.

Data protection. GDPR, local data residency rules, and consumer protection laws all shape your architecture. Some markets require that payment data never leaves national borders.

PCI DSS. If you touch card data at any point, you fall in scope. Tokenization and a compliant payment processor drastically reduce your burden.

Practical advice: many teams launch on top of a Banking-as-a-Service or regulated partner, then apply for their own license once volume justifies it.

Step 3: Map the Core Feature Set

Consumer App

  • Onboarding and eKYC with phone verification, ID capture, and biometric matching
  • Wallet balance with top-up from bank transfer, card, cash agents, or payroll deposit
  • QR scan and pay, supporting both merchant-presented and customer-presented codes
  • Peer-to-peer transfers by phone number, username, or QR
  • Bill payments for utilities, telecom, insurance, and government fees
  • Transaction history with search, receipts, categorization, and dispute filing
  • Cards for linking existing bank cards and issuing a virtual or physical card
  • Security controls including biometric login, device binding, transaction PIN, and session limits
  • Rewards such as cashback, coupons, referral bonuses, and tiered loyalty

Merchant App and Portal

  • Business onboarding with KYB verification
  • Static and dynamic QR generation
  • Real-time sale notifications and sound alerts
  • Settlement schedules and payout reports
  • Refunds, partial refunds, and void handling
  • Staff accounts with permissions
  • Integration with existing POS and accounting systems

Platform and Admin

  • User and merchant management with risk flags
  • Fraud rule engine and manual review queue
  • Ledger reconciliation and dispute workflow
  • Fee and pricing configuration
  • Analytics dashboards and regulatory reporting

Ecosystem Layer

Once the basics work, add mini programs or an embedded marketplace, open APIs for partners, credit and buy-now-pay-later products, savings or investment features, and insurance distribution.

Step 4: Design the Architecture

Ledger and Core Banking

The heart of a wallet app is a double-entry ledger. Every movement of money creates balanced debit and credit entries. Do not store balances as a single mutable number in a user table. Balances should be derived from immutable ledger entries so that every cent is auditable.

Key requirements:

  • Idempotency keys on every write so retries never double-charge
  • Immutable append-only entries with reversal entries instead of edits
  • Strong consistency for balance checks, eventual consistency acceptable for analytics
  • End-of-day reconciliation against bank and processor statements

Microservices Breakdown

A typical service decomposition looks like this:

  • Identity and auth service
  • KYC and onboarding service
  • Ledger and accounts service
  • Payments orchestration service
  • QR and tokenization service
  • Risk and fraud service
  • Notification service
  • Merchant service
  • Rewards and promotions service
  • Reporting and data service

Use an event bus such as Kafka for asynchronous flows like notifications, analytics, and reconciliation. Keep money movement synchronous and transactional.

Suggested Technology Stack

Mobile: Flutter or React Native for a shared codebase, or native Kotlin and Swift when you need deep biometric, NFC, and secure enclave control. High-security fintech apps often justify native.

Backend: Java with Spring Boot, Go, or Node.js with TypeScript. Java and Go dominate in payment cores because of maturity and performance.

Databases: PostgreSQL for transactional ledger data, Redis for sessions and rate limiting, Cassandra or ClickHouse for high-volume event and analytics data.

Infrastructure: Kubernetes on AWS, GCP, or Azure, with multi-region failover. Payment systems need active-active or at minimum warm standby.

Security tooling: HSM or cloud KMS for key management, Vault for secrets, mutual TLS between services.

QR Payment Flow

A merchant-presented QR flow typically runs like this:

  1. Merchant displays a QR encoding merchant ID and optional amount
  2. Customer scans, app decodes and requests payment intent from backend
  3. Backend validates merchant status, checks limits, runs risk scoring
  4. Customer confirms with biometric or PIN
  5. Ledger debits customer, credits merchant sub-account
  6. Both parties receive real-time push confirmation
  7. Settlement job moves funds to the merchant bank account on schedule

Design for offline resilience. Store-and-forward for weak connectivity, and dynamic QR expiry to prevent replay attacks.

Step 5: Build Security In From Day One

Payment apps are permanent targets. Security is a product requirement, not a checklist item.

  • Encryption in transit with TLS 1.3 and at rest with AES-256
  • Tokenization so raw card numbers never reach your servers
  • Device binding tying an account to a trusted device fingerprint
  • Certificate pinning and root/jailbreak detection in the mobile app
  • Code obfuscation and anti-tampering for the client
  • Rate limiting and velocity checks on transfers, logins, and OTP requests
  • Step-up authentication for high-value or unusual transactions
  • Behavioral biometrics analyzing typing patterns and device handling
  • Penetration testing before launch and at least annually after

Fraud prevention deserves its own investment. Start with rules (velocity, geolocation mismatch, new device plus large transfer) and layer machine learning models as transaction history accumulates.

Step 6: Plan the Development Process

Discovery and compliance mapping (4 to 8 weeks). Market research, regulatory analysis, feature prioritization, and technical architecture.

UX and UI design (6 to 10 weeks). Payment UX lives or dies on clarity. Every screen that involves money needs unambiguous amounts, recipients, and fees. Design for accessibility and for users with low digital literacy.

MVP build (4 to 7 months). Onboarding, wallet, top-up, P2P transfer, QR pay, transaction history, basic merchant tools, admin panel.

Integration and certification (4 to 10 weeks). Bank APIs, card processors, KYC vendors, SMS gateways, and any scheme certification required.

Testing. Functional, integration, load, security, and user acceptance. Load testing matters enormously; payment traffic spikes on paydays and holidays.

Pilot launch. Start in one city or one merchant category. Watch reconciliation reports obsessively.

Scale and expand. Add bill payments, credit, mini programs, and new corridors based on real usage data.

Step 7: Understand the Cost

Costs vary widely by region and scope, but a realistic range looks like this:

Scope Typical Range
Basic wallet MVP (P2P, top-up, QR pay) $90,000 – $180,000
Full consumer plus merchant platform $200,000 – $400,000
Alipay-style super app with mini programs, credit, marketplace $500,000 – $1,500,000+

Additional ongoing costs include licensing and legal fees, compliance staffing, KYC verification per user, cloud hosting that scales with transaction volume, customer support, and security audits. Budget 15 to 25 percent of build cost per year for maintenance and iteration.

Step 8: Solve the Adoption Problem

Technology is rarely why payment apps fail. Distribution is.

Two-sided cold start. Users will not join without merchants, and merchants will not join without users. Solve one side first with heavy subsidy. Alipay used Taobao. Many successful wallets used utility bill payments or transit fares as the hook.

Cash-in and cash-out network. In markets where cash dominates, an agent network for top-up and withdrawal is often more important than any app feature.

Merchant acquisition is a field sales business. Printed QR standees, onboarding in under ten minutes, and same-day or next-day settlement are the three things small merchants care about most.

Give people a reason to open the app daily. Bill reminders, transit, rewards, and social transfers create habit. A wallet opened once a month never becomes a super app.

Common Mistakes to Avoid

  • Treating the ledger as an afterthought and discovering reconciliation gaps at scale
  • Underestimating licensing timelines and burning runway waiting for approval
  • Copying Alipay's full feature list instead of finding a local wedge
  • Skipping idempotency and duplicating transactions during network retries
  • Building fraud rules only after the first serious attack
  • Ignoring customer support capacity; payment disputes generate heavy ticket volume
  • Launching nationally before reconciliation, settlement, and refunds are proven in a pilot

Final Thoughts

Building an app like Alipay is less a mobile development project and more a financial infrastructure project with a mobile front end. The interface is the easy part. The hard parts are the ledger, the compliance posture, the fraud systems, the settlement operations, and the two-sided market strategy that gets both consumers and merchants to show up.

Start narrow, get the money movement provably correct, earn trust, and then expand into the ecosystem. That is the sequence Alipay followed, and it remains the most reliable path to building a super app of your own.

Have a project in mind? Contact Sodio Technologies to discuss your requirements and explore the right technology solution for your business.

/// Work with us

Talk to the engineers who'd build it

You'll get a technical scope, timeline and cost estimate from the people doing the work, not an account manager. In-house team, no subcontracting, since 2016.

Contact Us