Nikhil

Reverse Engineering NCMC: Building an Open Interface for Transit Cards

Submitted Oct 5, 2026

NCMC is a specification designed to enable India’s “One Nation, One Card” initiative. Multiple intracity transit systems have their own NCMC cards, issued by different companies and backed by banks that provide the banking infrastructure required for the cards’ backend systems, RuPay OTG/QSPARC, to work.

Card providers typically contract a specification implementor to integrate with the standardized, EMV-based transaction ecosystem. For example, Bengaluru’s BharatYatra cards are provided by Pine Labs, backed by RBL Bank, with the specification implemented by Uvik, a CCAvenue company. Delhi’s Airtel NCMC cards are provided by Airtel, backed by Airtel Payments Bank, with ISG as the specification implementor.

Since these cards follow the same specification, it should be possible to build a single app that interfaces with different NCMC cards and retrieves information such as transaction history, current balance, and card metadata. However, no such universal app exists. The NCMC specification, developed by C-DAC, is proprietary.

This talk explores how I reverse-engineered the specification, piece by piece, using a combination of technical and non-technical techniques. I’ll walk through the process of understanding the underlying protocol and using those findings to build an app that can read NCMC card details and balances.

Readings:

  1. https://nkmason.dev/posts/reversing-ncmc-spec/
  2. https://tangled.org/nkmason.dev/OpenNCMC

Comments

{{ gettext('Login to leave a comment') }}

{{ gettext('Post a comment…') }}
{{ gettext('New comment') }}
{{ formTitle }}

{{ errorMsg }}

{{ gettext('No comments posted yet') }}

Hosted by

A FOSS-driven student developer community originally based at PES University. Since 2021, we have been raising awareness for open source and knowledge sharing.