How to Integrate M-Pesa Daraja API into Your Website or App
Accepting M-Pesa payments online requires connecting to Safaricom's Daraja API. Here's what Kenyan developers and business owners need to know about setup, costs, and common pitfalls.
If you're running an online business in Kenya, M-Pesa integration isn't optional anymoreâit's expected. Most customers won't complete a purchase without it. Safaricom's Daraja API is the official gateway for accepting M-Pesa payments on websites and apps, but the integration process trips up first-timers regularly.
The M-Pesa Daraja API lets you collect payments directly from customer phone numbers without redirecting them to a payment portal. It sounds simple until you hit authentication errors or sandbox testing issues. This guide walks through the actual setup steps, what to expect cost-wise, and where things commonly go wrong.
Register Your App on the Daraja Portal
Start at the Safaricom Daraja portal. Create an account using your email and a strong passwordâSafaricom enforces decent security here. Verify your email immediately; delays cost time.
Once logged in, navigate to the Apps section and click Create New App. You'll need your business name, a brief description of what you're building, and a callback URL (this is where M-Pesa sends payment confirmations back to your system).
After creating your app, Safaricom generates two critical credentials: a Consumer Key and Consumer Secret. Write these down somewhere secure. You'll authenticate every API request with these keys. Treat them like passwordsânever hardcode them into public repositories or share them in Slack messages.
The free sandbox environment is your testing ground. It mirrors production but uses fake M-Pesa accounts and test phone numbers. You can't skip this step; attempting live transactions before thorough sandbox testing often causes payment failures that anger customers and reflect poorly on your business.
Choose Your Integration Method and Implement It
Daraja supports two main payment flows: Lipa na M-Pesa Online and M-Pesa Express (STK Push). Lipa na M-Pesa Online redirects customers to Safaricom's payment page. STK Push sends a prompt directly to their phoneâfaster, more seamless, and generally preferred for e-commerce.
You'll need basic server-side knowledge for either approach. The API uses REST endpoints, meaning you send JSON requests and receive JSON responses. Most developers use libraries in their preferred language: Python, Node.js, PHP, or Java all have Daraja wrappers available on GitHub.
If you're not comfortable with backend code, consider hiring M-Pesa integration developers to handle implementation. Many charge KSh 15,000 to 50,000 for a basic setup, depending on complexity.
Test everything in sandbox mode first. Use test phone numbers provided by Safaricom (usually starting with 254708374149). Verify that payment confirmations arrive at your callback URL. Check that your database records transactions correctly. A single overlooked bug here costs money and trust later.
Going Live: Compliance and Ongoing Management
Before moving to production, ensure your business is registered with the Kenya Revenue Authority (KRA) and has a valid tax PIN. Safaricom may request verification documents. The transition from sandbox to production credentials takes 2-5 business days.
Monitor your transaction logs regularly. Payment reconciliationâmatching what M-Pesa sent you against what you recordedâshould happen daily. Some businesses automate this; others do it manually. Either way, discrepancies reveal bugs or fraud attempts early.
If integration feels overwhelming, find a verified Kenyan expert on Kaziiko who specializes in payment systems. They'll handle setup, testing, and can troubleshoot live issues quickly.
Frequently Asked Questions
Do I need a Safaricom Lipa na M-Pesa Till number to use Daraja?
No. Daraja works independently. You register your business on the developer portal, receive API credentials, and integrate directly. However, some high-volume merchants pair Daraja with a Till number for added flexibility and reporting.
How long does payment confirmation take?
Instantaneous in sandbox. Live payments typically confirm within 2-5 seconds, though network delays can extend this. Always implement timeout handling in your code.
What are the transaction fees?
M-Pesa applies standard transaction fees based on amount (currently around 2-3% for most transactions). Safaricom's Daraja API itself charges no integration fee. Check Safaricom's official pricing for the latest rates.
Can I test with real M-Pesa accounts?
No. The sandbox environment is strictly for testing. Attempting production transactions before you're ready causes failed payments and support headaches. Complete sandbox testing thoroughly first.
Find an Expert on Kaziiko
