Phone showing a booking slot picker used for online booking and payments in Kenya

M-Pesa Integration in Kenya: How to Actually Accept Payments on Your Website

A customer fills their cart. They are ready to buy. Then your checkout says: “Send payment to Paybill 123456, then WhatsApp us the screenshot.”

Roughly a third of them leave right there.

M-Pesa integration in Kenya is the difference between a website that displays products and a website that sells them. Yet most Kenyan business sites still run on screenshots, manual confirmation and someone checking their phone between customers.

This guide explains how proper integration works, what you need to set it up, what it costs, and where projects go wrong. It is written for business owners, not developers — although the technical section will help whoever builds it for you ask better questions.

What M-Pesa Integration Actually Means

Integration means your website can request, receive and confirm M-Pesa payments automatically. No screenshots. No manual checking. No delay.

The customer enters their phone number at checkout. A prompt appears on their phone asking for their M-Pesa PIN. They approve. Your website knows within seconds that the payment succeeded, marks the order paid, and sends the confirmation.

Behind that simple experience sits Daraja, Safaricom’s official developer platform for M-Pesa. Daraja is Swahili for “bridge,” which is exactly what it does — it bridges your website and Safaricom’s payment system. Safaricom rolled out Daraja 3.0 in late 2025, and it stabilised through early 2026 with faster onboarding and better capacity.

Why the manual method costs you more than you think

Many owners defend the screenshot method because it feels free. However, it carries real costs.

Lost sales. Every extra step between wanting and buying loses customers. Asking someone to leave your site, open M-Pesa, remember a Paybill, type an account number and then screenshot the result is five steps too many.

Wasted hours. Someone must check messages, match payments to orders and confirm manually. That is a salary line, not a saving.

Reconciliation chaos. Wrong amounts, missing account references and duplicate payments create disputes that take longer to resolve than the sale was worth.

Fraud exposure. Screenshots are trivially edited. Businesses relying on them get burned regularly.

We cover the wider pattern in why e-commerce websites fail in Africa.

The Three Ways to Accept M-Pesa Online

Before choosing, understand that you have three genuinely different options.

Option 1: Manual Paybill or Till

You display your number. The customer pays. You confirm by hand.

Cost: Standard Safaricom transaction charges only. Setup: Immediate. Verdict: Acceptable for a business doing a handful of orders a week. It stops working the moment volume grows.

Option 2: A payment aggregator

Providers such as Pesapal, Flutterwave, Paystack, IntaSend, DPO Pay and Kopokopo handle the Safaricom relationship for you. You integrate once with their system and get M-Pesa, cards and sometimes bank transfers together.

Cost: Typically around 1.4% to 3.5% per M-Pesa transaction, with card rates usually higher. Rates vary considerably between providers and are often negotiable at volume. Setup: Roughly three to ten business days for approval, plus a few days of development. Verdict: The right choice for most small and medium Kenyan businesses, especially those needing card payments too.

Option 3: Direct Daraja integration

You connect your website straight to Safaricom’s API using your own Paybill or Till.

Cost: Lower per transaction, since you pay Safaricom’s rates without an aggregator margin. Higher development cost upfront. Setup: Longer. You handle sandbox testing, production approval and your own error handling. Verdict: Best for higher-volume businesses, M-Pesa-only operations, or anyone needing custom payment logic.

Our guide to choosing the right payment gateway in Kenya compares providers in more detail.

How STK Push Actually Works

STK Push — branded by Safaricom as Lipa na M-Pesa Online or M-Pesa Express — is the prompt that appears on a customer’s phone. Understanding the sequence helps you spot a badly built checkout immediately.

Step 1. The customer enters their phone number and confirms the amount on your checkout page.

Step 2. Your server — not the browser — sends a request to Daraja containing the amount, the phone number and your order reference.

Step 3. Safaricom pushes a prompt to the customer’s phone: pay this amount to this business.

Step 4. The customer enters their M-Pesa PIN and approves.

Step 5. Safaricom sends the result to your callback URL, a secure address on your server that listens for the outcome.

Step 6. Your website records the receipt, marks the order paid and confirms to the customer.

The whole loop typically takes four to eight seconds.

Notice step five. That callback is the part that separates a working integration from a broken one, and it is where most amateur builds fail.

What You Need Before You Start

Gather these before anyone writes a line of code. Missing items are the usual cause of delayed launches.

A registered business. Safaricom requires business registration documents for a Paybill or Till.

A Paybill or Till number. If you do not have one, start the application immediately — it commonly takes two to three weeks.

A Safaricom Daraja developer account. Register free at developer.safaricom.co.ke to access the sandbox and documentation.

A valid SSL certificate. Safaricom will not send callbacks to an insecure address, and self-signed certificates do not work in production. See our guide to SSL certificates for Kenyan e-commerce stores.

A publicly reachable server. Localhost cannot receive callbacks. Your site must be live on real hosting.

Your API credentials. Consumer Key, Consumer Secret, Business Short Code and Passkey. These must live on your server, never in front-end code.

Paybill or Till — which do you need?

Till numbers suit businesses selling goods where you simply need the money. Shops, restaurants and retailers usually take this route.

Paybills suit businesses that need an account reference attached to each payment — schools collecting fees, landlords collecting rent, SACCOs, service providers with invoices. If you need to know which customer paid which invoice, you want a Paybill.

What M-Pesa Integration in Kenya Costs

Costs fall into three buckets, and quotes often hide one of them.

Setup and development. Straightforward aggregator integration on a standard platform is the cheapest route. Custom Daraja integration with proper error handling, reconciliation and admin tooling costs more because it is genuinely more work.

Transaction fees. Direct Daraja through your own Paybill or Till carries Safaricom’s merchant rates, generally the lowest available. Aggregators layer their margin on top — commonly in the 1.4% to 3.5% range for M-Pesa, higher for international cards. Always confirm current rates directly with the provider, since published figures change and volume discounts are common.

Ongoing maintenance. Access tokens expire hourly and must refresh automatically. Daraja evolves. Callbacks fail. Someone must monitor this.

Here is the calculation that decides the route. Aggregator convenience is worth paying for at low volume. Once monthly transaction value grows, the percentage difference between an aggregator and direct Daraja starts to exceed the cost of building direct. Run that maths with your actual numbers before choosing.

If you are still planning the wider build, our guide on getting a website in Kenya covers how payments fit into the total budget.

Where M-Pesa Integrations Break

These are the failures we see most often when auditing Kenyan e-commerce sites.

The callback URL is not properly reachable. It must be HTTPS, publicly accessible, and must return a 200 response. If it does not, Safaricom retries and then gives up — and your customer’s money leaves their account while your website never records the order.

The site trusts the browser. Some builds mark an order paid when the front end thinks payment succeeded. That is exploitable. Only the server-side callback should confirm payment.

Timeouts are not handled. Customers cancel. Phones lose network. PINs get entered late. Your checkout must handle cancelled, timed-out and failed states gracefully instead of hanging forever.

Duplicate payments are not caught. A customer taps twice. Without idempotency checks, you charge twice and refund manually.

No reconciliation view. Someone in the business must be able to see payments, match them to orders and investigate mismatches without calling the developer.

Credentials sit in front-end code. Consumer Key and Secret in JavaScript is a security incident waiting to happen.

Nobody tested failure. Testing only the happy path is the single most common mistake. Our post on common payment integration mistakes goes further.

Your Pre-Launch Testing Checklist

Before real customers touch it, run every one of these scenarios in the sandbox and then with small live amounts.

  • A successful STK Push payment
  • A payment the customer cancels on their phone
  • A payment that times out with no response
  • A wrong PIN entry
  • An insufficient balance attempt
  • A duplicate submission of the same order
  • A callback that arrives late, after the customer has already left the page
  • A partial or incorrect amount received

Then confirm the order status, the customer confirmation message and your admin dashboard all reflect reality in each case. Failed payments are not the customer’s problem to solve. Recovering them is your system’s job.

The Compliance Side Nobody Mentions

Two obligations sit alongside your payment setup.

Data protection. Phone numbers, names and transaction records are personal data under Kenya’s Data Protection Act 2019. Your privacy policy must state what you collect at checkout, why, and how long you keep it. The ODPC has issued real fines. Read our full guide to data protection for websites in Kenya.

Payment trust signals. Customers hesitate at checkout when a page looks unfamiliar. Display your business name clearly, show the exact amount before the prompt, confirm visibly on success, and never ask for an M-Pesa PIN on your own website. Legitimate integrations never do this. Our article on why payment experience affects trust explains the psychology.

Which Route Should You Take?

A simple decision framework.

Choose an aggregator if you need cards as well as M-Pesa, you want to launch quickly, your volume is modest, or you would rather not maintain a Safaricom integration yourself.

Choose direct Daraja if your customers are overwhelmingly Kenyan and pay by M-Pesa, your volume makes the fee difference material, you need custom payment logic such as instalments or split payments, or you already have development capacity.

Choose both if you are large enough that the maths works — many Kenyan stores run direct Daraja for M-Pesa and an aggregator for international cards. It costs more to maintain but lowers total fees.

Frequently Asked Questions

How long does M-Pesa integration in Kenya take? If you already have a Paybill or Till, expect a few days to a couple of weeks depending on complexity. If you need to apply for one, add two to three weeks for Safaricom’s process. Aggregator approval typically runs three to ten business days.

Do I need a registered business? Yes, for a Paybill or Till. Some aggregators offer routes for sole proprietors and freelancers, so ask if you are not yet fully registered.

Can I add M-Pesa to a WordPress or WooCommerce site? Yes. Most major aggregators publish plugins, and direct Daraja integration is entirely possible on WordPress with proper development.

Is direct Daraja cheaper than Pesapal or Flutterwave? Per transaction, usually yes, because you avoid the aggregator margin. However, it costs more to build and maintain. The break-even depends on your monthly volume.

Will my customer’s money be safe if my website crashes mid-payment? The money moves through Safaricom regardless. The risk is that your website fails to record it. That is exactly why callback handling and reconciliation matter.

Can I accept payments from outside Kenya? Not through M-Pesa alone. You need an aggregator supporting international cards. Note that Stripe does not officially support Kenyan businesses for payment acceptance.

Get Your Payments Working Properly

M-Pesa integration in Kenya is not simply a plugin you switch on. Done well, it is a payment system with proper server-side confirmation, sensible failure handling, clean reconciliation and a checkout customers trust. Done badly, it quietly loses money in ways you will not notice for months.

At Africa Web Experts, we build and fix payment integrations for Kenyan businesses — aggregator setups, direct Daraja builds, and audits of existing checkouts that are dropping orders.

If your current checkout still relies on screenshots, or you suspect payments are slipping through, that is worth a conversation.

👉 Talk to Africa Web Experts about M-Pesa integration

Similar Posts