HUACODE全球企业华人转型升级首选平台正式上线了
HUACODE - 全球华企数字转型研究中心
products-and-technologyKenya M-Pesa Daraja 3.0 STK Push C2B B2C B2B Paybill API integration payment integration

How to Do Kenya M-Pesa Payment Integration

To integrate M-Pesa into a Kenyan website or app, first choose the right option—C2B, STK Push, B2C or B2B—then calculate transaction fees, development, reconciliation and compliance costs. This article explains the suitable options and launch process for Malaysian Chinese businesses.

A
Admin
Author
2026-09-01
5 min read
2
Share:
How to Do Kenya M-Pesa Payment Integration

For a Kenyan website or app, M-Pesa is usually connected through Safaricom Daraja 3.0. Business Till collection fees are capped at 0.55% and KSh 200 per transaction; development cost depends on scope.

What is Kenya M-Pesa payment integration?

In simple terms, it means connecting Kenya's major mobile payment service, M-Pesa, to your website, app or back-office system.

Safaricom's Daraja 3.0 is the official API platform. Businesses can use it for collections, payouts, transaction queries and reconciliation.

It is not just adding a payment button. A real integration also covers order status, payment callbacks, exception handling, transaction queries and finance reconciliation.

· C2B: Customer to Business, where a customer pays the business.

· STK Push: the business sends a payment prompt to the customer's phone.

· B2C: Business to Customer, for payments to customers, employees or suppliers.

· B2B: a business pays another business through a Paybill or Buy Goods Till.

For online collections, start with C2B and STK Push. For refunds, commissions, payroll or bulk payouts, evaluate B2C. For supplier payments in Kenya, evaluate B2B.

How much does Kenya M-Pesa payment integration cost?

Separate the cost into two parts. The first is Safaricom transaction fees. The second is the development work for the website, app and back-office system.

Safaricom's Business Till tariff states that merchant collection fees are capped at 0.55% of the transaction value and KSh 200 per transaction. Collections of KSh 200 or below are free.

Customers generally pay no fee for Buy Goods payments, except for fuel-station transactions. A Business Till paying another Buy Goods Till is charged 0.27%, capped at KSh 200 per transaction.

Safaricom's official Paybill Standard Tariff lists three charging models: Mgao Tariff splits the charge between customer and business, Business Bouquet Tariff charges the customer, and Customer Bouquet Tariff charges the business. The current file covers Paybill transaction bands from KSh 1 to KSh 250,000, with the amount determined by the selected tariff and band.

Paybill sources:  Safaricom Paybill Standard Tariff | Safaricom Paybill RequirementsSafaricom's official announcement lists a maximum M-Pesa transaction amount of KSh 250,000 per transaction and KSh 500,000 per day. This is an account-level limit, not a substitute for your own order and risk controls.

Which should you choose: C2B, STK Push, B2C or B2B?

For an e-commerce or SaaS business, STK Push is often a better fit for online checkout. Customers do not need to remember a Paybill number and account number. The system sends the amount and phone number in the request, and the customer confirms on the phone.

For a platform business, do not ask only whether it can collect payments. First clarify whether the business is collecting for itself or processing funds for other merchants. The regulatory position may differ.

What functions do websites and apps need?

A complete payment flow usually looks like this:

1. The customer creates an order on the website or app.

2. The system locks the order amount and order number.

3. The backend sends an STK Push or C2B request to Daraja.

4. The customer confirms the payment and enters the M-Pesa PIN.

5. Safaricom sends the result to the business Callback URL.

6. The backend validates the callback and updates the order.

7. If the callback fails, the system checks the result through Transaction Status Query.

8. The finance team reconciles the order number, M-Pesa transaction ID and actual settlement amount.

Safaricom's technical material says the customer normally has about 1 minute 30 seconds to complete the STK Push action. The customer may enter the wrong PIN, cancel, be offline, or already have another STK transaction in progress.

One common trap is that failed callbacks are not automatically retried. Do not rely only on the browser's payment-success page. Keep a backend query mechanism.

How can a Malaysian Chinese business get started?

1. The customer creates an order on the website or app.

2. The system locks the order amount and order number.

3. The backend sends an STK Push or C2B request to Daraja.

4. The customer confirms the payment and enters the M-Pesa PIN.

5. Safaricom sends the result to the business Callback URL.

6. The backend validates the callback and updates the order.

7. If the callback fails, the system checks the result through Transaction Status Query.

8. The finance team reconciles the order number, M-Pesa transaction ID and actual settlement amount.

Can a Malaysian company directly apply for a Safaricom Paybill, Till or production API account? Safaricom's Paybill requirements include a category for foreign companies with a Kenyan Certificate of Compliance.

The listed documents include incorporation documents, the Certificate of Compliance, Kenyan directors' KRA PIN certificates, director identification and company bank details. A Malaysian company should assess whether it has these Kenyan registration and compliance documents before treating the application as eligible.

Kenya's Data Protection Act 2019 applies to businesses established outside Kenya that process personal data of people in Kenya. ODPC's FAQ lists registration fees of KSh 4,000 for Micro and Small, KSh 16,000 for Medium and KSh 40,000 for Large entities, with a certificate validity of 24 months.

A data controller generally needs to notify ODPC within 72 hours after discovering a notifiable breach with a real risk of harm. A data processor should notify the controller without delay and, where practicable, within 48 hours.

Items to confirm before launch

· Onboarding fees, monthly fees and minimum volume: Safaricom's public tariff materials do not list one universal fee structure for every Paybill, Business Till or STK Push account. Use the product-specific tariff and account terms.

· Production review and Go-Live timing: the public Daraja page confirms that businesses can create a Sandbox app and test APIs, but it does not turn Sandbox test duration into a production SLA. Confirm production review, credentials and callback requirements with Safaricom before launch.

· Current B2B limits: Safaricom's official B2B page confirms that the payer must have an existing M-PESA shortcode and enough funds. Confirm single-payment and bulk-payment limits against the current account, product permissions and Daraja documentation.

· API versions, endpoints, OAuth token lifetime, rate limits and error codes: use the current documentation and application settings inside Daraja for implementation. Do not treat paths or parameters from an old technical PDF as permanent.

· Software development, server, monitoring, support and annual maintenance fees: Safaricom does not publish one standard website or app integration price or one standard maintenance price. Quote these items by API count, order system, ERP/CRM, refunds, reconciliation, roles, testing and SLA scope.

· Settlement to a Malaysian bank account, settlement timing, bank fees and KES/MYR FX costs: public merchant materials do not confirm a pure offshore settlement setup. Safaricom, the Kenyan acquiring bank and the Malaysian receiving bank should assess the merchant structure.

· Malaysian tax treatment: the treatment of M-Pesa fees, overseas service fees, FX gains or losses, withholding tax, digital service tax and company income should be assessed by a Malaysian tax adviser based on the contracts, payment flow and entity structure.

· Own-business collection versus third-party payment aggregation: CBK places payment service providers within the National Payment System framework. The business model should be assessed with CBK or Kenyan counsel based on whether funds are processed, held or transferred for other merchants.

· CBK payment-service-provider licence fees: CBK's published NPS Regulations 2014 table lists a KSh 5,000 application fee, KSh 100,000 authorization fee and KSh 5 million core capital for an electronic retail payment service provider. A proposed licence applicant should also review CBK's current authorization page and later amendments.

· ODPC registration: ODPC guidance states that an entity established outside Kenya that processes personal data of people in Kenya may need to register. Whether the entity registers as a controller, processor or both depends on the actual data flow.

FAQ

What conditions are needed for Kenya M-Pesa API integration?

Confirm the business case, merchant eligibility, shortcode, Daraja account, Sandbox testing and production requirements. Safaricom's Paybill requirements include a foreign-company category requiring a Kenyan Certificate of Compliance, Kenyan directors' KRA PIN certificates, director identification and company bank details.

What is the difference between M-Pesa website and app payments?

The underlying APIs may be similar, but the user flow differs. Websites need browser redirects, order returns and page states; apps are better suited to STK Push combined with native notifications and order queries.

How much are M-Pesa integration fees?

Business Till collection fees are capped at 0.55% and KSh 200 per transaction. B2C, B2B and Paybill use different charging models and should be checked against the account-specific tariff.

What should happen to an order after an M-Pesa STK Push fails?

Do not rely only on the front-end result. Receive the Callback and call Transaction Status Query when the callback fails or the status is unclear.

Can a Malaysian company directly apply for Kenya M-Pesa?

Safaricom's Paybill requirements include a foreign-company category with a Kenyan Certificate of Compliance. Confirm the Certificate of Compliance, Kenyan directors' KRA PIN certificates, director identification and company bank details before treating the application as eligible.

Comments (0)

No comments yet. Be the first to comment!