M-Pesa e-commerce integration

Turn M-Pesa payments into verified orders, not screenshots and guesswork

Production-minded Daraja integrations for Kenyan stores: STK Push initiation, callback validation, transaction records, reconciliation, customer status and safe recovery when networks or callbacks fail.

Customers get a clear checkout experience while operations and finance work from verified payment state rather than manual messages.

M-Pesa phone payment verified against an e-commerce order and reconciliation record

Where time and orders leak

The workflow should surface exceptions—not create them

  • Customers send transaction screenshots and staff manually match them to orders.
  • A successful customer payment does not always produce a successful callback.
  • Repeated clicks can create duplicate requests or confusing order states.
  • Finance cannot reconcile M-Pesa transactions cleanly against store orders.
  • Sandbox demos work, but production monitoring, security and exception handling are missing.

What is delivered

A system your team can understand, operate and recover

Checkout integration

Server-side STK Push initiation with controlled order states and useful customer feedback.

Callback and query handling

Validated callbacks, idempotent updates and a query/recovery path for delayed or ambiguous results.

Reconciliation records

Transaction references, timestamps, amounts and order relationships stored for operations and finance.

Security and observability

Secret handling, minimal logs, error alerts, rate controls and a production runbook.

Delivery process

Measured before automated

  1. 01

    Merchant readiness

    Confirm Daraja access, shortcode type, callback domain, store platform and the intended payment lifecycle.

  2. 02

    State design

    Define pending, paid, failed, cancelled, timed-out and review states before writing integration code.

  3. 03

    Sandbox validation

    Test authentication, requests, callbacks, duplicate events, amount mismatches and unavailable dependencies.

  4. 04

    Controlled go-live

    Move credentials securely, monitor live transactions and reconcile the first production batch.

Systems that can be connected

The final architecture depends on API access, data quality, ownership and operational return.

  • Safaricom Daraja
  • Shopify
  • WooCommerce
  • Custom Node.js
  • ERP and POS
  • CRM
  • Accounting
  • WhatsApp notifications

Relevant proof

Kenyan pharmacy e-commerce system

Review a complex commerce build involving a large regulated catalogue, operational integrations and local-market requirements.

Read the case study

Questions before an integration starts

Do I need a Paybill or Till number?

Your merchant setup and the Daraja product available to it determine the integration path. The technical audit confirms the shortcode, credentials and business process before implementation.

What happens if the callback is delayed?

The order remains in a non-paid state until verified. The integration can query transaction status, alert staff and provide a review path rather than marking an order paid from the browser alone.

Can M-Pesa work with Shopify or WooCommerce?

Yes, through an appropriate payment app, custom extension or middleware service. The best option depends on checkout constraints, ownership, expected volume and maintenance requirements.

Do you store customer M-Pesa PINs?

No. The PIN is entered on Safaricom-controlled prompts and must never be collected or stored by the store integration.

Start with the workflow, not the tool

Share the systems involved and the manual work that slows the team down. You will receive a structured brief for technical review.

Request the audit
WhatsApp
Get in touch