Guides

How to Integrate M-Pesa STK Push Payments in Kenya: Complete Developer Guide 2024

Admin User Aug 17, 2026 2 min read 412 views
How to Integrate M-Pesa STK Push Payments in Kenya: Complete Developer Guide 2024

M-Pesa processes over 60 million transactions daily in Kenya, making it the dominant payment method for online and offline commerce. For developers building apps and websites targeting Kenyan consumers, integrating M-Pesa STK Push is not optional but essential for business success.

What is M-Pesa STK Push?

STK Push, also known as Lipa Na M-Pesa Online, is a payment initiation method where the merchant sends a payment request directly to the customer's phone. The customer receives a prompt displaying the business name and amount, then enters their M-Pesa PIN to authorize. This eliminates the need for customers to remember paybill numbers or till numbers, reducing errors and cart abandonment significantly.

Why Choose DigiPay for M-Pesa Integration?

Integrating directly with Safaricom's Daraja API requires managing OAuth token refresh cycles, formatting timestamps in the exact required format, generating base64-encoded passwords, handling asynchronous callbacks, and managing production certificates. DigiPay abstracts all this complexity into a single REST API call. You send us the phone number and amount, we handle everything else including retry logic and callback verification.

Prerequisites

Before you begin, create a DigiPay merchant account at digipay.co.ke. Complete KYC verification which typically takes one to two business days. Once approved, create an application in your dashboard to receive your API Key and Secret. These credentials authenticate all payment requests.

Making Your First STK Push Request

Send a POST request to our M-Pesa endpoint with the customer's phone number in 254 format, the amount in KES, a unique reference for your records, and an optional description. DigiPay validates the request, authenticates with Safaricom, and initiates the STK push within milliseconds.

Handling Callbacks and Webhooks

Payment results are delivered to your webhook URL asynchronously. DigiPay sends a POST request containing the transaction reference, M-Pesa receipt number, payment status, and timestamp. Always verify webhook signatures to prevent fraudulent callbacks. Return a 200 status code promptly to acknowledge receipt.

Error Handling Best Practices

Common failure scenarios include wrong PIN entered, insufficient funds, timeout after 60 seconds, and unregistered phone numbers. Your application should display user-friendly messages for each scenario and allow customers to retry. Implement exponential backoff for status polling and never charge customers without confirmed payment.

Going to Production

DigiPay provides both sandbox and production environments. Test thoroughly in sandbox with test phone numbers before switching to production. Monitor your webhook endpoint uptime since missed callbacks mean missed payment confirmations. Set up alerting for failed payments exceeding normal rates.

TAGS: mpesa stk-push integration api kenya
SHARE: