Payment Integration

How to Get M-Pesa Daraja API Keys: Consumer Key, Secret and Passkey (2026)

What the three Daraja credentials are, how to get sandbox keys in a few minutes, how to go live with your own Paybill or Till, and how to keep the keys from leaking.

To take M-Pesa payments on a website or app with STK Push (the prompt that pops up on the customer's phone asking for their PIN), you need three things from Safaricom's Daraja portal: a consumer key, a consumer secret and a passkey. You get test versions straight away. Live versions take a go-live request, and that is where most people get stuck.

This guide walks through both, in the order you will actually do them. Facts were checked against Safaricom's Daraja documentation and FAQ in October 2026.

The three credentials and what each one does

  • Consumer key and consumer secret. These identify your Daraja app. Your server sends them to Safaricom to get an OAuth access token, and every API call after that carries the token. Think of them as the username and password of your app.
  • Passkey. This one is only for Lipa na M-Pesa Online (STK Push). Your server combines the passkey with your shortcode and a timestamp to build the Password field of each STK Push request. Safaricom uses it to check the request really comes from the owner of that shortcode.

There are two sets of each: sandbox (test, no real money) and production (live, real money into your Paybill or Till). They are not interchangeable. If you want to see how the token and password are used in code, our STK Push tutorial shows it step by step.

Step 1: Get sandbox keys

The Daraja portal (it calls itself Daraja 3.0) is at developer.safaricom.co.ke.

  1. Create an account on developer.safaricom.co.ke.
  2. Create an app. New apps start in the sandbox.
  3. Open My Apps. Your app shows its Consumer Key and Consumer Secret.
  4. Use the sandbox shortcode and passkey. For Lipa na M-Pesa Online the sandbox shortcode is 174379. The sandbox passkey is shown in the simulator. It is a public test passkey that everyone shares, so it is fine to see it written down:
Shortcode: 174379
Passkey:   bfb279f9aa9bdbcf158e97dd71a467cd2e0c893059b10f78e6b72ada1ed2c919

With those four values you can send test STK Push requests. No real money moves in the sandbox. When something fails, our list of common Daraja API errors usually explains why, and M-Pesa callback URLs covers the address Safaricom sends results to.

Want to see an M-Pesa checkout before you deal with keys?

Our demo shows what a customer sees. It checks the phone format only, and no real prompt is sent.

Try the demo checkout · Try it free in sandbox

Before you go live: the Org Portal prerequisite

This is the step that trips most people up, so sort it out first. The go-live form asks for the M-Pesa username of a Business Administrator or Business Manager on the M-Pesa Org Portal (org.ke.m-pesa.com). That is a separate system from Daraja. It is where your business manages its Paybill or Till.

Many businesses have a Paybill or Till but nobody with that Org Portal role. If that is you:

  • Write a letter on your company letterhead, signed and stamped, giving the ID details of the person who should be the administrator.
  • Send it to M-PESABusiness@Safaricom.co.ke.
  • Wait for Safaricom to set up the user. They do not publish how long this takes, so start early.

The person you choose will also receive the go-live OTP on their Safaricom line, so pick someone who will be reachable on the day you submit.

Step 2: Go live and get production keys

  1. Open the Go Live tab in the Daraja portal.
  2. Enter your organisation shortcode. For a Paybill, that is the Paybill number. For a Till, it is the Store number (also called the head-office number), not the Till number itself.
  3. Enter your organisation name without symbols.
  4. Enter the M-Pesa username of your Org Portal Business Administrator or Business Manager. It is case-sensitive, so type it exactly as it appears in the Org Portal.
  5. Enter the OTP that Safaricom sends to that user's Safaricom line.
  6. Wait for approval. Daraja's FAQ says requests are approved within 24 working hours (Monday to Friday, 8am to 5pm). Evenings and weekends don't count.
  7. Collect your production keys. Your app moves to production with a new consumer key and consumer secret. Your sandbox keys will not work in production.
  8. Check your email for the production passkey. It is not shown next to the keys. Safaricom emails it to the developer account's email address after go-live.

Paybill or Till: which numbers go where

Both work with STK Push. The difference is which number you use in which place.

Paybill

  • Go-live shortcode: your Paybill number.
  • STK Push: BusinessShortCode is the Paybill number, and TransactionType is CustomerPayBillOnline.

Till (Buy Goods)

  • Go-live shortcode: your Store (head-office) number.
  • STK Push, per Daraja's FAQ:
BusinessShortCode: <store / head-office number>
PartyB:            <till number>
TransactionType:   CustomerBuyGoodsOnline

The store number and the Till number go in different fields, so write both down before you start. Till and Paybill payments are also charged under different Safaricom tariffs: see our guide to what the M-Pesa API costs.

Keeping your keys safe

Anyone with your live consumer key, consumer secret and passkey can send payment requests in your business's name. Treat them like the PIN to your Paybill.

  • Server only. Keep them in environment variables or a secrets store on your server, never in code you commit.
  • Never in a front end. Not in a web page, not in a mobile app, and not in the front end of a site built with an AI builder. Anything that runs in the visitor's browser or on their phone can be read by them.
  • Don't paste them into chats. That includes WhatsApp groups, support forums and AI chat tools.
  • Replace them if they leak. If you have ever pasted the keys somewhere public, treat them as leaked: get new ones and update every place that uses them.
  • Keep sandbox and live apart. Label them clearly so test keys never end up in your live setup, or the other way round.

Using your keys with KenZobe Checkout

Getting keys is only the start. You still need a server to request tokens, build the STK password, receive Safaricom's callbacks and confirm each payment. Doing that yourself is a fair choice if you have a developer. KenZobe Checkout, our own product, is another option: it does that work for you and gives you a hosted checkout, payment links, a pay button for any website, a REST API and webhooks.

You bring your own Daraja app and your own Paybill or Till. Customer money goes straight into your Paybill or Till; KenZobe never receives or holds it. To be clear about the limits: it handles M-Pesa only, and for live payments you still need the Daraja keys and go-live described above.

  1. Sign up free. Your account starts in test mode (sandbox). You can try a test payment straight away using KenZobe's own sandbox app, before you even have Daraja keys.
  2. Paste your sandbox keys in the dashboard when you have them: consumer key, consumer secret and passkey, plus your shortcode.
  3. Paste your live keys after go-live. For a Paybill, enter the Paybill number. For a Till, enter the store number and the till number. KenZobe uses each in the right place.
  • Encrypted and never shown again. Keys are encrypted when you save them, and the dashboard never displays them back to you.
  • Live changes re-ask your password. Saving, replacing or deleting live keys asks for your password again at that moment. Two-step sign-in (an authenticator app) must be on before live keys can be saved.
  • Live payments open with a paid monthly plan, paid by M-Pesa. Sandbox testing is free.

To add a payment button to your site once your keys are in, see how to add an M-Pesa pay button. For the bigger picture of every way to take M-Pesa online, start with how to accept M-Pesa payments on your website.

Frequently Asked Questions

Where do I find the passkey for production?+

Not in the portal next to your keys. After Safaricom approves your go-live, the app moves to production with a new consumer key and consumer secret, and the production passkey is sent to the email address on your Daraja developer account. If you cannot find it, check that inbox (and its spam folder). The sandbox passkey is different: it is the public test passkey shown in the Daraja simulator.

Can I use a Till number instead of a Paybill?+

Yes. Daraja's FAQ says STK Push works for a Till too. At go-live you enter your Store (head-office) number as the shortcode, not the Till number. In the STK Push request, BusinessShortCode is that store number, PartyB is your Till number, and TransactionType is CustomerBuyGoodsOnline. For a Paybill, the shortcode is the Paybill number and TransactionType is CustomerPayBillOnline.

Why does Daraja go-live ask for an M-Pesa username?+

Safaricom needs someone with authority over the shortcode to approve the request. The username must belong to a Business Administrator or Business Manager on the M-Pesa Org Portal (org.ke.m-pesa.com), and it is case-sensitive. A one-time code (OTP) is sent to that person's Safaricom line. If nobody in your business has that role yet, you have to get one set up first by sending Safaricom a signed and stamped letter on company letterhead with the person's ID details to M-PESABusiness@Safaricom.co.ke.

How long does it take to get live Daraja keys?+

Sandbox keys appear as soon as you create an app. For live keys, Daraja's FAQ says go-live requests are approved within 24 working hours (Monday to Friday, 8am to 5pm). That clock only starts once you can submit the request, so if you still need an Org Portal Business Administrator, allow extra time for that step. Safaricom does not publish how long that takes.

Is it free to get M-Pesa API keys?+

Safaricom lists no fee for using the Daraja API itself, in sandbox or production. What you pay are the normal M-Pesa tariffs on each payment that reaches your Paybill or Till. There is a fuller breakdown in our guide "Is the M-Pesa API free?" at kenzobe.com/blog/is-mpesa-api-free.

Can I put my consumer key and secret in my website or app?+

No. The consumer key, consumer secret and passkey belong on a server only. Anything in a web page, a mobile app or the front end of an AI-built site can be read by anyone who opens it. If you have ever pasted them somewhere public, treat them as leaked and replace them.

Next step

Get your sandbox keys today; it takes minutes. Start the Org Portal administrator step at the same time if you don't have one, because that is the slow part of going live.

If you would rather not build the payment server yourself, try it free in sandbox or try the demo checkout first (no real prompt is sent). If you want someone to set up the whole thing for you, talk to our team.