Skip to content
M-Pesa & Payments

M-Pesa for Online Business: Every Payment Option Compared

Updated 11 min read

On this page
  1. How online M-Pesa payments work
  2. Option 1: Manual payments with confirmation
  3. Option 2: STK push via Daraja
  4. Option 3: Payment aggregators and gateways
  5. Option 4: Cards and diaspora payments
  6. The four options side by side
  7. Reconciliation compared
  8. A note on Till versus Paybill
  9. Which option fits your business
  10. Questions to ask before you commit
  11. Getting it built

There are four realistic mpesa payment options for an online business in Kenya: a manual Till or Paybill with someone confirming payments, STK push built directly on Safaricom's Daraja API, a payment aggregator that bundles M-Pesa with other methods, and a card gateway for buyers who do not use M-Pesa at all. They differ far more in daily admin work than in what the customer sees. This guide puts all four side by side so you can pick by setup effort, reconciliation and checkout experience rather than by whichever plugin you heard about first.

If you want the background on why integration matters in the first place, our earlier piece on M-Pesa integrated websites covers that. Here we focus on the choice between routes.

How online M-Pesa payments work

Every M-Pesa payment, online or at a shop counter, moves money from a customer's wallet to a business shortcode. A shortcode is either a Till number (Buy Goods) or a Paybill number. What changes between the options below is who starts the payment and how your website finds out it happened.

  • Customer-started payments. The buyer opens the M-Pesa menu or app, types your number and amount, and pays. Your website knows nothing unless someone tells it, or unless your shortcode is registered to send confirmations to your server.
  • Business-started payments. Your website asks Safaricom to send a payment prompt to the buyer's phone. The buyer only enters a PIN. Safaricom then reports the result back to your server.

Personal numbers and Pochi la Biashara sit outside both models for websites. They are fine for a side hustle on WhatsApp, but there is no supported way for a website to receive automatic confirmations from them, and mixing business takings with a personal wallet makes bookkeeping and KRA records harder.

Option 1: Manual payments with confirmation

This is the starting point for most small sellers. Your checkout page shows your Till or Paybill number, the customer pays from their phone, and then they either paste the M-Pesa confirmation code into a box or send it on WhatsApp. A person on your side checks the M-Pesa statement or SMS and marks the order as paid.

Where it works

  • Low order volumes, say a few orders a day, where one person can check every payment.
  • Made-to-order goods where you talk to the customer anyway before delivery.
  • Testing an idea before spending money on integration.

Where it hurts

Every step depends on a human. Orders placed at 11pm sit unconfirmed until morning. Customers mistype the Till number and pay a stranger. Two buyers pay the same amount within minutes and your staff cannot tell which code belongs to which order. On a Paybill the account number field helps, but only if customers type it correctly, and many do not.

A small improvement costs nothing: ask customers to use their order number as the Paybill account reference, and show that reference in large text on the order confirmation page. It will not remove the manual check, but it shortens it.

Option 2: STK push via Daraja

STK push, which Safaricom brands as M-Pesa Express or Lipa Na M-Pesa Online, is the "prompt on your phone" experience Kenyans already know from paying utility bills and shopping apps. Your website sends Safaricom a request with the amount, your shortcode and the buyer's phone number. The buyer sees a prompt, enters their PIN, and Safaricom sends the outcome to a callback address on your server. We explain the full flow and its failure cases in what M-Pesa STK push is and how it works.

What it takes

  • A Till or Paybill registered to your business, with access to the M-Pesa organisation portal.
  • An account on Safaricom's developer portal, Daraja, and approval to move from the sandbox to live credentials.
  • Hosting with a valid SSL certificate so Safaricom can reach your callback address over HTTPS.
  • A developer to build the request, the callback handler and the logic that updates orders.

Why businesses choose it

Nobody types a business number, so the "paid the wrong Till" problem disappears. The order reference travels with the request, so matching is automatic. Money lands directly in your own shortcode with no middleman holding it, and you only pay Safaricom's normal charges for your account type.

The trade-off is ownership. You, or whoever maintains your site, are responsible for keeping credentials safe, renewing anything that expires and fixing the integration when something changes. If you want to understand the owner's side of that, read Safaricom Daraja explained for business owners.

Option 3: Payment aggregators and gateways

An aggregator is a licensed company that has already integrated with M-Pesa, Airtel Money, card networks and sometimes bank transfers. You sign up with them, install their plugin or embed their checkout, and they handle the connections. Names you will come across in Kenya include Pesapal, Flutterwave and DPO Pay, among others. Availability, onboarding requirements and features change, so confirm the current position with each provider before committing.

How the money moves

With most aggregators, the customer pays the aggregator's collection account, not your shortcode. The aggregator then settles the balance to your bank account or M-Pesa on a schedule, after deducting its fees. Some offer settlement within a day or two; others hold funds longer, especially for new merchants. Ask for the settlement schedule in writing.

Strengths

  • One integration gives you M-Pesa, Airtel Money and cards together.
  • Ready-made plugins for WooCommerce, Shopify and other platforms, so setup can be quick.
  • The aggregator carries much of the card-security burden, which matters a lot if you take Visa or Mastercard.

Weaknesses

  • Fees stack: the aggregator charges a percentage or fixed fee on top of the underlying network cost. Each provider publishes its own pricing page, and those figures change, so compare current rates rather than old blog posts.
  • Your money waits for settlement instead of arriving in your shortcode instantly.
  • Customers may see the aggregator's name on the prompt or receipt rather than yours, which can cause "who is this?" hesitation.
  • If the aggregator has an outage or freezes your account during a review, you cannot take payments until it is resolved.

Option 4: Cards and diaspora payments

M-Pesa covers most local buyers. It does not cover a tourist booking a safari lodge from Germany, a corporate client whose finance team pays by company card, or a Kenyan in Dallas paying school fees for a nephew. For them you need a card gateway, which in practice usually means an aggregator or a bank's own e-commerce acquiring service.

Card payments bring obligations M-Pesa does not. Card data falls under the PCI DSS security standard, which is why almost every small business should use a hosted payment page where the card details are typed on the gateway's site, not yours. Card payments can also be disputed through chargebacks weeks after the sale. We compare these differences by customer type in M-Pesa vs card payments online, and the diaspora angle in particular in how to accept payments from diaspora customers.

The four options side by side

FactorManual Till/PaybillSTK push (Daraja)AggregatorCard gateway
Setup effortMinutesDeveloper work plus Safaricom go-liveSign-up, KYC review, pluginUsually via aggregator or bank; KYC review
Customer types business number?YesNo, just a PINNo for M-Pesa prompt; variesTypes card details on hosted page
Order marked paidBy a personAutomatically on callbackAutomatically via webhookAutomatically via webhook
Where money landsYour shortcode, instantlyYour shortcode, instantlyAggregator, then settled to youGateway, then settled to you
FeesSafaricom tariff onlySafaricom tariff onlyNetwork cost plus aggregator feeCard processing fee
Who maintains itNobody (but staff time daily)You or your developerMostly the aggregatorMostly the gateway
Reaches non-M-Pesa buyersNoNoOften yesYes

Safaricom publishes the current M-Pesa business tariffs on its website, and charges differ between Till and Paybill accounts and between tariff types. Check those directly, because any figure we printed here would date quickly.

Reconciliation compared

Reconciliation is the boring question that decides which option you can live with. It means proving that every shilling received matches an order, an invoice or a refund, and that every paid order has a matching shilling.

  • Manual: your team compares the M-Pesa statement (downloadable from the organisation portal) against the order list, line by line. It works at low volume and becomes a daily chore as you grow. Duplicate amounts and missing references are where errors creep in.
  • STK push: each callback carries the M-Pesa receipt number, the amount and the reference your site sent. Matching is automatic for those payments. You still need a routine for the odd customer who pays manually to the same shortcode, which is why many integrations also register for Daraja's C2B confirmations.
  • Aggregator: the aggregator's dashboard matches payments to your orders, but you now reconcile twice: orders against the aggregator's records, then the aggregator's settlement against what reached your bank, minus fees.
  • Cards: similar to aggregators, with the extra step of tracking chargebacks and refunds that may arrive weeks later.

The account reference convention you choose matters more than the tool. Our M-Pesa reconciliation guide sets out references that make matching work, and what to do with overpayments and part-payments.

A note on Till versus Paybill

Every option above starts with a shortcode, and the type you hold shapes what is possible. A Till has no account number, so manual payments cannot carry an order reference. A Paybill does, which helps anyone paying outside your checkout. Both support STK push. If you are still choosing, our comparison of Till vs Paybill for a website goes through it from the integration side.

Which option fits your business

Use these rules as a starting point. They assume the business is registered and has, or can get, its own shortcode.

Choose manual Till or Paybill if

  • You take fewer than a handful of online orders a day and someone is always near the phone.
  • You are testing demand and do not want to commit money yet.

Choose STK push via Daraja if

  • Most of your customers are in Kenya and pay with M-Pesa.
  • Payment volume is steady enough that staff time on checking payments is noticeable.
  • You want money in your own shortcode immediately and only Safaricom's charges.
  • You have a developer or support arrangement to maintain it.

Choose an aggregator if

  • You need M-Pesa and cards in one checkout and want someone else to carry the card compliance.
  • You run on a platform with an existing plugin and do not have a developer on call.
  • You can accept settlement delays and an extra fee in exchange for less maintenance.

Add cards if

  • You sell to tourists, the diaspora, NGOs or corporates whose staff pay by card.
  • Your average order is large enough that losing a card buyer costs real money.

A worked example

Say a Nakuru bakery takes cake orders online, around 15 a day, with a deposit by M-Pesa. Today one staff member spends the first hour of every morning matching overnight payments to orders on WhatsApp. With STK push, the deposit request goes out at checkout, the order turns green on the dashboard when the callback lands, and that hour is freed. Cards would add little, because almost every customer is local. An aggregator would work too, but the bakery would wait for settlement and pay an extra fee for a card option it barely needs. Direct STK push is the better fit here.

Now picture a Diani boutique hotel where half the bookings come from overseas. M-Pesa alone would lose those guests at checkout. An aggregator with cards plus M-Pesa in one flow is the sensible choice, possibly with direct STK push added later for local walk-in deposits.

Questions to ask before you commit

  1. Is the Till or Paybill registered to the business, and who holds the organisation portal login?
  2. If we use an aggregator, how long do payouts take, and what triggers a hold on our account?
  3. Whose name does the customer see on the payment prompt and the SMS?
  4. How does the system record a payment that arrives without a matching order?
  5. Who fixes it, and how fast, if payments stop reflecting on a Saturday?
  6. Can we export a monthly report our accountant can match to the bank or M-Pesa statement?

If the answers to the last two are vague, keep looking. A payment option is only as good as the support behind it.

Getting it built

We build M-Pesa checkouts on business websites and stores, and payment flows inside custom systems where invoices, fees or bookings need to clear themselves. The web development service page explains how we work, and if payments are part of a larger internal system, see system development. For a sense of overall budgets, our website cost guide for Kenya lists starting prices, all plus 16% VAT.

FAQ

Questions about this topic

You can receive money on a personal line or Pochi la Biashara, but neither connects to a website through Safaricom's Daraja API, so every payment has to be checked by hand. Automated options such as STK push need a Till or Paybill registered to the business. Many aggregators also ask for registration documents before they pay out, so registering early saves time later.

Not usually on a per-transaction basis, because the aggregator adds its own fee on top of what the payment network charges. What you save is setup and maintenance work, since the aggregator holds the integration and often adds cards in the same checkout. Compare the published fee pages of each provider against your expected monthly volume before deciding.

For a manual Till or Paybill on a contact page, no. For STK push through Daraja, yes, because someone has to write and host the code that talks to Safaricom and listens for callbacks. Hosted aggregator links sit in between: many small businesses paste a link or install a ready-made plugin, though a developer helps with order updates.

For a shop doing a handful of orders a week, a Till number with clear instructions can work for a while. Once orders arrive daily, STK push or an aggregator saves real staff time because orders update themselves. If you also sell to tourists or diaspora buyers, an aggregator that bundles M-Pesa and cards is often the simplest single checkout.

Ready to build something great?

Tell us what you need. We'll come back with a fixed-scope proposal within one business day.

Start a conversation
Chat with us