MCP server for M-PESA Daraja API — STK push, B2C, balance, status. 7 tools.
- ✓Open-source license (MIT)
- ✓Actively maintained (<30d)
- ✓Clear description
- ✓Topics declared
- ✓Documented (README)
claude mcp add mpesa-mcp -- uvx mpesa-mcp{
"mcpServers": {
"mpesa-mcp": {
"command": "uvx",
"args": ["mpesa-mcp"],
"env": {
"MPESA_CONSUMER_KEY": "<mpesa_consumer_key>",
"MPESA_CONSUMER_SECRET": "<mpesa_consumer_secret>",
"MPESA_CALLBACK_URL": "<mpesa_callback_url>",
"AT_USERNAME": "<at_username>",
"AT_API_KEY": "<at_api_key>"
}
}
}
}MPESA_CONSUMER_KEYMPESA_CONSUMER_SECRETMPESA_CALLBACK_URLAT_USERNAMEAT_API_KEYMCP Servers overview
# mpesa-mcp
<!-- mcp-name: io.github.gabrielmahia/mpesa-mcp -->
> MCP server for East African fintech APIs — M-Pesa (Safaricom Daraja) and Africa's Talking
Give your AI agent the ability to trigger M-Pesa payments, check transaction status, send SMS, and top up airtime across 20+ African telecom networks.
[](https://github.com/gabrielmahia/mpesa-mcp/actions)
[](https://pypi.org/project/mpesa-mcp/)
[](LICENSE)
[](https://glama.ai/mcp/servers/gabrielmahia/mpesa-mcp)
[](https://smithery.ai/server/@gabrielmahia/mpesa-mcp)
[](https://glama.ai/mcp/servers/gabrielmahia/mpesa-mcp)
[](https://www.nsa.gov/Portals/75/documents/Cybersecurity/CSI_MCP_SECURITY.pdf)
[](https://glama.ai/mcp/servers/gabrielmahia/mpesa-mcp)
## Tested With
```
claude-sonnet-5 (recommended — call get_model_hint() for guidance)
claude-opus-4-8 (for highest-accuracy compliance reasoning)
```
Claude Sonnet 5 (released June 30, 2026) finishes multi-step M-PESA workflows
without stopping short and self-corrects tool-call errors without prompting.
Terminal-Bench score 80.4% vs Sonnet 4.6's 67.0% — the benchmark most
analogous to payment agent work.
## Why this exists
M-Pesa processes more transactions per day than PayPal does in Africa. Africa's Talking
reaches users in 20+ countries on basic phones via SMS and USSD. Neither has an MCP server.
This means every AI agent built today — Claude, GPT, Gemini, or any MCP-compatible runtime —
cannot trigger an M-Pesa payment or send a Kiswahili SMS without custom integration work.
`mpesa-mcp` closes that gap in one `pip install`.
## Tools
| Tool | Description |
|---|---|
| `mpesa_stk_push` | Trigger STK Push payment prompt on customer's M-Pesa phone |
| `mpesa_stk_query` | Check status of an STK Push request |
| `mpesa_transaction_status` | Query any M-Pesa transaction by receipt number |
| `sms_send` | Send SMS to 1–1,000 recipients across African networks |
| `airtime_send` | Send airtime top-up to any subscriber (KES, NGN, GHS, UGX, etc.) |
## Coverage
- **M-Pesa:** Kenya (Safaricom Daraja v3) — STK Push, C2B, transaction status
- **SMS/Airtime:** Kenya, Nigeria, Ghana, Tanzania, Uganda, Rwanda, South Africa, and 15+ more via Africa's Talking
## Glama (hosted MCP)
mpesa-mcp is available as a hosted MCP server on [Glama](https://glama.ai/mcp/servers/gabrielmahia/mpesa-mcp):
[](https://glama.ai/mcp/servers/gabrielmahia/mpesa-mcp)
[](https://glama.ai/mcp/servers/gabrielmahia/mpesa-mcp)
## Security — NSA MCP Guidance Compliant
`mpesa-mcp` was updated in response to **NSA CSI U/OO/6030316-26 (May 2026)** — the NSA Artificial Intelligence Security Center's Cybersecurity Information Sheet on Model Context Protocol security.
The implementation below documents compliance against the NSA's MCP security framework, control by control.
| NSA Control | Implementation |
|---|---|
| Parameter validation | KE phone regex `^254[17]\d{8}$` + amount bounds [1–150,000 KES] |
| Audit logging | Structured log per tool call; phone numbers SHA-256 hashed |
| Token lifecycle | OAuth token cached with expiry; auto-refreshed |
| Error containment | Structured error dicts; no raw exception propagation |
| HTTPS enforcement | All Daraja API calls HTTPS-only |
| No hardcoded secrets | All credentials via environment variables |
See [SECURITY.md](./SECURITY.md) for the full compliance table.
> **Reference:** [NSA CSI_MCP_SECURITY.pdf](https://www.nsa.gov/Portals/75/documents/Cybersecurity/CSI_MCP_SECURITY.pdf) — May 2026, UNCLASSIFIED
## Install
```bash
pip install mpesa-mcp
```
Or run directly with `uvx`:
```bash
uvx mpesa-mcp
```
## Configuration
Set these environment variables before starting the server:
```bash
# M-Pesa (Safaricom Daraja)
MPESA_CONSUMER_KEY=your_consumer_key
MPESA_CONSUMER_SECRET=your_consumer_secret
MPESA_SHORTCODE=174379 # sandbox test shortcode
MPESA_PASSKEY=your_passkey
MPESA_CALLBACK_URL=https://yourdomain.com/mpesa/callback
MPESA_SANDBOX=true # set false for production
# Africa's Talking
AT_USERNAME=sandbox # your AT username (sandbox for testing)
AT_API_KEY=your_at_api_key
```
### Sandbox credentials
New Daraja account, or setting this up on a new machine? Follow the [sandbox setup guide](https://github.com/gabrielmahia/mpesa-python/blob/main/docs/SANDBOX_SETUP.md): it records the verified procedure (create the app with only **Lipa Na M-Pesa Sandbox** ticked, use the published test shortcode and passkey, point `MPESA_CALLBACK_URL` at a public HTTPS address you can watch) and what a healthy result looks like. Consumer keys cannot be shared, so each developer creates their own free sandbox app.
**M-Pesa sandbox:** https://developer.safaricom.co.ke — create a free app to get test credentials.
- Test shortcode: `174379`
- Test passkey: `bfb279f9aa9bdbcf158e97dd71a467cd2e0c893059b10f78e6b72ada1ed2c919`
**Africa's Talking sandbox:** https://account.africastalking.com — use `username=sandbox`, any API key.
## Usage with Claude Desktop
Add to `~/Library/Application Support/Claude/claude_desktop_config.json` (macOS):
```json
{
"mcpServers": {
"mpesa": {
"command": "uvx",
"args": ["mpesa-mcp"],
"env": {
"MPESA_CONSUMER_KEY": "your_key",
"MPESA_CONSUMER_SECRET": "your_secret",
"MPESA_SHORTCODE": "174379",
"MPESA_PASSKEY": "your_passkey",
"MPESA_CALLBACK_URL": "https://yourdomain.com/mpesa/callback",
"MPESA_SANDBOX": "true",
"AT_USERNAME": "sandbox",
"AT_API_KEY": "your_at_key"
}
}
}
}
```
## Usage with Claude Code
```bash
claude mcp add mpesa -- uvx mpesa-mcp
```
Set env vars in your shell before running `claude`.
## Example prompts
Once connected, you can ask your AI agent:
> "Send KES 500 STK Push to +254712345678 for order #1234"
> "Check if the payment QKL8ABC123 has been received"
> "Send an SMS to these 50 farmers with today's maize price: [list]"
> "Top up KES 50 airtime for our field agents: [list of numbers]"
## Real-world scenarios
**Field agent payment dispatch**
> "Send KES 300 STK Push to each of these 12 field agents for today's data collection: [list]"
The agent triggers 12 sequential STK pushes, tracks each `checkout_request_id`, and
polls for confirmation — without any code from you.
**Farmer alert + airtime**
> "SMS these 200 Garissa farmers that the river is rising. Then top up KES 20 airtime each so they can call in reports."
One prompt → 200 SMS messages and 200 airtime top-ups across Safaricom, Airtel, and Telkom.
**Payment reconciliation**
> "Check whether receipt OKL8M3B2HF was a successful payment and how much it was for"
Useful for support agents using Claude to verify M-Pesa transactions in real time.
## Tool annotations
All tools declare [MCP tool annotations](https://spec.modelcontextprotocol.io/specification/2025-03-26/server/tools/#tool-annotations) so clients can gate calls appropriately:
| Tool | readOnly | destructive | idempotent |
|------|----------|-------------|------------|
| `mpesa_stk_push` | ❌ | ✅ | ❌ |
| `mpesa_stk_query` | ✅ | ❌ | ✅ |
| `mpesa_transaction_status` | ✅ | ❌ | ✅ |
| `sms_send` | ❌ | ✅ | ❌ |
| `airtime_send` | ❌ | ✅ | ❌ |
Claude Desktop and other MCP clients will request confirmation before triggering payment, SMS, or airtime operations.
## Server discovery
Capabilities are advertised via [`.well-known/mcp.json`](.well-known/mcp.json) — the emerging MCP Server Cards standard. Registries and browsers can index this server's tools without connecting to it.
```bash
# Check capabilities
curl https://raw.githubusercontent.com/gabrielmahia/mpesa-mcp/main/.well-known/mcp.json
```
## Testing and accuracy
The MCP ecosystem benchmark (CData, 2026) found most MCP servers accurate 60–75% of the time on complex queries — particularly silent failures on write operations and partial parameter application.
mpesa-mcp is tested against all three Kenyan phone number formats, boundary amount values, and missing optional fields:
```bash
pytest tests/ -v # run full suite
pytest tests/test_phone_formats.py # format normalization
pytest tests/test_boundary_amounts.py # min/max amount edge cases
```
Write operations (STK push, SMS, airtime) have explicit validation before any API call is made.
## Ecosystem context — Mojaloop + MCP
**Mojaloop** (funded by the Gates Foundation) handles payment *interoperability* — connecting banks, mobile money wallets, and merchants across DFSPs in East Africa and beyond.
**mpesa-mcp** handles the *AI agent tooling layer* — enabling AI coding assistants to trigger and query M-Pesa payments programmatically.
These are complementary:
- Mojaloop: the interoperability rails between financial providers
- mpesa-mcp: the MCP interface layer that connects AI agents to those rails
See the [Mojaloop documentation contribution](https://github.com/mojaloop/documentation/issues/553) for more on this pattern.
## MCP vs A2A — two different protocols
mpesa-mcp implements **MCP** (Model Context Protocol) — how an AI agent talks to tools.
There is a complementary protocol, **A2A** (Agent-to-Agent), which handles how agents
talk to *each other*. They soWhat people ask about mpesa-mcp
What is gabrielmahia/mpesa-mcp?
+
gabrielmahia/mpesa-mcp is mcp servers for the Claude AI ecosystem. MCP server for M-PESA Daraja API — STK push, B2C, balance, status. 7 tools. It has 4 GitHub stars and its last recorded update is dated 2026-10-10.
How do I install mpesa-mcp?
+
You can install mpesa-mcp by cloning the repository (https://github.com/gabrielmahia/mpesa-mcp) or following the README instructions on GitHub. ClaudeWave also provides quick install blocks on this page.
Is gabrielmahia/mpesa-mcp safe to use?
+
Our security agent has analyzed gabrielmahia/mpesa-mcp and assigned a Trust Score of 95/100 (tier: Verified). See the full breakdown of passed checks and flags on this page.
Who maintains gabrielmahia/mpesa-mcp?
+
gabrielmahia/mpesa-mcp is maintained by gabrielmahia. The last recorded GitHub activity is dated 2026-10-10, with 0 open issues.
Are there alternatives to mpesa-mcp?
+
Yes. On ClaudeWave you can browse similar mcp servers at /categories/mcp, sorted by popularity or recent activity.
Deploy mpesa-mcp to your cloud
Ship this repo to production in minutes. Each platform spins up its own environment with editable env vars.
Maintain this repo? Add a badge to your README
Drop the badge into your GitHub README to show it's tracked on ClaudeWave. Each badge links back to this page and reflects the live Trust Score.
[](https://claudewave.com/repo/gabrielmahia-mpesa-mcp)<a href="https://claudewave.com/repo/gabrielmahia-mpesa-mcp"><img src="https://claudewave.com/api/badge/gabrielmahia-mpesa-mcp" alt="Featured on ClaudeWave: gabrielmahia/mpesa-mcp" width="320" height="64" /></a>More MCP Servers
Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.
User-friendly AI Interface (Supports Ollama, OpenAI API, ...)
An open-source AI agent that brings the power of Gemini directly into your terminal.
Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface
🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
The fastest path to AI-powered full stack observability, even for lean teams.