mpesa-mcp

by gabrielmahia

Not rated
GitHub

About

MCP server for M-Pesa (Safaricom Daraja) and Africa's Talking APIs. Gives AI coding assistants — Claude Code, Cursor, GitHub Copilot — direct access to East African payment and SMS infrastructure from a single server. What it does: STK Push payments via Safaricom Daraja…

Details

Author
gabrielmahia
Categories
Productivity, Other, Communication, Finance, API

Setup

Install mpesa-mcp in your MCP client (Claude Desktop, Cursor, Windsurf, and others).

Repository: https://github.com/gabrielmahia/mpesa-mcp

Follow the installation instructions in the repository README, then restart your MCP client.

MCP server for East African fintech APIs — M-Pesa (Safaricom Daraja) and Africa's Talking

Give your AI agent the ability to trigger M-Pesa payments, check transaction status, send SMS, and top up airtime across 20+ African telecom networks.

claude-sonnet-5 (recommended — call get_model_hint() for guidance) claude-opus-4-8 (for highest-accuracy compliance reasoning)

Claude Sonnet 5 (released June 30, 2026) finishes multi-step M-PESA workflows without stopping short and self-corrects tool-call errors without prompting. Terminal-Bench score 80.4% vs Sonnet 4.6's 67.0% — the benchmark most analogous to payment agent work.

M-Pesa processes more transactions per day than PayPal does in Africa. Africa's Talking reaches users in 20+ countries on basic phones via SMS and USSD. Neither has an MCP server.

This means every AI agent built today — Claude, GPT, Gemini, or any MCP-compatible runtime — cannot trigger an M-Pesa payment or send a Kiswahili SMS without custom integration work.

mpesa-mcpcloses that gap in onepip install.

- M-Pesa:Kenya (Safaricom Daraja v3) — STK Push, C2B, transaction status
- SMS/Airtime:Kenya, Nigeria, Ghana, Tanzania, Uganda, Rwanda, South Africa, and 15+ more via Africa's Talking

mpesa-mcp is available as a hosted MCP server onGlama:

mpesa-mcpwas updated in response toNSA CSI U/OO/6030316-26 (May 2026)— the NSA Artificial Intelligence Security Center's Cybersecurity Information Sheet on Model Context Protocol security.

The implementation below documents compliance against the NSA's MCP security framework, control by control.

SeeSECURITY.mdfor the full compliance table.

Reference:NSA CSI_MCP_SECURITY.pdf— May 2026, UNCLASSIFIED

Set these environment variables before starting the server:

# M-Pesa (Safaricom Daraja) MPESA_CONSUMER_KEY=your_consumer_key MPESA_CONSUMER_SECRET=your_consumer_secret MPESA_SHORTCODE=174379 # sandbox test shortcode MPESA_PASSKEY=your_passkey MPESA_CALLBACK_URL=https://yourdomain.com/mpesa/callback MPESA_SANDBOX=true # set false for production # Africa's Talking AT_USERNAME=sandbox # your AT username (sandbox for testing) AT_API_KEY=your_at_api_key

M-Pesa sandbox:https://developer.safaricom.co.ke— create a free app to get test credentials.

- Test shortcode:174379
- Test passkey:bfb279f9aa9bdbcf158e97dd71a467cd2e0c893059b10f78e6b72ada1ed2c919

Africa's Talking sandbox:https://account.africastalking.com— useusername=sandbox, any API key.

Add to~/Library/Application Support/Claude/claude_desktop_config.json(macOS):

{ "mcpServers": { "mpesa": { "command": "uvx", "args": ["mpesa-mcp"], "env": { "MPESA_CONSUMER_KEY": "your_key", "MPESA_CONSUMER_SECRET": "your_secret", "MPESA_SHORTCODE": "174379", "MPESA_PASSKEY": "your_passkey", "MPESA_CALLBACK_URL": "https://yourdomain.com/mpesa/callback", "MPESA_SANDBOX": "true", "AT_USERNAME": "sandbox", "AT_API_KEY": "your_at_key" } } } }

Set env vars in your shell before runningclaude.

Once connected, you can ask your AI agent:

"Send KES 500 STK Push to +254712345678 for order #1234"

"Check if the payment QKL8ABC123 has been received"

"Send an SMS to these 50 farmers with today's maize price: [list]"

"Top up KES 50 airtime for our field agents: [list of numbers]"

"Send KES 300 STK Push to each of these 12 field agents for today's data collection: [list]"

The agent triggers 12 sequential STK pushes, tracks eachcheckout_request_id, and polls for confirmation — without any code from you.

"SMS these 200 Garissa farmers that the river is rising. Then top up KES 20 airtime each so they can call in reports."

One prompt → 200 SMS messages and 200 airtime top-ups across Safaricom, Airtel, and Telkom.

"Check whether receipt OKL8M3B2HF was a successful payment and how much it was for"

Useful for support agents using Claude to verify M-Pesa transactions in real time.

All tools declareMCP tool annotationsso clients can gate calls appropriately:

Claude Desktop and other MCP clients will request confirmation before triggering payment, SMS, or airtime operations.

Capabilities are advertised via.well-known/mcp.json— the emerging MCP Server Cards standard. Registries and browsers can index this server's tools without connecting to it.

# Check capabilities curl https://raw.githubusercontent.com/gabrielmahia/mpesa-mcp/main/.well-known/mcp.json

The MCP ecosystem benchmark (CData, 2026) found most MCP servers accurate 60–75% of the time on complex queries — particularly silent failures on write operations and partial parameter application.

mpesa-mcp is tested against all three Kenyan phone number formats, boundary amount values, and missing optional fields:

pytest tests/ -v # run full suite pytest tests/test_phone_formats.py # format normalization pytest tests/test_boundary_amounts.py # min/max amount edge cases

Write operations (STK push, SMS, airtime) have explicit validation before any API call is made.

Mojaloop(funded by the Gates Foundation) handles paymentinteroperability— connecting banks, mobile money wallets, and merchants across DFSPs in East Africa and beyond.

mpesa-mcphandles theAI agent tooling layer— enabling AI coding assistants to trigger and query M-Pesa payments programmatically.

- Mojaloop: the interoperability rails between financial providers
- mpesa-mcp: the MCP interface layer that connects AI agents to those rails

See theMojaloop documentation contributionfor more on this pattern.

mpesa-mcp implementsMCP(Model Context Protocol) — how an AI agent talks to tools.

There is a complementary protocol,A2A(Agent-to-Agent), which handles how agents talk toeach other. They solve different problems and work together:

- MCP: Your AI agent → mpesa-mcp → Daraja API / Africa's Talking
- A2A: Orchestrator agent ↔ payment sub-agent ↔ notification sub-agent

For most integrations you only need MCP. A2A becomes relevant when you're building multi-agent systems where a payment workflow coordinates with other specialized agents.

git clone https://github.com/gabrielmahia/mpesa-mcp cd mpesa-mcp pip install -e ".[dev]" pytest tests/ -v

Do not commit API keys. Use environment variables or a secrets manager.
Report vulnerabilities to:contact@aikungfu.dev

MCP ecosystem benchmark(CData, 2026): Most MCP servers achieve 60-75% accuracy on complex queries. mpesa-mcp includes explicit validation and bounds checking to exceed this baseline.

Swahili AI accuracy(arXiv:2509.04516, 2025): AI models produce 4× more errors in Swahili than English. mpesa-mcp's Swahili-native tool descriptions are designed to minimize this gap for Swahili-speaking users by eliminating the translation step in tool selection.

MCP security research(arXiv:2603.18063, arXiv:2603.21642, 2026): Prompt injection via tool descriptions is the primary MCP attack vector. mpesa-mcp mitigates this through static, versioned tool descriptions and strict input validation.

- wapimaji-mcp— Kenya water/drought MCP
-
civic-agent-kit— Kenya civic data MCP
-
swahili-health-mcp— Kenya DHIS2 health data MCP
-
kenya-legal-rag— Kenya legal corpus MCP
- Full portfolio:
gabrielmahia.github.io

Or watch this repo on GitHub for release notifications.

All MIT · All part of the East African civic AI stack

Part of the East Africa Coordination Stack

This MCP server is one of 32 tools in the Kenya coordination infrastructure. Connect it toafrica-coord-bus— the coordination event bus that routes signals between domains automatically.

All 32 servers:pypi.org/user/gmahiaLive demo:coord-cascade-demo

MIT licensed. Feedback via GitHub Issues only — pull requests are not accepted. Demo data is labeled DEMO and is not suitable for operational decisions. Full policy:docs/architecture/IP_POLICY.md. Security reports: seeSECURITY.md.

Part of the East Africa coordination stack

- Install & run:pip install reli-cli && reli list— 33 MCP servers on theofficial MCP Registryunderio.github.gabrielmahia
- Evaluate any model on Swahili agent tasks:
kipimo·dataset·leaderboard
- Coordinate across servers:
africa-coord-bus— offline-first event bus with a built-in Kenya routing table
- Datasets:
huggingface.co/gmahia·Docs hub:nairobi-stack

Model-agnostic by design: closed APIs, open-weight models, and small distilled models are all first-class citizens.

A public MCP server that gives AI agents access to real UK carrier phone numbers for SMS verification. Agents can rent disposable or rental numbers, pay Lightning invoices, and read incoming SMS, all through standard MCP tool calls with no authentication required.

Enables seamless integration with communication platform that allows you to reach your customers globally across any channel.

Platfone - Receive SMS & Virtual Numbers MCP

Virtual phone number platform for AI agents — rent numbers across 200+ countries, receive SMS, and manage the full activation lifecycle

Plug unlimited SMS, OTP verification, and inbound webhooks into your AI coding assistant using your paired Android phone as the gateway. Same SMS8 API key, JSON-RPC tools for every flow. No Twilio, no A2P 10DLC, no per-message fees.

Wavix is a global communications platform offering APIs for voice, SMS, 2FA, and phone numbers. Our MCP server brings these capabilities to AI agents and agentic workflows.

Remote MCP server (Streamable HTTP, read-only, no auth) at https://doc.2328.io/mcp — integration documentation for the 2328 payment platform.

Self-hosted email and SMS platform for AI agents — each agent gets a real email address, phone number, inbox, and API key.

Send SMS messages using the Aligo SMS API.

Secure agent purchasing with human-approved virtual cards.

A read-only MCP server by CData for querying live Authorize.Net data.

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.