Download the PHP package siberfx/mpesa-payment without Composer

On this page you can find all versions of the php package siberfx/mpesa-payment. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package mpesa-payment

M-Pesa Payment Gateway for PHP & Laravel

A modern, fully typed M-Pesa integration for PHP 8.4 / 8.5, usable standalone or with Laravel 12 / 13.

Market API Driver
πŸ‡°πŸ‡ͺ Kenya (Safaricom) Daraja daraja
πŸ‡ΉπŸ‡Ώ Tanzania (Vodacom) M-Pesa OpenAPI openapi
πŸ‡¨πŸ‡© DR Congo (Vodacom) M-Pesa OpenAPI openapi
πŸ‡±πŸ‡Έ Lesotho (Vodacom) M-Pesa OpenAPI openapi

Contents

Features

Daraja (Kenya)

Vodacom OpenAPI (Tanzania, DRC, Lesotho)

Engineering

Requirements

Installation


Standalone usage

Multiple accounts and markets

Pass any PSR-16 cache (Redis, APCu, filesystem…) so access tokens survive between requests. Without one, an in-memory cache is used for the lifetime of the object.


Laravel usage

The service provider and Mpesa facade are auto-discovered. Publish the config:

Minimal .env for Kenya:

Or inject Siberfx\MpesaPayment\Mpesa anywhere the container resolves dependencies.

Callback routes and events

The package registers these POST routes (prefix configurable via MPESA_ROUTES_PREFIX, default payments/callbacks):

Route Event
/payments/callbacks/stk StkCallbackReceived
/payments/callbacks/c2b/validation C2BValidationReceived
/payments/callbacks/c2b/confirmation C2BConfirmationReceived
/payments/callbacks/result/{type?} ResultReceived
/payments/callbacks/timeout/{type?} TimeoutReceived
/payments/callbacks/b2b-checkout B2BCheckoutCallbackReceived
/payments/callbacks/ratiba StandingOrderCallbackReceived

Any callback URL you leave empty in the config is filled in automatically from these routes, using MPESA_CALLBACK_BASE_URL (or APP_URL), with ?account=<name>&token=<MPESA_CALLBACK_TOKEN> appended. Events live in Siberfx\MpesaPayment\Laravel\Events:

Note: Safaricom rejects C2B URLs containing words such as mpesa, safaricom, exe, cmd, sql or query, which is why the default prefix is payments/callbacks.

Validating C2B payments

Then register your URLs with Safaricom:

Securing callbacks


API reference (Daraja)

All methods return an ApiResponse (accepted(), failed(), description(), get(), toArray(), array access, plus helpers such as checkoutRequestId() and conversationId()).

STK push (M-Pesa Express)

C2B

B2C

B2B and B2B Express Checkout

Balance, status, reversal

The final results arrive on your result URL; parse them with ResultCallback::fromArray($payload). For balances, $result->balances() returns structured rows.

Dynamic QR

KRA tax remittance

M-Pesa Ratiba (standing orders)

API reference (Vodacom OpenAPI)

These APIs are synchronous β€” the response already contains the final result (output_ResponseCode INS-0 on success).

Known markets (vodacomTZN, vodacomDRC, vodacomLES) get their country and currency automatically. For other markets on the same platform, set country, currency and country_code explicitly. For DRC, set currency to CDF if you settle in Congolese francs.

Callback parsing without Laravel

Complete examples

1. Laravel checkout with STK push (end to end)

Migration β€” keep the identifiers M-Pesa gives you, you will need them to match callbacks:

Controller β€” start the payment:

Listener β€” the callback is the source of truth:

Fallback job β€” covers callbacks that never arrive:

2. Paybill (C2B) payments with invoice validation

3. B2C payouts with traceable IDs

4. Plain PHP (no framework) with a file cache

5. Tanzania checkout (Vodacom OpenAPI)

6. Daily balance check (scheduled)


Pitfalls & best practices

These are the mistakes that most often cost money or hours in M-Pesa integrations. Read them before going live.

"Accepted" is not "paid"

$response->accepted() on an STK push, B2C, B2B, balance or reversal request only means M-Pesa queued the request. The outcome arrives later on your callback. Mark an order as paid only when the callback (or an STK query) reports result code 0. Also check that the amount in the callback matches what you expected.

Callbacks are unreliable: design for it

Never blindly resend a payment

If a B2C/B2B/reversal request throws ConnectionException (for example a timeout), the money may already have moved. The package deliberately does not retry in that case. Before resending, check with transactionStatus(originatorConversationId: ...) using the ID you passed in. That is why passing your own originatorConversationId is strongly recommended.

Callback URLs

Credentials and environments

Data rules the API enforces

Vodacom OpenAPI specifics

Operational


Error handling

Exception When
ConfigurationException Missing credentials, callback URLs or unknown accounts
ValidationException Invalid phone numbers, amounts or arguments
AuthenticationException Token or session could not be obtained
RequestException The API returned an HTTP error (statusCode, errorCode, requestId, body)
ConnectionException The API could not be reached

All extend Siberfx\MpesaPayment\Exceptions\MpesaException.

Testing

To test your own code, pass a Guzzle client with a MockHandler to Mpesa::make(..., http: $client), or bind a pre-configured Mpesa instance in the Laravel container.

Security

If you discover a security issue, please email [email protected] instead of opening a public issue.

License

The MIT License (MIT). See LICENSE.md.


All versions of mpesa-payment with dependencies

PHP Build Version
Package Version
Requires php Version ~8.4.0 || ~8.5.0
ext-json Version *
ext-openssl Version *
guzzlehttp/guzzle Version ^7.9
psr/log Version ^3.0
psr/simple-cache Version ^3.0
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package siberfx/mpesa-payment contains the following files

Loading the files please wait ...