MCP server for M-Pesa mobile-money integration in Kenya
M-Pesa MCP Server (io.github.gabrielmahia/mpesa-mcp)
M-Pesa MCP server for mobile-money integration in Kenya. It targets East African fintech APIs including M-Pesa via Safaricom Daraja. The server provides capabilities for triggering payments, checking transaction status, sending SMS, and topping up airtime across 20+ African telecom networks.
๐ ๏ธ Key Features
M-Pesa integration using Safaricom Daraja
Trigger M-Pesa payments
Check transaction status
Send SMS
Top up airtime across 20+ African telecom networks
๐ Use Cases
Enable AI agents to perform M-Pesa payment actions
Monitor and verify transaction outcomes
Initiate SMS notifications related to payment flows
Perform airtime top-ups for telecom users
โก Developer Benefits
Open-source MCP server for the Model Context Protocol
Python-focused integration (topics include python)
Packaged for distribution (PyPI badge shown in readme excerpt)
CI workflow present (tests badge shown in readme excerpt)
โ ๏ธ Limitations
The provided excerpt does not describe configuration details, authentication, or available MCP tools/count.
Claude Sonnet 5 (released June 30, 2026) finishes multi-step M-PESA workflows
without stopping short and self-corrects tool-call errors without prompting.
Terminal-Bench score 80.4% vs Sonnet 4.6's 67.0% โ the benchmark most
analogous to payment agent work.
Why this exists
M-Pesa processes more transactions per day than PayPal does in Africa. Africa's Talking
reaches users in 20+ countries on basic phones via SMS and USSD. Neither has an MCP server.
This means every AI agent built today โ Claude, GPT, Gemini, or any MCP-compatible runtime โ
cannot trigger an M-Pesa payment or send a Kiswahili SMS without custom integration work.
mpesa-mcp closes that gap in one pip install.
Tools
Tool
Description
mpesa_stk_push
Trigger STK Push payment prompt on customer's M-Pesa phone
mpesa_stk_query
Check status of an STK Push request
mpesa_transaction_status
Query any M-Pesa transaction by receipt number
sms_send
Send SMS to 1โ1,000 recipients across African networks
airtime_send
Send airtime top-up to any subscriber (KES, NGN, GHS, UGX, etc.)
Coverage
M-Pesa: Kenya (Safaricom Daraja v3) โ STK Push, C2B, transaction status
SMS/Airtime: Kenya, Nigeria, Ghana, Tanzania, Uganda, Rwanda, South Africa, and 15+ more via Africa's Talking
Glama (hosted MCP)
mpesa-mcp is available as a hosted MCP server on Glama:
Security โ NSA MCP Guidance Compliant
mpesa-mcp was updated in response to NSA CSI U/OO/6030316-26 (May 2026) โ the NSA Artificial Intelligence Security Center's Cybersecurity Information Sheet on Model Context Protocol security.
The implementation below documents compliance against the NSA's MCP security framework, control by control.
NSA Control
Implementation
Parameter validation
KE phone regex ^254[17]\d{8}$ + amount bounds [1โ150,000 KES]
Audit logging
Structured log per tool call; phone numbers SHA-256 hashed
Token lifecycle
OAuth token cached with expiry; auto-refreshed
Error containment
Structured error dicts; no raw exception propagation
Set these environment variables before starting the server:
bash
# M-Pesa (Safaricom Daraja)
MPESA_CONSUMER_KEY=your_consumer_key
MPESA_CONSUMER_SECRET=your_consumer_secret
MPESA_SHORTCODE=174379 # sandbox test shortcode
MPESA_PASSKEY=your_passkey
MPESA_CALLBACK_URL=https://yourdomain.com/mpesa/callback
MPESA_SANDBOX=true# set false for production# Africa's Talking
AT_USERNAME=sandbox # your AT username (sandbox for testing)
AT_API_KEY=your_at_api_key
Claude Desktop and other MCP clients will request confirmation before triggering payment, SMS, or airtime operations.
Server discovery
Capabilities are advertised via .well-known/mcp.json โ the emerging MCP Server Cards standard. Registries and browsers can index this server's tools without connecting to it.
The MCP ecosystem benchmark (CData, 2026) found most MCP servers accurate 60โ75% of the time on complex queries โ particularly silent failures on write operations and partial parameter application.
mpesa-mcp is tested against all three Kenyan phone number formats, boundary amount values, and missing optional fields:
bash
pytest tests/ -v # run full suite
pytest tests/test_phone_formats.py # format normalization
pytest tests/test_boundary_amounts.py # min/max amount edge cases
Write operations (STK push, SMS, airtime) have explicit validation before any API call is made.
Ecosystem context โ Mojaloop + MCP
Mojaloop (funded by the Gates Foundation) handles payment interoperability โ connecting banks, mobile money wallets, and merchants across DFSPs in East Africa and beyond.
mpesa-mcp handles the AI agent tooling layer โ enabling AI coding assistants to trigger and query M-Pesa payments programmatically.
These are complementary:
Mojaloop: the interoperability rails between financial providers
mpesa-mcp: the MCP interface layer that connects AI agents to those rails
For most integrations you only need MCP. A2A becomes relevant when you're building
multi-agent systems where a payment workflow coordinates with other specialized agents.
Do not commit API keys. Use environment variables or a secrets manager.
Report vulnerabilities to: contact@aikungfu.dev
Research Context
MCP ecosystem benchmark (CData, 2026): Most MCP servers achieve 60-75% accuracy on complex queries. mpesa-mcp includes explicit validation and bounds checking to exceed this baseline.
Swahili AI accuracy (arXiv:2509.04516, 2025): AI models produce 4ร more errors in Swahili than English. mpesa-mcp's Swahili-native tool descriptions are designed to minimize this gap for Swahili-speaking users by eliminating the translation step in tool selection.
MCP security research (arXiv:2603.18063, arXiv:2603.21642, 2026): Prompt injection via tool descriptions is the primary MCP attack vector. mpesa-mcp mitigates this through static, versioned tool descriptions and strict input validation.
This MCP server is one of 32 tools in the Kenya coordination infrastructure.
Connect it to africa-coord-bus โ
the coordination event bus that routes signals between domains automatically.
MIT licensed. Feedback via GitHub Issues only โ pull requests are not accepted. Demo data is labeled DEMO and is not suitable for operational decisions. Full policy: docs/architecture/IP_POLICY.md. Security reports: see SECURITY.md.
Part of the East Africa coordination stack
Install & run:pip install reli-cli && reli list โ 33 MCP servers on the official MCP Registry under io.github.gabrielmahia