OzuPay Payment Gateway for M-Pesa

OzuPay Payment Gateway for M-Pesa

Details
View on WordPress

OzuPay accepts M-Pesa payments in WooCommerce. Customers enter their Safaricom number at checkout and receive a payment prompt on their phone.

What’s included in the free edition

  • STK Push payments — send a payment prompt directly to the customer’s phone via the Daraja API
  • Payment waiting modal — shows payment status in real time on the confirmation page
  • Retry support — customers can resend the STK Push prompt up to 2 times if they missed it
  • Manual verification fallback — if automation fails, customers can submit their M-Pesa transaction code for admin review
  • Paybill fallback matching — matches an external Paybill payment by account reference
  • Transaction log — every Daraja API request and callback is logged for easy troubleshooting
  • Sandbox testing panel — test your Daraja credentials in the sandbox before going live
  • Health check — instant feedback on missing credentials, SSL issues, and other common misconfigurations
  • Privacy tools integration — supports WooCommerce personal-data export and erasure
  • HPOS compatible — works with WooCommerce High-Performance Order Storage
  • Blocks compatible — works with the WooCommerce Cart/Checkout Block editor

What OzuPay Pro adds

  • M-Pesa on Delivery (COD Deposit) — deposit + balance on delivery gateway
  • C2B Buy Goods (Till) Reconciliation — match Till payments made outside an STK prompt
  • B2C Automatic Refunds — process WooCommerce refunds via the Daraja B2C API
  • Analytics Dashboard — revenue, conversion, and payment path charts
  • Scheduled Email Reports — daily, weekly, or monthly payment summary emails
  • POS REST API — REST endpoints for the OzuPay Android cashier application
  • Webhook Enrichment — add M-Pesa receipt data to WooCommerce webhook payloads

Upgrade at ozupay.com

Requirements

  • WooCommerce is required — OzuPay is a WooCommerce payment gateway and does not run without it
  • A Safaricom Daraja developer account (free at developer.safaricom.co.ke)
  • Store currency must be set to KES (Kenyan Shilling)
  • A public HTTPS URL for Daraja callbacks (required for production; not needed for sandbox testing)

External services

This plugin relies on the following external services. Nothing else is contacted.

1. Safaricom Daraja API (required)

The plugin connects to Daraja to send STK Push prompts and receive payment results. This core service is required.

Endpoints: https://api.safaricom.co.ke (production) and https://sandbox.safaricom.co.ke (sandbox, used only when you select Sandbox mode in settings).

What is sent, and when:

  • When a customer places an order with the M-Pesa gateway: the customer’s Safaricom phone number, the order amount, your store’s Paybill/Till shortcode, the order number as the payment reference, and your site’s callback URL.
  • When the plugin needs an API token (before each request batch): your Daraja Consumer Key and Consumer Secret.
  • While a customer is on the payment-waiting page and their payment hasn’t confirmed after 15 seconds: your store’s Paybill/Till shortcode and the CheckoutRequestID for that specific payment, to proactively check whether Daraja already has an outcome (rate-limited to once every 30 seconds per order).
  • Safaricom sends results back to your site’s callback URL; nothing is sent by the plugin in that direction.

You supply your own Daraja credentials, so your store’s relationship is directly with Safaricom.

Safaricom Daraja API terms and conditions: https://developer.safaricom.co.ke/terms
Safaricom data privacy statement: https://www.safaricom.co.ke/dataprivacystatement/

2. OzuPay diagnostics (optional, disabled by default)

If you enable “Share optional diagnostic telemetry” in OzuPay Settings Advanced, the plugin sends a daily report to https://ozupay.com/wp-json/ozls/v1/telemetry. It also sends once immediately after opt-in. Fresh installs default to off.

What is sent, and when: once per day (and once immediately after you enable it) — your site’s hostname, the plugin/PHP/WordPress/WooCommerce version numbers, store locale and country, whether the site is a WordPress multisite install, whether the site is in sandbox or production mode, whether HPOS and block checkout are in use, whether your M-Pesa shortcode is a Paybill or Till, boolean configuration-health flags (for example “credentials configured: yes/no”, “callback URL reachable: yes/no”), install and last-active dates, daily aggregate payment counts (initiated, confirmed, failed, retried), and error type slugs with their frequency.

What is never sent: customer names, phone numbers, emails, addresses, order IDs, order contents, payment amounts, M-Pesa receipt numbers, or your Daraja API credentials.

OzuPay terms of service: https://ozupay.com/terms
OzuPay privacy policy: https://ozupay.com/privacy

Details

Plugin code:
ozupay-payment-gateway
Plugin version:
5.1.15
Author:
Outdated:
No
WP version:
6.0 or higher
PHP version:
8.0 or higher
Test up to WP version:
7.1
Total installations:
0
Last updated:
2026-08-28
Rating:
Times rated:
0
kenya
mpesa
payment-gateway
safaricom
woocommerce