M-Pesa Payments Pro collects M-Pesa payments inside WHMCS and, more
importantly, works out which invoice each one belongs to. Clients pay from the invoice page without leaving
it, paybill payments made straight from a phone are matched automatically, and anything the module is not
certain about waits in a queue that explains itself instead of guessing.
$4.20 per month
or KSh 500 per month
Buy this module
One licence, one WHMCS domain
Updates and support included
Version 1.11.1 · WHMCS 8.x · PHP 8.1+ · by Hostnali
· Documentation
Two ways to be paid, one place to see it
✉
Payment requests on the invoice
The client presses your normal Pay Now button, types their number, and approves the payment on their
phone. The invoice page updates itself the moment the money lands — no reloading, no "have you
paid yet".
∑
Paybill payments made on their own
Someone who pays your paybill from their phone, with no browser involved, still gets their invoice
marked paid within seconds — provided they quoted the invoice number, which the module checks and
corrects for common typing mistakes.
The matching engine is the difference
Taking a payment is the easy half. The hard half is a payment that arrives with the wrong account number,
the right number but the wrong amount, or nothing useful at all. Most modules either guess or give up. This
one scores every plausible invoice and tells you why.
| What the module found | Score |
| The account number matches an invoice | 70 |
| It matches after fixing a typo, such as O for zero | 50 |
| The phone belongs to a client, or has paid before | 40 |
| Exactly one open invoice has that balance | 35 |
| The amount equals the balance exactly | +20 |
| Paid from the number on that client's account | +15 |
| It would leave a balance owing | +5 |
| It is more than the balance | −10 |
| That invoice is already settled | −45 |
Confidence is not enough on its own
A payment is only recorded automatically when it clears your confidence threshold and beats
the next best candidate by a clear margin.
Without that second rule, a client with two identical monthly invoices would
get a coin toss recorded as a decision. Two close candidates always go to a person.
The queue explains itself
Anything not applied automatically appears with the invoice the payer actually named pinned to the top,
the reason it is waiting stated in plain English, and one-click actions: apply it, apply it to a different
invoice, hold it as client credit, mark it as already recorded, or set it aside.
What happens when the amount is wrong
Part payments
Recorded against the invoice with the balance left owing, or held for review. Your choice.
Overpayments
Settle the invoice and push the excess to the client's credit balance, record the lot, or hold it.
Rounding
M-Pesa only accepts whole shillings, so an invoice ending in cents always collects a little over. A
tolerance absorbs it silently instead of dripping cents into credit balances.
Everything else it does
⇆
Reconciliation against the M-Pesa statement
Upload the CSV from the M-Pesa portal and see four answers: matched, in the statement but not in
WHMCS, in WHMCS but not the statement, and payments you know succeeded but were never named. Bring any
of them in with one click.
←
Refunds, with real guards
Money can only ever go back to the number that paid — there is no field to type a destination.
Large refunds need approval, the requester cannot approve their own, and a daily ceiling applies across
every admin.
☕
Till numbers and payment codes
Buy Goods tills carry no account number, so clients confirm a payment by entering the code from their
M-Pesa message. Every code is checked against your records and, if needed, with Safaricom directly
— never simply trusted.
⚖
Roles and permissions
Decide which admin roles can see transactions, work the queue, change credentials or send refunds.
Fourteen separate capabilities, off by default, with Full Administrators always keeping access.
✉
Notifications that reach you
Email on a payment received, a payment needing matching, or a failed request — each switched on
or off separately. Sent through your WHMCS SMTP settings, so they come from your own address and land in
inboxes.
▣
A dashboard worth opening
Collected today and this month, completion rate on payment requests, anything waiting, your paybill
balance, a fourteen-day collections chart and the split between invoice-page and direct paybill
payments.
Built for money, not demos
- Nothing is ever recorded twice. The M-Pesa receipt is a unique key, so a resent
callback, a retried cron or an impatient client cannot double-pay an invoice.
- Safaricom is never kept waiting. Callbacks are answered immediately and the work
happens after the connection is released, so provisioning a hosting account has the time it needs without
the payment being lost.
- A payment is never refused because of us. If a check fails internally, the payment is
accepted and flagged, not turned away at the till.
- Nothing is invented. When a figure cannot be confirmed — a balance, a
conversion rate, a code — the module says so and dates it, rather than showing a number that looks
live and is not.
- Every call is logged. Requests to and from Safaricom, with secrets stripped before
anything is written down.
How it goes in
- Upload and activate
Two folders into your WHMCS installation, then activate the addon. Tables create themselves.
- Add your Daraja credentials
Consumer key, secret, shortcode and passkey, with a Test connection button that proves them before a
single payment depends on them.
- Register your callback address
One button. The module also tells you in advance if your address contains a word Safaricom refuses.
- Turn on the gateway
M-Pesa appears on the invoice page with a button that inherits your theme, or the colour you choose.
Paybill or till? Paybill gets the full experience, because the account number is what
makes automatic matching possible. A Buy Goods till works too — payment requests, instructions and
code verification — but more payments will pass through the queue, since a till carries no account
number for the module to read.
Requirements
| WHMCS | 8.x |
| PHP | 8.1 or newer, with curl, json and mbstring |
| Safaricom | A production Daraja app on your own paybill or till, with Lipa na M-Pesa Online enabled |
| Your server | Reachable from the internet over HTTPS, so Safaricom can deliver callbacks |
| Currency | Kenya Shillings, or another currency with an exchange rate configured in WHMCS |
| Optional | An API operator name and security credential, needed only for refunds, live balance checks and code verification |
Licensing and support
One licence covers one WHMCS domain. An expired licence pauses the admin screens and stops new payments
being started — but payments already on their way are still received and recorded, so money never goes
missing while a renewal is sorted out.