Premium Cloud Hosting!

Contact Info

Hostnali Webhost Limited

+254 748285257

[email protected]

ORDER NOW

M-Pesa Payment Gateway Module for WHMCS

M-Pesa Payments Pro for WHMCS

Accept M-Pesa payments. Match them to the right invoice automatically.

Give your customers a faster way to pay their WHMCS invoices with M-Pesa Payments Pro. Accept payments directly from the invoice page or your M-Pesa Paybill, then intelligently match incoming payments to the correct WHMCS invoice without relying on manual reconciliation.

Mpesa Payment Module for WHMCS

M-Pesa Payments Pro for WHMCS is a powerful M-Pesa payment gateway and payment matching module for WHMCS designed for Kenyan web hosting companies, domain registrars, SaaS providers, and online businesses. The module allows customers to pay their WHMCS invoices directly using M-Pesa without leaving the invoice page, while also automatically processing payments made directly through your M-Pesa Paybill. With support for M-Pesa payment requests, direct Paybill payments, and Buy Goods Till payments, businesses can provide customers with a convenient local payment experience while keeping all transactions connected to WHMCS.

What makes M-Pesa Payments Pro different is its intelligent M-Pesa payment matching engine. Receiving a payment is only part of the challenge—correctly identifying which WHMCS invoice the payment belongs to is equally important. The module evaluates multiple factors including invoice numbers, customer phone numbers, payment amounts, previous payment history, account references, and common typing mistakes to determine the most likely invoice. Payments that meet the required confidence and matching criteria are automatically applied, while uncertain transactions are placed into a clear review queue instead of being incorrectly assigned. This helps prevent duplicate payments, incorrect invoice allocations, and manual reconciliation work.

The module also provides powerful M-Pesa reconciliation and payment management tools for WHMCS, including CSV statement reconciliation, partial payments, overpayments, automatic client credit handling, payment verification, refunds with approval controls, transaction logs, admin permissions, payment notifications, and a real-time payment dashboard. Every M-Pesa receipt is uniquely tracked to prevent duplicate processing, while callbacks are handled efficiently so payments can be received without unnecessary delays. With M-Pesa Payments Pro for WHMCS, hosting companies can automate M-Pesa collections, reduce payment-related support tickets, simplify financial reconciliation, and give customers a faster and more reliable way to pay their WHMCS invoices.

M-Pesa Payments Pro collects M-Pesa payments inside WHMCS and, more importantly, works out which invoice each one belongs to. Clients pay from the invoice page without leaving it, paybill payments made straight from a phone are matched automatically, and anything the module is not certain about waits in a queue that explains itself instead of guessing.

$4.20 per month
or KSh 500 per month
Buy this module
One licence, one WHMCS domain Updates and support included

Version 1.11.1 · WHMCS 8.x · PHP 8.1+ · by Hostnali · Documentation

Two ways to be paid, one place to see it

Payment requests on the invoice

The client presses your normal Pay Now button, types their number, and approves the payment on their phone. The invoice page updates itself the moment the money lands — no reloading, no "have you paid yet".

Paybill payments made on their own

Someone who pays your paybill from their phone, with no browser involved, still gets their invoice marked paid within seconds — provided they quoted the invoice number, which the module checks and corrects for common typing mistakes.

The matching engine is the difference

Taking a payment is the easy half. The hard half is a payment that arrives with the wrong account number, the right number but the wrong amount, or nothing useful at all. Most modules either guess or give up. This one scores every plausible invoice and tells you why.

What the module foundScore
The account number matches an invoice70
It matches after fixing a typo, such as O for zero50
The phone belongs to a client, or has paid before40
Exactly one open invoice has that balance35
The amount equals the balance exactly+20
Paid from the number on that client's account+15
It would leave a balance owing+5
It is more than the balance−10
That invoice is already settled−45

Confidence is not enough on its own

A payment is only recorded automatically when it clears your confidence threshold and beats the next best candidate by a clear margin.

Without that second rule, a client with two identical monthly invoices would get a coin toss recorded as a decision. Two close candidates always go to a person.

The queue explains itself

Anything not applied automatically appears with the invoice the payer actually named pinned to the top, the reason it is waiting stated in plain English, and one-click actions: apply it, apply it to a different invoice, hold it as client credit, mark it as already recorded, or set it aside.

What happens when the amount is wrong

Part payments

Recorded against the invoice with the balance left owing, or held for review. Your choice.

Overpayments

Settle the invoice and push the excess to the client's credit balance, record the lot, or hold it.

Rounding

M-Pesa only accepts whole shillings, so an invoice ending in cents always collects a little over. A tolerance absorbs it silently instead of dripping cents into credit balances.

Everything else it does

Reconciliation against the M-Pesa statement

Upload the CSV from the M-Pesa portal and see four answers: matched, in the statement but not in WHMCS, in WHMCS but not the statement, and payments you know succeeded but were never named. Bring any of them in with one click.

Refunds, with real guards

Money can only ever go back to the number that paid — there is no field to type a destination. Large refunds need approval, the requester cannot approve their own, and a daily ceiling applies across every admin.

Till numbers and payment codes

Buy Goods tills carry no account number, so clients confirm a payment by entering the code from their M-Pesa message. Every code is checked against your records and, if needed, with Safaricom directly — never simply trusted.

Roles and permissions

Decide which admin roles can see transactions, work the queue, change credentials or send refunds. Fourteen separate capabilities, off by default, with Full Administrators always keeping access.

Notifications that reach you

Email on a payment received, a payment needing matching, or a failed request — each switched on or off separately. Sent through your WHMCS SMTP settings, so they come from your own address and land in inboxes.

A dashboard worth opening

Collected today and this month, completion rate on payment requests, anything waiting, your paybill balance, a fourteen-day collections chart and the split between invoice-page and direct paybill payments.

Built for money, not demos

  • Nothing is ever recorded twice. The M-Pesa receipt is a unique key, so a resent callback, a retried cron or an impatient client cannot double-pay an invoice.
  • Safaricom is never kept waiting. Callbacks are answered immediately and the work happens after the connection is released, so provisioning a hosting account has the time it needs without the payment being lost.
  • A payment is never refused because of us. If a check fails internally, the payment is accepted and flagged, not turned away at the till.
  • Nothing is invented. When a figure cannot be confirmed — a balance, a conversion rate, a code — the module says so and dates it, rather than showing a number that looks live and is not.
  • Every call is logged. Requests to and from Safaricom, with secrets stripped before anything is written down.

How it goes in

  1. Upload and activate Two folders into your WHMCS installation, then activate the addon. Tables create themselves.
  2. Add your Daraja credentials Consumer key, secret, shortcode and passkey, with a Test connection button that proves them before a single payment depends on them.
  3. Register your callback address One button. The module also tells you in advance if your address contains a word Safaricom refuses.
  4. Turn on the gateway M-Pesa appears on the invoice page with a button that inherits your theme, or the colour you choose.
Paybill or till? Paybill gets the full experience, because the account number is what makes automatic matching possible. A Buy Goods till works too — payment requests, instructions and code verification — but more payments will pass through the queue, since a till carries no account number for the module to read.

Requirements

WHMCS8.x
PHP8.1 or newer, with curl, json and mbstring
SafaricomA production Daraja app on your own paybill or till, with Lipa na M-Pesa Online enabled
Your serverReachable from the internet over HTTPS, so Safaricom can deliver callbacks
CurrencyKenya Shillings, or another currency with an exchange rate configured in WHMCS
OptionalAn API operator name and security credential, needed only for refunds, live balance checks and code verification

Licensing and support

One licence covers one WHMCS domain. An expired licence pauses the admin screens and stops new payments being started — but payments already on their way are still received and recorded, so money never goes missing while a renewal is sorted out.

Changeslog

Feature releases for M-Pesa Payments Pro, newest first. Maintenance releases that only correct behaviour are not listed. Every release upgrades in place — replace the files and the database updates itself the next time you open the module.

1.11 Current

Licence behaviour separated from payment collection, and callbacks answered before the heavy work starts.

  • An expired licence no longer risks losing money. New payments cannot be started, but payments already on their way are still received and recorded, and every cron sweep keeps running.
  • Callbacks are answered immediately. Safaricom gets its acknowledgement first, then the payment is recorded and WHMCS provisions the service with a five-minute allowance instead of the normal web request limit — so slow hosting setups finish properly rather than being cut off part-way.
  • Neutral wording for clients. If M-Pesa is unavailable for any reason, the invoice page says so plainly and suggests another method. Licensing is never mentioned to your customers.
1.10 Major

Till support, customer-supplied payment codes, and a paybill balance that keeps itself current.

  • Buy Goods till numbers. A separate till number field, so payment requests reach the right destination on accounts where the till and store numbers differ.
  • Clients can confirm a payment with its code. An "already paid?" box on the invoice takes the reference from their M-Pesa message. Codes are checked against your records, your imported statement, and Safaricom directly — never taken on trust.
  • Protection against claiming someone else's payment. A code already used is refused, a payment made to another shortcode is rejected, a code from a number not on the account waits for a person, and attempts are rate limited.
  • Payment codes needing attention appear at the top of the matching queue, with the option to ask Safaricom again or set them aside.
  • The paybill balance refreshes itself about once an hour, and always states where the figure came from and when, so a stale number can never be mistaken for a live one.
  • Already recorded. A one-click action for a payment WHMCS already has on an invoice, plus automatic detection of the same payment arriving twice.
1.9 Major

Licensing, and settings reorganised into sections.

  • Licensing built in, tied to your WHMCS domain, with a grace period so a temporary outage never interrupts a working install.
  • Settings split into eleven sections down a side menu — credentials, payments, paybill, amounts, matching, refunds, notifications, client area, records, licence and access — each saved on its own.
  • Mobile payment window repositioned so the phone number field stays visible when the keyboard opens.
1.8 Major

Reconciliation, refunds, the client area page, and role-based access.

  • Reconciliation. Upload the M-Pesa statement and compare it against WHMCS: matched, in the statement only, in WHMCS only, and payments confirmed but never named. Bring missing ones in with one click.
  • Refunds. Money returns only to the number that paid. Large refunds need approval, the person who asked cannot approve their own, and a daily ceiling applies across all admins.
  • A client area page listing every M-Pesa payment on the client's account, with separate switches for the page itself and its menu link.
  • Roles and permissions. Fourteen capabilities across viewing and acting, assignable per WHMCS admin role, with Full Administrators always retaining access.
  • Accounting guidance. Detects Ledgerly and explains the one mapping worth setting, rather than posting a second journal and doubling your revenue.
  • Danger zone for removing all module data deliberately, which deactivating never does.
1.7 Feature

A dashboard worth opening.

  • Fourteen-day collections chart, stacked by how the money arrived, with a figure for each day on hover.
  • How people are paying — the split between invoice-page requests and direct paybill payments, and what that split means for your matching.
  • Larger, clearer type and colour-coded figures throughout the admin area.
1.6 Feature

Paybill balance.

  • Your shortcode balance on the dashboard, on each transaction and in the payment email, taken from what Safaricom reports with each payment at no extra cost.
1.5 Major

The invoice page updates itself, and email notifications arrive.

  • Live invoice updates. A client who pays the paybill from their phone sees the invoice turn paid without reloading anything, with configurable frequency and a limit so idle tabs stop checking.
  • Email notifications for a payment received, a payment needing matching, and a failed request — each switched separately, with a test button that proves the mail path.
  • Sent through your WHMCS SMTP settings, so notifications come from your own address rather than the server hostname.
1.4 Feature

Callback addresses Safaricom will actually accept.

  • A callback address free of the words Safaricom refuses, and a warning before you register if your own domain contains one.
  • An override for hosts whose main domain cannot be used, so an alternative hostname can receive callbacks.
1.3 Major

Money rules, the invoice payment window, and transaction reporting.

  • Rules for amounts that do not match. Part payments, overpayments to client credit, and a tolerance that absorbs the rounding M-Pesa forces on invoices ending in cents.
  • Transaction costs recorded against each payment, so net revenue stays accurate without charging the customer.
  • Other currencies converted at your WHMCS rates, or refused outright — never guessed.
  • A payment window on the invoice, opened by your own Pay Now button, with the M-Pesa mark and a colour you control.
  • Transaction filters, totals and CSV export, plus paybill instructions built into the same window for anyone whose prompt does not arrive.
1.2 Major

The matching engine.

  • Every plausible invoice scored on the account number, common typing mistakes, the payer's phone and the amount — with the reasons shown in plain English.
  • Confident matches recorded automatically, but only when the best candidate is also clearly ahead of the next one.
  • A matching queue for everything else, with apply, hold as credit, and set aside.
  • Payments that arrive before their invoice exists are retried for seven days.
1.1 Feature

Paybill payments made without touching the invoice.

  • Payments made straight to your paybill are received, recorded and shown, whether or not anyone opened an invoice.
  • One-button registration of your addresses with Safaricom, and the option to turn away payments quoting an account number you do not recognise.
  • A sandbox test payment so the whole path can be proven without a phone.
1.0 First release

Payment requests from the invoice page.

  • Payment requests to the client's phone from the invoice, with the amount taken from what is actually still owing.
  • Payments recorded automatically when confirmed, and never recorded twice however many times Safaricom repeats itself.
  • A transaction record and an API log of every exchange with Safaricom, with secrets removed before anything is stored.

Dates are omitted deliberately: releases are made when they are ready. Upgrading is always a file replacement — no database work, no reconfiguration.

Our Customers Love Our Services