generated: '2026-07-17' method: searched source: >- https://developer.safaricom.co.ke/ (Daraja sandbox + test credentials) + https://peternjeru.co.ke/blog/m-pesa-daraja-api-credentials/ description: >- M-Pesa Daraja's sandbox test environment and the public default test values Safaricom publishes for it. Test and live are separated by HOST (sandbox.safaricom.co.ke vs api.safaricom.co.ke) and by separate app credentials created per environment in the Daraja portal. No real money moves in sandbox. All values below are the published Daraja sandbox defaults, captured verbatim — never invent test values. docs: - https://developer.safaricom.co.ke/ hosts: sandbox: https://sandbox.safaricom.co.ke production: https://api.safaricom.co.ke mode_separation: >- Separation is by host + per-environment app keys, not by a key prefix. A sandbox app's consumer key/secret only authenticate against sandbox.safaricom.co.ke; go-live issues distinct production credentials for a real shortcode. test_values: business_shortcode: '174379' lipa_na_mpesa_passkey: bfb279f9aa9bdbcf158e97dd71a467cd2e0c893059b10f78e6b72ada1ed2c919 test_msisdn: '254708374149' test_pin: Any 4-digit PIN is accepted in sandbox. test_c2b_shortcode: '600000-600999 range assigned in the sandbox simulator UI' notes: >- - 174379 is the default sandbox Lipa Na M-Pesa Online (paybill) test shortcode paired with the passkey above; use them to build the STK Push Password = Base64(Shortcode+Passkey+Timestamp). - 254708374149 is the standard test customer MSISDN; STK Push prompts against it auto-succeed (or use the C2B simulate endpoint) in sandbox. - For B2C/B2B/Reversal in sandbox, the SecurityCredential is generated by encrypting the test initiator password with the SANDBOX M-Pesa public certificate (the production cert differs). - c2bSimulate (openapi/mpesa-openapi.yml#c2bSimulate) exists ONLY in sandbox to inject inbound payments; it is not available in production.