mpesa-mcp
mpesa-mcp
MCP-сервер для финтех-API в Восточной Африке — M-Pesa (Safaricom Daraja) и Africa's Talking
Предоставьте своему ИИ-агенту возможность инициировать платежи M-Pesa, проверять статус транзакций, отправлять SMS и пополнять баланс в более чем 20 африканских телекоммуникационных сетях.
Зачем это нужно
M-Pesa обрабатывает больше транзакций в день, чем PayPal в Африке. Africa's Talking охватывает пользователей в более чем 20 странах на простых телефонах через SMS и USSD. Ни у одного из них нет MCP-сервера.
Это означает, что любой ИИ-агент, созданный сегодня — Claude, GPT, Gemini или любая среда выполнения, совместимая с MCP, — не может инициировать платеж M-Pesa или отправить SMS на суахили без специальной интеграции.
mpesa-mcp устраняет этот пробел с помощью одной команды pip install.
Related MCP server: M-Pesa MCP Server
Инструменты
Инструмент | Описание |
| Запуск запроса на оплату STK Push на телефоне клиента M-Pesa |
| Проверка статуса запроса STK Push |
| Запрос любой транзакции M-Pesa по номеру квитанции |
| Отправка SMS от 1 до 1000 получателям в африканских сетях |
| Пополнение баланса любого абонента (KES, NGN, GHS, UGX и т. д.) |
Покрытие
M-Pesa: Кения (Safaricom Daraja v3) — STK Push, C2B, статус транзакции
SMS/Airtime: Кения, Нигерия, Гана, Танзания, Уганда, Руанда, Южная Африка и еще более 15 стран через Africa's Talking
Glama (хостинговый MCP)
mpesa-mcp доступен как хостинговый MCP-сервер на Glama:
Установка
pip install mpesa-mcpИли запустите напрямую с помощью uvx:
uvx mpesa-mcpКонфигурация
Установите эти переменные окружения перед запуском сервера:
# M-Pesa (Safaricom Daraja)
MPESA_CONSUMER_KEY=your_consumer_key
MPESA_CONSUMER_SECRET=your_consumer_secret
MPESA_SHORTCODE=174379 # sandbox test shortcode
MPESA_PASSKEY=your_passkey
MPESA_CALLBACK_URL=https://yourdomain.com/mpesa/callback
MPESA_SANDBOX=true # set false for production
# Africa's Talking
AT_USERNAME=sandbox # your AT username (sandbox for testing)
AT_API_KEY=your_at_api_keyПесочница (Sandbox)
M-Pesa sandbox: https://developer.safaricom.co.ke — создайте бесплатное приложение, чтобы получить тестовые учетные данные.
Тестовый короткий код:
174379Тестовый пароль (passkey):
bfb279f9aa9bdbcf158e97dd71a467cd2e0c893059b10f78e6b72ada1ed2c919
Africa's Talking sandbox: https://account.africastalking.com — используйте username=sandbox и любой API-ключ.
Использование с Claude Desktop
Добавьте в ~/Library/Application Support/Claude/claude_desktop_config.json (macOS):
{
"mcpServers": {
"mpesa": {
"command": "uvx",
"args": ["mpesa-mcp"],
"env": {
"MPESA_CONSUMER_KEY": "your_key",
"MPESA_CONSUMER_SECRET": "your_secret",
"MPESA_SHORTCODE": "174379",
"MPESA_PASSKEY": "your_passkey",
"MPESA_CALLBACK_URL": "https://yourdomain.com/mpesa/callback",
"MPESA_SANDBOX": "true",
"AT_USERNAME": "sandbox",
"AT_API_KEY": "your_at_key"
}
}
}
}Использование с Claude Code
claude mcp add mpesa -- uvx mpesa-mcpУстановите переменные окружения в вашей оболочке перед запуском claude.
Примеры промптов
После подключения вы можете попросить своего ИИ-агента:
"Отправь STK Push на сумму 500 KES на номер +254712345678 для заказа #1234"
"Проверь, был ли получен платеж QKL8ABC123"
"Отправь SMS этим 5 фермерам с сегодняшней ценой на кукурузу: [список]"
"Пополни баланс на 50 KES для наших полевых агентов: [список номеров]"
Реальные сценарии
Выплата полевым агентам
"Отправь STK Push на сумму 300 KES каждому из этих 12 полевых агентов для сегодняшнего сбора данных: [список]"
Агент инициирует 12 последовательных STK-запросов, отслеживает каждый checkout_request_id и опрашивает систему для подтверждения — без написания вами кода.
Оповещение фермеров + пополнение баланса
"Отправь SMS этим 200 фермерам в Гариссе, что уровень реки поднимается. Затем пополни баланс каждого на 20 KES, чтобы они могли позвонить и сообщить отчеты."
Один промпт → 200 SMS-сообщений и 200 пополнений баланса в сетях Safaricom, Airtel и Telkom.
Сверка платежей
"Проверь, был ли платеж по квитанции OKL8M3B2HF успешным и на какую сумму"
Полезно для агентов поддержки, использующих Claude для проверки транзакций M-Pesa в режиме реального времени.
Аннотации инструментов
Все инструменты объявляют аннотации инструментов MCP, чтобы клиенты могли соответствующим образом ограничивать вызовы:
Инструмент | readOnly | destructive | idempotent |
| ❌ | ✅ | ❌ |
| ✅ | ❌ | ✅ |
| ✅ | ❌ | ✅ |
| ❌ | ✅ | ❌ |
| ❌ | ✅ | ❌ |
Claude Desktop и другие MCP-клиенты будут запрашивать подтверждение перед запуском операций оплаты, отправки SMS или пополнения баланса.
Обнаружение сервера
Возможности рекламируются через .well-known/mcp.json — новый стандарт MCP Server Cards. Реестры и браузеры могут индексировать инструменты этого сервера без подключения к нему.
# Check capabilities
curl https://raw.githubusercontent.com/gabrielmahia/mpesa-mcp/main/.well-known/mcp.jsonТестирование и точность
Бенчмарк экосистемы MCP (CData, 2026) показал, что большинство MCP-серверов точны в 60–75% случаев при выполнении сложных запросов — особенно при скрытых сбоях в операциях записи и частичном применении параметров.
mpesa-mcp протестирован на всех трех форматах кенийских телефонных номеров, граничных значениях сумм и отсутствующих необязательных полях:
pytest tests/ -v # run full suite
pytest tests/test_phone_formats.py # format normalization
pytest tests/test_boundary_amounts.py # min/max amount edge casesОперации записи (STK push, SMS, пополнение баланса) проходят явную проверку перед выполнением любого вызова API.
Контекст экосистемы — Mojaloop + MCP
Mojaloop (финансируемый Фондом Гейтса) обеспечивает функциональную совместимость платежей — соединяя банки, мобильные кошельки и продавцов через DFSP в Восточной Африке и за ее пределами.
mpesa-mcp обеспечивает уровень инструментов для ИИ-агентов — позволяя ИИ-помощникам программировать и запрашивать платежи M-Pesa программно.
Они дополняют друг друга:
Mojaloop: рельсы функциональной совместимости между финансовыми провайдерами
mpesa-mcp: уровень интерфейса MCP, который соединяет ИИ-агентов с этими рельсами
См. вклад в документацию Mojaloop для получения дополнительной информации об этом шаблоне.
MCP против A2A — два разных протокола
mpesa-mcp реализует MCP (Model Context Protocol) — то, как ИИ-агент взаимодействует с инструментами.
Существует дополнительный протокол, A2A (Agent-to-Agent), который управляет тем, как агенты общаются друг с другом. Они решают разные проблемы и работают вместе:
MCP: Ваш ИИ-агент → mpesa-mcp → Daraja API / Africa's Talking
A2A: Агент-оркестратор ↔ платежный субагент ↔ субагент уведомлений
Для большинства интеграций вам нужен только MCP. A2A становится актуальным, когда вы создаете мультиагентные системы, где платежный рабочий процесс координируется с другими специализированными агентами.
Разработка
git clone https://github.com/gabrielmahia/mpesa-mcp
cd mpesa-mcp
pip install -e ".[dev]"
pytest tests/ -vБезопасность
Не коммитьте API-ключи. Используйте переменные окружения или менеджер секретов. Сообщайте об уязвимостях по адресу: contact@aikungfu.dev
Лицензия
MIT — © 2026 Gabriel Mahia
Будьте в курсе
Получайте уведомления о новых релизах и разработках API в Восточной Африке: Подписаться на обновления →
Или следите за этим репозиторием на GitHub для получения уведомлений о релизах.
Родственные пакеты
Пакет | Установка | Описание |
| MCP-сервер для анализа засухи в Кении | |
| SDK для гражданского ИИ в Восточной Африке |
Связанные пакеты
Все MIT · Все являются частью стека гражданского ИИ Восточной Африки
Пакет | Установка | Описание |
| MCP-сервер для анализа засухи в Кении | |
| MCP-сервер данных здравоохранения Кении — NHIF, учреждения, материнство, права | |
| SDK для гражданского ИИ в Восточной Африке |
Полное портфолио: gabrielmahia.github.io
Available Tools
5 toolsairtime_sendSend AirtimeADestructive
Send airtime top-up to any MTN/Safaricom/Airtel/Vodafone subscriber. Common use: NGO field incentives, survey rewards, agent payouts. No real airtime sent in sandbox mode.
| Name | Required | Description | Default |
|---|---|---|---|
| phone | Yes | Recipient phone in E.164 format e.g. '+254712345678' | |
| amount | Yes | Amount as string e.g. '50' (KES 50). Minimum KES 10 in production. | |
| currency_code | No | ISO currency code: KES, NGN, GHS, UGX, TZS, RWF, ZAR | KES |
Output Schema
| Name | Required | Description |
|---|---|---|
No output parameters | ||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already indicate destructive/destructiveHint=true. Description adds valuable sandbox behavior disclosure. Does not discuss other aspects like auth or rate limits, but the added sandbox note is useful beyond annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Three sentences, each adding distinct value: action, use cases, sandbox note. No fluff, highly efficient.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given that an output schema exists (return values not needed), the description covers purpose, common usage, and sandbox behavior. Lacks prerequisites or error scenarios, but sufficient for a simple tool with good annotations.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100% and already describes each parameter in detail (including minimum amount in production). Description does not add new parameter information beyond what's in the schema, so baseline 3 applies.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
Description clearly states action (send airtime top-up) and target (specific network subscribers). Common use cases provided. Distinguishes from siblings like mpesa_stk_push which are for money transfers.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Lists common use cases (NGO incentives, survey rewards, agent payouts) and mentions sandbox mode behavior. Does not explicitly compare to alternatives, but given sibling tools, context is clear.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
mpesa_stk_pushM-Pesa STK PushADestructive
Trigger an M-Pesa STK Push — sends a payment prompt to the customer's phone. The customer enters their M-Pesa PIN to complete payment. Returns a CheckoutRequestID to track the transaction with mpesa_stk_query. Async: use mpesa_stk_query after 10-30 seconds to check completion.
| Name | Required | Description | Default |
|---|---|---|---|
| phone | Yes | Customer phone number (any Kenyan format: +254..., 07..., 254...) | |
| amount | Yes | Amount in KES (whole number, minimum 1) | |
| account_ref | Yes | Account reference shown to customer on their phone (max 12 chars) | |
| description | No | Transaction description (max 13 chars) | Payment |
Output Schema
| Name | Required | Description |
|---|---|---|
No output parameters | ||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description adds significant behavioral context beyond annotations: it explains that the tool is async, that the customer enters their PIN to complete payment, and that a CheckoutRequestID is returned for follow-up. This aligns with destructiveHint=true and provides useful actionable information.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is concise with four short sentences, all of which provide necessary information. It front-loads the primary action and sequentially covers process, return value, and follow-up. There is no wasted text.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
The description covers the essential aspects of a payment initiation tool: what it does (trigger STK push), the user interaction (customer enters PIN), the result (CheckoutRequestID), and the asynchronous follow-up (use mpesa_stk_query after 10-30 seconds). With an output schema present, the description does not need to detail return fields.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The input schema has 100% coverage with descriptions for all parameters. The tool description does not add additional meaning beyond the schema (e.g., no examples or format clarification). Baseline 3 applies as schema already documents parameters adequately.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states that the tool triggers an M-Pesa STK Push, sends a payment prompt to the customer's phone, and returns a CheckoutRequestID for tracking. It distinguishes itself from sibling tools like mpesa_stk_query by noting that the query tool is for checking completion.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides explicit guidance on when to use the sibling tool mpesa_stk_query (after 10-30 seconds) to check completion. It implies that this tool is for initiating payments, but does not explicitly state when not to use it or mention alternatives like airtime_send.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
mpesa_stk_queryM-Pesa STK QueryARead-onlyIdempotent
Check the status of an STK Push request. Poll this 10-30 seconds after calling mpesa_stk_push. ResultCode 0 = success, 1032 = cancelled by user, 1037 = timed out.
| Name | Required | Description | Default |
|---|---|---|---|
| checkout_request_id | Yes | CheckoutRequestID from mpesa_stk_push response |
Output Schema
| Name | Required | Description |
|---|---|---|
No output parameters | ||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Beyond annotations (readOnlyHint, idempotentHint), the description adds polling timing and result code meanings, disclosing behavioral traits like non-immediate result and cancellation handling.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Three concise sentences, each essential: purpose, timing advice, and result interpretation. No extraneous text.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a simple read-only tool with one parameter and existing output schema, the description fully covers polling strategy, result codes, and usage context.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100% and the description merely restates the parameter's purpose ('CheckoutRequestID from mpesa_stk_push response') without adding additional meaning or constraints.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states 'Check the status of an STK Push request' with a specific verb and resource, distinguishing it from siblings like mpesa_stk_push (initiates) and mpesa_transaction_status.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Explicitly says to poll 10-30 seconds after calling mpesa_stk_push, and interprets result codes (0=success, 1032=cancelled, 1037=timed out), providing clear when-to-use and expected outcomes.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
mpesa_transaction_statusM-Pesa Transaction StatusARead-onlyIdempotent
Query the status of any M-Pesa transaction by receipt number. Requires MPESA_INITIATOR_NAME and MPESA_SECURITY_CREDENTIAL env vars.
| Name | Required | Description | Default |
|---|---|---|---|
| transaction_id | Yes | M-Pesa receipt number e.g. QKL8XXXXXX |
Output Schema
| Name | Required | Description |
|---|---|---|
No output parameters | ||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already indicate read-only, idempotent, non-destructive. Description adds valuable prerequisite info (env vars) beyond annotations. No contradictions.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two sentences, both essential. Front-loaded with purpose, then prerequisite. No redundant information.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given simple tool with output schema and rich annotations, description is mostly complete. Missing rate limits or side-effect details, but not critical.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Input schema covers 100% of parameter with example. Description adds no new semantics, so baseline 3.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
Clear specific verb (Query) and resource (transaction status) with receipt number. Distinguishes from sibling tools like airtime_send and sms_send.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Mentions required environment variables but does not explicitly state when to use this tool vs alternatives like mpesa_stk_query. Usage is implied by name and description.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
sms_sendSend SMSADestructive
Send SMS to one or many recipients via Africa's Talking. Supports up to 1,000 recipients per call. Works across Kenya, Nigeria, Ghana, Tanzania, Uganda, and 15+ African markets. Returns per-recipient status and cost.
| Name | Required | Description | Default |
|---|---|---|---|
| message | Yes | SMS message text. Unicode supported (Kiswahili, etc.) | |
| sender_id | No | Optional pre-registered alphanumeric sender ID | |
| recipients | Yes | List of phone numbers in E.164 format e.g. ['+254712345678'] |
Output Schema
| Name | Required | Description |
|---|---|---|
No output parameters | ||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already indicate destructiveHint=true and idempotentHint=false. The description adds valuable behavioral details: the maximum recipient limit, geographic coverage, and that it returns per-recipient status and cost. No contradictions with annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is three sentences long, each serving a distinct purpose: what the tool does, its capacity and scope, and its return value. No wasted words, and the most critical information is front-loaded.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a tool with three well-documented parameters and an existing output schema, the description covers the essential aspects: operation, capacity, geographic scope, and return format. It is sufficiently complete for an agent to understand and use the tool correctly.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the schema itself clearly documents all three parameters. The description adds no additional parameter-level meaning beyond what is in the schema (e.g., it mentions Unicode support which is already in the message description). Baseline score of 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool sends SMS via Africa's Talking, specifies the maximum recipients (1,000), mentions geographic coverage, and indicates return of per-recipient status and cost, distinguishing it from sibling tools like airtime_send or mpesa_stk_push which perform different operations.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides clear context for when to use the tool (sending SMS to one or many recipients) and includes practical limits (1,000 recipients). It does not explicitly mention when not to use it or compare to alternatives, but the sibling tools are sufficiently different that no confusion arises.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
5 tool updates
v0.1.0- First observed
airtime_send - First observed
mpesa_stk_push - First observed
mpesa_stk_query - First observed
mpesa_transaction_status - First observed
sms_send
TDQS
Scored across 5 tools
Each tool targets a distinct function: airtime sending, STK push initiation, STK push status query, transaction status by receipt, and SMS sending. There is no overlap or ambiguity.
Most tools follow a verb_noun or noun_verb pattern (e.g., airtime_send, sms_send, mpesa_stk_push), but mpesa_transaction_status lacks a verb, breaking the pattern slightly.
With 5 tools, the server is well-scoped for its purpose, covering core M-Pesa and SMS operations without being too few or too many.
The set covers STK push initiation/query and basic transaction status, but lacks airtime status, B2C/C2B transfers, or account balance queries, leaving notable gaps for a full M-Pesa integration.
Maintenance
Related MCP Connectors
South African MCP server for airtime, data, SMS, VAS, electricity, balance, and network lookup.
MCP Server for agents to onboard, pay, and provision services autonomously with InFlow
MCP server for Modern Treasury — payment orders, transactions, counterparties and ledgers.
MCP server for Codat — companies, connections, invoices, bills and financial statements.
Related MCP Servers
FlicenseNot gradedqualityDmaintenanceOpen-source MCP server that streamlines payment integration for AI agents and financial apps in Africa, providing unified tools for providers like M-Pesa.1-- FlicenseNot gradedqualityCmaintenanceAn experimental MCP server that lets AI agents interact with guarded payment workflows through typed tools, enabling safe agent-assisted payments with M-Pesa and mock Airtel Money.2-
- FlicenseNot gradedqualityDmaintenanceA Model Context Protocol (MCP) server that integrates Safaricom's M-PESA Daraja API with Claude, enabling natural language payment processing and real-time transaction notifications.3-
- AlicenseCqualityDmaintenanceAn MCP server that enables AI assistants to interact with Interswitch APIs for payments, transfers, VAS, cardless paycodes, Transaction Search, Card 360, lending, payouts, agency banking, and fintech card-processing utilities.7458 npm1MIT