Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

io.github.gabrielmahia/mpesa-mcp

PYPI · MPESA-MCP · SCANNED SEP 20

MCP server for M-Pesa mobile-money integration in Kenya

Available components

−16 this week 65 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →

Supply Chain Security50
  • Malware scan not yet available for this package.Unverified
  • No known CVEs affecting this package version or its production dependencies.Pass
  • Runs setuptools.build_meta at install time, a recognised native-build step with no shell scripting around it. View diagnostics → Pass
  • 2 of 25 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency35
Schema Quality & AI Usability77
  • AI-judged instruction clarity (good).Pass
  • Tool/resource definitions use about 2378 tokens (~103/item across 23 items; 23 tools + 0 resources), lean.Pass
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management83
  • Stability observed for 25 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
  • Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • All 5 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
  • An AI judge read all 24 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a current MCP spec version (2026-07-28).Pass
Install

How do I install the io.github.gabrielmahia/mpesa-mcp server?

io.github.gabrielmahia/mpesa-mcp runs locally as a PyPI package, launched with uvx mpesa-mcp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

pypi · mpesa-mcp

# add to Claude Code
claude mcp add gabrielmahia-mpesa-mcp -- uvx mpesa-mcp
// .cursor/mcp.json
{
  "mcpServers": {
    "gabrielmahia-mpesa-mcp": {
      "command": "uvx",
      "args": [
        "mpesa-mcp"
      ]
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "gabrielmahia-mpesa-mcp": {
      "command": "uvx",
      "args": [
        "mpesa-mcp"
      ]
    }
  }
}
# add to Codex CLI
codex mcp add gabrielmahia-mpesa-mcp -- uvx mpesa-mcp
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "gabrielmahia-mpesa-mcp": {
      "type": "local",
      "command": [
        "uvx",
        "mpesa-mcp"
      ],
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add gabrielmahia-mpesa-mcp --command uvx --arg mpesa-mcp
# ~/.hermes/config.yaml
mcp_servers:
  gabrielmahia-mpesa-mcp:
    command: "uvx"
    args: ["mpesa-mcp"]
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "gabrielmahia-mpesa-mcp": {
      "Transport": "stdio",
      "Command": "uvx",
      "Arguments": [
        "mpesa-mcp"
      ]
    }
  }
}
# add to Vellum
assistant mcp add gabrielmahia-mpesa-mcp -t stdio -c uvx -a mpesa-mcp
// mcp.json
{
  "mcpServers": {
    "gabrielmahia-mpesa-mcp": {
      "command": "uvx",
      "args": [
        "mpesa-mcp"
      ]
    }
  }
}
Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 18 Sept 26 −3
    • Stability: pass → 0.77 functional
  • 17 Sept 26 +1
    • Stability: 0.97 → pass security
  • 15 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 90 to 93. That category is still filling its 30-day observation window: 27 days of observed history at the previous scan, 28 at this one. The score rises as the window fills, whether or not the server changes.

  • 14 Sept 26 −15
    • Malware scan: pass → unverified security
  • 13 Sept 26 +16
    • Malware scan: unverified → pass security
  • 11 Sept 26 −18
    • Malware scan: pass → unverified security
    • Stability: pass → 0.80 functional
  • 10 Sept 26 +1
    • Stability: 0.97 → pass security
  • 8 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 90 to 93. That category is still filling its 30-day observation window: 27 days of observed history at the previous scan, 28 at this one. The score rises as the window fills, whether or not the server changes.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 20 Sept 2026 · Analysed pypi/mpesa-mcp@0.2.4

Provenance No attestation

The registry publishes no build provenance for this version, so there is nothing to verify.

Result No attestation
Ecosystem pypi

Background: How many MCP packages publish verified provenance →

Install scripts 1 script
Hook Tier Command
build_backend allowlisted setuptools.build_meta

Background: Why install scripts are a supply-chain risk →

Dependencies 25 packages
Packages resolved 25
Stale 2
Tree resolution Complete

Background: SBOMs and build attestations, explained →

MCP tools · 23 exposed · ~2,298 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
airtime_send ~135

Send airtime top-up to MTN/Safaricom/Airtel/Vodafone subscribers. Use for NGO field incentives, survey rewards, agent payouts. No real airtime sent in sandbox mode (AT_USERNAME=sandbox).

NameTypeReqDescription
amountstringyesAmount as string e.g. '50' (KES 50). Min KES 10 in production.
currency_codestringISO currency: KES, NGN, GHS, UGX, TZS, RWF, ZAR
phonestringyesRecipient phone in E.164 format e.g. '+254712345678'

Structured output declared, but exposes no named fields.

No examples provided.

get_model_hint ~37

Returns the recommended AI model for using mpesa-mcp tools. Call this first when selecting a model to pair with mpesa-mcp.

Input schema present but exposes no named parameters.

Structured output declared, but exposes no named fields.

No examples provided.

mpesa_account_balance ~86

Query current balance of the business M-Pesa account (shortcode/till). Result delivered async to MPESA_RESULT_URL. Requires MPESA_INITIATOR_NAME and MPESA_SECURITY_CREDENTIAL.

NameTypeReqDescription
identifier_typestring1=MSISDN, 2=Till, 4=Shortcode/Paybill
remarksstringQuery remarks

Structured output declared, but exposes no named fields.

No examples provided.

mpesa_b2b_express_checkout ~115

Initiate USSD Push to till — enables merchant-to-merchant payments. Recipient merchant receives a USSD prompt to confirm payment from their till. Use for wholesale supplier payments between Lipa Na M-PESA merchants. Requires MPESA_INITIATOR_NAME and MPESA_SECURITY_CREDENTIAL.

NameTypeReqDescription
account_referencestringyesAccount reference for the transaction
amountintegeryesAmount in KES
receiver_tillstringyesRecipient till number
remarksstringRemarks

Structured output declared, but exposes no named fields.

No examples provided.

mpesa_b2c ~130

Business To Customer disbursement — send money from shortcode to phone. Use for payroll, NGO field incentives, agent float, survey rewards. Result delivered async to MPESA_RESULT_URL. Requires MPESA_INITIATOR_NAME and MPESA_SECURITY_CREDENTIAL env vars.

NameTypeReqDescription
amountintegeryesAmount in KES to send
command_idstringSalaryPayment | BusinessPayment | PromotionPayment
occasionstringOptional occasion label
phonestringyesRecipient phone number (any Kenyan format)
remarksstringRemarks (max 100 chars)

Structured output declared, but exposes no named fields.

No examples provided.

mpesa_bill_manager_cancel ~59

Cancel an outstanding Bill Manager invoice. Customer will no longer be able to pay the cancelled invoice. Use when an order is cancelled or a duplicate invoice was created.

NameTypeReqDescription
external_referencestringyesThe externalReference used when creating the invoice

Structured output declared, but exposes no named fields.

No examples provided.

mpesa_bill_manager_invoice ~147

Create a Bill Manager invoice — customer receives SMS with payment link. They can pay directly via M-PESA by clicking the link or using the paybill. Returns invoice ID. Use mpesa_bill_manager_cancel to void outstanding invoices.

NameTypeReqDescription
account_refstringAccount reference for the payment
amountnumberyesInvoice amount in KES
billing_refstringyesCustomer billing account reference
due_datestringyesPayment due date YYYY-MM-DD
external_refstringyesYour internal invoice/reference number
invoice_namestringyesInvoice description shown to customer
phonestringyesCustomer phone to receive SMS notification

Structured output declared, but exposes no named fields.

No examples provided.

mpesa_bill_manager_optin ~91

Enrol your business in M-PESA Bill Manager. Must be called once before creating invoices. After opt-in, customers can pay your invoices directly via M-PESA.

NameTypeReqDescription
callback_urlstringCallback URL for Bill Manager events
emailstringyesBusiness email for Bill Manager notifications
logo_urlstringHTTPS URL to your business logo (PNG/JPG)

Structured output declared, but exposes no named fields.

No examples provided.

mpesa_business_buygoods ~72

Pay from business shortcode to a till/buy-goods number. Requires MPESA_INITIATOR_NAME and MPESA_SECURITY_CREDENTIAL.

NameTypeReqDescription
amountintegeryesAmount in KES
remarksstringTransaction remarks
till_numberstringyesDestination till number (Buy Goods)

Structured output declared, but exposes no named fields.

No examples provided.

mpesa_business_paybill ~95

Pay directly from business shortcode to another paybill number. Use for supplier payments, utility bills, inter-business transfers. Requires MPESA_INITIATOR_NAME and MPESA_SECURITY_CREDENTIAL.

NameTypeReqDescription
account_referencestringyesAccount number at destination paybill
amountintegeryesAmount in KES
receiver_paybillstringyesDestination paybill shortcode
remarksstringTransaction remarks

Structured output declared, but exposes no named fields.

No examples provided.

mpesa_business_pochi ~88

Pay from business shortcode to a Pochi la Biashara micro-SME wallet. Used for micro-enterprise supplier payments and informal sector settlements. Requires MPESA_INITIATOR_NAME and MPESA_SECURITY_CREDENTIAL.

NameTypeReqDescription
amountintegeryesAmount in KES
phonestringyesPochi wallet owner phone number
remarksstringRemarks

Structured output declared, but exposes no named fields.

No examples provided.

mpesa_dynamic_qr ~150

Generate a Dynamic M-PESA QR code for a specific payment amount. Customer scans QR with their M-PESA app — amount pre-fills automatically. Returns base64-encoded QR image. Use for receipts, invoices, POS displays.

NameTypeReqDescription
amountintegeryesAmount in KES to encode in QR
merchant_namestringyesBusiness/merchant name to display on QR
qr_sizeintegerQR image size in pixels (300-1000)
ref_nostringyesTransaction reference number
trx_codestringBG=Buy Goods, PB=Paybill, WA=Wallet, SM=Send Money, SB=Lipa Shortcode

Structured output declared, but exposes no named fields.

No examples provided.

mpesa_imsi_query ~79

Verify a Safaricom number — returns registration date, SIM age, last swap, and hashed IMSI. Enhanced KYC/AML signal for financial services compliance. Older SIMs with no recent swaps have lower fraud risk. Returns data suitable for risk scoring without exposing raw IMSI.

NameTypeReqDescription
phonestringyesPhone number to verify

Structured output declared, but exposes no named fields.

No examples provided.

mpesa_pull_transactions ~100

Pull all C2B transactions for reconciliation within a date range. Returns customer payments to your shortcode for audit and reconciliation. Max range: 48 hours per call. Max 10,000 records per call.

NameTypeReqDescription
end_datestringyesEnd date YYYY-MM-DD HH:MM:SS
offsetintegerPagination offset (0-based)
start_datestringyesStart date YYYY-MM-DD HH:MM:SS

Structured output declared, but exposes no named fields.

No examples provided.

mpesa_query_org_info ~65

Validate a shortcode — returns the registered name and tariff type. Use before sending B2B payments to confirm the destination shortcode is correct. Prevents accidental payments to wrong paybill numbers.

NameTypeReqDescription
shortcodestringyesShortcode to validate (paybill or till number)

Structured output declared, but exposes no named fields.

No examples provided.

mpesa_ratiba_create ~194

Create an M-PESA Ratiba standing order — automated recurring payments. Customer authorizes once; payments happen automatically on schedule. Perfect for subscription billing, rent collection, loan repayments, SACCO contributions. Returns a standing order ID to manage/cancel later.

NameTypeReqDescription
account_refstringyesAccount reference for each payment
amountintegeryesAmount in KES per payment
descriptionstringStanding order description
end_datestringyesEnd date YYYYMMDD
frequencystring1=One-Off 2=Daily 3=Weekly 4=Monthly 5=Bi-Monthly 6=Quarterly 7=Half-Year 8=Annually
phonestringyesCustomer phone number
standing_order_namestringyesName for the standing order
start_datestringyesStart date YYYYMMDD

Structured output declared, but exposes no named fields.

No examples provided.

mpesa_reversal ~100

Reverse an erroneous M-Pesa transaction. Use when a payment was sent to the wrong number or wrong amount. Requires MPESA_INITIATOR_NAME and MPESA_SECURITY_CREDENTIAL. Result delivered async to MPESA_RESULT_URL.

NameTypeReqDescription
amountintegeryesAmount to reverse in KES
remarksstringReason for reversal
transaction_idstringyesM-Pesa receipt to reverse e.g. QKL8XXXXXX

Structured output declared, but exposes no named fields.

No examples provided.

mpesa_sim_swap_query ~78

Check if a phone number's SIM card was recently swapped. Critical fraud prevention signal — SIM swaps often precede account takeovers. Use before high-value B2C disbursements to verify recipient identity is stable. Returns swap status and last swap date.

NameTypeReqDescription
phonestringyesPhone number to check for SIM swap activity

Structured output declared, but exposes no named fields.

No examples provided.

mpesa_stk_push ~133

Trigger M-Pesa STK Push — sends payment prompt to customer's phone. Customer enters M-PESA PIN to complete payment. Returns CheckoutRequestID; poll mpesa_stk_query after 10-30 seconds.

NameTypeReqDescription
account_refstringyesAccount reference shown to customer on phone (max 12 chars)
amountintegeryesAmount in KES (whole number, min 1, max 150000)
descriptionstringTransaction description (max 13 chars)
phonestringyesCustomer phone (any Kenyan format: +254..., 07..., 254...)

Structured output declared, but exposes no named fields.

No examples provided.

mpesa_stk_query ~69

Check STK Push status. Poll 10-30s after mpesa_stk_push. ResultCode 0 = success, 1032 = cancelled, 1037 = timed out.

NameTypeReqDescription
checkout_request_idstringyesCheckoutRequestID from mpesa_stk_push response

Structured output declared, but exposes no named fields.

No examples provided.

mpesa_tax_remittance ~101

Remit tax directly from M-PESA business account to Kenya Revenue Authority. Provide the KRA Payment Registration Number (PRN) as account_reference. KRA shortcode: 572572. Requires MPESA_INITIATOR_NAME and MPESA_SECURITY_CREDENTIAL.

NameTypeReqDescription
account_referencestringyesKRA Payment Registration Number (PRN)
amountintegeryesTax amount in KES
remarksstringRemittance remarks

Structured output declared, but exposes no named fields.

No examples provided.

mpesa_transaction_status ~66

Query status of any M-Pesa transaction by receipt number. Requires MPESA_INITIATOR_NAME and MPESA_SECURITY_CREDENTIAL. Result delivered async to MPESA_RESULT_URL.

NameTypeReqDescription
transaction_idstringyesM-Pesa receipt number e.g. QKL8XXXXXX

Structured output declared, but exposes no named fields.

No examples provided.

sms_send ~108

Send SMS to 1-1000 recipients via Africa's Talking. Works across Kenya, Nigeria, Ghana, Tanzania, Uganda, Rwanda and 15+ more. Returns per-recipient status and cost breakdown.

NameTypeReqDescription
messagestringyesSMS message text. Unicode supported (Kiswahili etc.)
recipientsarrayyesPhone numbers in E.164 format e.g. ['+254712345678']
sender_idstringOptional pre-registered alphanumeric sender ID

Structured output declared, but exposes no named fields.

No examples provided.

Common questions

What is the io.github.gabrielmahia/mpesa-mcp server?

io.github.gabrielmahia/mpesa-mcp is listed in the public MCP registry as io.github.gabrielmahia/mpesa-mcp. MCP server for M-Pesa mobile-money integration in Kenya. This page covers its PyPI package (mpesa-mcp).

Is the io.github.gabrielmahia/mpesa-mcp server safe to use?

io.github.gabrielmahia/mpesa-mcp scores 65 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 20 September 2026. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the io.github.gabrielmahia/mpesa-mcp server expose?

io.github.gabrielmahia/mpesa-mcp exposes 23 tools: mpesa_stk_push, mpesa_stk_query, mpesa_b2c, mpesa_business_paybill, mpesa_business_buygoods, and 18 more. Their descriptions and schemas cost roughly 2,298 tokens of context every time the server is loaded.

Is the io.github.gabrielmahia/mpesa-mcp server still maintained?

io.github.gabrielmahia/mpesa-mcp is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.