REST API - Payments#

M-Pesa (STK push) and Snippe (mobile money + hosted checkout).

EndpointMethodDescription
/projects/{id}/payments/settingsGET / PUTPayment provider settings
/projects/{id}/payments/mpesa/stk-pushPOSTM-Pesa STK push
/projects/{id}/payments/snippe/initiatePOSTSnippe direct payment
/projects/{id}/payments/snippe/sessionPOSTSnippe hosted checkout
/projects/{id}/payments/snippe/status/{reference}GETPayment status
/projects/{id}/payments/transactionsGETList transactions
/projects/{id}/payments/transactions/{transactionID}GETOne transaction

M-Pesa STK push#

POST /projects/{id}/payments/mpesa/stk-push
Text
{
  "phone": "+255712345678",
  "amount": 5000,
  "description": "Order #123"
}
JSON

The customer authorizes on their phone; RafikiDB receives the callback and records the transaction.

Snippe#

Initiate a direct payment:

{
  "amount": 5000,
  "phone": "+255712345678",
  "first_name": "Asha",
  "last_name": "Mwinyi",
  "email": "asha@example.com",
  "order_id": "ORD-123"
}
Text

Hosted checkout session:

{
  "amount": 25000,
  "description": "Checkout",
  "redirect_url": "https://myapp.com/thanks",
  "customer_name": "Asha Mwinyi",
  "customer_phone": "+255712345678",
  "expires_in": 3600
}
JSON

Status#

GET /projects/{id}/payments/snippe/status/{reference}
Text

Returns the payment state (pending / completed / failed / ...).

Callbacks#

Snippe and M-Pesa send callbacks to RafikiDB; you receive them as payment webhook deliveries (HMAC-signed like webhooks).

Security#

  • Accepts the project API key (or a project-user session)
  • Scoped keys: payments:read, payments:write