Back

Updating M-PESA Credentials After Setup

You can update your Daraja credentials at any time after the initial setup, whether after changing your app credentials in the Daraja portal or switching from the sandbox environment to production.

Before You Begin

Make sure you have the “Edit Payment Options” permission to access M-PESA settings. Users without this permission will not see the Payment Methods menu item.

 

Note: M-PESA is available only for accounts where Kenya is configured as the account country. 

Steps to Update Credentials

  1. From the main menu, navigate to “Payment Methods.”
  2. Locate the M-PESA card and click the settings icon (⚙) on it.
  3. The settings page opens displaying your saved credentials as follows:
    • Consumer Key: Shown in full.
    • Consumer Secret: Masked as ••••••••[last 4 characters] in a disabled field.
    • Business Shortcode: Shown in full.
    • Passkey: Masked as ••••••••[last 4 characters] in a disabled field.
    • Environment: Shows the currently selected option (Sandbox or Production).
  4. Click on any masked field to enable it and enter the new value.
  5. Modify the required fields.
  6. If you want to verify the new credentials before saving, click “Test Connection” — the system checks your newly entered (not yet saved) values against the Safaricom OAuth endpoint:
    • Success: “Connection successful.”
    • Failure: “Connection failed. Please check your credentials and try again.”
  7. Click “Save” — the message appears: M-PESA settings updated successfully.” You remain on the settings page.

Notes

  • Updating credentials only affects future payments — all historical M-PESA payment records remain unchanged.
  • All fields are required upon saving — an empty field shows: This field is required.”
  • Credentials are encrypted in the database and never appear in any logs, API responses, or anywhere on the frontend.