Production & Go-Live Checklist
Before transitioning from sandbox/test environments to live production payment processing with Safaricom Daraja 3.0, Pesapal, or Stripe, review this checklist.
1. Safaricom Daraja 3.0 Live Migration
- Production Credentials:
- Obtain your production
Consumer KeyandConsumer Secretfrom the Safaricom Daraja Developer Portal. - In production, your Paybill/Till shortcode and passkey will be provided upon completing Safaricom KYC verification.
- Obtain your production
- Environment Toggle:env
pesa.gateways.mpesa.env = live pesa.gateways.mpesa.shortcode = your_live_shortcode pesa.gateways.mpesa.consumer_key = your_live_consumer_key pesa.gateways.mpesa.consumer_secret = your_live_consumer_secret pesa.gateways.mpesa.passkey = your_live_passkey - Mandatory HTTPS & Valid SSL:
- Safaricom Daraja rejects any callback or webhook URL that is not served over valid HTTPS with a trusted CA certificate (self-signed certs are rejected).
- B2C Public Certificate Installation (for Payouts):
- Download the Safaricom Production Public Certificate (
.cerfile). - Place it in a secure non-public directory (e.g.
writable/certs/ProductionCertificate.cer) and configurecert_path:
envpesa.gateways.mpesa.initiator_name = live_initiator_username pesa.gateways.mpesa.initiator_password = live_plaintext_initiator_password pesa.gateways.mpesa.cert_path = '/path/to/writable/certs/ProductionCertificate.cer' - Download the Safaricom Production Public Certificate (
- Register Live C2B URLs:bash
php spark jengo:pesa mpesa register-c2b --shortcode=your_live_shortcode
2. Pesapal v3 Go-Live
- Switch endpoint from Cybqa Sandbox to Live:env
pesa.gateways.pesapal.env = live pesa.gateways.pesapal.consumer_key = your_live_key pesa.gateways.pesapal.consumer_secret = your_live_secret - Register your live IPN URL with Pesapal and set the resulting
notification_idinapp/Config/Pesa.phpor.env(pesa.gateways.pesapal.ipn_id).
3. Stripe Production Setup
- Configure live secret key and live webhook signing secret:env
pesa.gateways.stripe.secret = sk_live_... pesa.gateways.stripe.webhook_secret = whsec_... - In the Stripe Dashboard, add your webhook endpoint
https://yourdomain.com/pesa/webhook/stripelistening forcheckout.session.completed,payment_intent.succeeded, andcharge.refunded.
4. Database & Ledger Health
- Verify that
php spark migrate --allhas executed cleanly in production and thepesa_transactionstable exists with appropriate indexing ongateway,gateway_reference,reference, andstatus. - Ensure database timezone is aligned with UTC or Africa/Nairobi.
