M-pesa
For a Kenya-licensed operator, M-Pesa is the primary local rail—two-way, indicative ~1.5–3.5% on aggregator collections plus a small per-payout B2C fee, settling in KES to a local bank—but only within a GRA-compliant structure, with player funds held in a Kenyan-registered bank. With more than 37 million one-month-active users reported by Safaricom for the six months to September 2025, it dominates Kenya's mobile money market. Beyond East Africa, it is simply a regional wallet, so treat it as the anchor of a local stack, not a worldwide casino payment method.
WHY M-PESA ANCHORS THE KENYAN CASHIER
In its home market, M-Pesa is not “an alternative payment method“—it is the default. Roughly nine in ten Kenyan mobile-money transactions run on it, and licensed sportsbooks and casinos have built their entire cashier around the M-Pesa paybill for close to two decades. For a Kenya-facing operator, offering M-Pesa is the difference between a working local casino payment option and a dead cashier; for the wider region, it fits operators targeting Tanzania, the DRC, Mozambique and Lesotho, where Vodacom runs the same brand. It is not, however, a standalone global solution—it does not touch Nigeria, South Africa, most of Europe or the Americas, and even inside Africa it competes with Airtel Money and MTN MoMo.
Where M-Pesa beats a card-first cashier
M-Pesa‘s advantages cluster around reach, familiarity and settlement speed—the exact places card acquiring struggles in East Africa.
Reach that kills the issuer-decline problem. Near-universal adoption among Kenyan players removes the failed-card problem that plagues card-first cashiers, and the paybill flow is something every adult customer already knows. Deposits are effectively instant, which lifts conversion on impulse-driven sports and jackpot products.
No card or bank account required of the player. Funding needs only a SIM-bound PIN, settles in KES, and starts from as little as KES 1–10 at Kenyan betting sites—so the funnel stays open to casual bettors, not just high-rollers.
Pricing that is predictable and locally benchmarked. Collections run indicatively ~1.5–3.5% through an aggregator; the Daraja API itself is free, and near-real-time settlement to the paybill (then swept to a local bank) shortens the cash-flow cycle versus card acquiring.
One API for deposits and payouts. Safaricom’s Daraja exposes STK Push (M-Pesa Express) for one-tap deposits, C2B for paybill collections and B2C for automated withdrawals, with callbacks carrying the receipt number, payer number, amount and account reference—enough to reconcile cleanly and credit the wallet in real time.
The gaps an M-Pesa-only cashier leaves
The constraints are less about the rail’s mechanics and more about geography, regulation, and who gets excluded, so weigh each before you rely on it alone.
Geographic ceiling. M-Pesa lives in ~7 African markets. Outside them, it is simply unavailable as an online payment platform, so it can never be your only casino payment provider for a multi-region brand.
Regulatory gating (Kenya). Under the Gambling Control Act, 2025, all player funds must move through a Kenyan-registered bank, foreign operators must incorporate locally with ~30% Kenyan ownership, and remote-platform/payments technology needs authorization. M-Pesa access is therefore contingent on a compliant local structure, not just a technical integration. If you are unsure whether your intended corporate and banking setup satisfies the new GRA regime, the GR8_TECH team can map your target-market requirements before you commit to a shortcode.
Reversal exposure. M-Pesa‘s consumer reversal mechanism behaves like a lightweight chargeback: a mistaken or disputed C2B payment can be pulled back, so operators need reconciliation and hold logic rather than crediting on the STK prompt alone.
Tax drag on the funnel. Kenya’s Finance Act 2025 applies a 5% excise on deposits and a 5% excise on withdrawals, both felt by the player at the cashier—a material factor in deposit sizing and churn that operators should model, even though it is not an M-Pesa fee.
Non-Safaricom players. Airtel Money’s share is climbing past 10% in Kenya, so an M-Pesa-only cashier quietly excludes a growing minority of users.
WHERE M-PESA WORKS AS A GAMBLING RAIL
M-Pesa is a regional mobile-money network, not a worldwide scheme, and its usefulness as a gambling rail varies sharply by country. The table below covers where it is a genuine online casino payment method versus where it exists but is not a practical gambling channel.
| Market / GEO | M-Pesa availability | Operator considerations |
| Kenya | Ubiquitous; ~89–91% of mobile-money subscriptions; every major licensed operator (SportPesa, Betika, Odibets, Mozzart, 22Bet, betPawa) uses an M-Pesa paybill | Primary rail. Requires GRA license, local bank account for stakes/winnings, real-time monitoring; 5% deposit + 5% withdrawal excise |
| Tanzania | Vodacom M-Pesa is a leading wallet; regulated betting exists under the Gaming Board of Tanzania | Strong secondary market; confirm PSP support and local licensing; competes with Tigo Pesa / Airtel Money |
| DRC | Vodacom M-Pesa present but lower penetration; nascent gambling regulation | Usable but thin; treat as supplementary, pair with cards/other wallets |
| Mozambique | Vodacom M-Pesa widely used for P2P/merchant | Limited licensed online-gambling framework; verify legality and PSP acceptance before promising it |
| Lesotho | Vodacom M-Pesa is the dominant wallet | Small market; supplementary rail only |
💡 M-Pesa is not usable as a gambling rail in most of the world. It has no consumer footprint in Nigeria, South Africa (M-Pesa was withdrawn there in 2016), India, Romania, Albania, or the rest of Europe and the Americas. In Egypt and Ghana—nominal M-Pesa/adjacent markets—it is not a practical casino payment option: Egypt broadly prohibits gambling for residents, and Ghana’s mobile-money volume runs on MTN MoMo, not M-Pesa. Treat M-Pesa as an East-African rail and source separate local methods elsewhere.
M-Pesa and Kenya’s 2025 gambling law: what operators need to know
Kenya rewrote its gambling law in 2025, and the payment consequences are direct. This is the single most important context for any operator planning an M-Pesa cashier.
⚠️ Regulator and law. The Gambling Control Act, 2025 (Act No. 14 of 2025) replaced the 1966 Betting, Lotteries and Gaming Act and created the Gambling Regulatory Authority (GRA), which took over from the BCLB during a transition targeted for completion by the end of February 2026. License processing was paused during the switch; existing licenses continued until expiry.
⚠️ Funds must stay local. All transactions involving Kenyan players must be processed through a Kenyan-registered bank, with dedicated local accounts for stakes and winnings so the GRA and the Kenya Revenue Authority have full visibility. Your M-Pesa collections and B2C payouts have to settle into that structure.
⚠️ Local presence and monitoring. Foreign operators must incorporate in Kenya, keep a physical address and audited accounts, meet a ~30% Kenyan-ownership threshold, obtain remote-platform authorization, and connect to the GRA’s real-time monitoring system (local hosting or a real-time data mirror). Unlicensed operation carries fines up to KES 50 million.
⚠️ Advertising and tax. Celebrity and lifestyle gambling ads are banned, and all ads need GRA pre-approval; the Finance Act 2025 excise (5% on deposits, 5% on withdrawals) is deducted at the cashier.
DEPOSITS, B2C PAYOUTS AND KES SETTLEMENT
M-Pesa is a genuinely two-way rail: it both collects deposits (via paybill/STK Push) and pushes withdrawals (via B2C) back to the player’s registered number. The table states the operator-relevant behavior.
| Area | Operator view |
| Deposit availability | Yes—STK Push (M-Pesa Express) or manual paybill entry (Lipa na M-Pesa → Pay Bill), C2B into the operator shortcode |
| Withdrawal availability | Yes—automated B2C push to the player’s registered Safaricom number; no card-return dependency |
| Typical deposit speed | Seconds; player credited on the confirmed callback |
| Typical withdrawal speed | Instant to a few hours in practice; some operators queue payouts (minutes to 24h) for risk/AML checks |
| Settlement model | Near-real-time to the M-Pesa business account, swept to the operator’s Kenyan bank ~D+0/D+1; settlement currency KES |
| Deposit-only risk | Low—payouts are natively supported via B2C, unlike card or wallet rails that only return to source |
| Deposit–withdrawal asymmetry | Minor—deposits are free-flowing; withdrawals depend on prefunded B2C float/working capital and operator risk holds |
| What depends on the setup | License status, the Kenyan bank account, the shortcode/aggregator relationship, and B2C float sizing |
How B2C payouts clear in practice
M-Pesa is a payout processor, not merely a payout destination—the B2C API lets the operator (or its PSP) initiate a push straight to the player’s phone, which is a real advantage over deposit-only rails. Payouts must return to the same registered number that funds the account, which both simplifies name-matching and constrains withdrawal-destination fraud. The practical constraint is liquidity: B2C runs off a prefunded utility/float balance, so operators need working capital sitting in the M-Pesa business account to clear payouts without delay. Where an operator lacks direct B2C access, its aggregator handles the push and reconciles it. If you need to confirm whether your target PSP enables direct B2C payouts at the volumes you expect, the GR8_TECH payments team can check it against your providers before launch.
BENCHMARK M-PESA COSTS AND METRICS
The figures below anchor the unit economics; treat them as indicative and confirm current Safaricom tariffs at onboarding.
| Item | Indicative value |
| MDR / transaction fee | ~1.5–3.5% on mobile-money collections via an aggregator; direct Daraja API is free, but you still pay Safaricom’s per-transaction tariffs. Payouts (B2C) priced separately |
| B2C payout fee | Indicative small per-transaction fee scaling by amount band (roughly KES 5–35+); confirm current Safaricom B2C tariff |
| Rolling reserve | Not standard for a domestic wallet; aggregators/PSPs may hold reserves on higher-risk merchants—confirm at onboarding |
| Settlement cadence & currency | Near-real-time to paybill; sweep to bank ~D+0/D+1; currency KES |
| Deposit limits | From ~KES 1–10 minimum; per-transaction and daily caps set by Safaricom wallet limits (per-transaction cap in the low hundreds of thousands of KES; confirm current limits) |
| Withdrawal limits | Bounded by wallet/daily limits and operator payout policy |
| Indicative approval rate | High for confirmed STK flows, but expect drop-off (~10–30%) from unentered PINs, timeouts, offline phones, or insufficient balance; reduce with clear prompts, retry logic, and fallbacks |
| FX/repatriation | Settlement is KES; operators reporting in EUR/USD carry FX and treasury/prefunding exposure on both collections and B2C float |
BUILDING AN EAST-AFRICAN STACK AROUND M-PESA
M-Pesa wins the largest slice of a Kenyan cashier, but no single wallet covers a market—let alone a region. A resilient East African iGaming payment solution pairs M-Pesa with the specific rails that plug its real gaps: non-Safaricom users, higher-value and diaspora players, larger bank-funded deposits, and neighboring GEOs. Every row below is chosen because it fills a gap M-Pesa itself leaves.
| Complementary payment layer | Why operators need It | Priority markets |
| Airtel Money | Captures the ~10%+ (and growing) of Kenyan players not on Safaricom; same STK/paybill logic | Kenya, Tanzania |
| Cards (Visa/Mastercard) | Higher-value and diaspora players; cross-border funding where mobile money can’t reach | Kenya (urban), diaspora |
| Bank transfer / PesaLink | Larger, bank-funded deposits above wallet caps; supports the mandated local-bank flow | Kenya |
| Crypto (USDT) | Privacy-seeking and cross-border high-rollers; useful where local rails are thin | Pan-African / global tail |
| Vodacom M-Pesa + local wallets | Extends the same brand into Tanzania, DRC, Mozambique, Lesotho; Tigo Pesa/Airtel fill coverage | Tanzania, DRC, Mozambique |
| Payment orchestration | Cascades and routes across mobile money, cards and banks; one reconciliation layer and success-rate optimization | All multi-GEO operators |
💭 The commercial point is that M-Pesa maximizes volume, but a single-rail cashier caps your addressable market and your resilience; the margin is won by routing intelligently across mobile money, cards and banks. That routing, monitoring and reconciliation layer is exactly what the GR8_TECH payment gateway is built to provide.
Connecting to M-Pesa: routes, providers and lead times
Most operators reach M-Pesa in one of three ways. Building directly on Safaricom’s Daraja API means applying for your own paybill/till shortcode and wiring STK Push and C2B for deposits and B2C for payouts—full control, but roughly 2–6 weeks of shortcode application, go-live checks, and in-house development. A gambling-capable aggregator is faster: it already holds the shortcode relationship and exposes a single REST/checkout layer, typically going live in days to about two weeks. An orchestration gateway wraps M-Pesa alongside your other rails behind one integration and reconciliation layer.
For provider selection, the gambling-enabled aggregators seen in Kenya include Pesapal, Flutterwave, DPO Group (Network International), Cellulant (Tingg), IntaSend and dLocal; in Tanzania, Selcom, Cellulant and Flutterwave; and for pan-African aggregation, Flutterwave, Cellulant, dLocal and Onafriq. Confirm any provider is contractually enabled for gambling in your GEO—general M-Pesa support is not the same as gambling acceptance.
On the operational side, Daraja callbacks return the receipt/transaction ID, the payer’s phone number, amount, timestamp, and account reference; C2B uses validation/confirmation URLs, and B2C returns a result callback. Build idempotent handling, reconcile against Safaricom statements, and never credit a wallet on the STK request alone. Onboarding will ask for business registration, the GRA (or local) gambling license, directors’ KYC, the Kenyan bank account, target-market details, and processing history.
FRAUD AND RISK ON A SIM-BOUND WALLET
M-Pesa‘s SIM-bound, closed-loop design blocks some card-era fraud but opens vectors of its own. The provider secures the rail; the operator still owns the gambling-specific risk stack, so focus controls on the four exposures below.
SIM-swap account takeover. Because the wallet is tied to the SIM, a fraudulent SIM swap can hijack both deposits and B2C payouts. Safaricom controls SIM security, but the operator must layer device/behavior signals and step-up checks on withdrawals.
Third-party funding and ownership mismatch. A deposit from a number that is not the registered player breaks KYC and RG assumptions. Same-number payout rules help, but operators must enforce name/number matching and block mule-account patterns.
Consumer-reversal clawbacks. M-Pesa‘s reversal flow can pull back a C2B payment after crediting, functioning like a mini-chargeback. Use holds and reconciliation rather than instant crediting on unconfirmed transactions.
Paybill spoofing and social engineering. Fake paybills impersonating operators harm players and the brand even when the operator isn’t directly defrauded. Publish and enforce the correct paybill and monitor for impersonation.
💭 Chargeback-style loss is lower than on cards, but AML and RG exposure is higher: cash-in via agents plus rapid bet-and-withdraw cycles is a classic laundering pattern that regulators now watch in real time.
COMPLIANCE UNDER KENYA’S POST-2025 REGIME
M-Pesa and its aggregators reduce the operator’s payments workload; they do not transfer the operator’s regulatory obligations. Kenya’s post-2025 regime makes that split unusually explicit.
| Domain | Provider position | Operator implication |
| PCI DSS | Mobile-money flow carries no card PAN, cutting card-data scope | Still secure API credentials/tokens; PCI applies only to any parallel card rail |
| SCA / authentication | SIM-bound M-Pesa PIN + STK confirmation authenticates the payer | Add device/behavior signals and withdrawal step-up; PIN alone isn’t full player KYC |
| AML & KYC | Safaricom performs SIM-registration KYC on the wallet holder | Operator owns player onboarding KYC/AML, monitoring and reporting |
| Account ownership | Same-number funding/payout aids matching | Enforce name/number matching; block third-party and mule funding |
| Responsible gambling | Rail-neutral; RG is not the wallet’s job | Deposit/loss limits, self-exclusion and GRA-mandated RG tools sit with the operator |
| Data protection | Provider handles wallet data under Kenyan law | Comply with Kenya’s Data Protection Act 2019 / ODPC for player data you hold |
| Transaction monitoring | Aggregators offer transaction dashboards | Feed the GRA real-time monitoring system; keep independent monitoring |
| Local gambling-payment restrictions | Rails are permitted for licensed betting | Funds must flow through a Kenyan-registered bank; local accounts for stakes/winnings |
| Recordkeeping & reporting | Callbacks/statements provide transaction records | Retain records for GRA/KRA; reconcile tax (deposit/withdrawal excise) |
| Sanctions screening | Not a substitute for operator screening | Screen players/counterparties independently |
M-PESA: THE OPERATOR TAKEAWAY
For a Kenya-licensed operator, M-Pesa isn’t a choice so much as a precondition. It is the primary local casino payment method—two-way, instant on deposit, natively capable of payouts, and trusted by tens of millions of players and every major licensed sportsbook in the country. Leaving it out doesn’t trim the cashier; it shutters it.
What determines success is the scaffolding around the rail. The Daraja or aggregator integration is the straightforward part; the hard part is the Gambling Control Act, 2025—local incorporation, a Kenyan bank account for all player funds, GRA authorization, and real-time monitoring—together with the tax drag, reversal handling, and the slice of players who aren’t on Safaricom. Get that structure right, and M-Pesa becomes the anchor of an East African stack; get it wrong and the integration stalls regardless of how clean the code is. To map M-Pesa to your license plan and target GEOs, talk to the GR8_TECH team.
Share