Skip to content
NOSTREL
Nairobi

We got tired of
watching good businesses
reconcile by hand.

Taking money on M-Pesa is a solved problem for about a week. Then the questions start, and they are all the same question wearing different clothes: which record do I believe?

Safaricom says 412 payments. The database says 409. Nobody has written down which three, or when, and the statement goes out at nine. That afternoon, repeated monthly, in a spreadsheet, is the problem this exists to remove, and it is a bookkeeping problem rather than a payments one. Which is why the ledger was built before the API rather than after it.

01Decided early

Four things, and what each one cost

A principle with no cost attached is a slogan. Each of these made something slower, harder or less impressive, and we would make the same call again.

A balance should be a conclusion, not an assertion

If your balance is a column somebody updates, it is a claim. If it is the sum of its postings, it is arithmetic, and you can always show the working. This is five hundred years old and it is still the answer, and it is the reason the ledger came before the API here rather than after it.

The safe choice should be the default one

Two-person approval on payouts is on unless you turn it off. Idempotency keys are required rather than offered. The configuration that protects you should not be the one that requires somebody to find it, because the people who find it are not the population that loses money.

Say the uncomfortable thing first

We are pre-launch. We do not hold Central Bank authorisation. There is no uptime figure, because there is no live volume to measure one from. All of that is on this site, in the present tense, above the fold of the relevant page. A reader who finds the gap from us shrugs; one who finds it later does not.

One country, properly

Kenyan shillings as integers, Safaricom phone prefixes validated against the real list, bank paybills read off each bank's own website. Expanding to four markets before the first one is right is how a payments company ends up mediocre everywhere.

02What we got wrong

Four, and they are the useful part of this page

Anyone can write a list of principles. The thing you cannot get from a competitor's about page is what a company does when it is the one at fault.

  1. 01

    We credited the ledger from an unauthenticated POST

    For a while, anybody who found the callback URL could have created money. The controller even had a comment describing the protection it was supposed to have, and no code did it. It is written up in full on the security page, because a company that will tell you that is telling you something true.

  2. 02

    We wrote fourteen-day credentials into the logs, 434 times in one session

    The redaction list covered the request cookie header and not the response one. A denylist was the wrong shape for the problem and we replaced it with an allowlist, which is the version that cannot be defeated by somebody adding a field.

  3. 03

    We made merchants wait to do anything at all

    Payment links were gated on verification, which was correct, and so was everything else, which was not. People could not lay out their products or draft an invoice while they waited. The fix was to let everything be prepared and only gate the collecting.

  4. 04

    Our own console had 596 rows a keyboard could not open

    Found by an accessibility audit we ran on ourselves. Along with a dialog that trapped focus and then dropped it, and five controls with no accessible name at all. All fixed, all written down.

03Where we are

Honestly, in four sentences

The state of things, stated plainly so that nobody has to infer it from the tense of our marketing copy.

Pre-launch

No live volume. Every figure in a screenshot on this site is seeded development data, and every page carrying one says so.

Built and tested

The API, both consoles, the ledger, reconciliation, settlement and webhook delivery exist and are under test, against Safaricom's own sandbox rather than a mock.

Not yet authorised

Central Bank authorisation is a prerequisite to launch rather than a feature to add later. We are working through it, and the compliance page says so in its first sentence.

Small

A small team in Nairobi who have spent more time reading Daraja documentation than is strictly healthy. There is no sales floor. If you write to us, somebody who has read the code replies.

Tell us what you are building

Especially if it is awkward. A business with a strange shape teaches us more in one conversation than a month of guessing, and being early means we can still change things for you rather than around you.