Skip to content
NOSTREL
Integrations

No logo wall.
Here is the actual surface.

The convention for a page like this is a grid of company logos implying partnerships that, read closely, mean "we have an API and so do they". We are pre-launch and have signed nothing, so that grid would be a lie, and the one reader who checks is exactly the reader we need.

What exists is four ways in and out, five M-Pesa rails underneath them, and a bank directory that took longer to get right than the rest of this page put together. All of it is checkable, which is the only kind of claim worth making.

01The surface

Four ways in and out

If your system can make an HTTPS request, receive one, or read a CSV, it can talk to this.

A REST API

JSON over HTTPS

Three endpoints move money: create a collection, create a payout, read your balance. Keys carry scopes, every write takes an idempotency key, and everything the dashboard can do sits on the same API, so there is nothing you can see that you cannot automate.

The API

Signed webhooks

Events to your server

HMAC signed over the exact bytes, timestamped against replay, retried on a backoff, dead-lettered where you can see and replay them. Written in the same database transaction as the thing that happened, so an event cannot go missing because a queue was busy.

Webhooks

CSV, in and out

For the spreadsheet half of the world

Upload a payout run as a CSV with four columns. Export transactions and statements for any date range. A great deal of Kenyan business runs on a spreadsheet, and a platform that refuses to meet it there is a platform that gets used twice and abandoned.

Bulk payouts

A statement an accountant accepts

Opening, in, out, fees, closing

Drawn from the same ledger postings as everything else rather than computed a second way, which is why it reconciles with the transaction list instead of nearly reconciling with it.

Collections

02Underneath

Five Safaricom rails, one shape of record

Which rail a payment arrived on is a field, not a different data model and not a different screen.

  • M-Pesa STK push (money in)

    Lipa na M-Pesa Online. Prompt to a handset.

    in
  • M-Pesa paybill (money in)

    C2B, routed by account reference.

    in
  • M-Pesa till (money in)

    Buy Goods, for a counter.

    in
  • M-Pesa B2C (money out)

    Business to customer. Payouts to any number.

    out
  • M-Pesa B2B (money out)

    Business to paybill. How a withdrawal reaches a bank.

    out

03In practice

What people actually wire this into

Not partnerships. Patterns, written by the person whose system it is, in an afternoon.

  • Your own order system

    A collection created when an order is placed, a webhook that marks it paid, and a reference that is your order number so support never has to translate between two numbering schemes.

  • An accounting package

    A statement export per period, or the transactions endpoint on a schedule. Fees arrive as their own ledger entries, which is the shape a bookkeeper expects rather than a net figure they have to decompose.

  • A spreadsheet

    Payouts up as a CSV, transactions down as a CSV. It is not glamorous and it is how a very large number of real Kenyan businesses run, including profitable ones.

  • A messaging workflow

    A payment link generated per customer and sent from whatever already sends your messages. No integration at all on the payment side.

  • An internal tool

    Scoped API keys, so the thing that reads balances cannot send money. A key that can only read is a key that cannot be used to steal.

the whole integration, honestlyts
// Mark an order paid when the webhook arrives, not before.import { verify } from './nostrel-signature'; export async function handler(req, res) {  // The bytes, not a re-serialised object.  const raw = await readRawBody(req);  if (!verify(process.env.NOSTREL_WEBHOOK_SECRET, req.headers['nostrel-signature'], raw)) {    return res.status(400).end();  }   const event = JSON.parse(raw);  if (event.type === 'collection.succeeded') {    await orders.markPaid(event.data.reference, {      amount: event.data.amount,      receipt: event.data.provider_receipt,    });  }   // Acknowledge fast; do the slow work elsewhere.  res.status(200).end();}

That is not a simplified excerpt. Verifying the signature and acting on one event type is most of what a collections integration is, and the webhooks page covers the rest, including why the raw bytes matter so much.

04Not here yet

What we have not built

Written in the future tense, because that is what it is.

Plugins for the shop platforms

There is no WooCommerce or Shopify plugin. The API is public and small enough that one is a short afternoon, and if you build one we will link to it on the credits page and help you with the awkward parts.

Official client libraries

Three endpoints and an HMAC check is a thin wrapper in any language, and a badly maintained SDK is worse than none. If demand says otherwise, that changes.

Card payments

This is an M-Pesa platform. Adding cards would mean a different regulator, a different fraud model and a different set of promises, and doing it badly would be worse than not doing it.

Anything outside Kenya

One country, one currency, one regulator, done properly. Expanding before that is true is how a payments company ends up mediocre in four markets.

Tell us what you need to connect

If the answer is a field we do not return or an event we do not raise, that is a short conversation and often a short change. We would rather hear it now than read about it later.