Till, Paybill, or Pochi number linked to the transaction
Select Identifier▼
✗ Account inactive
You haven't subscribed yet. Go to Setup → Billing to choose a plan and start verifying.
✗ Verification unavailable
Your employer has not paid for the subscription. Verification and the live transaction feed are paused until the merchant renews. Please contact the account owner.
Incoming Transactions
LIVE
Quick Verify
Use a transaction code or paste an M-Pesa SMS
How to read the result:
✅ Verified — Code found in network. Payment is 100% confirmed.⚠️ Unverified — Network Delay? — SMS structure looks valid, but code not in network. Could be a real payment that hasn't reached us yet, OR a clever fake. Use caution — do NOT rely on this alone.❌ Fraud / Tampered — SMS failed structure checks, do NOT release goods.
⚠️ Important: A clever fraudster can fabricate an SMS that passes format checks. The only 100% proof is a ✅ Verified result (code found in the network). For large amounts, always wait for the code to appear in the network before releasing goods.
✓ Transaction Details
Status—
Sender Name—
Amount—
Date—
Time—
Transaction Code—
Account Number—
Delay (Sender → You)—
✓ Customer Sale Confirmation
Generate a code and ask the customer to read it back. This creates an auditable proof-of-sale record.
Code for
000000
Show the code to the customer and ask them to read it back to confirm the sale.
Pesa Verify stores only the data you give us or that is necessary for payment verification:
Account info: first name, last name, phone number, and a hashed password
Transaction data: M-Pesa transaction codes, sender names, amounts, timestamps, and the identifier (Till/Paybill/Pochi) used
Sale confirmations: customer phone number and timestamp of confirmed sales (for fraud dispute evidence)
Usage logs: audit trail of who verified what and when
2. What We Never Collect
M-Pesa PINs or passwords — the app never asks for, sees, or stores your M-Pesa PIN
Personal documents — no ID numbers, bank accounts, or other sensitive personal identifiers
Location, contacts, or device data
3. Where Your Data Lives
On your own server. Pesa Verify is a self-hosted application. Your data stays on the machine you run it on. The developers of Pesa Verify never access your server or your data. Backup files also stay on your server.
4. How We Use Your Data
To verify M-Pesa payments by matching transaction codes against the M-Pesa network
To detect and flag potentially fraudulent transactions
To provide you with usage reports and audit logs
To manage your subscription and billing
We do not sell, rent, or share your data with third parties. We do not use your data for advertising or analytics.
5. Your Rights (Data Protection Act 2019)
Under Kenya's Data Protection Act, 2019, you have the right to:
Access — request a copy of all data we hold about you
Correction — update inaccurate or incomplete data
Deletion — permanently delete your account and all associated data (Setup → Security → Danger Zone)
Data portability — export your data in a machine-readable format
To exercise any of these rights, email support@pesaverify.com or use the Delete Customer Data tool in your account.
6. Data Retention
We retain your data for as long as your account is active. If you delete your account, all associated data is permanently removed within 24 hours. Backup files containing your data are automatically rotated and deleted within 48 days.
7. Security
Passwords are hashed — we never store them in plain text
Login sessions expire after inactivity
Accounts are temporarily locked after 5 failed login attempts
Your server is yours — you control its security
8. Third-Party Services
When subscription payments are processed via M-Pesa STK Push, the transaction is handled directly between you and Safaricom. Pesa Verify never sees your M-Pesa PIN and does not process payments directly.
9. Changes to This Policy
If this policy changes materially, you'll be notified the next time you log in. Continued use after changes means you accept the updated policy.
Pesa Verify is an independent software tool. It is not affiliated with, endorsed by, or sponsored by Safaricom PLC, M-Pesa, or any of their subsidiaries. All trademarks belong to their respective owners.
Liability Disclaimer
Pesa Verify is a verification aid provided "as is." It does not guarantee the authenticity of any transaction. Merchants remain solely responsible for their own business decisions, including but not limited to releasing goods or services based on verification results. The developers of Pesa Verify shall not be held liable for any losses arising from the use of this software.
By registering for, accessing, or using Pesa Verify ("the Service"), you agree to be bound by these Terms of Service. If you do not agree, do not use the Service.
2. Description of Service
Pesa Verify is a self-hosted software tool that helps merchants verify M-Pesa payments by matching transaction codes and detecting potentially suspicious activity. Merchants install and run the software on their own server. The Service is provided "as is" without any warranty — see Section 8 below.
3. Account Registration
You must provide accurate and complete information when creating an account
You are responsible for safeguarding your login credentials
You may not create multiple merchant accounts to circumvent subscription billing
Each merchant account must have a unique phone number and name — duplicate registrations are prohibited
You must be a registered business or individual operating lawfully in Kenya
4. Subscriptions & Billing
New accounts receive a free trial period (currently 3 days) with full Plus-tier features
After the trial, a paid subscription (Single or Plus) is required to continue verifying transactions
Subscription fees are paid via M-Pesa STK Push to the Paybill number displayed in your account
Payments are processed by Safaricom — Pesa Verify never stores M-Pesa PINs or payment credentials
Subscriptions auto-expire after 30 days unless renewed. No auto-renewal — you must manually renew each month
All fees are in Kenyan Shillings (KES) and are non-refundable except as required by Kenyan law
5. Acceptable Use
You may use the Service solely for legitimate payment verification in your business operations
You may not use the Service for fraudulent activity, money laundering, or any unlawful purpose
You may not reverse-engineer, copy, or redistribute the software without written permission
You may not attempt to bypass subscription billing or access restrictions
You are responsible for all activity under your account
6. Data & Privacy
Your use of the Service is governed by our Privacy Policy, which is incorporated into these Terms by reference. In summary:
Your data stays on your own server — we never access it
Transaction data is used only for verification and fraud detection within your account
We do not sell or share your data with third parties
You can delete your account and all associated data at any time
7. Limitation of Liability
Pesa Verify is a verification aid only. It does not guarantee the authenticity of any transaction, the correctness of any verification result, or the availability of the M-Pesa network. To the maximum extent permitted by law, the developers of Pesa Verify shall not be liable for any direct, indirect, incidental, or consequential damages arising from your use of the Service, including but not limited to:
Releasing goods or services based on a verification result that later proves incorrect
Service interruptions, downtime, or data loss
Fraudulent transactions that the system fails to detect
Any business losses, lost profits, or reputational harm
You assume full responsibility for your business decisions. If you are dissatisfied with the Service, your sole remedy is to stop using it and delete your account.
8. Disclaimer of Warranties
The Service is provided "as is" and "as available" without warranty of any kind, express or implied, including but not limited to merchantability, fitness for a particular purpose, or non-infringement. The developers do not warrant that the Service will be uninterrupted, error-free, secure, or that defects will be corrected.
9. Termination
You may delete your account at any time from Settings → Security → Danger Zone. The developers reserve the right to suspend or terminate accounts that violate these Terms, with or without notice. Upon termination, your data is permanently deleted within 24 hours.
10. Changes to Terms
These Terms may be updated from time to time. Material changes will be notified on your next login after the change. Continued use of the Service after changes constitutes acceptance of the updated Terms.
11. Governing Law
These Terms are governed by the laws of the Republic of Kenya. Any disputes arising from these Terms shall be resolved in the courts of Kenya.
Reversals where the customer had confirmed the sale. These are potential fraud disputes.
By Employee
No activity for this date.
Daily Reports
Transaction summaries and breakdowns
0
Transactions
KES 0
Total Volume
KES 0
Average
By Identifier
By Employee
Hourly Breakdown
Top Transactions
Code
Sender
Amount
Identifier
Time
Daily Breakdown
Transactions per day this month
Per Employee — Monthly Totals
Each employee's transaction count and volume
No transactions found for this period.
Audit Logs
System activity for your account and employees
Time
User
Action
Details
Status
🛡️ Admin Panel
Merchant overview — signups, subscriptions, and revenue
—
Total Merchants
—
Active
—
Expired
KES 0
Monthly Rev
KES 0
Annual Proj.
KES 0
Total Paid
0
Inactive
0
Single
0
Plus
📋 Recent Signups
Loading...
🔍 Search Merchants (name, phone, username, or till/paybill/pochi)
📊 All Merchants
Name, phone, username, tier, status, and days remaining
Name
Phone
Username
Tier
Status
Days Left
Actions
💳 Recent Payments
Every subscription payment received — real money, newest first
Payer
User
Tier
Amount
Phone
When
🔍 Verify Receipt with Safaricom
Paste an M-Pesa receipt code (e.g. MAB1234567) to query Safaricom's own record of it — confirms a payment is genuine and pulls the amount, time and payer name.
🛠️ System Errors
Last 50 unhandled app errors — catch bugs before users tell you about them
Loading...
📅 Due Subscribers
Subscribers expiring in 7 days, 3 days, 2 days, or 1 day — and overdue. Reach out before they lose access.
Loading...
Fraud Analytics
Real-time fraud detection for your transactions
—
Unresolved
—
Critical
—
Resolved
Alerts
🚨 Disputed Reversals
Transactions where the customer confirmed the sale but a reversal was still processed. Merchant should dispute with Safaricom.
Detection Rules
Enable or disable fraud detection rules. Toggling applies immediately.
🌐 Global Rules
Manage fraud detection rules for all merchants from one view.
📡 Connect Your Till/Paybill
When a customer pays, the transaction auto-appears in your Live Feed
How to set up:
Open MySafaricom App for Business
Go to your Till / Paybill settings
Find C2B Callback URL or Payment Notifications
Paste the URLs below — one for Confirmation, one for Validation
That’s it — next payment will show up in Live Feed 🎯
Your callback URLs:
✅ Confirmation
—
🔍 Validation
—
⚡ Not using MySafaricom? Call Safaricom (100 or *234#) and say: "Register this URL for C2B notifications on my Till: —"
Auto-registers your callback URL with Safaricom for all your identifiers (Till/Paybill/Pochi numbers). Requires Daraja API to be configured.
Developer Settings
Advanced configuration for developer accounts only
To go live:
Register at developer.safaricom.co.ke
Get Consumer Key, Secret, and Passkey
Edit .env file in project root
Set SAFARICOM_ENV=production
Set CALLBACK_BASE_URL to your HTTPS domain
Compliance Tools
Current Plan
—
—
⚠️ Your subscription expires soon — renew to avoid interruption
Single
KES 295 / month
1 employee • 2 identifiers
Current
Plus ⭐
KES 585 / month
Unlimited employees & identifiers
Recommended
Current
My Identifiers
Till, Paybill, and Pochi numbers you own
No identifiers yet. Add your Till/Paybill/Pochi numbers above.
Change Password
▶ Danger Zone
Delete Account — Permanently removes your account, all employees, and all data. Cannot be undone.
Frequently Asked Questions
Answers to common questions about the app
Getting Started
What is Pesa Verify? ▼
A tool for businesses to verify M-Pesa payments in real-time. Register your Till, Paybill, or Pochi number, then paste a customer's M-Pesa SMS — the app parses the code, checks the sender and amount, and flags anything suspicious.
How do I sign up? ▼
Click Sign Up in the top bar, enter your first name, last name, phone number, and a password. Your username is auto-generated from your name. After signing up you'll be taken to Setup → Billing to choose a plan and subscribe before you can start using the app.
What do I need to get started? ▼
Just two things: a registered M-Pesa business number (Till, Paybill, or Pochi) and a way to receive your customers' M-Pesa confirmation messages. You'll also need your phone number to set up your account and subscribe. No API keys or technical setup required.
I forgot my password — how do I reset it? ▼
It's a two-step process:
Step 1: On the login page, click Reset Password. Enter your first and last name and click Lookup Account. The app checks what recovery options are available for your account.
Step 2: You'll see only the options that work for your account — if you have identifiers (Till, Paybill, Pochi) those will show up; otherwise only Phone Number will be available. Enter the value, click Reset Password, and a temporary password is generated. Copy it, log in, and you'll be prompted to set a new one. Note: only merchant accounts can self-reset; employees should ask their merchant to reset their password.
I don't have any identifiers set up and forgot my password — what do I do? ▼
The password reset flow automatically detects that. After entering your name, the app will only show Phone Number as the recovery option (your identifiers section will be hidden). Use the phone number you registered with. If that doesn't work either, contact support@pesaverify.com for a manual password reset.
Verification
How does transaction verification work? ▼
Enter your identifier (Till/Paybill/Pochi number), paste the customer's M-Pesa SMS, and click Verify. The app extracts the transaction code, sender name, amount, date, and time — then cross-checks against both your records and the entire Pesa Verify network. Results appear instantly.
How do I read the verdict? What does each result mean? ▼
✅ Verified — The code was found in the Pesa Verify network. Another merchant received this exact payment. 100% confirmed — safe to release goods.
🟡 Unverified — Not in Network — The SMS format passes basic checks (has "Confirmed on" + amount), but the code is NOT in the network. This does NOT confirm the payment is real. It could be:
• A real transaction that hasn't reached the network yet (try again in 30s)
• A cleverly fabricated SMS by a fraudster Use caution. For large amounts, wait for ✅ Verified before releasing goods.
❌ Fraud / Tampered — The SMS failed structure checks (invalid code format, missing keywords, or code found but sender/amount don't match). Do NOT release goods.
⚠️ Important: A clever fraudster can fabricate an SMS that passes format checks. The only 100% proof is a ✅ Verified result where the code is found in the network. Always use your judgment.
What does "Unverified — Not in Network" mean? ▼
The SMS format passes basic checks, but the transaction code is not found in the Pesa Verify network. This does NOT confirm the payment is real — a clever fraudster can fabricate a convincing SMS. Only a ✅ Verified result is 100% proof. If the customer paid recently, try again in 30 seconds — it may appear after a brief network delay. For large amounts, wait for network confirmation before releasing goods.
Can I verify without pasting the full SMS? ▼
Yes. Switch to By Code mode and enter just the transaction code (e.g. RJX9H82KLM). The app will match it against your records and show the transaction details.
Why does it flag "Tampered SMS"? ▼
The transaction code exists in your records, but the sender name or amount in the SMS doesn't match. This could mean the customer edited the SMS screenshot — a common fraud tactic. The app flags it so you can double-check before releasing goods.
Identifiers
What's the difference between Till, Paybill, and Pochi? ▼
Till numbers are for Lipa Na M-Pesa (buy goods/services). Paybill numbers are for bill payments — the business number is what you register. Pochi is a personal Till for informal businesses. All three work with this app.
For Paybills, do I register the business number or account number? ▼
The business number (shortcode). That's what Safaricom sends callbacks to. The account number (e.g. INV-001) is just what your customer types when paying — the app extracts it from the SMS for display.
How do I add an identifier? ▼
Go to Setup → Identifiers, pick the type (Till/Paybill/Pochi), enter the number, and click Add. For Paybills you can also enter an optional Account Number (e.g. INV-001) that your customers include when paying. To auto-receive payment notifications, connect your Till/Paybill via the Connect Your Till/Paybill card in Setup → Account.
Employees & Team
How do I give an employee access to a specific Till? ▼
Go to Employees, find the employee's card, pick the identifier type and enter the number, then click Grant. The employee can now verify payments against that number.
What can employees do? ▼
Employees can verify payments against the identifiers you've granted them. They cannot manage billing, add or remove identifiers, manage other employees, or delete the account.
What happens when I remove an employee? ▼
Their account is deleted immediately and all granted identifiers are revoked. This action is permanent — it cannot be undone.
An employee forgot their password — what do I do? ▼
Go to Employees, find their card, type a new password in the New password field, and click Reset. The employee can then log in with the new password. They'll be prompted to change it on first login.
Billing & Subscription
How much does it cost? ▼
Single: KES 295/month — 1 employee, 2 identifiers. Plus: KES 585/month — unlimited employees and identifiers. New accounts start inactive — choose a plan and pay via M-Pesa STK Push to activate.
How do I pay for a subscription? ▼
Go to Setup → Billing, select Single or Plus, enter your M-Pesa phone number, and click Pay. You'll receive an STK Push on your phone — enter your M-Pesa PIN to confirm. Your subscription activates automatically once the payment clears.
What happens if I don't subscribe? ▼
Your account stays inactive. You can log in and view the billing page, but adding identifiers, managing employees, and verifying transactions are all blocked until you subscribe. Your account, data, and info are preserved — just pick a plan and pay to start.
Can I switch plans later? ▼
Yes. Upgrade from Single to Plus anytime from the Billing tab. You're charged the full Plus price (KES 585) and get a fresh 30-day cycle starting immediately.
Security & Privacy
Is my M-Pesa data safe? ▼
Yes. The app runs entirely on your own server. It never sees or stores your M-Pesa PIN. Transaction data stays on your system — only you and your employees can access it. No data is sent to third parties.
How does fraud detection work? ▼
The app runs multiple checks on every verification: code format validation, SMS structure integrity, sender name matching, amount matching, and time-sensitivity. If a reversal comes in for a transaction the customer already confirmed, it raises a CRITICAL fraud alert.
How do I delete my account? ▼
Go to Setup → Security, expand the Danger Zone, enter your password, and confirm. This permanently deletes your account, all employees, identifiers, transactions, and verification history.
What if someone tries to guess my password? ▼
After 5 failed login attempts, that account is locked for 5 minutes. The block applies per username, so other users on your team aren't affected.
🔒 Change Password
Your password was reset. Set a new one to continue.
Scan to share Pesa Verify
Pesa Verify — A tool for verifying M-Pesa payments.
•Privacy Policy•Terms of Service Not affiliated with, endorsed by, or sponsored by Safaricom PLC, M-Pesa, or their subsidiaries. Pesa Verify is provided "as is" — merchants remain responsible for their own verification decisions.
🔧 Fix Account
Reset the merchant's password and/or correct their name. Leave a field empty to keep it unchanged.
🎁 Gift Days
Extend this subscriber's expiry. Great for giveaways and generous days! 🎉