Blog · 2026-09-25 · 8 min read
Sandbox to production: a practical M-Pesa go-live checklist
A field checklist for moving Kenyan M-Pesa collections from test credentials to real customers without the usual Friday-night surprises.
Sandbox success is not production readiness. The checklist below is the one we wish every team ran before the first real STK Push to a customer.
Before you flip the switch
Confirm shortcode, passkey, and callback URL for the live environment. Callbacks must be public HTTPS with a valid certificate. Disable sandbox URLs in config—mixed environments are a classic source of “it works on my machine” payments.
Run a small real payment to a phone you control. Verify the callback body, your database row, and the customer-facing success state. Then test decline and timeout paths so support knows what the UI will say.
After go-live
Watch error rates for 48 hours. Keep a manual reconciliation path for the first week. Document who can rotate credentials and where they live (secret store, not a chat history).
When collections are stable, you can invest in product UX. Until then, reliability beats cleverness.
Questions
- How long does Safaricom go-live take?
- It varies with documentation quality and shortcode type. Build buffer into your launch plan instead of assuming same-day approval.