🕵️ SicherheitslückenWeb Application Firewall Rule Bypass in Jetpack WAF Runtime(17.09.2026 um 16:34 Uhr)
🕵️ SicherheitslückenCross-Site Request Forgery in WooCommerce Product and Term Ordering(17.09.2026 um 16:34 Uhr)
🕵️ SicherheitslückenUnescaped Output in Enable Media Replace Error View(17.09.2026 um 16:34 Uhr)
🕵️ SicherheitslückenStored Cross-Site Scripting in WooCommerce Order Notes REST API v4(17.09.2026 um 16:34 Uhr)
🕵️ SicherheitslückenUnescaped Attribute Output in Enable Media Replace Upsell View(17.09.2026 um 16:34 Uhr)
🕵️ SicherheitslückenWeb Application Firewall Rule Bypass in Jetpack WAF Runtime(17.09.2026 um 16:34 Uhr)
🕵️ SicherheitslückenCross-Site Request Forgery in WooCommerce Product and Term Ordering(17.09.2026 um 16:34 Uhr)
🕵️ SicherheitslückenUnescaped Output in Enable Media Replace Error View(17.09.2026 um 16:34 Uhr)
🕵️ SicherheitslückenStored Cross-Site Scripting in WooCommerce Order Notes REST API v4(17.09.2026 um 16:34 Uhr)
🕵️ SicherheitslückenUnescaped Attribute Output in Enable Media Replace Upsell View(17.09.2026 um 16:34 Uhr)
🔧 Programmierung 🕛 vor 2 Monaten 4 Min Lesezeit
0

Automating M-Pesa Rent Collection in Kenya: The Technical Architecture

↗ Quelle (dev.to)
🗣️ Stimme:
📑 Inhaltsübersicht

M-Pesa handles over 90% of rent payments in Kenya. But most landlords still reconcile these payments manually — downloading statements, matching transactions to tenants line by line in Excel. We automated this entire flow.



Here is how we built the M-Pesa rent collection system inside



2. IPN (Instant Payment Notification) callbacks



Safaricom sends a POST request to our endpoint every time a payment is made. This gives us real-time data — no polling, no delays.




CODE
# Simplified IPN handler
@csrf_exempt
def mpesa_callback(request):
data = json.loads(request.body)

transaction_id = data['TransID']
amount = Decimal(data['TransAmount'])
account_ref = data['BillRefNumber'] # Unit number
phone = data['MSISDN']

# Find tenant by unit reference
tenant = Tenant.objects.filter(
unit__unit_number__iexact=account_ref,
unit__property__organization=org
).first()

if tenant:
# Record payment
payment = MpesaPayment.objects.create(
tenant=tenant,
amount=amount,
transaction_id=transaction_id,
phone_number=phone
)
# Auto-reconcile against outstanding invoice
reconcile_payment(payment)
# Send SMS receipt
send_receipt_sms(tenant, amount, transaction_id)

return JsonResponse({'ResultCode': 0})






3. Fuzzy matching for account references



Tenants do not always type their unit number correctly. "A3" might come in as "a3", "A 3", "Unit A3", or "apt3". We normalize the account reference before matching:




CODE
def normalize_account_ref(ref):
"""Normalize M-Pesa account reference for matching."""
ref = ref.strip().upper()
ref = re.sub(r'[^A-Z0-9]', '', ref) # Remove special chars
ref = ref.replace('UNIT', '').replace('APT', '').replace('ROOM', '')
return ref






4. STK Push for proactive collection



Instead of waiting for tenants to initiate payment, we can trigger an STK Push — a payment prompt appears on the tenant's phone:




CODE
def trigger_stk_push(tenant, amount):
"""Send M-Pesa payment prompt to tenant's phone."""
payload = {
'BusinessShortCode': PAYBILL_NUMBER,
'Amount': amount,
'PartyA': tenant.phone_number,
'PartyB': PAYBILL_NUMBER,
'PhoneNumber': tenant.phone_number,
'AccountReference': tenant.unit.unit_number,
'TransactionDesc': f'Rent for {tenant.unit.unit_number}'
}
response = daraja_api.stk_push(payload)
return response






This is triggered automatically when reminders are sent — the tenant gets an SMS reminder AND a payment prompt simultaneously.






Results




  • Payment matching: 95%+ auto-reconciled without human intervention

  • Receipt delivery: under 10 seconds from payment to SMS receipt

  • Late payment reduction: 40-60% reduction with automated reminders + STK push

  • Admin time saved: 8+ hours/month for a 50-unit portfolio






The Stack





  • Backend: Django + Django REST Framework


  • Database: PostgreSQL


  • Task Queue: Celery + Redis (for async SMS sending and reconciliation)


  • M-Pesa Integration: Safaricom Daraja API v2


  • SMS: Africa's Talking API


  • Hosting: AWS (ECS + RDS + S3)


  • Frontend: React (web) + React Native (mobile)






Try It



The platform is live at

Vollständiger Original-Artikel
Den kompletten Beitrag mit allen Details direkt auf dev.to lesen.
↗ Original-Artikel auf dev.to lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
Microsoft Office Ohne Abonnement? Jetzt kostet es ein paar Hundert - Jablíčkář
1 Quelle
Windows Defender: Falsche Warnung täuscht Sicherheitslücke vor - ad-hoc-news.de
1 Quelle
DFN-CERT-2026-4930 FFmpeg: Mehrere Schwachstellen ermöglichen u. a. das Ausführen ...
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Automating M-Pesa Rent Collection in Kenya: The Technical Architecture

Thematisch verwandte Begriffe: Automating, MPesa, Rent, Collection · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...