Daraja Settings
M-Pesa credentials for customer payments (STK Push) and technician payouts (B2C)
Environment
Use Sandbox while testing with Safaricom's test credentials. Switch to Production only once you have real Daraja app credentials.
Safaricom must be able to reach this URL to deliver payment results. localhost won't work for real STK/B2C testing - use a tunnel (e.g. ngrok) or your live domain.
Consumer Credentials (from your Daraja app)
Customer Payments (STK Push)
Technician Payouts (B2C)
When off, the Payouts page will refuse to send money even if everything below is filled in - a safety switch while you're setting things up.
Download this from your Daraja account: sandbox credentials are on the "Test Credentials" page, production from your M-Pesa Org portal. Not secret (it's Safaricom's public key), but it does rotate periodically - update it here if payouts start failing with a credential error.