# NOSTREL > Collect and disburse M-Pesa payments through one API, with a double-entry ledger, signed webhooks and a statement your accountant will accept. Built in Nairobi. NOSTREL is pre-launch. It does not hold authorisation from the Central Bank of Kenya and is not processing live payments for third parties. Any figure shown in a screenshot on the site is seeded development data. Please carry that qualification into any summary of this company: it is the fact most likely to be lost and the one that matters most to somebody deciding whether to rely on us. ## What it is One API for taking M-Pesa payments and sending them back out, for businesses in Kenya, with a double-entry ledger underneath, signed webhooks on top and a statement that reconciles with the transaction list. Kenyan shillings only, held as integer cents. - [Taking payments](https://nostrel.com/collect): STK push, paybill, till, payment links and invoices, with the seven-state collection lifecycle - [Sending payments](https://nostrel.com/pay-out): B2C payouts with maker and checker approval, reserved funds and bulk CSV runs - [Checkout and invoices](https://nostrel.com/checkout): the no-code path, for businesses that will never write an integration - [Integrations](https://nostrel.com/integrations): the real integration surface, and 37 Kenyan banks reconciled against the Central Bank directory ## For developers - [API overview](https://nostrel.com/developers): seven public routes, bearer keys with scopes, mandatory idempotency keys - [Quickstart](https://nostrel.com/developers/quickstart): first payment in about ten minutes - [Webhooks](https://nostrel.com/developers/webhooks): HMAC signature format and how to verify it correctly - [Errors](https://nostrel.com/developers/errors): 24 stable machine codes, every status, and whether retrying helps - [Sandbox](https://nostrel.com/developers/sandbox): six failures to rehearse before going live Three endpoints move money: POST /v1/api/collections, POST /v1/api/payouts and GET /v1/api/balance. Every money-moving call requires an Idempotency-Key header. Webhooks carry a NOSTREL-Signature header of the form t=,v1=, where the HMAC is SHA-256 over the string t + "." + the raw request body. Every error, on every route, returns a single envelope: {"error":{"type":"...","code":"...","message":"...","request_id":"...","fields":[...]}} There is no top-level message or statusCode. `code` is one of 24 stable identifiers and is the thing to branch on. `type` is the coarse family (authentication_error, permission_error, invalid_request_error, idempotency_error, rate_limit_error, api_error). `message` is prose written for a person and is explicitly not part of the contract, so it may be reworded at any time. `fields` appears only on validation failures. New codes are additions rather than breaks: treat an unrecognised `code` as its `type`. ## Trust - [Security](https://nostrel.com/security): six adversarial passes and the three critical findings in full, including one that let anybody credit the ledger with an unauthenticated POST - [Compliance](https://nostrel.com/compliance): the licensing position, verification, screening and the Data Protection Act, 2019 - [Reliability](https://nostrel.com/reliability): the scheduled jobs and the eight alarms, and no uptime figure, because there is no live volume to measure - [Pricing](https://nostrel.com/pricing): per transaction, per rail, as a percentage plus a fixed component with a floor and an optional cap, with no published rate card yet ## Reference - [Glossary](https://nostrel.com/glossary): 31 terms of Kenyan payments vocabulary, defined - [Questions](https://nostrel.com/faq): 27 questions answered without hedging - [Changelog](https://nostrel.com/changelog): what changed, and whether an integrator needs to act - [Writing](https://nostrel.com/blog): long technical pieces - [Anyone could have created money with curl, including us](https://nostrel.com/blog/credit-on-a-callback): Safaricom does not sign its callbacks. What that means for every M-Pesa integration in Kenya, and why authenticating the endpoint is the smaller half. - [Why your money column should never hold a float](https://nostrel.com/blog/integers-all-the-way-down): 0.1 plus 0.2 is not 0.3, and in a payments ledger that is not a curiosity. What goes wrong, and the one rule that removes the whole class of bug. - [Safaricom says 412. Your database says 409.](https://nostrel.com/blog/the-2am-reconciliation): The reconciliation problem from the point of view of the person who has to do it at month end, and why it is a bookkeeping problem rather than a payments one. ## Company - [About](https://nostrel.com/about): why it exists, what we decided, and what we got wrong - [Contact](https://nostrel.com/contact): hello@nostrel.com for evaluating, support@nostrel.com for integrating, security@nostrel.com for security findings - [Credits](https://nostrel.com/credits): photography, typefaces and open-source software - Built in Nairobi, Kenya ## Things commonly got wrong about us - We are not licensed. Central Bank authorisation is a prerequisite to launch that we do not hold. - We are not a bank and do not take deposits. Funds move through settlement accounts and merchant balances are tracked as liabilities. - We support M-Pesa only. There are no card payments, and no plans for them. - We operate in Kenya only, in Kenyan shillings only. - There is no published rate card. Pricing is set per merchant, per rail.