> ## Documentation Index
> Fetch the complete documentation index at: https://docs.centipidbilling.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Gateway credential reference

> Credential fields and current UI availability for every backend payment gateway option.

# Review gateway credential requirements

Obtain every value from the provider/merchant account belonging to the ISP. “Required” below reflects the current credential component, except in the explicitly marked backend-only section, where it reflects backend readiness rules. A provider can impose additional dashboard configuration such as callback URLs, IP allowlists, product activation, or settlement verification.

## Kenya and manual instruction methods

### `SAFARICOM`

[Full setup guide](/billing/payment-gateways/safaricom)

* Collection method: Paybill or Till.
* Paybill number **or** normal till number (required, maximum 20 digits).
* M-Pesa shortcode (required; same as paybill in paybill mode, distinct Daraja shortcode in till mode).
* Consumer key (required, secret field).
* Consumer secret (required).
* Passkey (required for STK push).

### `PAYBILL`

[Full setup guide](/billing/payment-gateways/paybill)

* Paybill number (required, digits only, 4–20 characters).

No Daraja keys are requested: the STK push is raised with the platform's Daraja credentials. See [Paybill](/billing/payment-gateways/paybill).

### `TILL_NUMBER`

[Full setup guide](/billing/payment-gateways/till-number)

* Till number (required, maximum 20 characters).

No Daraja keys are requested: the Buy Goods STK push is raised with the platform's Daraja credentials. See [Till number](/billing/payment-gateways/till-number).

### `BANK`

[Full setup guide](/billing/payment-gateways/bank)

* Receiving bank/paybill (required; selected from the current bank list or saved option).
* Bank account number (required).

Changing the bank/paybill clears the account number so an account for the previous bank is not saved accidentally. Use a business account owned by the ISP.

### `KOPOKOPO`

[Full setup guide](/billing/payment-gateways/kopokopo)

* STK till number (required, starts with `K`, maximum 30 characters).
* Client ID (required).
* Client secret (required).
* API key (required).

<img src="https://mintcdn.com/centipidtechnologies/FF2sAgJAU-6SlOSu/images/payment-kopokopo-settings.png?fit=max&auto=format&n=FF2sAgJAU-6SlOSu&q=85&s=93ec3c2053c05b49cdd06ae411ef904b" alt="Kopo Kopo payment gateway settings with the demo till number redacted" width="800" height="550" data-path="images/payment-kopokopo-settings.png" />

### `CENTIPID`

[Full setup guide](/billing/payment-gateways/centipid)

* Kenya: payment number (required, maximum 10 characters, starts with `0`).
* Other supported countries: no stored recipient field in this form; withdrawal recipient details are entered at withdrawal time.

## Regional/mobile-money APIs

### `IOTEC`

[Full setup guide](/billing/payment-gateways/iotec)

* Iotec wallet ID (required).
* Iotec client ID (required).
* Iotec API secret (required).

### `AIRTEL_MONEY`

[Full setup guide](/billing/payment-gateways/airtel-money)

* Airtel client ID (required).
* Airtel client secret (required).
* Country code override (optional ISO two-letter code, maximum 3 characters in the form).
* Currency code override (optional ISO three-letter code, maximum 3 characters).

Leave overrides blank to use your account's country and currency unless provider onboarding requires a different explicit value.

### `PAWAPAY`

[Full setup guide](/billing/payment-gateways/pawapay)

* PawaPay API token (required).

### `CLICKPESA`

[Full setup guide](/billing/payment-gateways/clickpesa)

* API key (required).
* Client ID (required).

### `PALMPESA`

[Full setup guide](/billing/payment-gateways/palmpesa)

* API token (required, secret field).
* API host (optional URL; blank uses the default PalmPesa endpoint).

The API token is the only field required to switch to PalmPesa. Checkout also needs a payer email address and a Tanzanian phone number — see [PalmPesa](/billing/payment-gateways/palmpesa).

### `AZAMPAY`

[Full setup guide](/billing/payment-gateways/azampay)

* Environment: Sandbox or Production (required).
* App name (required; exactly as configured at AzamPay).
* Client ID (required).
* Client secret (required).
* Authenticator base URL (required URL).
* Checkout base URL (required URL).
* Callback password (optional in Sandbox; follow provider requirements for Production).

### `HUBTEL`

[Full setup guide](/billing/payment-gateways/hubtel)

* Hubtel client ID (required).
* Hubtel client secret (required).

### `ORANGE_MONEY`

[Full setup guide](/billing/payment-gateways/orange-money)

* Merchant key (required; Web Payment key).
* Consumer key (required).
* Consumer secret (required).

Customers complete payment on Orange's hosted checkout and return to the application; verify both return and provider notification behavior.

## Backend options without credential components

<Warning>
  The backend exposes the following gateways by country, but the current **Settings → Payments** frontend does not render credential inputs for them. The fields document the backend contract for support and upgrade planning; they are not an instruction to bypass the Settings UI or edit stored configuration directly.
</Warning>

### `MTN_MOMO`

[Full setup guide](/billing/payment-gateways/mtn-momo)

Backend readiness requires:

* subscription key (`mtn_momo_subscription_key`);
* API user (`mtn_momo_api_user`);
* API key (`mtn_momo_api_key`, secret).

The backend country catalog includes MTN MoMo for Uganda, Ghana, Côte d’Ivoire, Zambia, Benin, and Cameroon. Do not select it for a new account until a dedicated credential component or another approved configuration workflow is available.

### `VODACOM_MPESA`

[Full setup guide](/billing/payment-gateways/vodacom-mpesa)

Backend readiness requires:

* API key (`vodacom_api_key`, secret);
* public key (`vodacom_public_key`, secret-handled by the application);
* merchant code (`vodacom_merchant_code`).

The backend also recognizes an optional currency value (`vodacom_currency`); the service resolves to `CDF` unless `USD` is explicitly configured. The backend country catalog offers this gateway for the Democratic Republic of the Congo. Do not select it for a new account until a dedicated credential component or another approved configuration workflow is available.

## Card, bank, and multi-method providers

### `PESAPAL`

[Full setup guide](/billing/payment-gateways/pesapal)

* Consumer key (required).
* Consumer secret (required).

Saving these also registers your IPN URL with PesaPal and stores the id it
issues; PesaPal rejects orders that carry no IPN id, so a registration failure
is reported on the settings page rather than left for checkout.

<img src="https://mintcdn.com/centipidtechnologies/FF2sAgJAU-6SlOSu/images/payment-pesapal-settings.png?fit=max&auto=format&n=FF2sAgJAU-6SlOSu&q=85&s=fa1d515aad83d40b4dcac1831dfd1107" alt="PesaPal payment gateway settings in Centipid" width="800" height="520" data-path="images/payment-pesapal-settings.png" />

### `PAYPAL`

[Full setup guide](/billing/payment-gateways/paypal)

* Client ID (required).
* Client secret (required).
* Settlement currency (required; choose from the current currency list).

<img src="https://mintcdn.com/centipidtechnologies/FF2sAgJAU-6SlOSu/images/payment-paypal-settings.png?fit=max&auto=format&n=FF2sAgJAU-6SlOSu&q=85&s=0635efae465a43eb438a8dbb580fc058" alt="PayPal payment gateway settings in Centipid" width="800" height="620" data-path="images/payment-paypal-settings.png" />

### `OPAY`

[Full setup guide](/billing/payment-gateways/opay)

* Merchant ID (required).
* Public key (required).
* Private key (required; used for callback signature validation).

### `MONNIFY`

[Full setup guide](/billing/payment-gateways/monnify)

* API key (required).
* Secret key (required; also signs the webhook).
* Contract code (required).
* Environment: Live or Sandbox.

### `RELWORX`

[Full setup guide](/billing/payment-gateways/relworx)

* Relworx account number / `account_no` (required).
* Relworx API key (required).
* Webhook signing key (required).

<img src="https://mintcdn.com/centipidtechnologies/FF2sAgJAU-6SlOSu/images/payment-relworx-settings.png?fit=max&auto=format&n=FF2sAgJAU-6SlOSu&q=85&s=0e22b1d9522ad408d8cf93918f7860de" alt="Relworx payment gateway settings and callback URL in Centipid" width="800" height="720" data-path="images/payment-relworx-settings.png" />

### `PAYSTACK`

[Full setup guide](/billing/payment-gateways/paystack)

* Live secret key (required; current form expects `sk_live_…`).
* Live public key (required; current form expects `pk_live_…`).

<img src="https://mintcdn.com/centipidtechnologies/FF2sAgJAU-6SlOSu/images/payment-paystack-settings.png?fit=max&auto=format&n=FF2sAgJAU-6SlOSu&q=85&s=05a2c41af064d74633d14a085e1cd68b" alt="Paystack payment gateway settings with the demo public key redacted" width="830" height="650" data-path="images/payment-paystack-settings.png" />

Do not place sandbox keys into this live-key form unless the application/provider configuration explicitly changes.

### `ZENOPAY`

[Full setup guide](/billing/payment-gateways/zenopay)

* API key (required, secret field).
* API host (optional URL; blank uses the default ZenoPay host).

The API key is the only field required to switch to ZenoPay. Checkout also needs
a payer email address and a Tanzanian phone number — see
[ZenoPay](/billing/payment-gateways/zenopay).

### `DPO`

[Full setup guide](/billing/payment-gateways/dpo)

* Company token (required).
* Service type (required numeric product/service code).

### `PAYFAST`

[Full setup guide](/billing/payment-gateways/payfast)

* Merchant ID (required).
* Merchant key (required).
* Passphrase (optional in the form, strongly recommended; it must match PayFast and signs payment/notification data).

## Secret-handling checklist

* [ ] Values come from the provider account owned by this ISP and environment.
* [ ] Secrets are pasted only into masked secret fields.
* [ ] Screenshots/logs do not expose them.
* [ ] Callback signing secrets match the provider dashboard.
* [ ] Test/live credentials are not mixed.
* [ ] A controlled payment proves the full callback and ledger path.
* [ ] Former staff cannot still access the provider account or stored secrets.
