PesaBridge
Ìwé/Owó tó ń jáde/Send money (payouts)

Owó tó ń jáde

Send money (payouts)

Pay customers, businesses and tax authorities from your settlement account, with an optional second factor and async results.

Ìṣẹ́jú 6 láti kà

A kọ àwọn ìtọ́sọ́nà olùgbéṣẹ́ ní èdè Gẹ̀ẹ́sì kí kóòdù, orúkọ àwọn pápá àti àwọn ìfiránṣẹ́ àṣìṣe lè bá API mu gẹ́lẹ́.

Lórí ojú-ìwé yìí
  1. Fund your settlement account
  2. Payout types
  3. Second factor: Initiator and SecurityCredential
  4. Synchronous or async

Fund your settlement account

Payouts come from your settlement account. Load it with POST /partner/topup ({"amount": 100000}) and check it with GET /partner/balance.

Payout types

EndpointPaysKey fields
POST /partner/b2cA customer walletto_msisdn, amount, remarks
POST /partner/bizpocketA customer's Biz Pocketto_msisdn, amount, remarks
POST /partner/b2bAnother businessto_shortcode, amount, account_reference
POST /partner/taxTax or a government billerto_shortcode, amount, prn

Each accepts an idem key. Retry with the same key after a timeout and you get the original payout, never a second one.

Shell
curl -s https://pesa-bridge.com/api/bridgepay/v1/partner/b2c \
  -H "Authorization: Bearer $TOKEN" -H "Content-Type: application/json" \
  -d '{"to_msisdn":"254708374149","amount":2500,"remarks":"Refund #91","idem":"refund-91"}'

Second factor: Initiator and SecurityCredential

Protect money-out calls with a second factor. Set an initiator password once with POST /partner/initiator. From then on, payouts and reversals must carry initiator plus a security_credential: that password RSA-encrypted (PKCS#1 v1.5) with our certificate, base64-encoded.

  1. 1

    Download the certificate

    GET /security/certificate returns our public X.509 certificate (PEM).

  2. 2

    Encrypt on your side

    Encrypt the initiator password with it. The password never travels in clear text.

  3. 3

    Send both fields

    Add initiator and security_credential to each payout or reversal.

Make a SecurityCredential
curl -s https://pesa-bridge.com/api/bridgepay/v1/security/certificate -o pesabridge.pem
openssl x509 -in pesabridge.pem -pubkey -noout > pesabridge_pub.pem
printf '%s' "$INITIATOR_PASSWORD" \
  | openssl pkeyutl -encrypt -pubin -inkey pesabridge_pub.pem -pkeyopt rsa_padding_mode:pkcs1 \
  | base64 -w0
In the sandbox, POST /security/credential can encrypt a test password for you. In production, always encrypt on your own server.

Synchronous or async

Without result_url, a payout answers when it's done. With result_url (and optionally timeout_url) you get an immediate acknowledgement, and the final Result is POSTed there, signed like any webhook, so verify it the same way.

Àwọn onímọ̀-ẹ̀rọ wa ń dáhùn ìbéèrè nípa ìsopọ̀. Fi nọ́mbà ìtọ́kasí ìbéèrè náà ránṣẹ́ sí wa, a ó sì rí ìpè náà gẹ́lẹ́.

Kàn sí ìrànlọ́wọ́