September 5, 2026 · By Super Admin · 3 views

Securing Airtime Purchases: Threats & Mitigations

Securing Airtime Purchases: Threats & Mitigations

Threat landscape

Airtime purchases involve financial value and PII (phone numbers). Common threats are replay attacks, stolen API keys, abused webhooks, and automated fraud.

Concrete mitigations

  1. Secrets management
  2. Store keys (Daraja passkey, consumer secret) in environment variables.
  3. Use a secrets manager for production; don't commit keys.
  4. Webhook verification
  5. Persist raw webhook payloads and compute a signature check if the provider offers signing.
  6. Verify sender IP ranges where possible (if published) and require HTTPS.
  7. Rate limiting & anti-abuse
  8. Rate limit critical endpoints (STK push request endpoints) per IP and per account.
  9. Detect patterns like high-frequency small-amount purchases from the same account.
  10. Idempotency
  11. Use CheckoutRequestID as a unique identifier to avoid processing the same callback twice.
  12. PCI awareness
  13. You generally shouldn't store card details; for mobile-money (M-Pesa) keep PINs or credentials out of your systems and never log them.
  14. Monitoring & alerts
  15. Monitor ResultCode spikes, callback failures, and failed reconciliation attempts — alert on thresholds.

Incident response checklist

  1. Rotate compromised API keys immediately.
  2. Reconcile affected transactions and notify affected customers.
  3. Preserve logs for forensic analysis.
  4. Report serious incidents to relevant authorities per regulation.


Need airtime right now?

Buy Airtime