HarambeePay is a self-hosted fundraising and donation platform — campaigns, M-Pesa Daraja & Pesapal payments, wallets, payouts, corporate CSR, affiliates and a signed module system — packaged as full Laravel source code you deploy, brand and own.
Six areas of the platform, all in the box: fundraising mechanics, payment infrastructure, admin tooling, and the module/API layer that lets you keep extending it after launch.
Platform fees, featured-campaign promotion, support donations, wallets, payouts and affiliate commissions are all configurable from day one.
Native Daraja handles donor STK Push plus B2C/B2B payouts, with Pesapal hosted checkout available alongside it.
The 3.1.47 release corrects dark-theme teal usage across dashboards, settings, navigation and every supporting screen.
Charities, community organizers, CSR teams and crowdfunding entrepreneurs all fit the same core architecture.
Architecture, installation, production operation, wallet behaviour and release procedures are all written up.
CSRF protection, authorization gates, throttling and signed updates are part of the codebase, not an afterthought.
Categories, goals, cover images, visibility, end dates, live updates and organizer ownership — the full campaign lifecycle.
Donation flows, donor messages, payment retries, supporter lists and related-campaign discovery keep givers engaged.
Members join a campaign team and get personal tracking links so individual contribution can be measured.
Channel-specific tracking links cover WhatsApp, email, SMS, native share and copy-link, each attributed back to the member.
Campaigners can pay to feature their campaign, with configurable daily pricing and promotion analytics behind it.
New campaigns and campaign edits move through approve, reject and resubmission before they go live.
STK Push and STK Query for donor payments, with B2C and B2B payout integrations for organizers and affiliates.
Hosted payment flow with callback/IPN handling and server-side status verification into the ledger.
Eligibility rules, auditable credits and debits, withdrawal policy controls and M-Pesa settlement paths.
Campaign payout requests route to M-Pesa destinations under platform-level controls.
Referral commissions post through the same wallet ledger, including M-Pesa withdrawal.
Payment attempts, callback reconciliation, stale-payout checks and duplicate-safe posting live in the service layer.
Analytics, campaign review, donations, payouts, wallet operations and user management in one dashboard.
Branding, SEO, campaign rules, payments, wallet, security, monitoring and update configuration — all admin-controlled.
Donation and supporter reporting with CSV and PDF export, plus platform-level operational reports.
Health checks and operational monitoring live inside the admin experience, not a separate tool.
SMTP delivery, reusable templates, verification mail, recovery messages and event-driven emails.
Swap between landing experiences and campaign-discovery layouts for different positioning.
Interactive reporting for admins and campaigners, with event recording and export permissions.
Enrollment, tracking links, attribution, commissions and wallet withdrawals as a standalone module.
SEO-first publishing with categories, tags, authorship and editorial administration.
Template-driven, event-triggered delivery for verification, recovery and platform messaging.
Versioned endpoints for campaign and donation reads, plus signed outbound webhooks for key events.
ZIP packages verified by manifest and file hash, with compatibility checks and protected core modules.
Composer-managed dependencies on a PSR-4 application structure.
Migration-based schema with dedicated financial, campaign, user and integration tables.
Server-rendered, responsive, with the light/dark Matrix teal system applied throughout.
Installation docs cover Composer, HTTPS, cron and shared-hosting deployment paths.
Preflight checks, database connectivity testing and a stateful install flow, no manual SQL surgery.
Ed25519-signed update manifests, SHA-256 verified packages before anything is applied.
Completed donations flow through a transaction-and-ledger trail rather than a mutable campaign total. Wallet mutations use integer minor units, idempotency controls and row locking, so double-processed callbacks don't corrupt a balance.
Building a payment-grade fundraising platform from zero means solving campaigns, wallets, reconciliation and admin tooling before you've onboarded a single organizer. This gives you that foundation already working.
Self-host under your own domain and infrastructure — no per-seat fees, no platform lock-in.
Set your branding, fees, payment rules, wallet policy, campaign behaviour and platform messaging.
Build new modules, integrations and landing experiences on architecture that's already there.
CSRF protection, authorization gates, throttling, encrypted secrets and signed updates from day one.
A branded digital fundraising hub for ongoing campaigns and donations.
Personal, family, education, medical, emergency and community causes.
Launch a niche donation marketplace under your own brand.
Structured workspace for CSR campaigns, matching rules and impact reporting.
Run campaigns, promotion, reporting and teams for multiple clients at once.
Start in Kenya on M-Pesa, then expand through the API and module layer.
Illustrative ledger entries — every mutation is stored in minor units with idempotency controls.
Laravel CSRF middleware guards every state-changing browser request.
Admin and moderation surfaces sit behind authentication, verification, capability gates and rate limits.
M-Pesa attempt tracking, callback handling and duplicate-safe ledger completion built into the service layer.
Update manifests use Ed25519 signatures; downloaded packages are SHA-256 verified before being applied.
The core Laravel application — authentication, campaign management, payments, payouts, wallets, administration, corporate fundraising, reports, landing pages, SEO and system services.
Advanced Analytics, Blog & Magazine, Email & Notifications, Platform API & Webhooks, Referral & Affiliate — plus the module manager that handles signed extensions.
Installer services, preflight checks, update channels, signed release verification, package validation, database backup/restore and rollout controls.
A sizeable test suite plus documentation covering architecture, installation, production operation, security, wallet behaviour, modules, payments and release procedures.
Yes — it's supplied as Laravel source code for you to deploy on your own hosting and domain.
PHP 8.4+ is required, running against MySQL 8.0+ or MariaDB 10.6+.
Yes — Safaricom Daraja covers donor STK Push/Query plus automated B2C/B2B payouts, once you connect your own Daraja credentials.
Yes — corporate profiles, CSR campaigns, matching rules, corporate donation identification and donation certificates are included.
Yes — the module architecture supports manifests, compatibility checks, signed packages and an admin module manager, alongside the Platform API/Webhooks module.
No — your own M-Pesa/Daraja, Pesapal, hosting and domain accounts are separate from the source-code purchase.
Connect your own payment accounts, apply your branding, and deploy under your own infrastructure — donation platform, crowdfunding marketplace or corporate CSR portal.