App credentials (consumer key / secret)
Allow-list of consumerKey:consumerSecret pairs the OAuth endpoint validates. An unknown pair → 400 errorCode 999991; the minted Bearer is checked by every business endpoint (401 errorCode 404.001.03 when bad).
Shortcode & passkey
STK Push requests
Actions resolve the request immediately and fire the callback to its CallBackURL; the handset page picks the Delivery Delay. Callbacks are unsigned — correlate by CheckoutRequestID.
B2C / status / reversal
C2B registered URLs
Minted OAuth tokens
Callback deliveries
Requests from the backend
Danger zone
wipes payments, logs and every runtime override — back to configured defaults