RDCPASSBusiness
RDCPASS for Business

Verify customers against the DRC's national register

RDCPASS is the official national and international digital identity of the Democratic Republic of the Congo. With one API, you can confirm who a customer is, check them for risk and open their account, using data certified by the national register instead of self-declared details.

Developer? Read the documentation
  • Official national platform
  • Signed and encrypted requests
  • Free sandbox

The sandbox is free and needs no approval. Production access follows a review of your business and your application.

A citizen's RDCPASS digital national ID displayed on a phone

Verification

COD-2103-0214-4937
  1. Identity

    …

  2. Selfie

    …

  3. AML screening

    …

Account opened

8

identity and risk services on one platform

< 300 ms

median verification time

10,000

records per batch request

CDF · USD

Mobile Money, card or monthly invoice

Solutions by goal

Start from what you need to do

Choose a business goal to see which RDCPASS services get you there.

Open accounts without paperwork or a branch visit

Replace paper forms and branch visits with a verified identity. Your customer enters their RDCPASS ID or document number, takes a selfie, and you receive certified KYC data you can rely on.

  • Fewer customers abandon sign-up
  • No manual re-typing or document checks
  • The same flow on the web, in your app and at the counter
See onboarding use cases

For every size of organization

For small teams and national institutions

The same platform serves a two-person startup and a national bank. Only the billing model and support level change.

Startups & SMEs

Launch verified onboarding without a compliance department, and pay only for what you use.

  • Free sandbox to build and test
  • Prepaid wallet topped up with Mobile Money or card
  • Public volume tiers, no negotiation needed
See pay-as-you-go pricing

Banks, telecoms & large platforms

Verify millions of customers with batch processing, a monthly invoice and dedicated support.

  • Batches of up to 10,000 records
  • Negotiated volume pricing and an SLA
  • A dedicated account manager
Talk to sales

Public sector & NGOs

Deliver services and aid to the right person, exactly once, with the identity citizens already hold.

  • Beneficiary registration without duplicates
  • Login with RDCPASS for citizen portals
  • A full audit trail for programme reporting
See public-sector use cases

Products

Eight services on one integration

Every service shares the same authentication, the same KYC scope model and the same request modes. Most organizations start with one service and add others later.

Identity

KYC Validation

Verify a person against their certified RDCPASS account and receive the data you are approved for.

  • RDCPASS ID, passport or CENI voter card
  • Basic KYC with every match
  • Single, batch, sync or async
Learn more
Biometrics

Face Recognition

Confirm that the person in front of the camera is the owner of the identity.

  • 1:1 verification and 1:N search
  • Passive liveness detection
  • Audited reason on every request
Learn more
Identity

Age Verification

Check that a user meets an age threshold without collecting identity documents.

  • Any threshold, such as 18+
  • A yes-or-no answer
  • Basic KYC only
Learn more
Identity

Login with RDCPASS

Let citizens sign in with their national identity and share only what they consent to.

  • OpenID Connect with PKCE
  • Face check on the citizen’s phone
  • Consented KYC claims
Learn more
Business

KYB Verification

Verify that a company is registered and find out who runs and owns it.

  • RCCM, ID NAT or NIF lookup
  • Officers and beneficial owners
  • Licences and documents
Learn more
Compliance

AML & CTF Screening

Screen people and companies before you onboard them, then keep watching.

  • Sanctions, PEP and adverse media
  • Continuous monitoring
  • People and companies
Learn more
Risk

Credit Scoring

Assess applicants who have no bank credit history, with their consent.

  • Mobile money, telecom, banking and utility data
  • Consent approved in the RDCPASS app
  • Real-time decisions
Learn more
Risk

Fraud Reporting

Report fraud cases to the national fraud desk and follow them to resolution.

  • Usurpation, SIM swap, robbery and more
  • Case updates by webhook
  • Free for approved organizations
Learn more

In practice

Three example customer journeys

Three common flows, from the customer’s first tap to your decision.

CustomerRDCPASSYour business

Mobile money

Opening a mobile money wallet

  1. Customer

    Enters their RDCPASS ID in your app and takes a selfie

  2. RDCPASS

    Matches the selfie against the national register and returns basic KYC

  3. Your business

    Pre-fills the profile and opens the wallet at the right tier

Result: A verified wallet with no paperwork and no branch visit.

Microfinance

Approving a microloan

  1. Your business

    Identifies the applicant with KYC Validation

  2. Customer

    Approves the credit score request in their RDCPASS app

  3. RDCPASS

    Returns the credit score and the AML screening result

  4. Your business

    Decides on the loan with a complete, auditable record

Result: A same-day decision backed by consent and a full audit trail.

Online platform

Signing up a new user in one tap

  1. Customer

    Taps “Login with RDCPASS” and confirms with a face check

  2. Customer

    Chooses which details to share with you

  3. RDCPASS

    Sends the consented details and confirms the age threshold

  4. Your business

    Creates a verified account with no password to manage

Result: A verified, age-checked account in a single tap.

Why RDCPASS

If you serve customers in the DRC, check them against the national register

RDCPASS is the official digital identity of the Democratic Republic of the Congo. Banks, telecom operators, fintechs, platforms and institutions that serve customers, users, merchants or partners in the DRC can check identities against it directly, instead of relying on foreign identity vendors or self-declared information.

  • Identities issued and kept up to date by the national register
  • Congolese identity data stays under Congolese governance
  • One verification recognised across banking, telecoms, health, education and public services
  • Consent, data scopes and audit built in to meet data-protection and AML obligations

Getting started

From sign-up to your first verified customer

  1. 1

    Create your organization

    Sign up with your RDCPASS identity, invite your team and give each member the right role.

  2. 2

    Build and test for free

    Choose your services and KYC scopes, then test every flow in the sandbox with synthetic identities.

  3. 3

    Complete due diligence

    Submit your business review (governance) and your application review (security, scopes and testing).

  4. 4

    Go live

    Receive your production keys and mTLS certificate, choose prepaid or postpaid billing, and start verifying real customers.

The sandbox onboarding flow: uploading proofs, validation, and the resulting digital ID

For developers

A plain HTTPS API with samples in eight languages

Plain HTTPS and JSON, with request signing and payload encryption on every call. Every reference page has ready-to-run samples, and the sandbox returns the same fields as production.

  • Samples in cURL, Node.js, Python, Go, Java, Rust, PHP and C#
  • Synthetic identities, businesses and faces for testing
  • Signed webhooks for async jobs, batches and fraud cases

Official SDKs

validate-identity.sh
# Plaintext body shown — encrypt it per /docs/authentication before sending.
curl https://api.rdcpass.cd/v1/kyc/validations \
  -X POST \
  -H "X-RDCPASS-Key-Id: key_live_8f2a1c0e9b" \
  -H "X-RDCPASS-Timestamp: 1790417700" \
  -H "X-RDCPASS-Nonce: 6f1c9b2e-4a3d-4e11-9c7a-2d8e5f1b0a44" \
  -H "X-RDCPASS-Signature: 3f7a9c...e21d" \
  -H "Content-Type: application/json" \
  -d '{
    "reference": "cust-0001",
    "identifier": {
      "type": "rdcpass_id",
      "value": "COD-2103-0214-4937"
    },
    "match": {
      "full_name": "Kabeya Mwamba Tshisekedi",
      "date_of_birth": "1988-04-12"
    },
    "purpose": "customer_onboarding",
    "scopes": [
      "kyc.documents.primary",
      "kyc.phone_numbers"
    ],
    "document_delivery": "signed_url"
  }'
200 OK
{
  "id": "kyc_8d2f6a1c93",
  "object": "kyc_validation",
  "livemode": true,
  "reference": "cust-0001",
  "status": "completed",
  "result": "verified",
  "certified_account": true,
  "identifier": {
    "type": "rdcpass_id",
    "value": "COD-2103-0214-4937"
  },
  "match": {
    "full_name": "match",
    "date_of_birth": "match",
    "age": "not_provided",
    "score": 0.98
  },
  "account": {
    "rdcpass_id": "COD-2103-0214-4937",
    "status": "active",
    "certified": true,
    "created_at": "2025-03-14T09:22:41Z",
    "level_of_assurance": "LOA3"
  },
  "kyc": {
    "basic": {
      "full_name": "Kabeya Mwamba Tshisekedi",
      "first_name": "Kabeya",
      "last_name": "Tshisekedi",
      "date_of_birth": "1988-04-12",
      "age": 38,
      "gender": "male",
      "nationality": "COD"
    },
    "documents": {
      "primary": {
        "type": "passport",
        "number": "OB1234567",
        "issued_at": "2022-06-01",
        "expires_at": "2027-05-31",
        "issuing_authority": "Direction Générale de Migration",
        "status": "valid",
        "image": {
          "content_type": "image/jpeg",
          "url": "https://files.rdcpass.cd/d/9f2c41e8b7a3?sig=Qm9fX2t5Y19zaWc&exp=1790418002",
          "expires_at": "2026-09-26T10:20:02Z"
        }
      }
    },
    "phone_numbers": [
      {
        "number": "+243812345678",
        "operator": "Vodacom",
        "is_primary": true,
        "verified": true
      },
      {
        "number": "+243991234567",
        "operator": "Airtel",
        "is_primary": false,
        "verified": true
      }
    ]
  },
  "scopes_applied": [
    "kyc.basic",
    "kyc.documents.primary",
    "kyc.phone_numbers"
  ],
  "scopes_withheld": [],
  "purpose": "customer_onboarding",
  "created_at": "2026-09-26T10:15:02Z"
}
official SDKs
7
official SDKs
languages in every sample
8
languages in every sample
sandbox with synthetic test data
Free
sandbox with synthetic test data

Security

Security for a national identity register

RDCPASS holds identity data for every citizen of the DRC, so every layer below is mandatory. Each one is enforced before a request reaches our application code.

Layer 1

mTLS client certificates

Every production connection is mutually authenticated. Your application presents a client certificate before any request data is read.

Stops: Unknown or impersonated clients

Layer 2

HMAC-SHA256 request signing

Each request is signed with your secret key and carries a nonce and timestamp.

Stops: Tampered and replayed requests

Layer 3

AES-256-GCM payload encryption

Request and response bodies are encrypted end to end, independently of TLS.

Stops: Data exposure in transit

Layer 4

Scopes, purposes & audit

Applications receive only the data they are approved for, for a declared purpose, and every access is logged.

Stops: Over-collection and misuse

Security disclosures

Report a vulnerability

Found a vulnerability in our API, our documentation or your own integration? Tell us. We investigate every credible report, and we would rather hear about a problem from you than from an incident.

Read our security practices

When you report

  1. 1Include clear steps to reproduce the issue
  2. 2Never access, change or keep data that is not yours
  3. 3Give us reasonable time to fix it before any public disclosure

Verify your first customer in the sandbox

Create your organization and start testing today. For volume pricing or a large deployment, talk to our team first.