RDCPASS documentation

RDCPASS is the Democratic Republic of the Congo’s national digital identity. Any business that onboards customers, users, merchants or partners from the DRC can verify them against RDCPASS — the sovereign, authoritative source — rather than relying on foreign identity-verification vendors or self-declared data.

Eight services over one authenticated API, each available as single or batch requests, synchronously or asynchronously. Every application gets sandbox access instantly.

Services

Start in 5 minutes

1
Create your organization
Sign up at console.rdcpass.cd with your RDCPASS identity and create your organization.
2
Create a sandbox application
Select the services and scopes you need. Sandbox keys are issued immediately, and every service is free in sandbox.
3
Make your first call
Validate the test identity COD-0000-0000-0001 with KYC Validation, as shown in the quickstart.
4
Go further
Move to batch and asynchronous requests, then submit your dossiers to go to production.

Platform concepts

Every request is authenticated in three layers

RDCPASS requires all three on every request — a request missing any one of them is rejected:

  • API key + HMAC request signing — identifies your application and proves the request was not tampered with in transit.
  • mTLS client certificates — proves your application holds a certificate RDCPASS issued, not just a leaked secret.
  • AES-256-GCM payload encryption — keeps request and response bodies unreadable to anything between you and RDCPASS.

The exact headers, signing string and encryption steps are covered in Authentication.

Start the quickstartFrom sign-up to your first verified identity.

Questions about your integration? Contact developer support