RDCPASS documentation
RDCPASS is the Democratic Republic of the Congo’s national digital identity. Any business that onboards customers, users, merchants or partners from the DRC can verify them against RDCPASS — the sovereign, authoritative source — rather than relying on foreign identity-verification vendors or self-declared data.
Eight services over one authenticated API, each available as single or batch requests, synchronously or asynchronously. Every application gets sandbox access instantly.
Services
KYC ValidationPOST /v1/kyc/validationsVerify a person by RDCPASS ID or identity document and receive Basic KYC plus the scopes you subscribe to.Face RecognitionPOST /v1/face/recognitions1:1 face verification against an identity, or 1:N identification, with passive liveness.Age VerificationPOST /v1/age/verificationsConfirm a person is over an age threshold, returning Basic KYC only.KYB VerificationPOST /v1/kyb/verificationsVerify a business by RCCM, ID NAT or NIF, with officers, beneficial owners, licences and documents.AML & CTF ScreeningPOST /v1/aml/screeningsScreen people and businesses against sanctions, PEP, adverse media and watchlists, with ongoing monitoring.Credit ScoringPOST /v1/credit/scoresA consented credit score from mobile money, telecom, banking and utility data.Fraud ReportingPOST /v1/fraud/reportsReport identity usurpation, account takeover, SIM swap, payment fraud and more to RDCPASS.Login with RDCPASSOpenID Connect · /v1/oidc/*OpenID Connect sign-in where citizens approve exactly the scopes you request.
Start in 5 minutes
1
Create your organization
Sign up at console.rdcpass.cd with your RDCPASS identity and create your organization.
2
Create a sandbox application
Select the services and scopes you need. Sandbox keys are issued immediately, and every service is free in sandbox.
3
Make your first call
Validate the test identity
COD-0000-0000-0001 with KYC Validation, as shown in the quickstart.4
Go further
Move to batch and asynchronous requests, then submit your dossiers to go to production.
Platform concepts
Single, batch & asyncFour request modes on every service, job and batch objects, webhooks.KYC scopes & subscriptionsBasic KYC, additional scopes and the three-layer subscription model.Documents & biometricsSigned URLs, base64 delivery and biometric templates.ApplicationsServices, scopes, purposes, keys per environment and audit log.Teams & rolesSix roles, RDCPASS sign-in with mandatory MFA, separation of duties.Going to productionBusiness and application due diligence, production keys.BillingPrepaid or postpaid, Mobile Money top-ups, metering rules.
Every request is authenticated in three layers
RDCPASS requires all three on every request — a request missing any one of them is rejected:
- API key + HMAC request signing — identifies your application and proves the request was not tampered with in transit.
- mTLS client certificates — proves your application holds a certificate RDCPASS issued, not just a leaked secret.
- AES-256-GCM payload encryption — keeps request and response bodies unreadable to anything between you and RDCPASS.
The exact headers, signing string and encryption steps are covered in Authentication.