KYB Verification

POST/v1/kyb/verificationsPOST/v1/kyb/verifications/batches

Verify a Congolese business against the national business registries — RCCM, ID NAT and NIF — and get back its legal identity, standing, officers, beneficial owners, licenses and registry documents in one call. Use it to onboard merchants, vet suppliers and partners, and keep your B2B portfolio compliant with authoritative data instead of self-declared forms.

Not the same as RDCPASS’s business due diligence of your organization

This API verifies a business that you work with — a merchant, supplier or partner your customer claims to be. It is unrelated to the business due diligence RDCPASS performs on your own organization before issuing production keys. See Going to production for that process.

At a glance

SinglePOST /v1/kyb/verifications
BatchPOST /v1/kyb/verifications/batches — up to 50 items synchronously, 10,000 asynchronously
Identifiersrccm, id_nat, nif
Always returnedbusiness.basic — legal identity and registry status
Optional dataNine kyb.* scopes, subject to your subscription
Resultsverified, not_found, inactive
Webhookkyb_verification.completed (asynchronous calls)
AuthenticationSigned and encrypted request — see Authentication

Business identifiers

Look a business up by any one of its three official numbers. RDCPASS resolves the identifier against the corresponding registry and returns the other two numbers in business.basic, so a single identifier is enough to reconcile your records.

typeIdentifierFormat example
rccmRCCM — Registre du Commerce et du Crédit Mobilier (trade register number, including the registry office code, e.g. KIN, LSH, GOM)CD/KIN/RCCM/23-B-01234
id_natID NAT — Identification nationale (national business identification number)01-83-N45127K
nifNIF — Numéro d’identification fiscale (tax identification number issued by the DGI)A2314567890X

Send the value exactly as printed on the certificate. RDCPASS normalises case and surrounding whitespace; any other deviation returns invalid_identifier. Personal identifiers such as rdcpass_id or passport return unsupported_identifier_type on this endpoint.

Request

The plaintext body below is encrypted and signed before it is sent, as described in Authentication. Every POST also accepts the optional Idempotency-Key header for safe retries (24-hour window) and Prefer: respond-async to run the verification asynchronously.

FieldTypeRequiredDescription
identifierobjectYesThe business to verify.
identifier.typestring enumYesrccm, id_nat or nif.
identifier.valuestringYesThe identifier exactly as issued — see the format examples above.
matchobjectNoClaims to compare with the registry record. Omit it to simply look the business up.
match.business_namestringNoThe name your customer declared. Compared with both the legal and trade names.
match.registration_datestring (date)NoThe declared registration date, YYYY-MM-DD.
purposestring enumYesOne of the purposes approved for your application — typically customer_onboarding, regulatory_compliance, fraud_prevention or credit_assessment.
scopesstring[]NoSubset of the KYB scopes granted to your application. Defaults to all granted scopes.
document_deliverystring enumNosigned_url (default) or base64 for files in kyb.documents — see Documents & biometrics.
referencestringNoYour own identifier for this business, echoed back in the response and webhooks.
Request body (plaintext, before encryption)
{
  "identifier": {
    "type": "rccm",
    "value": "CD/KIN/RCCM/23-B-01234"
  },
  "match": {
    "business_name": "Congo Digital Solutions SARL",
    "registration_date": "2023-02-14"
  },
  "purpose": "customer_onboarding",
  "scopes": ["kyb.addresses", "kyb.officers", "kyb.beneficial_owners", "kyb.licenses"],
  "document_delivery": "signed_url",
  "reference": "supp-0042"
}

Response

A successful call returns 200 OK with a kyb_verification object. The table describes the top-level fields; the complete sample further down shows every block with all scopes granted.

FieldTypeDescription
idstringUnique identifier, prefixed kyb_.
objectstringAlways kyb_verification.
livemodebooleantrue in production, false in the sandbox.
referencestring | nullThe reference you sent, or null.
statusstring enumAlways completed for a synchronous call. Asynchronous and batch items can be failed.
resultstring enumverified, not_found or inactive — see Results below.
identifierobjectThe identifier you submitted.
matchobjectPer-claim outcome (match, partial_match, no_match or not_provided) for business_name and registration_date, plus an overall score from 0 to 1.
businessobjectbasic plus one block per applied scope. Absent when result is not_found.
scopes_appliedstring[]Scopes that returned data, always starting with kyb.basic.
scopes_withheldstring[]Scopes requested and granted for which the registry holds no data. Withheld scopes are omitted from business and are not billed — they never cause an error.
purposestringThe purpose you declared.
created_atstring (RFC 3339)When the verification was performed.

Results

resultMeaning
verifiedThe business exists in the registry and its status is active. business.basic and every applied scope are returned.
not_foundNo registry record matches the identifier. No business block is returned. Billed at the base rate.
inactiveThe business exists but its status is suspended, dissolved or in_liquidation. Only business.basic is returned so you can see the exact status; requested scopes are listed in scopes_withheld.

Treat inactive as a stop signal

A dissolved or liquidating company can still present a genuine RCCM certificate. Never open an account, sign a contract or pay a supplier on the strength of a matching name alone — check result and business.basic.status.

business.basic — always returned

Every verified or inactive result includes the business’s legal identity. It requires no additional subscription and is included in the base price of the call.

FieldTypeDescription
legal_namestringRegistered legal name (raison sociale).
trade_namestring | nullTrading name (enseigne), if declared.
rccmstringRCCM number.
id_natstringID NAT number.
nifstringNIF (tax identification number).
legal_formstring enumLegal form: SARL, SA, SAS, SARLU, SNC, SCS, GIE, ETS (sole proprietorship), ASBL or OTHER.
statusstring enumactive, suspended, dissolved or in_liquidation.
registration_datestring (date)Date of registration in the trade register, YYYY-MM-DD.
countrystringISO 3166-1 alpha-3 country of registration — COD.

KYB scopes

Additional business data is organised in its own scope family and follows the same three-layer model as KYC: your organization subscribes to a scope, each application selects the scopes it needs, and each request can narrow them further with scopes. See KYC scopes & subscriptions for how subscriptions and billing work.

ScopeReturns
kyb.addressesbusiness.addresses — the registered_office (province, city, commune, quartier, avenue, number, verified_at) and every declared branches entry.
kyb.contactsbusiness.contacts — phone_numbers (E.164, is_primary, verified), emails and website.
kyb.activitiesbusiness.activities — sector codes (classification, code), description and is_primary.
kyb.officersbusiness.officers — directors, managers and auditors with role, appointed_at, their rdcpass_id and basic KYC (kyc.basic).
kyb.beneficial_ownersbusiness.beneficial_owners — every natural person holding 25 % or more, with ownership_percent, control_type (direct | indirect), rdcpass_id and basic KYC.
kyb.shareholdersbusiness.shareholders — the full shareholder register: individuals (rdcpass_id, full_name) and entities (legal_name, rccm), with shares and ownership_percent.
kyb.licensesbusiness.licenses — sector licenses and approvals: regulator (e.g. BCC, ARPTC, ARCA, ministries), license_type, license_number, status, issued_at, expires_at.
kyb.documentsbusiness.documents — statutes, RCCM extract, ID NAT and NIF certificates, each with type, issued_at and a file object.
kyb.financialsbusiness.financials — share_capital, declared_turnover_band and fiscal_year.

Officers and beneficial owners are resolved to their RDCPASS identity, so you get the same verified basic KYC as a KYC Validation call — without a separate request per person. To screen them for sanctions and PEP exposure, pass their rdcpass_id to AML & CTF Screening.

Documents are delivered as file objects: a signed URL valid for 5 minutes by default, or inline base64 with document_delivery: "base64". Fetch signed URLs server-side and never store them — see Documents & biometrics.

Full response

A verified result with all nine KYB scopes applied:

200 OK (verified, after decryption)
{
  "id": "kyb_3e7a9c1f52",
  "object": "kyb_verification",
  "livemode": true,
  "reference": "supp-0042",
  "status": "completed",
  "result": "verified",
  "identifier": { "type": "rccm", "value": "CD/KIN/RCCM/23-B-01234" },
  "match": {
    "business_name": "match",
    "registration_date": "match",
    "score": 0.99
  },
  "business": {
    "basic": {
      "legal_name": "Congo Digital Solutions SARL",
      "trade_name": "CongoDigital",
      "rccm": "CD/KIN/RCCM/23-B-01234",
      "id_nat": "01-83-N45127K",
      "nif": "A2314567890X",
      "legal_form": "SARL",
      "status": "active",
      "registration_date": "2023-02-14",
      "country": "COD"
    },
    "addresses": {
      "registered_office": {
        "province": "Kinshasa",
        "city": "Kinshasa",
        "commune": "Gombe",
        "quartier": "Batetela",
        "avenue": "Avenue du Commerce",
        "number": "112",
        "verified_at": "2025-11-03T08:40:00Z"
      },
      "branches": [
        {
          "name": "Agence Lubumbashi",
          "province": "Haut-Katanga",
          "city": "Lubumbashi",
          "commune": "Lubumbashi",
          "quartier": "Makutano",
          "avenue": "Avenue Lumumba",
          "number": "45",
          "verified_at": "2025-11-03T08:40:00Z"
        }
      ]
    },
    "contacts": {
      "phone_numbers": [
        { "number": "+243812345678", "is_primary": true, "verified": true },
        { "number": "+243997001122", "is_primary": false, "verified": true }
      ],
      "emails": [
        { "address": "contact@congodigital.cd", "is_primary": true, "verified": true }
      ],
      "website": "https://congodigital.cd"
    },
    "activities": [
      {
        "classification": "ISIC_REV4",
        "code": "6201",
        "description": "Programmation informatique",
        "is_primary": true
      },
      {
        "classification": "ISIC_REV4",
        "code": "6311",
        "description": "Traitement de données, hébergement et activités connexes",
        "is_primary": false
      }
    ],
    "officers": [
      {
        "role": "manager",
        "appointed_at": "2023-02-14",
        "rdcpass_id": "COD-2103-0214-4937",
        "kyc": {
          "basic": {
            "full_name": "Kabeya Mwamba Tshisekedi",
            "first_name": "Kabeya",
            "last_name": "Tshisekedi",
            "date_of_birth": "1988-04-12",
            "age": 38,
            "gender": "male",
            "nationality": "COD"
          }
        }
      },
      {
        "role": "statutory_auditor",
        "appointed_at": "2024-06-30",
        "rdcpass_id": "COD-1907-5530-1186",
        "kyc": {
          "basic": {
            "full_name": "Mbuyi Ilunga Nsimba",
            "first_name": "Mbuyi",
            "last_name": "Nsimba",
            "date_of_birth": "1979-09-23",
            "age": 47,
            "gender": "female",
            "nationality": "COD"
          }
        }
      }
    ],
    "beneficial_owners": [
      {
        "ownership_percent": 60.0,
        "control_type": "direct",
        "rdcpass_id": "COD-2103-0214-4937",
        "kyc": {
          "basic": {
            "full_name": "Kabeya Mwamba Tshisekedi",
            "first_name": "Kabeya",
            "last_name": "Tshisekedi",
            "date_of_birth": "1988-04-12",
            "age": 38,
            "gender": "male",
            "nationality": "COD"
          }
        }
      },
      {
        "ownership_percent": 30.0,
        "control_type": "indirect",
        "rdcpass_id": "COD-1512-8841-0273",
        "kyc": {
          "basic": {
            "full_name": "Mukendi Kalala Tshibanda",
            "first_name": "Mukendi",
            "last_name": "Tshibanda",
            "date_of_birth": "1983-01-07",
            "age": 43,
            "gender": "male",
            "nationality": "COD"
          }
        }
      }
    ],
    "shareholders": [
      {
        "type": "individual",
        "shares": 600,
        "ownership_percent": 60.0,
        "rdcpass_id": "COD-2103-0214-4937",
        "full_name": "Kabeya Mwamba Tshisekedi"
      },
      {
        "type": "entity",
        "shares": 300,
        "ownership_percent": 30.0,
        "legal_name": "Kalala Holding SA",
        "rccm": "CD/LSH/RCCM/19-B-00871"
      },
      {
        "type": "individual",
        "shares": 100,
        "ownership_percent": 10.0,
        "rdcpass_id": "COD-1907-5530-1186",
        "full_name": "Mbuyi Ilunga Nsimba"
      }
    ],
    "licenses": [
      {
        "regulator": "ARPTC",
        "license_type": "Fournisseur de services à valeur ajoutée",
        "license_number": "ARPTC/SVA/2024/0317",
        "status": "active",
        "issued_at": "2024-03-01",
        "expires_at": "2029-02-28"
      },
      {
        "regulator": "BCC",
        "license_type": "Agent de monnaie électronique",
        "license_number": "BCC/DSIF/AME/2025/042",
        "status": "active",
        "issued_at": "2025-07-15",
        "expires_at": "2028-07-14"
      }
    ],
    "documents": [
      {
        "type": "statutes",
        "issued_at": "2023-02-10",
        "file": {
          "content_type": "application/pdf",
          "url": "https://files.rdcpass.cd/d/9f2c41e7b0?sig=Qm9h2x",
          "expires_at": "2026-09-26T10:20:02Z"
        }
      },
      {
        "type": "rccm_extract",
        "issued_at": "2026-01-12",
        "file": {
          "content_type": "application/pdf",
          "url": "https://files.rdcpass.cd/d/3a7d0c25f9?sig=Lp4r8k",
          "expires_at": "2026-09-26T10:20:02Z"
        }
      },
      {
        "type": "id_nat_certificate",
        "issued_at": "2023-03-02",
        "file": {
          "content_type": "application/pdf",
          "url": "https://files.rdcpass.cd/d/c81e5b9a44?sig=Tz7w1n",
          "expires_at": "2026-09-26T10:20:02Z"
        }
      }
    ],
    "financials": {
      "share_capital": { "value": 10000, "currency": "USD" },
      "declared_turnover_band": "USD_1M_5M",
      "fiscal_year": 2025
    }
  },
  "scopes_applied": [
    "kyb.basic",
    "kyb.addresses",
    "kyb.contacts",
    "kyb.activities",
    "kyb.officers",
    "kyb.beneficial_owners",
    "kyb.shareholders",
    "kyb.licenses",
    "kyb.documents",
    "kyb.financials"
  ],
  "scopes_withheld": [],
  "purpose": "customer_onboarding",
  "created_at": "2026-09-26T10:15:02Z"
}

Example request

The header values are illustrative placeholders — see Authentication for how to compute a real X-RDCPASS-Signature and encrypt the body.

verify-business.sh
# Plaintext body shown — it is AES-256-GCM encrypted (IV in X-RDCPASS-IV) and signed per /docs/authentication before sending.
curl https://api.rdcpass.cd/v1/kyb/verifications \
  -X POST \
  -H "X-RDCPASS-Key-Id: key_live_8f2a1c0e9b" \
  -H "X-RDCPASS-Timestamp: 1735689600" \
  -H "X-RDCPASS-Nonce: 9c3f7a1e-2b6d-4c85-9e3a-5f8b0d4e7a92" \
  -H "X-RDCPASS-Signature: 5e9b3c...a17f" \
  -H "X-RDCPASS-IV: mX4p9Qz2Lr8sT1vB" \
  -H "Idempotency-Key: b7e2c4a1-5d9f-4e3b-8a61-2f0c9d7e4b18" \
  -H "Content-Type: application/json" \
  -d '{
    "identifier": { "type": "rccm", "value": "CD/KIN/RCCM/23-B-01234" },
    "match": { "business_name": "Congo Digital Solutions SARL", "registration_date": "2023-02-14" },
    "purpose": "customer_onboarding",
    "scopes": ["kyb.addresses", "kyb.officers", "kyb.beneficial_owners", "kyb.licenses"],
    "reference": "supp-0042"
  }'

Request modes

KYB Verification supports all four request modes. See Single, batch & async for polling, pagination and cancellation.

Synchronous (default)Asynchronous (Prefer: respond-async)
Single200 with the kyb_verification object202 with a job; result via kyb_verification.completed or GET /v1/jobs/{job_id}
Batch200 with every result — up to 50 items202 with a batch — up to 10,000 items; results via webhook or GET /v1/batches/{batch_id}/results

Batch: verify a supplier or merchant portfolio

Re-verify your entire supplier base before a payment run, or screen a merchant portfolio for dissolved or suspended businesses. Each item carries its own reference; purpose and scopes set at batch level apply to every item unless the item overrides them. Items succeed or fail independently.

cURL
curl https://api.rdcpass.cd/v1/kyb/verifications/batches \
  -X POST \
  -H "X-RDCPASS-Key-Id: key_live_8f2a1c0e9b" \
  -H "X-RDCPASS-Timestamp: 1735689600" \
  -H "X-RDCPASS-Nonce: 9c3f7a1e-2b6d-4c85-9e3a-5f8b0d4e7a92" \
  -H "X-RDCPASS-Signature: 5e9b3c...a17f" \
  -H "X-RDCPASS-IV: mX4p9Qz2Lr8sT1vB" \
  -H "Idempotency-Key: b7e2c4a1-5d9f-4e3b-8a61-2f0c9d7e4b18" \
  -H "Content-Type: application/json" \
  -d @suppliers.json   # plaintext shown; encrypt per /docs/authentication before sending
suppliers.json (plaintext, before encryption)
{
  "purpose": "regulatory_compliance",
  "scopes": ["kyb.officers", "kyb.beneficial_owners", "kyb.licenses"],
  "items": [
    {
      "reference": "supp-0042",
      "identifier": { "type": "rccm", "value": "CD/KIN/RCCM/23-B-01234" },
      "match": { "business_name": "Congo Digital Solutions SARL" }
    },
    {
      "reference": "supp-0043",
      "identifier": { "type": "nif", "value": "A1907733410K" }
    },
    {
      "reference": "supp-0044",
      "identifier": { "type": "id_nat", "value": "05-93-N88214M" },
      "scopes": ["kyb.licenses"]
    }
  ]
}
200 OK — batch results (abridged)
{
  "object": "list",
  "data": [
    {
      "reference": "supp-0042",
      "status": "succeeded",
      "result": {
        "id": "kyb_3e7a9c1f52",
        "object": "kyb_verification",
        "result": "verified",
        "business": { "basic": { "legal_name": "Congo Digital Solutions SARL", "status": "active", "...": "..." }, "...": "..." },
        "...": "..."
      }
    },
    {
      "reference": "supp-0043",
      "status": "succeeded",
      "result": {
        "id": "kyb_7b20e4d9a1",
        "object": "kyb_verification",
        "result": "inactive",
        "business": {
          "basic": {
            "legal_name": "Mines et Transports du Kivu SARL",
            "trade_name": "MTK",
            "rccm": "CD/GOM/RCCM/17-B-00412",
            "id_nat": "19-61-N30572P",
            "nif": "A1907733410K",
            "legal_form": "SARL",
            "status": "in_liquidation",
            "registration_date": "2017-05-22",
            "country": "COD"
          }
        },
        "scopes_applied": ["kyb.basic"],
        "scopes_withheld": ["kyb.officers", "kyb.beneficial_owners", "kyb.licenses"],
        "...": "..."
      }
    },
    {
      "reference": "supp-0044",
      "status": "failed",
      "error": {
        "code": "invalid_identifier",
        "message": "identifier.value is not a valid ID NAT number."
      }
    }
  ],
  "next_cursor": null
}

Synchronous batches over 50 items return 413 batch_too_large. Add Prefer: respond-async for up to 10,000 items, then page through GET /v1/batches/{batch_id}/results (up to 500 results per page) once you receive batch.completed or batch.completed_with_errors. Each item is billed individually.

Asynchronous verification

Send Prefer: respond-async with a single request to get a job back immediately. When the verification completes, RDCPASS delivers a kyb_verification.completed event to your application’s webhook URL; its data is the completed job, with the same object a synchronous call returns embedded in result. You can also poll GET /v1/jobs/{job_id}.

Response
HTTP/1.1 202 Accepted

{
  "id": "job_4b1d9e7a2c",
  "object": "job",
  "service": "kyb_verification",
  "status": "pending",
  "created_at": "2026-09-26T10:15:00Z",
  "result_url": "/v1/jobs/job_4b1d9e7a2c"
}
Webhook event: kyb_verification.completed
{
  "id": "evt_2c9f4e7a1b8d3f60",
  "object": "event",
  "type": "kyb_verification.completed",
  "livemode": true,
  "created_at": "2026-09-26T10:15:04Z",
  "data": {
    "object": {
      "id": "job_4b1d9e7a2c",
      "object": "job",
      "service": "kyb_verification",
      "status": "completed",
      "created_at": "2026-09-26T10:15:00Z",
      "result_url": "/v1/jobs/job_4b1d9e7a2c",
      "result": {
        "id": "kyb_3e7a9c1f52",
        "reference": "supp-0042",
        "object": "kyb_verification",
        "status": "completed",
        "result": "verified",
        "business": { "basic": { "...": "..." }, "...": "..." },
        "...": "..."
      }
    }
  }
}

Verify the webhook signature before trusting the payload — see Webhooks.

Errors

Errors use the standard format described in Errors. Codes specific to this service:

CodeHTTPWhen
invalid_identifier400identifier.value does not match the format of the declared identifier.type.
unsupported_identifier_type400The identifier type is not a business identifier (for example rdcpass_id).
insufficient_balance402Prepaid wallet balance is exhausted.
credit_limit_reached402Postpaid usage has reached your credit limit.
scope_not_granted403A requested scope is not granted to this application.
purpose_not_approved403The purpose is not approved for this application.
service_not_enabled403KYB Verification is not enabled on this application.
production_access_required403A production key was used before the application was approved for production.
job_not_found404The job ID does not exist for this application.
batch_not_found404The batch ID does not exist for this application.
batch_too_large413More than 50 items in a synchronous batch.
quota_exceeded429Your plan’s quota for the period is exhausted.
rate_limited429Too many requests — retry after the indicated delay.

Next steps

Questions about your integration? Contact developer support