KYC scopes & subscriptions

What identity data RDCPASS returns, how your organization and application are entitled to it, and how each request can ask for less.

Every verified identity comes back with basic KYC. Anything beyond it — documents, addresses, contact details, biometrics — is an additional scope. Scopes let each business receive exactly the data it has a lawful need for, and nothing more: RDCPASS is the national digital identity, and data minimization is built into how it is shared.

Basic KYC

Basic KYC is returned on every successful identity match, at no extra subscription. It is what you need to know that a real, certified person stands behind an identifier: who they are, and the state of their RDCPASS account.

Its field set is configured by RDCPASS in the back office as platform-wide policy — the same for every organization — and applies to all identity services. The default set is:

FieldTypeDescription
rdcpass_idstringThe citizen’s RDCPASS ID, e.g. COD-2103-0214-4937.
account.statusstring enumactive, suspended, paused or deleted.
account.certifiedbooleanWhether the account has completed certification.
account.created_atstringWhen the RDCPASS account was created.
account.level_of_assurancestring enumLOA2, LOA3 or LOA4 — the assurance level of the identity proofing.
full_namestringFull legal name as recorded.
first_namestringFirst name.
last_namestringLast name.
date_of_birthstringDate of birth, YYYY-MM-DD.
ageintegerAge in whole years on the day of the request.
genderstring enummale or female.
nationalitystringISO 3166-1 alpha-3 code, e.g. COD.

In API responses the account fields appear in the account block and the personal fields in kyc.basic. Basic KYC is always listed in scopes_applied as kyc.basic.

Scope catalogue

Each additional scope adds one block to the kyc object. Scopes fall into three tiers:

  • Standard Identity and contact data. Available after standard due diligence.
  • Sensitive Special-category personal data. Requires enhanced due diligence.
  • Biometric Biometric data. Requires enhanced due diligence and the strictest handling.
ScopeData returnedTier
kyc.documents.primaryThe primary identity document: type, number, issued_at, expires_at, issuing_authority, status and image.Standard
kyc.documents.allEvery other document on record, same shape, as an array.Standard
kyc.addressesResidential and postal addresses: province, city, commune, quartier, avenue, number, is_primary, verified_at.Standard
kyc.emailsEmail addresses: address, is_primary, verified.Standard
kyc.phone_numbersPhone numbers in E.164: number, operator, is_primary, verified.Standard
kyc.professionsProfessions and employment: title, employer, sector, since.Standard
kyc.place_of_birthPlace of birth: country, province, city.Standard
kyc.marital_statussingle, married, divorced or widowed.Standard
kyc.languagesSpoken languages as ISO 639 codes, e.g. fra, lin, swa, kon, lua.Standard
kyc.religionReligion.Sensitive
kyc.ethnicityEthnic group.Sensitive
kyc.biometrics.selfieEnrollment selfie (image) and its capture date.Biometric
kyc.biometrics.fingerprintFingerprint templates, ISO/IEC 19794-2, one per finger.Biometric
kyc.biometrics.irisIris templates, ISO/IEC 19794-6, left and right.Biometric

Document images and biometric files are delivered as file objects — see Documents & biometrics.

Sensitive and biometric tiers require enhanced due diligence

Before a sensitive or biometric scope can be used in production, your organization must provide a data-protection impact assessment (DPIA), the legal basis for processing, and a named data-protection officer, and pass a penetration test of the application. See Going to production.

The three-layer model

Access to a scope is decided in three layers. Each layer can only narrow what the layer above allows — never widen it.

Layer 1 — Organization

The organization subscribes

Your organization subscribes to additional scopes under its commercial agreement with RDCPASS. Each subscribed scope is billed per returned record on top of the base call price.

Managed by: Owner or Administrator

Layer 2 — Application

The application selects

When an application is created, you select the scopes it needs from your organization’s subscriptions. You can edit the selection later; changes to a production application are re-reviewed.

Managed by: Administrator (Developer for sandbox applications)

Layer 3 — Request

The request narrows

Each call can pass scopes to ask for a subset of what the application is granted. Omit it to receive every granted scope.

Managed by: Your code, per call

Worked example

An organization subscribes to five scopes, its onboarding application selects four, and one request asks for two:

Layer 1 — Organization
kyc.documents.primarykyc.addresseskyc.phone_numberskyc.professionskyc.biometrics.selfie
Layer 2 — Application
kyc.documents.primarykyc.addresseskyc.phone_numberskyc.professionskyc.biometrics.selfie
Layer 3 — Request
kyc.documents.primarykyc.addresseskyc.phone_numberskyc.professionskyc.biometrics.selfie
Returnedkyc.basic, kyc.addresses — kyc.professions is withheld because this citizen has no profession on record.

scopes_applied and scopes_withheld

Every response lists exactly which scopes were honoured, so you never have to infer it from which blocks are present.

SituationOutcome
scopes omitted from the requestEvery scope granted to the application is applied.
scopes is an empty arrayBasic KYC only.
Scope requested, granted, and data on recordBlock returned; scope listed in scopes_applied.
Scope requested and granted, but no data on recordBlock omitted; scope listed in scopes_withheld. Not an error, and no scope surcharge.
Scope requested but not granted to the applicationThe whole request fails with 403 scope_not_granted.
Result is not_found or not_certifiedNo kyc block; scopes_applied and scopes_withheld are empty.

Narrowing scopes on a request

This application is granted four scopes, but for this call only needs the customer’s address and profession:

POST /v1/kyc/validations (plaintext, before encryption)
{
  "reference": "cust-0412",
  "identifier": { "type": "rdcpass_id", "value": "COD-1908-0521-7730" },
  "purpose": "customer_onboarding",
  "scopes": ["kyc.addresses", "kyc.professions"]
}
200 OK — kyc.professions withheld
{
  "id": "kyc_3f7c0b92e5",
  "object": "kyc_validation",
  "livemode": true,
  "reference": "cust-0412",
  "status": "completed",
  "result": "verified",
  "certified_account": true,
  "identifier": { "type": "rdcpass_id", "value": "COD-1908-0521-7730" },
  "match": {
    "full_name": "not_provided",
    "date_of_birth": "not_provided",
    "age": "not_provided",
    "score": null
  },
  "account": {
    "rdcpass_id": "COD-1908-0521-7730",
    "status": "active",
    "certified": true,
    "created_at": "2024-11-02T13:08:19Z",
    "level_of_assurance": "LOA3"
  },
  "kyc": {
    "basic": {
      "full_name": "Mbuyi Ilunga Nsimba",
      "first_name": "Mbuyi",
      "last_name": "Nsimba",
      "date_of_birth": "1992-11-03",
      "age": 33,
      "gender": "female",
      "nationality": "COD"
    },
    "addresses": [
      {
        "type": "residential",
        "province": "Nord-Kivu",
        "city": "Goma",
        "commune": "Karisimbi",
        "quartier": "Katindo",
        "avenue": "Avenue du Lac",
        "number": "17",
        "is_primary": true,
        "verified_at": "2024-11-02T13:30:44Z"
      }
    ]
  },
  "scopes_applied": ["kyc.basic", "kyc.addresses"],
  "scopes_withheld": ["kyc.professions"],
  "purpose": "customer_onboarding",
  "created_at": "2026-09-26T11:02:37Z"
}

Pricing

Each call is billed at the service’s base price. Every additional scope returned adds a per-scope surcharge per returned record — a withheld scope costs nothing, and basic KYC is always included. In a batch, each item is billed individually. See Billing.

Which services scopes apply to

ServiceHow scopes are requestedData returned
KYC ValidationscopesBasic KYC + granted scopes on every verified result.
Face RecognitionscopesBasic KYC + granted scopes when the face matches; nothing on no_match.
Login with RDCPASSrdcpass:<scope>profile for basic KYC claims, plus rdcpass:<scope> for each additional scope, e.g. rdcpass:kyc.addresses. The citizen approves the exact list on the consent screen.
AML & CTF ScreeningscopesBasic KYC + granted scopes when the subject resolves to an RDCPASS identity.
Credit Scoring—Basic KYC only. Additional scopes never apply.
Age Verification—Basic KYC only. Additional scopes never apply.

KYB scopes

Businesses have their own scope family, used by KYB Verification. Every KYB result includes the business’s basic record — legal name, trade name, RCCM, ID NAT, NIF, legal form, status, registration date and country — and the following additional scopes follow the same three-layer model:

ScopeData returned
kyb.addressesRegistered office and branches.
kyb.contactsPhones, emails and website.
kyb.activitiesSector codes and activity description.
kyb.officersDirectors and managers, with role, RDCPASS ID and basic KYC.
kyb.beneficial_ownersOwners of 25 % or more, with ownership_percent and RDCPASS ID.
kyb.shareholdersShareholders.
kyb.licensesSector licenses: regulator, license number, status (e.g. BCC, ARPTC, ARCA).
kyb.documentsStatutes, RCCM extract, ID NAT certificate — delivered as file objects.
kyb.financialsShare capital and declared turnover band.

Frequently asked questions

Can we change which fields are in basic KYC?

No. Basic KYC is configured by RDCPASS as platform-wide policy so that every business receives the same baseline. If you need more, subscribe to the relevant additional scope.

Do we pay for a scope that comes back in scopes_withheld?

No. The per-scope surcharge applies only to data actually returned. A withheld scope means the citizen has nothing on record for it.

We added a scope to our production application. When can we use it?

Once the change is approved. Scope changes on production applications go back through review, with enhanced review for sensitive or biometric scopes. Sandbox applications pick up changes immediately.

Should we always request every scope we are granted?

No. Pass scopes on each request to ask only for what that step of your flow needs. You pay less, store less, and every lookup is visible to the citizen in their RDCPASS app.

Why did a request fail with scope_not_granted instead of just leaving the block out?

Because asking for a scope your application is not entitled to is an integration error, not a data gap. Failing loudly prevents code from silently depending on data it will never receive.

Next steps

Questions about your integration? Contact developer support