KYC scopes & subscriptions
What identity data RDCPASS returns, how your organization and application are entitled to it, and how each request can ask for less.
Every verified identity comes back with basic KYC. Anything beyond it — documents, addresses, contact details, biometrics — is an additional scope. Scopes let each business receive exactly the data it has a lawful need for, and nothing more: RDCPASS is the national digital identity, and data minimization is built into how it is shared.
Basic KYC
Basic KYC is returned on every successful identity match, at no extra subscription. It is what you need to know that a real, certified person stands behind an identifier: who they are, and the state of their RDCPASS account.
Its field set is configured by RDCPASS in the back office as platform-wide policy — the same for every organization — and applies to all identity services. The default set is:
| Field | Type | Description |
|---|---|---|
| rdcpass_id | string | The citizen’s RDCPASS ID, e.g. COD-2103-0214-4937. |
| account.status | string enum | active, suspended, paused or deleted. |
| account.certified | boolean | Whether the account has completed certification. |
| account.created_at | string | When the RDCPASS account was created. |
| account.level_of_assurance | string enum | LOA2, LOA3 or LOA4 — the assurance level of the identity proofing. |
| full_name | string | Full legal name as recorded. |
| first_name | string | First name. |
| last_name | string | Last name. |
| date_of_birth | string | Date of birth, YYYY-MM-DD. |
| age | integer | Age in whole years on the day of the request. |
| gender | string enum | male or female. |
| nationality | string | ISO 3166-1 alpha-3 code, e.g. COD. |
In API responses the account fields appear in the account block and the personal fields in kyc.basic. Basic KYC is always listed in scopes_applied as kyc.basic.
Scope catalogue
Each additional scope adds one block to the kyc object. Scopes fall into three tiers:
- Standard Identity and contact data. Available after standard due diligence.
- Sensitive Special-category personal data. Requires enhanced due diligence.
- Biometric Biometric data. Requires enhanced due diligence and the strictest handling.
| Scope | Data returned | Tier |
|---|---|---|
| kyc.documents.primary | The primary identity document: type, number, issued_at, expires_at, issuing_authority, status and image. | Standard |
| kyc.documents.all | Every other document on record, same shape, as an array. | Standard |
| kyc.addresses | Residential and postal addresses: province, city, commune, quartier, avenue, number, is_primary, verified_at. | Standard |
| kyc.emails | Email addresses: address, is_primary, verified. | Standard |
| kyc.phone_numbers | Phone numbers in E.164: number, operator, is_primary, verified. | Standard |
| kyc.professions | Professions and employment: title, employer, sector, since. | Standard |
| kyc.place_of_birth | Place of birth: country, province, city. | Standard |
| kyc.marital_status | single, married, divorced or widowed. | Standard |
| kyc.languages | Spoken languages as ISO 639 codes, e.g. fra, lin, swa, kon, lua. | Standard |
| kyc.religion | Religion. | Sensitive |
| kyc.ethnicity | Ethnic group. | Sensitive |
| kyc.biometrics.selfie | Enrollment selfie (image) and its capture date. | Biometric |
| kyc.biometrics.fingerprint | Fingerprint templates, ISO/IEC 19794-2, one per finger. | Biometric |
| kyc.biometrics.iris | Iris templates, ISO/IEC 19794-6, left and right. | Biometric |
Document images and biometric files are delivered as file objects — see Documents & biometrics.
Sensitive and biometric tiers require enhanced due diligence
Before a sensitive or biometric scope can be used in production, your organization must provide a data-protection impact assessment (DPIA), the legal basis for processing, and a named data-protection officer, and pass a penetration test of the application. See Going to production.The three-layer model
Access to a scope is decided in three layers. Each layer can only narrow what the layer above allows — never widen it.
Layer 1 — Organization
The organization subscribes
Your organization subscribes to additional scopes under its commercial agreement with RDCPASS. Each subscribed scope is billed per returned record on top of the base call price.
Managed by: Owner or Administrator
Layer 2 — Application
The application selects
When an application is created, you select the scopes it needs from your organization’s subscriptions. You can edit the selection later; changes to a production application are re-reviewed.
Managed by: Administrator (Developer for sandbox applications)
Layer 3 — Request
The request narrows
Each call can pass scopes to ask for a subset of what the application is granted. Omit it to receive every granted scope.
Managed by: Your code, per call
Worked example
An organization subscribes to five scopes, its onboarding application selects four, and one request asks for two:
scopes_applied and scopes_withheld
Every response lists exactly which scopes were honoured, so you never have to infer it from which blocks are present.
| Situation | Outcome |
|---|---|
| scopes omitted from the request | Every scope granted to the application is applied. |
| scopes is an empty array | Basic KYC only. |
| Scope requested, granted, and data on record | Block returned; scope listed in scopes_applied. |
| Scope requested and granted, but no data on record | Block omitted; scope listed in scopes_withheld. Not an error, and no scope surcharge. |
| Scope requested but not granted to the application | The whole request fails with 403 scope_not_granted. |
| Result is not_found or not_certified | No kyc block; scopes_applied and scopes_withheld are empty. |
Narrowing scopes on a request
This application is granted four scopes, but for this call only needs the customer’s address and profession:
{
"reference": "cust-0412",
"identifier": { "type": "rdcpass_id", "value": "COD-1908-0521-7730" },
"purpose": "customer_onboarding",
"scopes": ["kyc.addresses", "kyc.professions"]
}{
"id": "kyc_3f7c0b92e5",
"object": "kyc_validation",
"livemode": true,
"reference": "cust-0412",
"status": "completed",
"result": "verified",
"certified_account": true,
"identifier": { "type": "rdcpass_id", "value": "COD-1908-0521-7730" },
"match": {
"full_name": "not_provided",
"date_of_birth": "not_provided",
"age": "not_provided",
"score": null
},
"account": {
"rdcpass_id": "COD-1908-0521-7730",
"status": "active",
"certified": true,
"created_at": "2024-11-02T13:08:19Z",
"level_of_assurance": "LOA3"
},
"kyc": {
"basic": {
"full_name": "Mbuyi Ilunga Nsimba",
"first_name": "Mbuyi",
"last_name": "Nsimba",
"date_of_birth": "1992-11-03",
"age": 33,
"gender": "female",
"nationality": "COD"
},
"addresses": [
{
"type": "residential",
"province": "Nord-Kivu",
"city": "Goma",
"commune": "Karisimbi",
"quartier": "Katindo",
"avenue": "Avenue du Lac",
"number": "17",
"is_primary": true,
"verified_at": "2024-11-02T13:30:44Z"
}
]
},
"scopes_applied": ["kyc.basic", "kyc.addresses"],
"scopes_withheld": ["kyc.professions"],
"purpose": "customer_onboarding",
"created_at": "2026-09-26T11:02:37Z"
}Pricing
Each call is billed at the service’s base price. Every additional scope returned adds a per-scope surcharge per returned record — a withheld scope costs nothing, and basic KYC is always included. In a batch, each item is billed individually. See Billing.
Which services scopes apply to
| Service | How scopes are requested | Data returned |
|---|---|---|
| KYC Validation | scopes | Basic KYC + granted scopes on every verified result. |
| Face Recognition | scopes | Basic KYC + granted scopes when the face matches; nothing on no_match. |
| Login with RDCPASS | rdcpass:<scope> | profile for basic KYC claims, plus rdcpass:<scope> for each additional scope, e.g. rdcpass:kyc.addresses. The citizen approves the exact list on the consent screen. |
| AML & CTF Screening | scopes | Basic KYC + granted scopes when the subject resolves to an RDCPASS identity. |
| Credit Scoring | — | Basic KYC only. Additional scopes never apply. |
| Age Verification | — | Basic KYC only. Additional scopes never apply. |
KYB scopes
Businesses have their own scope family, used by KYB Verification. Every KYB result includes the business’s basic record — legal name, trade name, RCCM, ID NAT, NIF, legal form, status, registration date and country — and the following additional scopes follow the same three-layer model:
| Scope | Data returned |
|---|---|
| kyb.addresses | Registered office and branches. |
| kyb.contacts | Phones, emails and website. |
| kyb.activities | Sector codes and activity description. |
| kyb.officers | Directors and managers, with role, RDCPASS ID and basic KYC. |
| kyb.beneficial_owners | Owners of 25 % or more, with ownership_percent and RDCPASS ID. |
| kyb.shareholders | Shareholders. |
| kyb.licenses | Sector licenses: regulator, license number, status (e.g. BCC, ARPTC, ARCA). |
| kyb.documents | Statutes, RCCM extract, ID NAT certificate — delivered as file objects. |
| kyb.financials | Share capital and declared turnover band. |
Frequently asked questions
Can we change which fields are in basic KYC?
No. Basic KYC is configured by RDCPASS as platform-wide policy so that every business receives the same baseline. If you need more, subscribe to the relevant additional scope.
Do we pay for a scope that comes back in scopes_withheld?
No. The per-scope surcharge applies only to data actually returned. A withheld scope means the citizen has nothing on record for it.
We added a scope to our production application. When can we use it?
Once the change is approved. Scope changes on production applications go back through review, with enhanced review for sensitive or biometric scopes. Sandbox applications pick up changes immediately.
Should we always request every scope we are granted?
No. Pass scopes on each request to ask only for what that step of your flow needs. You pay less, store less, and every lookup is visible to the citizen in their RDCPASS app.
Why did a request fail with scope_not_granted instead of just leaving the block out?
Because asking for a scope your application is not entitled to is an integration error, not a data gap. Failing loudly prevents code from silently depending on data it will never receive.
Next steps
- KYC Validation — the full response with every scope block.
- Documents & biometrics — handle file objects safely.
- Applications — select scopes when creating an application.
- Going to production — scope justifications and enhanced due diligence.