Glossary

Every RDCPASS-specific term used across these docs, defined once, in one place, instead of scattered across the pages that happen to use them.

Organizations, teams & applications

Tenant / organization
The company or institution integrating with RDCPASS — a bank, telecom operator, fintech, NGO or public agency. The organization is the tenant: it holds the members, the scope subscriptions, the billing plan and every application. Nothing is shared between organizations.
Application
A single integration within an organization, with its own services, selected scopes, declared purposes, webhook URL, IP allowlist, keys (sandbox and production), quotas and audit log. See Applications.
Member role
The role a member holds in an organization: Owner (one per organization, everything including ownership transfer), Administrator, Developer, Financial officer, Compliance officer or Marketing. Members sign in with their own RDCPASS identity, MFA is mandatory and every action is audited. See Teams & roles.
Subscription
The commercial agreement by which an organization gains access to an additional KYC or KYB scope. Each application then selects a subset of the organization’s subscriptions. Each additional scope is billed per returned record on top of the base call price.
Purpose
The declared reason for a request — customer_onboarding, credit_assessment, age_gating…. Purposes are declared on the application and approved during due diligence; every request carries one, and an unapproved purpose is rejected with purpose_not_approved.

Due diligence

Business due diligence
RDCPASS’s governance review of your organization before production access: legal existence (RCCM, ID NAT, NIF), statutes, directors and beneficial owners identified with RDCPASS, sector licence where applicable, data-protection officer, AML/CTF policy and the signed data-sharing agreement. See Going to production.
Application due diligence
The review of each application before it receives production keys: security, justification for every scope, authorization of who sees returned data, data-handling best practices and sandbox test evidence.
Enhanced due diligence
Additional review required for Face Recognition, Credit Scoring and every sensitive or biometric scope: a data-protection impact assessment (DPIA), a documented reason policy and an on-site or video audit.
KYB (Know Your Business)
Two different things share the name. KYB Verification is an API service: your application verifies another business against the national business registers. Business due diligence is what RDCPASS does to your own organization before granting production access — it is not called KYB in these docs.

Identity & KYC data

RDCPASS ID (COD-…)
The primary, lifelong identifier of a citizen in RDCPASS, formatted COD-2103-0214-4937. Accepted as rdcpass_id by every identity service and returned in the account block.
Certified account
An RDCPASS account whose identity has been verified and activated by RDCPASS. Identity services return verified only for certified accounts; an account that exists but is not yet certified returns not_certified.
Level of assurance (LOA)
How strongly the identity behind an account has been proven: LOA2, LOA3 or LOA4 (highest, with in-person enrollment and biometrics). Returned as account.level_of_assurance.
Basic KYC
The field set returned on every successful identity match at no extra subscription — RDCPASS ID, account status, certification, creation date, level of assurance, full name, first and last name, date of birth, age, gender and nationality. The set is defined by RDCPASS platform policy.
KYC scope
A named block of additional identity data beyond basic KYC — for example kyc.addresses, kyc.documents.primary, kyc.biometrics.selfie. An organization subscribes to scopes, each application selects a subset, and each request can narrow further. See KYC scopes & subscriptions.
Scope tier (standard / sensitive / biometric)
The protection level of a scope. Standard scopes (documents, addresses, contacts, professions…) need a justification. Sensitive scopes (religion, ethnicity) and biometric scopes (selfie, fingerprint, iris) are special-category data and require enhanced due diligence.
Signed URL
The default delivery of document images and biometric files: a single-tenant HTTPS URL valid for 5 minutes. Fetch it server-side immediately and never store the URL itself. See Documents & biometrics.

Requests

Asynchronous request
A request sent with Prefer: respond-async. RDCPASS answers 202 at once and delivers the result later by webhook or polling. Priced the same as a synchronous request. See Single, batch & async.
Job
The object returned for an asynchronous single request (job_4b1d9e7a2c), moving from pending to processing to completed or failed. A completed job embeds the same result the synchronous call returns; results are kept 30 days.
Batch
Many items of the same service in one request, each with your own reference: up to 50 items synchronously, up to 10,000 asynchronously (bat_7c2e91f04a). Results are paged 500 at a time and kept 30 days; each item is billed individually.
Quota
The number of single calls an application may make to a given service, metered per service and per application. Batches have a separate batch quota (batch items and batch submissions per day). Distinct from the burst rate limit and from billing limits. See Rate limits & quotas.

Identity services

1:1 verification
Face Recognition with an identifier: RDCPASS compares the submitted face to the enrolled face of that one person and answers match or no_match.
1:N identification
Face Recognition with a face only: RDCPASS searches the enrolled population for the person. More intrusive than 1:1, so every call carries an audited reason.
Liveness
Detection that a submitted face comes from a live person, not a photo, screen or mask. Face Recognition runs passive liveness by default; a failure returns liveness_failed.
Match verdict
The per-claim comparison result when you send claims to check — match, partial_match, no_match or not_provided — with an overall confidence score between 0 and 1. See KYC Validation.
PEP (politically exposed person)
Someone who holds or has held a prominent public function, or a close relative or associate of one. AML & CTF Screening reports PEP status, level and positions.
CENAREF
Cellule Nationale des Renseignements Financiers — the DRC’s financial intelligence unit. Its national list is one of the lists AML & CTF Screening checks, alongside the UN, OFAC, EU and UK lists.
Fraud Reporting
The service for reporting a suspected fraud to RDCPASS — identity usurpation (type identity_usurpation), document forgery, account takeover, SIM swap, money laundering and more. Each report receives a case number and status updates by webhook. See Fraud Reporting.

Business identifiers (DRC)

RCCM
Registre du Commerce et du Crédit Mobilier — the trade and personal-property credit register; every company’s registration number, e.g. CD/KIN/RCCM/23-B-01234.
ID NAT
Identification nationale — the national identification number assigned to every business entity.
NIF
Numéro d’identification fiscale — the tax identification number issued by the tax administration (DGI).

Billing

Prepaid
Payment model in which the organization tops up a wallet (Mobile Money, bank transfer or card) and each billable call debits it in real time. At zero balance, production calls return 402 insufficient_balance. See Billing.
Postpaid
Payment model with a monthly invoice in USD or CDF, net 30, within a credit limit set after financial due diligence. Usage over the limit returns 402 credit_limit_reached.

Credentials

API Key
An identifier, not a secret — like an AWS Access Key ID. Sent on every request as X-RDCPASS-Key-Id to tell RDCPASS which application is calling.
Secret Key
Shown once, at creation. Used to HMAC-sign every request — see HMAC-SHA256 below. Never sent on the wire itself.
Payload Encryption Key
Shown once, at creation. A 32-byte AES-256-GCM key used to encrypt every request body and decrypt every response body, independent of TLS.
mTLS client certificate
A certificate your application presents at the TLS layer, proving its identity before a single byte of request data is read. See Authentication for how to get one signed.

Request security

HMAC-SHA256 (request signing)
A cryptographic signature computed over a request's method, path, timestamp, nonce, and body hash, using your Secret Key. Proves the request came from you and wasn't tampered with in transit.
Nonce
A random value included on every request, remembered for a short window so a captured request can't be replayed — reusing a nonce is rejected outright.
AES-256-GCM (payload encryption)
Encrypts request and response bodies end-to-end using your Payload Encryption Key, independent of TLS — the payload stays sealed even if TLS terminates somewhere upstream of RDCPASS.

Environments

Sandbox
Instant, self-service, no review — synthetic identity records, free of charge. See Sandbox & environments.
Production
The real national identity register. Production keys are issued only once both the business due diligence and the application due diligence are approved.

Login with RDCPASS (OpenID Connect)

OpenID Connect (OIDC)
The identity-layer standard Login with RDCPASS is built on, on top of OAuth 2.0 — chosen specifically so standard OIDC client libraries work against it unmodified.
PKCE (Proof Key for Code Exchange)
Proves whoever exchanges an authorization code for tokens is the same party that started the login. Mandatory on every request — there is no confidential-client exception.
ID token
A signed JWT proving a citizen’s identity to your application, returned from the token exchange. Contains a pairwise sub, the basic KYC claims when profile is granted, and one rdcpass: claim per additional scope the citizen approved.
Redirect URI
The exact, pre-registered URL RDCPASS sends a citizen back to after they authenticate. Must match what’s on file byte-for-byte — no wildcards, no partial matches.
Scope (OIDC)
What a Login with RDCPASS request asks to see: openid (required), profile for basic KYC, and rdcpass:<scope> for each additional KYC scope granted to the application. The consent screen shows exactly these scopes.
Face recognition (Login with RDCPASS)
A server-verified match against the citizen’s enrolled RDCPASS biometric record, required to approve a Login with RDCPASS request — not just whatever unlocks their phone. Completed inside the RDCPASS app itself, never by your application.

Questions about your integration? Contact developer support