Quickstart

From a new organization to your first verified identity in the sandbox: create the organization, invite your team, create an application, get keys and validate a test identity by RDCPASS ID.

1. Create your organization

Sign up at the RDCPASS console with Login with RDCPASS — you approve the sign-in in the RDCPASS app, so there is no password to create. Then create your organization: your company’s legal name and RCCM. You become its Owner.

2. Invite your team

Under Settings → Team, invite colleagues by email and give each the roles they need — typically Developer for engineers, Financial officer for billing and Compliance officer for due diligence. Everyone signs in with their own RDCPASS identity. See Teams & roles.

3. Create a sandbox application

Under Applications → New application, name the application, then choose:

  • Services — for this quickstart, enable KYC Validation. All eight services are free in sandbox.
  • Scopes — add kyc.phone_numbers. Basic KYC is always included.
  • Purposes — declare customer_onboarding.
  • Webhook URL — optional for now; you need it for asynchronous requests.

Every field is explained in Applications.

4. Copy your sandbox keys

Creating the application issues its sandbox credentials immediately:

CredentialUsed for
API key (key_test_…)Sent as X-RDCPASS-Key-Id on every request. An identifier, not a secret.
Secret KeyHMAC-SHA256 signature of every request (X-RDCPASS-Signature).
Payload Encryption KeyAES-256-GCM encryption of request bodies and decryption of responses.

The Secret Key and Payload Encryption Key are shown once

Copy both into a secrets manager before closing the dialog. RDCPASS cannot display them again; if one is lost, issue a new key set and revoke the old one.

5. Validate a test identity

Call KYC Validation in the sandbox with the test identity COD-0000-0000-0001, a certified account holding every scope. Sign and encrypt the body as described in Authentication:

first-call.sh
# Plaintext body shown — encrypt it per /docs/authentication before sending.
curl https://gateway.staging.rdcpass.cd/v1/kyc/validations \
  -X POST \
  -H "X-RDCPASS-Key-Id: key_test_3c7e1a9f42" \
  -H "X-RDCPASS-Timestamp: 1790417700" \
  -H "X-RDCPASS-Nonce: 5f3e2a1b-8c9d-4e6f-a1b2-3c4d5e6f7a8b" \
  -H "X-RDCPASS-Signature: 8e1b4d...a07c" \
  -H "Content-Type: application/json" \
  -d '{
    "reference": "quickstart-001",
    "identifier": { "type": "rdcpass_id", "value": "COD-0000-0000-0001" },
    "match": { "full_name": "Kabeya Mwamba Tshisekedi", "date_of_birth": "1988-04-12" },
    "purpose": "customer_onboarding",
    "scopes": ["kyc.phone_numbers"]
  }'
200 OK (after decryption)
{
  "id": "kyc_0f3a9c2e71",
  "object": "kyc_validation",
  "livemode": false,
  "reference": "quickstart-001",
  "status": "completed",
  "result": "verified",
  "certified_account": true,
  "identifier": { "type": "rdcpass_id", "value": "COD-0000-0000-0001" },
  "match": { "full_name": "match", "date_of_birth": "match", "age": "not_provided", "score": 0.99 },
  "account": {
    "rdcpass_id": "COD-0000-0000-0001",
    "status": "active",
    "certified": true,
    "created_at": "2025-01-06T08:00:00Z",
    "level_of_assurance": "LOA3"
  },
  "kyc": {
    "basic": {
      "full_name": "Kabeya Mwamba Tshisekedi",
      "first_name": "Kabeya",
      "last_name": "Tshisekedi",
      "date_of_birth": "1988-04-12",
      "age": 38,
      "gender": "male",
      "nationality": "COD"
    },
    "phone_numbers": [
      { "number": "+243810000001", "operator": "Vodacom", "is_primary": true, "verified": true }
    ]
  },
  "scopes_applied": ["kyc.basic", "kyc.phone_numbers"],
  "scopes_withheld": [],
  "purpose": "customer_onboarding",
  "created_at": "2026-09-27T09:30:12Z"
}

6. Handle the result

Branch on result. The other sandbox test identities let you exercise each branch — COD-0000-0000-0002 returns not_certified and COD-0000-0000-0404 returns not_found. See Sandbox & environments for the full list.

handle-result.js
switch (validation.result) {
  case 'verified':
    // Certified RDCPASS identity: use validation.kyc.basic and the scopes
    // listed in validation.scopes_applied. Check validation.match too.
    break
  case 'not_certified':
    // Account exists but is not yet certified: only validation.account is
    // returned. Ask the customer to complete certification in RDCPASS.
    break
  case 'not_found':
    // No certified account for this identifier: no identity data returned.
    break
}

Each sandbox call is counted against your application’s sandbox quota and appears in the application’s request logs. See Rate limits & quotas.

Next steps

Questions about your integration? Contact developer support