Sandbox & environments
RDCPASS runs two fully separate environments. Build and test in the sandbox, with synthetic identities and free usage for all eight services; move to production once your due-diligence dossiers are approved.
Credentials never work across environments
Production and sandbox are separate systems end to end — separate data and separate credentials. A key or certificate issued for one environment is rejected by the other.Two environments
api.rdcpass.cd"livemode": true.gateway.staging.rdcpass.cd"livemode": false.# Production
https://api.rdcpass.cd
# Sandbox
https://gateway.staging.rdcpass.cdThe request and response formats are identical in both environments: switching is a matter of base URL and keys.
The sandbox plan
Every application gets the free sandbox plan at creation, covering all eight services: KYC Validation, Face Recognition, Age Verification, KYB Verification, AML & CTF Screening, Credit Scoring, Fraud Reporting and Login with RDCPASS. Every scope — including Sensitive and Biometric ones — can be selected in sandbox without subscription or enhanced due diligence, so you can build your full integration before going live. Single, batch and asynchronous requests all work exactly as in production.
| Service | Sandbox quota (per application, per day) |
|---|---|
| kyc_validation | 1,000 |
| face_recognition | 200 |
| age_verification | 1,000 |
| kyb_verification | 500 |
| aml_screening | 500 |
| credit_score | 200 |
| fraud_report | 100 |
| Login with RDCPASS | 1,000 |
Quotas reset daily at 00:00 UTC. These quotas cover single calls; batches have a separate batch quota of 5,000 items and 20 batches per day per service. Beyond the quota, calls return 429 quota_exceeded — see Rate limits & quotas. Sandbox calls are never billed and never return 402.
Test identities
Use these RDCPASS IDs with KYC Validation, Age Verification, AML & CTF Screening, Credit Scoring and Face Recognition (1:1). Each produces a fixed, documented outcome:
| RDCPASS ID | Name · date of birth | Behaviour |
|---|---|---|
| COD-0000-0000-0001 | Kabeya Mwamba Tshisekedi · 1988-04-12 | verified, certified account (LOA3), data on record for every KYC scope, including documents, addresses and biometrics. AML: low risk, no hits. |
| COD-0000-0000-0003 | Mbuyi Ilunga Nsimba · 1992-11-03 | verified, certified account with Basic KYC only: every additional scope requested appears in scopes_withheld. |
| COD-0000-0000-0002 | Ngalula Kasongo Mujinga · 1995-07-21 | not_certified: the account exists but is not yet certified — only account is returned. |
| COD-0000-0000-0404 | — | not_found: no certified account for this identifier. |
| COD-0000-0000-0017 | Lukusa Mbayo Kalala · 2009-02-14 | verified, aged 17: Age Verification with threshold: 18 returns over_threshold: false. |
| COD-0000-0000-0666 | Test Sanctioned Subject · 1970-01-01 | AML & CTF Screening: risk_level: "high", a sanctions hit on the UN Security Council Consolidated List (match_score 0.97). |
| COD-0000-0000-0777 | Tshiala Mukendi Banza · 1965-09-30 | AML & CTF Screening: risk_level: "medium", pep.is_pep: true (national-level position). |
| COD-0000-0000 | — | Malformed identifier: returns 400 invalid_identifier. |
The same people can also be looked up by document: passport OB0000001 and CENI card 0000000000001 resolve to COD-0000-0000-0001.
Other test fixtures
| Service | Input | Behaviour |
|---|---|---|
| Face Recognition | image.url = https://files.rdcpass.cd/sandbox/faces/match-0001.jpg | match with COD-0000-0000-0001 (similarity 0.96, liveness passed). In 1:N mode, identifies COD-0000-0000-0001. |
| Face Recognition | image.url = https://files.rdcpass.cd/sandbox/faces/no-match.jpg | no_match — no identity data returned. |
| Face Recognition | image.url = https://files.rdcpass.cd/sandbox/faces/two-faces.jpg | 422 multiple_faces_detected. |
| Face Recognition | image.url = https://files.rdcpass.cd/sandbox/faces/liveness-fail.jpg | 422 liveness_failed. |
| KYB Verification | rccm = CD/KIN/RCCM/00-B-00001 | verified, active SARL with data for every KYB scope, including officers and beneficial owners. |
| KYB Verification | rccm = CD/LSH/RCCM/00-B-00002 | inactive — the company is dissolved. |
| KYB Verification | rccm = CD/KIN/RCCM/00-B-00404 | not_found. |
| Credit Scoring | consent.consent_id = cns_test_approved | Valid consent for COD-0000-0000-0001: score 712, band B. |
| Credit Scoring | consent.consent_id = cns_test_expired | 403 consent_required. |
| Fraud Reporting | type = identity_usurpation | Case created with status: "received", moves to under_review after 1 minute and confirmed after 5 minutes, sending fraud_report.status_changed each time. |
Asynchronous jobs and batches complete within seconds in sandbox and deliver the same webhooks as production, so you can test your whole event pipeline.
Path to production
When your integration is ready, submit your business and application dossiers from the console. Your sandbox request logs serve as test evidence. Once approved, the same application receives production keys — see Going to production.