RDCPASSBusiness
Age Verification · Identity

Check a customer’s age against their certified date of birth

Age Verification tells you whether a person has reached the minimum age you have to enforce. The answer is based on the date of birth held in the RDCPASS national digital identity, so you do not rely on a birthday the customer typed in or a scan of their papers, and you can prove the check took place.

  • You set the threshold, for example 18+
  • Only basic KYC is shared
  • Check one customer, or up to 10,000 in a batch
Sandbox example

Check an age threshold

Identifier
RDCPASS ID · COD-2103-0214-4937
Threshold
18+
Purpose
Age gating
  1. Signing request · HMAC-SHA256
  2. Encrypting payload · AES-256-GCM
  3. Reading date of birth from the register
  4. Comparing with the threshold

Result

age threshold, e.g. 18+
Any
age threshold, e.g. 18+
answer returned
Yes / no
answer returned
documents collected
0
documents collected
records per batch
10,000
records per batch

Why businesses choose Age Verification

1

Keep minors out, with proof

An “I am over 18” checkbox proves nothing. This answer comes from the certified national register, and every check leaves a record.

2

Hold less personal data

The service never returns documents, addresses or biometrics. You keep only what an age check needs.

3

Short sign-up

Customers give an identifier they already have. Nobody has to photograph their papers and upload them.

How it works

  1. 01

    Your customer gives you an identifier

    They enter their RDCPASS ID or a document number when they sign up, at checkout or at your counter.

  2. 02

    You set the minimum age

    Your system submits the identifier with the age threshold that applies to your activity, such as 18.

  3. 03

    RDCPASS checks the certified date of birth

    We match the identifier to a certified identity and work out the person’s age on the day of the check.

  4. 04

    You get the answer

    Over or under your threshold, with basic KYC so you can tie the check to the right customer. Or the identity is not found.

Capabilities

What you receive

Each check returns a short answer:

  • The status: verified or not found
  • Whether the person is over or under your threshold
  • Their age in whole years on the day of the check
  • Basic KYC, so you can link the check to the right customer record
  • The threshold that was applied, for your own records
01

Any threshold

Enforce 13, 16, 18, 21 or any other minimum age set by law, by your regulator or by your own policy.

02

Five accepted identifiers

RDCPASS ID, passport, CENI voter card, driving licence or national ID. Customers can use the one they have on them.

03

Basic KYC only

Additional data scopes never apply here, even if your organization subscribes to them for other services.

04

Batch re-checks

Re-check your whole player or subscriber base by sending up to 10,000 records in one request.

05

Real-time or in the background

Get the answer during sign-up. Large checks can run in the background and notify your system when they finish.

06

A record of every check

You can store each result as proof that you checked age before giving access.

Integration

One integration for sandbox and production

Requests are HTTPS calls with JSON bodies, signed and encrypted. The sandbox returns the same formats as production, so the code you test with is the code you ship.

  1. 1

    Create an application

    Sign up, create a sandbox application and select the services and data scopes you need.

  2. 2

    Make your first call

    Start from an official SDK or from the samples on the right. Eight languages are covered.

  3. 3

    Go live

    After due diligence, replace the sandbox keys with production keys and add your mTLS certificate. The request code stays the same.

Request modes

Single · sync

One record, answered immediately.

Single · async

One record, result by webhook.

Batch · sync

Up to 50 records per call.

Batch · async

Up to 10,000 records, result by webhook.

mTLSHMAC-SHA256AES-256-GCMAudit log
verify-age.sh
# Plaintext body shown for readability - encrypt and sign it as described in /docs/authentication before sending.
curl https://api.rdcpass.cd/v1/age/verifications \
  -X POST \
  -H "X-RDCPASS-Key-Id: key_live_8f2a1c0e9b" \
  -H "X-RDCPASS-Timestamp: 1735689600" \
  -H "X-RDCPASS-Nonce: 7a3c9e1b-5d2f-4b86-a0e4-1c8f6d2b9a73" \
  -H "X-RDCPASS-IV: Zt4Kp1Qw8Rm3Xv6N" \
  -H "X-RDCPASS-Signature: 1d6f2a...b48e" \
  -H "Content-Type: application/json" \
  -d '{
    "identifier": { "type": "rdcpass_id", "value": "COD-2103-0214-4937" },
    "threshold": 18,
    "purpose": "age_gating",
    "reference": "player-KIN-55012"
  }'
200 OK
{
  "id": "age_5f1b8c3d27",
  "object": "age_verification",
  "livemode": true,
  "reference": "player-KIN-55012",
  "status": "completed",
  "result": "verified",
  "over_threshold": true,
  "threshold": 18,
  "age": 38,
  "identifier": { "type": "rdcpass_id", "value": "COD-2103-0214-4937" },
  "account": {
    "rdcpass_id": "COD-2103-0214-4937",
    "status": "active",
    "certified": true,
    "created_at": "2025-03-14T09:22:41Z",
    "level_of_assurance": "LOA3"
  },
  "kyc": {
    "basic": {
      "full_name": "Kabeya Mwamba Tshisekedi",
      "first_name": "Kabeya",
      "last_name": "Tshisekedi",
      "date_of_birth": "1988-04-12",
      "age": 38,
      "gender": "male",
      "nationality": "COD"
    }
  },
  "scopes_applied": ["kyc.basic"],
  "scopes_withheld": [],
  "purpose": "age_gating",
  "created_at": "2026-09-26T10:15:02Z"
}

Trust & privacy

  • Only basic KYC is returned. Documents, addresses and biometrics are never part of an age check.
  • Every request states its purpose, and every access is logged for audit.
  • Requests are signed and encrypted end to end, over mutually authenticated connections.
  • Production access is granted only after due diligence on both your business and your application.

Pricing

Billed per verification.

Only basic KYC applies, so there are no scope surcharges. Batch items are billed at a lower rate and background checks cost the same as instant ones. Requests rejected with an error are never billed, and the sandbox is always free.

Frequently asked questions

Which age threshold should I use?+

Whichever applies to your activity under Congolese law, your regulator’s rules or your own policy. You set it on each check. If you do not, it defaults to 18.

Will I receive the customer’s date of birth?+

Yes, as part of basic KYC, so you can link the check to your customer. If all you need is proof that the check happened, keep the result and delete the rest.

What happens if the customer is not found?+

Treat it as a failed check. Ask the customer to register with RDCPASS, or to try another identifier such as their passport or CENI voter card.

Can I try it before going live?+

Yes. The sandbox is free. It returns the same fields as production, using synthetic test identities.

Start using Age Verification

Building and testing in the sandbox is free. You go live once your business and application have passed due diligence.