RDCPASSBusiness
Face Recognition · Biometrics

Match a live face to a certified identity

Face Recognition compares a live photo with the faces enrolled in the RDCPASS national digital identity. Use it to confirm a customer is who they say they are, or to identify someone who has lost their documents. Each photo is also checked for spoofing with printed photos, screens and masks.

  • 1:1 verification and 1:N identification
  • Passive liveness, so the user has nothing extra to do
  • Every check carries a declared reason that is audited
Sandbox example

Match a selfie

Identity
RDCPASS ID · COD-2103-0214-4937
Mode
1:1 verification
Reason
Account opening
  1. Signing request · HMAC-SHA256
  2. Encrypting payload · AES-256-GCM
  3. Checking liveness
  4. Comparing with the registered face

Result

verification or identification
1:1 · 1:N
verification or identification
liveness detection
Passive
liveness detection
records per batch
10,000
records per batch
reason on every request
Audited
reason on every request

Why businesses choose Face Recognition

1

Stop impersonation

Knowing someone’s document number is no longer enough. The person has to match the face certified in the national register.

2

Check who is behind a high-risk request

Before you approve a SIM swap, a cash withdrawal or a new account, confirm the person asking is the account holder.

3

Serve people who have lost their papers

When no document is available, you can establish who someone is from their face alone.

How it works

  1. 01

    Your customer takes a live photo

    Your app, a kiosk or a camera in the branch takes one photo. The customer does not need to blink or turn their head.

  2. 02

    You send it with a specific reason

    Your system submits the photo, the claimed identity if there is one, and the reason for this check.

  3. 03

    RDCPASS checks liveness and compares faces

    We look for signs of a spoof first. The photo is then compared with the enrolled face of the claimed identity, or searched across certified identities.

  4. 04

    You get a match or no match

    A match comes with basic KYC and your approved data. A no match discloses no identity data at all.

Capabilities

What you receive

Each check returns a result you can audit later:

  • The verdict: match or no match
  • A similarity score and the strictness level applied
  • The outcome of the liveness check
  • On a match, the RDCPASS account and basic KYC, plus any additional data scopes your application is approved for
  • Your declared purpose and reason, as recorded in the audit trail
01

Verification (1:1)

Checks that a face belongs to the identity your customer claims. It is quick, and the least intrusive option.

02

Identification (1:N)

Finds which certified identity a face belongs to, if any, when the person cannot show a document.

03

Passive liveness

Printed photos, screen replays and masks are detected from the same single photo.

04

Adjustable strictness

Set how close a match must be for each check. Routine high-volume checks and high-value transactions can use different levels.

05

Batch and background checks

Verify one person at the counter, or send up to 10,000 faces in one request and get notified when the batch is done.

06

Audited reason on every check

Each request records why it was made, who triggered it and what it found, so your compliance team has a full record to work from.

Integration

One integration for sandbox and production

Requests are HTTPS calls with JSON bodies, signed and encrypted. The sandbox returns the same formats as production, so the code you test with is the code you ship.

  1. 1

    Create an application

    Sign up, create a sandbox application and select the services and data scopes you need.

  2. 2

    Make your first call

    Start from an official SDK or from the samples on the right. Eight languages are covered.

  3. 3

    Go live

    After due diligence, replace the sandbox keys with production keys and add your mTLS certificate. The request code stays the same.

Request modes

Single · sync

One record, answered immediately.

Single · async

One record, result by webhook.

Batch · sync

Up to 50 records per call.

Batch · async

Up to 10,000 records, result by webhook.

mTLSHMAC-SHA256AES-256-GCMAudit log
verify-face.sh
# Plaintext body shown for readability - encrypt and sign it as described in /docs/authentication before sending.
IMAGE_B64=$(base64 < selfie.jpg | tr -d '\n')

curl https://api.rdcpass.cd/v1/face/recognitions \
  -X POST \
  -H "X-RDCPASS-Key-Id: key_live_8f2a1c0e9b" \
  -H "X-RDCPASS-Timestamp: 1735689600" \
  -H "X-RDCPASS-Nonce: 2d7e4b1a-9c3f-4a58-b6e2-7f0c1d9a3e55" \
  -H "X-RDCPASS-IV: q3Jx8mT2vLp9Wc1R" \
  -H "X-RDCPASS-Signature: 8b4e1f...c93a" \
  -H "Content-Type: application/json" \
  -d '{
    "image": { "data": "'"$IMAGE_B64"'" },
    "identifier": { "type": "rdcpass_id", "value": "COD-2103-0214-4937" },
    "liveness": "passive",
    "threshold": 0.85,
    "reason": "Current account opening at Gombe branch, Kinshasa - applicant present at counter 3, ticket KIN-GOM-2026-004812",
    "purpose": "customer_onboarding",
    "reference": "cust-0001"
  }'
200 OK
{
  "id": "face_3c9a7e1f52",
  "object": "face_recognition",
  "livemode": true,
  "reference": "cust-0001",
  "status": "completed",
  "mode": "verification",
  "result": "match",
  "similarity": 0.96,
  "threshold": 0.85,
  "liveness": { "checked": true, "passed": true, "score": 0.97 },
  "identifier": { "type": "rdcpass_id", "value": "COD-2103-0214-4937" },
  "account": {
    "rdcpass_id": "COD-2103-0214-4937",
    "status": "active",
    "certified": true,
    "created_at": "2025-03-14T09:22:41Z",
    "level_of_assurance": "LOA3"
  },
  "kyc": {
    "basic": {
      "full_name": "Kabeya Mwamba Tshisekedi",
      "first_name": "Kabeya",
      "last_name": "Tshisekedi",
      "date_of_birth": "1988-04-12",
      "age": 38,
      "gender": "male",
      "nationality": "COD"
    },
    "documents": {
      "primary": {
        "type": "passport",
        "number": "OB1234567",
        "issued_at": "2022-06-02",
        "expires_at": "2032-06-01",
        "issuing_authority": "Direction Générale de Migration",
        "status": "valid",
        "image": {
          "content_type": "image/jpeg",
          "url": "https://files.rdcpass.cd/d/9f2c41e7b0?sig=Kx82hQ",
          "expires_at": "2026-09-26T10:20:02Z"
        }
      },
      "others": [
        {
          "type": "ceni",
          "number": "1234567890123",
          "issued_at": "2023-02-17",
          "expires_at": null,
          "issuing_authority": "Commission Électorale Nationale Indépendante",
          "status": "valid",
          "image": {
            "content_type": "image/jpeg",
            "url": "https://files.rdcpass.cd/d/4b7d02a9c1?sig=Pm31tZ",
            "expires_at": "2026-09-26T10:20:02Z"
          }
        }
      ]
    },
    "addresses": [
      {
        "type": "residential",
        "province": "Kinshasa",
        "city": "Kinshasa",
        "commune": "Gombe",
        "quartier": "Golf",
        "avenue": "Avenue de la Justice",
        "number": "45",
        "is_primary": true,
        "verified_at": "2025-03-14T09:40:12Z"
      }
    ],
    "emails": [
      { "address": "kabeya.tshisekedi@example.cd", "is_primary": true, "verified": true }
    ],
    "phone_numbers": [
      { "number": "+243812345678", "operator": "Vodacom", "is_primary": true, "verified": true },
      { "number": "+243970112233", "operator": "Airtel", "is_primary": false, "verified": true }
    ],
    "professions": [
      { "title": "Ingénieur réseaux", "employer": "Société Nationale d'Électricité", "sector": "energy", "since": "2016-09-01" }
    ],
    "place_of_birth": { "country": "COD", "province": "Kasaï-Oriental", "city": "Mbuji-Mayi" },
    "marital_status": "married",
    "languages": ["fra", "lin", "lua"],
    "religion": "catholic",
    "ethnicity": "Luba",
    "biometrics": {
      "selfie": {
        "captured_at": "2025-03-14T09:31:55Z",
        "file": {
          "content_type": "image/jpeg",
          "url": "https://files.rdcpass.cd/d/c81e5f3a20?sig=Wq07vB",
          "expires_at": "2026-09-26T10:20:02Z"
        }
      },
      "fingerprints": [
        {
          "format": "ISO_19794_2",
          "finger": "right_index",
          "file": {
            "content_type": "application/octet-stream",
            "url": "https://files.rdcpass.cd/d/e2a9d7b614?sig=Hn55cR",
            "expires_at": "2026-09-26T10:20:02Z"
          }
        }
      ],
      "iris": [
        {
          "format": "ISO_19794_6",
          "eye": "left",
          "file": {
            "content_type": "application/octet-stream",
            "url": "https://files.rdcpass.cd/d/07f4b3c8e9?sig=Lt62xD",
            "expires_at": "2026-09-26T10:20:02Z"
          }
        }
      ]
    }
  },
  "scopes_applied": [
    "kyc.basic",
    "kyc.documents.primary",
    "kyc.documents.all",
    "kyc.addresses",
    "kyc.emails",
    "kyc.phone_numbers",
    "kyc.professions",
    "kyc.place_of_birth",
    "kyc.marital_status",
    "kyc.languages",
    "kyc.religion",
    "kyc.ethnicity",
    "kyc.biometrics.selfie",
    "kyc.biometrics.fingerprint",
    "kyc.biometrics.iris"
  ],
  "scopes_withheld": [],
  "purpose": "customer_onboarding",
  "reason": "Current account opening at Gombe branch, Kinshasa - applicant present at counter 3, ticket KIN-GOM-2026-004812",
  "created_at": "2026-09-26T10:15:02Z"
}

Trust & privacy

  • Every check carries a specific reason written in plain language. It is stored and reviewed during RDCPASS audits.
  • Production access requires enhanced due diligence, including a documented reason policy and a data-protection impact assessment.
  • A no match never reveals a candidate. Identification is reserved for cases where there is no claimed identity.
  • Requests are signed and encrypted end to end, over mutually authenticated connections.

Pricing

Billed per recognition.

Basic KYC is included with every match. On a match, each additional scope that returns data adds a small surcharge. Batch items are billed at a lower rate and background checks cost the same as instant ones. Requests rejected with an error are never billed, and the sandbox is always free.

Frequently asked questions

What is the difference between verification and identification?+

Verification checks a face against the identity your customer claims. Identification searches certified identities to find who a face belongs to. If you know the claimed identity, use verification.

Does the user need to blink or turn their head?+

No. Liveness is checked passively from the one photo you send. For the user it is the same as having their picture taken.

Why must every request include a reason?+

Matching a face against the national identity has real privacy consequences. The reason is recorded with every check and reviewed in audits, so each use can be justified to the citizen and to the authorities.

What does it take to go live?+

You can use the sandbox straight away. Production requires enhanced due diligence: a documented reason policy, a data-protection impact assessment and a review of how you capture faces.

Start using Face Recognition

Building and testing in the sandbox is free. You go live once your business and application have passed due diligence.