RDCPASSBusiness
KYC Validation · Identity

Verify customers against the national register

KYC Validation checks the ID number your customer gives you against the national register. If a certified identity exists, you get their basic details back straight away, plus any extra data your organization has been approved for.

  • Accepts an RDCPASS ID, passport, CENI voter card, driving licence or national ID
  • Basic KYC comes with every verified match
  • Check one customer, or up to 10,000 in a batch
Sandbox example

Verify a customer

Identifier
RDCPASS ID · COD-2103-0214-4937
Claimed name
Kabeya Mwamba Tshisekedi
Purpose
Customer onboarding
  1. Signing request · HMAC-SHA256
  2. Encrypting payload · AES-256-GCM
  3. Matching against the national register
  4. Applying your approved scopes

Result

accepted identifier types
5
accepted identifier types
additional data scopes
14
additional data scopes
records per batch
10,000
records per batch
request modes
4
request modes

Why businesses choose KYC Validation

1

Less paperwork at onboarding

Branch staff no longer need to photocopy documents and check them by hand. One verification call replaces that step.

2

Catch fake and borrowed identities

A result only comes back as verified when the national register holds a certified identity. What the customer declares is not enough on its own.

3

Receive only the data you use

You decide which data your application gets back, which makes data-protection compliance easier to manage.

How it works

  1. 01

    Your customer gives you an identifier

    They type their RDCPASS ID or a document number into your app or website, or hand it over at the counter.

  2. 02

    You send it with a declared purpose

    Your system submits the identifier along with the reason for the check, for example customer onboarding.

  3. 03

    RDCPASS checks the national register

    We look for a certified identity matching the identifier and compare it with any details you collected.

  4. 04

    You get the result

    The identity is verified, not found or not certified. Verified results include basic KYC and the data you are approved for.

Capabilities

What you receive

For each verified customer, RDCPASS returns data from the national register:

  • The status: verified, not found or not certified
  • Basic KYC, the core identity details every organization receives
  • How each detail you collected compares with the certified record
  • Any additional data scopes your application is approved for, such as documents or addresses
  • Which scopes were shared and which were withheld
01

Five accepted identifiers

RDCPASS ID, passport, CENI voter card, driving licence or national ID. Customers can use the one they have on them.

02

Claim comparison

Compare the name, date of birth or age your customer gave you with the certified record.

03

Subscribed data scopes

Documents, addresses, phone numbers, professions, biometrics and other scopes are returned only if your organization subscribes to them.

04

Batch verification

Send up to 10,000 records in one request, for example to refresh your customer files overnight.

05

Real-time or in the background

A teller can get an answer while the customer waits. Longer checks can run in the background and notify your system when they finish.

06

Purpose on every request

Each check records why it was made. Your compliance team can show that record to an auditor.

Integration

One integration for sandbox and production

Requests are HTTPS calls with JSON bodies, signed and encrypted. The sandbox returns the same formats as production, so the code you test with is the code you ship.

  1. 1

    Create an application

    Sign up, create a sandbox application and select the services and data scopes you need.

  2. 2

    Make your first call

    Start from an official SDK or from the samples on the right. Eight languages are covered.

  3. 3

    Go live

    After due diligence, replace the sandbox keys with production keys and add your mTLS certificate. The request code stays the same.

Request modes

Single · sync

One record, answered immediately.

Single · async

One record, result by webhook.

Batch · sync

Up to 50 records per call.

Batch · async

Up to 10,000 records, result by webhook.

mTLSHMAC-SHA256AES-256-GCMAudit log
validate-identity.sh
# Plaintext body shown — encrypt it per /docs/authentication before sending.
curl https://api.rdcpass.cd/v1/kyc/validations \
  -X POST \
  -H "X-RDCPASS-Key-Id: key_live_8f2a1c0e9b" \
  -H "X-RDCPASS-Timestamp: 1790417700" \
  -H "X-RDCPASS-Nonce: 6f1c9b2e-4a3d-4e11-9c7a-2d8e5f1b0a44" \
  -H "X-RDCPASS-Signature: 3f7a9c...e21d" \
  -H "Content-Type: application/json" \
  -d '{
    "reference": "cust-0001",
    "identifier": {
      "type": "rdcpass_id",
      "value": "COD-2103-0214-4937"
    },
    "match": {
      "full_name": "Kabeya Mwamba Tshisekedi",
      "date_of_birth": "1988-04-12"
    },
    "purpose": "customer_onboarding",
    "scopes": [
      "kyc.documents.primary",
      "kyc.phone_numbers"
    ],
    "document_delivery": "signed_url"
  }'
200 OK
{
  "id": "kyc_8d2f6a1c93",
  "object": "kyc_validation",
  "livemode": true,
  "reference": "cust-0001",
  "status": "completed",
  "result": "verified",
  "certified_account": true,
  "identifier": {
    "type": "rdcpass_id",
    "value": "COD-2103-0214-4937"
  },
  "match": {
    "full_name": "match",
    "date_of_birth": "match",
    "age": "not_provided",
    "score": 0.98
  },
  "account": {
    "rdcpass_id": "COD-2103-0214-4937",
    "status": "active",
    "certified": true,
    "created_at": "2025-03-14T09:22:41Z",
    "level_of_assurance": "LOA3"
  },
  "kyc": {
    "basic": {
      "full_name": "Kabeya Mwamba Tshisekedi",
      "first_name": "Kabeya",
      "last_name": "Tshisekedi",
      "date_of_birth": "1988-04-12",
      "age": 38,
      "gender": "male",
      "nationality": "COD"
    },
    "documents": {
      "primary": {
        "type": "passport",
        "number": "OB1234567",
        "issued_at": "2022-06-01",
        "expires_at": "2027-05-31",
        "issuing_authority": "Direction Générale de Migration",
        "status": "valid",
        "image": {
          "content_type": "image/jpeg",
          "url": "https://files.rdcpass.cd/d/9f2c41e8b7a3?sig=Qm9fX2t5Y19zaWc&exp=1790418002",
          "expires_at": "2026-09-26T10:20:02Z"
        }
      }
    },
    "phone_numbers": [
      {
        "number": "+243812345678",
        "operator": "Vodacom",
        "is_primary": true,
        "verified": true
      },
      {
        "number": "+243991234567",
        "operator": "Airtel",
        "is_primary": false,
        "verified": true
      }
    ]
  },
  "scopes_applied": [
    "kyc.basic",
    "kyc.documents.primary",
    "kyc.phone_numbers"
  ],
  "scopes_withheld": [],
  "purpose": "customer_onboarding",
  "created_at": "2026-09-26T10:15:02Z"
}

Trust & privacy

  • Your organization subscribes to data scopes once. Each application then selects only the ones it needs.
  • Every request states its purpose, and every access is logged for audit.
  • Requests are signed and encrypted end to end, over mutually authenticated connections.
  • Production access is granted only after due diligence on both your business and your application.

Pricing

Billed per validation.

Basic KYC is included with every verified match. Each additional scope that returns data adds a small surcharge. Batch items are billed at a lower rate, and requests rejected with an error are never billed.

Frequently asked questions

What if my customer does not have an RDCPASS ID?+

Use their passport, CENI voter card, driving licence or national ID number instead. RDCPASS will look for the certified identity linked to that document.

Which data will I receive?+

Every verified result includes basic KYC. Additional data such as documents, addresses or biometrics is returned only if your organization subscribes to that scope and your application is approved for it.

Can I check thousands of existing customers at once?+

Yes. A batch request takes up to 10,000 records, and the results are sent to your system when they are ready. This suits periodic KYC refreshes.

Can I try it before going live?+

Yes. The sandbox is free. It returns the same fields as production, using synthetic test identities.

Start using KYC Validation

Building and testing in the sandbox is free. You go live once your business and application have passed due diligence.