KYC Validation checks the ID number your customer gives you against the national register. If a certified identity exists, you get their basic details back straight away, plus any extra data your organization has been approved for.
Verify a customer
Result
Branch staff no longer need to photocopy documents and check them by hand. One verification call replaces that step.
A result only comes back as verified when the national register holds a certified identity. What the customer declares is not enough on its own.
You decide which data your application gets back, which makes data-protection compliance easier to manage.
They type their RDCPASS ID or a document number into your app or website, or hand it over at the counter.
Your system submits the identifier along with the reason for the check, for example customer onboarding.
We look for a certified identity matching the identifier and compare it with any details you collected.
The identity is verified, not found or not certified. Verified results include basic KYC and the data you are approved for.
For each verified customer, RDCPASS returns data from the national register:
RDCPASS ID, passport, CENI voter card, driving licence or national ID. Customers can use the one they have on them.
Compare the name, date of birth or age your customer gave you with the certified record.
Documents, addresses, phone numbers, professions, biometrics and other scopes are returned only if your organization subscribes to them.
Send up to 10,000 records in one request, for example to refresh your customer files overnight.
A teller can get an answer while the customer waits. Longer checks can run in the background and notify your system when they finish.
Each check records why it was made. Your compliance team can show that record to an auditor.
Integration
Requests are HTTPS calls with JSON bodies, signed and encrypted. The sandbox returns the same formats as production, so the code you test with is the code you ship.
Create an application
Sign up, create a sandbox application and select the services and data scopes you need.
Make your first call
Start from an official SDK or from the samples on the right. Eight languages are covered.
Go live
After due diligence, replace the sandbox keys with production keys and add your mTLS certificate. The request code stays the same.
Request modes
Single · sync
One record, answered immediately.
Single · async
One record, result by webhook.
Batch · sync
Up to 50 records per call.
Batch · async
Up to 10,000 records, result by webhook.
# Plaintext body shown — encrypt it per /docs/authentication before sending.
curl https://api.rdcpass.cd/v1/kyc/validations \
-X POST \
-H "X-RDCPASS-Key-Id: key_live_8f2a1c0e9b" \
-H "X-RDCPASS-Timestamp: 1790417700" \
-H "X-RDCPASS-Nonce: 6f1c9b2e-4a3d-4e11-9c7a-2d8e5f1b0a44" \
-H "X-RDCPASS-Signature: 3f7a9c...e21d" \
-H "Content-Type: application/json" \
-d '{
"reference": "cust-0001",
"identifier": {
"type": "rdcpass_id",
"value": "COD-2103-0214-4937"
},
"match": {
"full_name": "Kabeya Mwamba Tshisekedi",
"date_of_birth": "1988-04-12"
},
"purpose": "customer_onboarding",
"scopes": [
"kyc.documents.primary",
"kyc.phone_numbers"
],
"document_delivery": "signed_url"
}'{
"id": "kyc_8d2f6a1c93",
"object": "kyc_validation",
"livemode": true,
"reference": "cust-0001",
"status": "completed",
"result": "verified",
"certified_account": true,
"identifier": {
"type": "rdcpass_id",
"value": "COD-2103-0214-4937"
},
"match": {
"full_name": "match",
"date_of_birth": "match",
"age": "not_provided",
"score": 0.98
},
"account": {
"rdcpass_id": "COD-2103-0214-4937",
"status": "active",
"certified": true,
"created_at": "2025-03-14T09:22:41Z",
"level_of_assurance": "LOA3"
},
"kyc": {
"basic": {
"full_name": "Kabeya Mwamba Tshisekedi",
"first_name": "Kabeya",
"last_name": "Tshisekedi",
"date_of_birth": "1988-04-12",
"age": 38,
"gender": "male",
"nationality": "COD"
},
"documents": {
"primary": {
"type": "passport",
"number": "OB1234567",
"issued_at": "2022-06-01",
"expires_at": "2027-05-31",
"issuing_authority": "Direction Générale de Migration",
"status": "valid",
"image": {
"content_type": "image/jpeg",
"url": "https://files.rdcpass.cd/d/9f2c41e8b7a3?sig=Qm9fX2t5Y19zaWc&exp=1790418002",
"expires_at": "2026-09-26T10:20:02Z"
}
}
},
"phone_numbers": [
{
"number": "+243812345678",
"operator": "Vodacom",
"is_primary": true,
"verified": true
},
{
"number": "+243991234567",
"operator": "Airtel",
"is_primary": false,
"verified": true
}
]
},
"scopes_applied": [
"kyc.basic",
"kyc.documents.primary",
"kyc.phone_numbers"
],
"scopes_withheld": [],
"purpose": "customer_onboarding",
"created_at": "2026-09-26T10:15:02Z"
}Billed per validation.
Basic KYC is included with every verified match. Each additional scope that returns data adds a small surcharge. Batch items are billed at a lower rate, and requests rejected with an error are never billed.
Use their passport, CENI voter card, driving licence or national ID number instead. RDCPASS will look for the certified identity linked to that document.
Every verified result includes basic KYC. Additional data such as documents, addresses or biometrics is returned only if your organization subscribes to that scope and your application is approved for it.
Yes. A batch request takes up to 10,000 records, and the results are sent to your system when they are ready. This suits periodic KYC refreshes.
Yes. The sandbox is free. It returns the same fields as production, using synthetic test identities.
Confirm that the person in front of the camera is the owner of the identity.
Learn moreScreen people and companies before you onboard them, then keep watching.
Learn moreCheck that a user meets an age threshold without collecting identity documents.
Learn moreBuilding and testing in the sandbox is free. You go live once your business and application have passed due diligence.