RDCPASSBusiness
Login with RDCPASS · Authentication

Let citizens sign in with their RDCPASS identity

Login with RDCPASS puts one button where your sign-up form and password field used to be. The citizen approves on their own phone with a face match, sees what data you are asking for, and comes back to your application already verified.

  • Passwordless: a push notification and a face match
  • The citizen consents to every piece of data shared
  • Built on OpenID Connect
Sandbox example

Sign in with RDCPASS

Application
Your Company
Requested
Profile · phone · address
  1. Redirecting to RDCPASS (PKCE)
  2. Push notification to the citizen’s app
  3. Face check and consent
  4. Issuing tokens to your app

Result

standard, with mandatory PKCE
OIDC
standard, with mandatory PKCE
for the citizen to approve
60 s
for the citizen to approve
pseudonymous identifier per app
1
pseudonymous identifier per app
passwords to manage
0
passwords to manage

Why businesses choose Login with RDCPASS

1

Sign-up with no forms

New users arrive with a certified identity and the details you asked for. Your team has nothing to check by hand.

2

No passwords to steal or reset

Each sign-in is confirmed by a face match on the citizen’s own phone. There is no password to phish, reuse or forget.

3

Consent the citizen can see

Citizens review and approve what you receive before it is sent. That helps with data-protection compliance, and users can see what they agreed to.

How it works

  1. 01

    The citizen taps “Login with RDCPASS”

    Your application redirects them to a secure RDCPASS page. They never type their identity details into your app.

  2. 02

    They approve on their phone

    The RDCPASS app shows a notification with your company’s verified name and the data you are requesting.

  3. 03

    They confirm with a face match

    A short face check against their enrolled RDCPASS identity confirms it is really them.

  4. 04

    They return to your application, signed in

    You receive signed proof of who they are, with basic KYC and each additional scope they approved.

Capabilities

What you receive

When the citizen approves, your application receives signed proof of identity that you can verify:

  • A stable identifier for that citizen, unique to your application
  • Basic KYC, the core identity details, if you request it
  • Each additional data scope the citizen approved, such as addresses or phone numbers
  • The certification status and level of assurance of the RDCPASS account
  • The same “access denied” outcome whenever sign-in does not complete
01

No passwords at all

Sign-in uses the citizen’s enrolled phone and their face. There is no password fallback.

02

Verified company name

The consent screen shows your organization’s name as confirmed by RDCPASS, so citizens know who is asking.

03

All-or-nothing consent

The citizen sees every requested scope, with sensitive data flagged, and approves or declines the request as a whole.

04

Private identifier per application

Each application gets its own stable identifier for a citizen. Users cannot be tracked from one service to another.

05

Standard integration

OpenID Connect with mandatory PKCE, so common login libraries work without changes.

06

Credit-scoring consent

On the same screen, you can ask the citizen to consent to a credit score for use with Credit Scoring.

Integration

One integration for sandbox and production

Requests are HTTPS calls with JSON bodies, signed and encrypted. The sandbox returns the same formats as production, so the code you test with is the code you ship.

  1. 1

    Create an application

    Sign up, create a sandbox application and select the services and data scopes you need.

  2. 2

    Make your first call

    Start from an official SDK or from the samples on the right. Eight languages are covered.

  3. 3

    Go live

    After due diligence, replace the sandbox keys with production keys and add your mTLS certificate. The request code stays the same.

mTLSHMAC-SHA256AES-256-GCMAudit log
exchange-code.sh
curl https://api.rdcpass.cd/v1/oidc/token \
  -X POST \
  --cert your-app-client-cert.pem \
  --key your-app-client-key.pem \
  -H "Content-Type: application/x-www-form-urlencoded" \
  -d "grant_type=authorization_code" \
  -d "code=auth_9f2ac3d0e1b74a2f9c7d5b3a1e6f8c0d" \
  -d "redirect_uri=https://yourapp.example.com/callback" \
  -d "client_id=app_8f2a1c0e9b" \
  -d "code_verifier=dBjftJeZ4CVP-mB92K27uhbUJU1p1r_wW1gFWFOEjXk"
200 OK
{
  "access_token": "rdcp_at_9f2ac3d0e1b74a2f8c0d5b3a1e6f8c0d",
  "id_token": "eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJodHRwczovL2FwaS5yZGNwYXNzLmNkIiwic3ViIjoiY2l0XzdmMWUyYTljNGIzZDhmNjAiLCJhdWQiOiJhcHBfOGYyYTFjMGU5YiIsImV4cCI6MTczNTY5MzIwMCwiaWF0IjoxNzM1Njg5NjAwfQ.signature",
  "token_type": "Bearer",
  "expires_in": 3600,
  "scope": "openid profile rdcpass:kyc.addresses rdcpass:kyc.phone_numbers rdcpass:kyc.emails rdcpass:kyc.documents.primary"
}

Trust & privacy

  • Citizens authenticate only on the RDCPASS page. Your application never sees their document number or biometrics.
  • No data is released until the citizen has seen and approved every scope in the request.
  • A declined request, a failed face match and a timeout all look the same to you, so you learn nothing about what the citizen did.
  • You can request only the scopes your organization subscribes to and your application has selected. Sensitive or biometric scopes require enhanced due diligence.

Pricing

Billed per monthly active user.

Each additional scope the citizen consents to adds a small surcharge. Requests rejected with an error are never billed, and the sandbox is always free.

Frequently asked questions

What if a citizen does not have the RDCPASS app?+

The RDCPASS page guides them through installing the app and enrolling their face before they continue. There is no password option.

Why does a failed sign-in never say what happened?+

A declined request, a failed face match and a timeout all return the same “access denied” outcome, so your application learns nothing the citizen did not choose to share. Offer them the option to try again.

Do I receive the citizen’s national ID number?+

Not through the sign-in identifier, which is private to your application. Their RDCPASS ID comes with basic KYC. You get a verified document number only if you request the documents scope and the citizen approves it.

How long does the citizen have to approve?+

The notification, consent and face match must all be completed within 60 seconds. After that the request ends, and the citizen can start again.

Start using Login with RDCPASS

Building and testing in the sandbox is free. You go live once your business and application have passed due diligence.