{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "sumsub",
    "name": "Sumsub",
    "vendor": "Sum and Substance Ltd",
    "vendorUrl": "https://sumsub.com",
    "kind": "http-api",
    "category": "identity-verification",
    "summary": "Sumsub verifies people from identity documents and a liveness check, verifies businesses against registries, and screens both against sanctions and watchlists. Agents reach it through a signed REST API and a hosted MCP server.",
    "url": "https://www.anchorterminal.com/tools/sumsub",
    "markdownUrl": "https://www.anchorterminal.com/tools/sumsub.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/sumsub.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/sumsub.json",
    "repo": "https://github.com/sumsub/agent-skills",
    "license": "Proprietary service under Sumsub's terms and conditions. The agent skills repository and the @sumsub/websdk npm package are MIT",
    "transports": [
      "http"
    ],
    "remoteUrl": "https://api.sumsub.com",
    "packages": [
      {
        "registry": "npm",
        "name": "@sumsub/websdk"
      }
    ],
    "auth": "mixed",
    "authNotes": "The REST API takes an app token generated in the Dashboard by a signed-in team member. Each request carries `X-App-Token`, `X-App-Access-Ts` and `X-App-Access-Sig`, an HMAC-SHA256 signature made with the token's secret key over the timestamp, method, path and body. A token has its own permissions, an optional IP allowlist, an optional expiry date and optional source keys that limit it to a group of applicants, and it can be disabled or deleted but not edited. Sandbox and production tokens are separate. The MCP server at https://api.sumsub.com/mcp/ uses OAuth with PKCE and dynamic client registration, signs the user in with Sumsub, and needs the Use MCP server role permission. Production mode opens after Sumsub verifies the integration (https://docs.sumsub.com/reference/about-sumsub-api).",
    "pricing": "usage",
    "pricingNotes": "Basic is $1.35 per verification with a $149 monthly minimum, and Compliance is $1.85 with a $299 minimum and adds AML screening and address checks. Business verification, transaction monitoring and fraud prevention are on a custom plan through sales. Only completed checks are charged. Sandbox mode is free in any account, limited to 500 new applicants and 1,000 transactions per 24 hours. The 14-day trial of 50 real checks asks for bank card details (https://sumsub.com/pricing/, https://docs.sumsub.com/docs/self-service, checked 2026-10-08).",
    "priceSummary": "$1.35 / tx",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the API reference, the OpenAPI spec or the pricing page (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": null,
      "npmWeekly": 172226,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://docs.sumsub.com",
    "llmsTxt": "https://docs.sumsub.com/llms.txt",
    "openapi": "https://api.sumsub.com/openapi.json",
    "capabilities": [
      "kyc.identity",
      "kyc.business",
      "kyc.documents",
      "kyc.screening",
      "kyc.cases"
    ],
    "tags": [
      "hosted",
      "usage-based",
      "sandbox",
      "api-key",
      "oauth",
      "mcp",
      "openapi",
      "llms-txt",
      "webhooks",
      "status-page",
      "sla",
      "bug-bounty",
      "soc2",
      "iso27001"
    ],
    "lastRelease": "2026-10-03",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 68.5,
      "grade": "B",
      "agentReady": false,
      "rank": 167,
      "ranked": true,
      "rankOf": 629,
      "categoryRank": 2,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 60,
        "maintenance": 74,
        "payments": 25,
        "reliability": 80,
        "schema": 78,
        "security": 80,
        "transparency": 74
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 80,
          "points": 16,
          "reason": "Graded on the REST API, hosted lines. Statuspage at status.sumsub.com with API, WebSDK and MobileSDK components for three regions (20). In the 90 days to 8 October 2026 it shows a complete outage of 13 minutes on 31 August, 13 minutes of SDK 403 errors on 14 July, 75 minutes of AML screening errors on 20 July, Dashboard search errors on 14 September and an open minor incident for some networks in Vietnam, none an hour of core API downtime (20). Limits published as 300 GET and 50 POST per 5 seconds (15). 429 is documented, but no Retry-After, backoff guidance or idempotency key was found (5). 99.5 per cent monthly availability in Annex 1 of the public terms (10). The API is generally available (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 78,
          "points": 12.68,
          "reason": "Public OpenAPI 3.0.1 spec at api.sumsub.com/openapi.json with 157 operations (25). llms.txt on docs and API hosts, and every docs page as Markdown (10). Reference pages give an overview, required permission and field tables per method, but only 24 of 157 operations in the spec carry a summary or description, and when not to use a method is rarely stated (12). 1,119 schemas with 132 enums and 319 required lists, though 189 of 5,343 properties are described (10). Request and response examples on reference pages and a table of 139 error codes, while 154 operations declare only a default response (11). A weekly dated changelog, but the spec stays at version 1.0.0 with no version in the path (10)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 60,
          "points": 9.75,
          "reason": "`fields` on 8 operations and limit and offset on 16 let responses be sized. The MCP tool list couldn't be read without an account (13). Offset paging, a cursor on audit events, case filters and transaction queries, but not on every list (16). Errors return code, description and correlationId, with errorCode and errorName for 139 documented cases (18). No idempotency keys. A caller's own externalUserId can be used to look an applicant up before retrying a create. MCP annotations weren't readable (6). No server SDK, and every request needs an HMAC signature over timestamp, method, path and body. Signing examples exist in seven languages (7)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 80,
          "points": 14,
          "reason": "App tokens with per-token permissions, IP allowlist, optional expiry, disable and delete, and HMAC signing so the secret never travels. MCP uses OAuth with PKCE and dynamic client registration (30). View and manage permissions are separate, source keys limit a token to a group of applicants, and a role permission gates MCP. No confirmation step for destructive calls was found (15). The API returns applicant-supplied text and document data. No injection guidance was found. Sumsub's skills refuse non-sandbox tokens (4). Audit trail events API with IP and user agent, 30-day usage per token, and an email on token creation (13). security.txt valid to 31 December 2027, a Bugcrowd engagement, SOC 2 Type 2, ISO/IEC 27001 and PCI DSS listed. No public advisories page found (18). Judgement call, no deduction for the webhook digest test endpoint, which takes a webhook secret in the query string, because the API credential itself can't."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 25,
          "points": 3.13,
          "reason": "No x402, MPP or L402 (0). Per-verification prices are public for two plans ($1.35 and $1.85, with $149 and $299 monthly minimums). Business verification, transaction monitoring and fraud prevention are quoted by sales (15). Sandbox mode is free without a card and returns test results only. The trial of 50 real checks asks for bank card details (10). Signup, token creation and MCP sign-in all need a person in a browser (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 74,
          "points": 6.48,
          "reason": "The changelog's latest entry covers 28 September to 2 October 2026, and agent skills 1.5.0 shipped on 3 October (30). Weekly changelog entries through July, August and September (20). Closed service with a dated changelog, a support site and a feedback tool in the MCP server. Response times weren't measurable (10). The WebSDK on npm is at 2.9.0 and mobile SDKs have their own changelogs, but there is no server SDK and no entry in the official MCP registry (8). The skills repository has had five releases since 3 July, and the signing examples took dependency updates until 11 June 2026. No CI workflows in either (6)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 74,
          "points": 6.48,
          "note": "editorial 52, provenance 96",
          "reason": "Closed service with public terms dated 21 May 2026 naming the contracting entities. Skills and WebSDK are MIT (16). The data processing agreement is Annex 3 of the terms and the privacy notice is dated 19 March 2026. Customers set retention, and data is deleted after a year of inactivity following cancellation. Clause 6.9 lets Sumsub use personal data to develop fraud detection with machine learning, which is disclosed but broad (20). The API reference says breaking changes are versioned and existing endpoints aren't affected. Mobile SDK versions are supported for one year. The older audit endpoint is marked for deprecation without a date (8). Hosting regions EU, UAE and SGP appear on the status page. The subprocessor list is in the Dashboard, not public (8)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "`fields` on 8 operations and limit and offset on 16 let responses be sized. The MCP tool list couldn't be read without an account (13). Offset paging, a cursor on audit events, case filters and transaction queries, but not on every list (16). Errors return code, description and correlationId, with errorCode and errorName for 139 documented cases (18). No idempotency keys. A caller's own externalUserId can be used to look an applicant up before retrying a create. MCP annotations weren't readable (6). No server SDK, and every request needs an HMAC signature over timestamp, method, path and body. Signing examples exist in seven languages (7).",
          "maintenance": "The changelog's latest entry covers 28 September to 2 October 2026, and agent skills 1.5.0 shipped on 3 October (30). Weekly changelog entries through July, August and September (20). Closed service with a dated changelog, a support site and a feedback tool in the MCP server. Response times weren't measurable (10). The WebSDK on npm is at 2.9.0 and mobile SDKs have their own changelogs, but there is no server SDK and no entry in the official MCP registry (8). The skills repository has had five releases since 3 July, and the signing examples took dependency updates until 11 June 2026. No CI workflows in either (6).",
          "payments": "No x402, MPP or L402 (0). Per-verification prices are public for two plans ($1.35 and $1.85, with $149 and $299 monthly minimums). Business verification, transaction monitoring and fraud prevention are quoted by sales (15). Sandbox mode is free without a card and returns test results only. The trial of 50 real checks asks for bank card details (10). Signup, token creation and MCP sign-in all need a person in a browser (0).",
          "reliability": "Graded on the REST API, hosted lines. Statuspage at status.sumsub.com with API, WebSDK and MobileSDK components for three regions (20). In the 90 days to 8 October 2026 it shows a complete outage of 13 minutes on 31 August, 13 minutes of SDK 403 errors on 14 July, 75 minutes of AML screening errors on 20 July, Dashboard search errors on 14 September and an open minor incident for some networks in Vietnam, none an hour of core API downtime (20). Limits published as 300 GET and 50 POST per 5 seconds (15). 429 is documented, but no Retry-After, backoff guidance or idempotency key was found (5). 99.5 per cent monthly availability in Annex 1 of the public terms (10). The API is generally available (10).",
          "schema": "Public OpenAPI 3.0.1 spec at api.sumsub.com/openapi.json with 157 operations (25). llms.txt on docs and API hosts, and every docs page as Markdown (10). Reference pages give an overview, required permission and field tables per method, but only 24 of 157 operations in the spec carry a summary or description, and when not to use a method is rarely stated (12). 1,119 schemas with 132 enums and 319 required lists, though 189 of 5,343 properties are described (10). Request and response examples on reference pages and a table of 139 error codes, while 154 operations declare only a default response (11). A weekly dated changelog, but the spec stays at version 1.0.0 with no version in the path (10).",
          "security": "App tokens with per-token permissions, IP allowlist, optional expiry, disable and delete, and HMAC signing so the secret never travels. MCP uses OAuth with PKCE and dynamic client registration (30). View and manage permissions are separate, source keys limit a token to a group of applicants, and a role permission gates MCP. No confirmation step for destructive calls was found (15). The API returns applicant-supplied text and document data. No injection guidance was found. Sumsub's skills refuse non-sandbox tokens (4). Audit trail events API with IP and user agent, 30-day usage per token, and an email on token creation (13). security.txt valid to 31 December 2027, a Bugcrowd engagement, SOC 2 Type 2, ISO/IEC 27001 and PCI DSS listed. No public advisories page found (18). Judgement call, no deduction for the webhook digest test endpoint, which takes a webhook secret in the query string, because the API credential itself can't.",
          "transparency": "Closed service with public terms dated 21 May 2026 naming the contracting entities. Skills and WebSDK are MIT (16). The data processing agreement is Annex 3 of the terms and the privacy notice is dated 19 March 2026. Customers set retention, and data is deleted after a year of inactivity following cancellation. Clause 6.9 lets Sumsub use personal data to develop fraud detection with machine learning, which is disclosed but broad (20). The API reference says breaking changes are versioned and existing endpoints aren't affected. Mobile SDK versions are supported for one year. The older audit endpoint is marked for deprecation without a date (8). Hosting regions EU, UAE and SGP appear on the status page. The subprocessor list is in the Dashboard, not public (8)."
        },
        "sources": [
          {
            "what": "docs index for agents",
            "url": "https://docs.sumsub.com/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "OpenAPI spec",
            "url": "https://api.sumsub.com/openapi.json",
            "seen": "2026-10-08"
          },
          {
            "what": "authentication and request signing",
            "url": "https://docs.sumsub.com/reference/authentication.md",
            "seen": "2026-10-08"
          },
          {
            "what": "app tokens, permissions and IP allowlist",
            "url": "https://docs.sumsub.com/docs/app-tokens.md",
            "seen": "2026-10-08"
          },
          {
            "what": "rate limits",
            "url": "https://docs.sumsub.com/reference/rate-limits.md",
            "seen": "2026-10-08"
          },
          {
            "what": "error codes",
            "url": "https://docs.sumsub.com/reference/error-codes-description.md",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP server",
            "url": "https://docs.sumsub.com/docs/mcp-server.md",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP OAuth metadata",
            "url": "https://api.sumsub.com/.well-known/oauth-authorization-server",
            "seen": "2026-10-08"
          },
          {
            "what": "agent tools, skills and Markdown docs",
            "url": "https://docs.sumsub.com/docs/build-on-sumsub-with-ai.md",
            "seen": "2026-10-08"
          },
          {
            "what": "agent skills repository",
            "url": "https://github.com/sumsub/agent-skills",
            "seen": "2026-10-08"
          },
          {
            "what": "request-signing examples",
            "url": "https://github.com/SumSubstance/AppTokenUsageExamples",
            "seen": "2026-10-08"
          },
          {
            "what": "Sandbox mode and limits",
            "url": "https://docs.sumsub.com/docs/test-in-sandbox.md",
            "seen": "2026-10-08"
          },
          {
            "what": "self-service plans and trial",
            "url": "https://docs.sumsub.com/docs/self-service.md",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing",
            "url": "https://sumsub.com/pricing/",
            "seen": "2026-10-08"
          },
          {
            "what": "status incidents",
            "url": "https://status.sumsub.com/api/v2/incidents.json",
            "seen": "2026-10-08"
          },
          {
            "what": "terms, SLA (Annex 1) and DPA (Annex 3)",
            "url": "https://sumsub.com/terms-and-conditions/",
            "seen": "2026-10-08"
          },
          {
            "what": "service privacy notice",
            "url": "https://sumsub.com/privacy-notice-service/",
            "seen": "2026-10-08"
          },
          {
            "what": "trust centre and certifications",
            "url": "https://sumsub.com/sumsub-trust-center/",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt",
            "url": "https://sumsub.com/.well-known/security.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "changelog, September 2026",
            "url": "https://docs.sumsub.com/changelog/september-2026.md",
            "seen": "2026-10-08"
          },
          {
            "what": "webhook retries and signatures",
            "url": "https://docs.sumsub.com/docs/webhook-manager.md",
            "seen": "2026-10-08"
          },
          {
            "what": "audit trail events API",
            "url": "https://docs.sumsub.com/reference/get-audit-trail-events.md",
            "seen": "2026-10-08"
          },
          {
            "what": "official MCP registry search (no result)",
            "url": "https://registry.modelcontextprotocol.io/v0.1/servers?search=sumsub",
            "seen": "2026-10-08"
          },
          {
            "what": "WebSDK on npm",
            "url": "https://registry.npmjs.org/@sumsub/websdk/latest",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: the MCP server's tool list, count, input schemas and annotations (tools/list needs a signed-in Sumsub account)",
          "unchecked: whether signing up for a Sandbox-only account asks for a card. The docs ask for card details only when activating the trial",
          "unchecked: GitHub stars and open issues for sumsub/agent-skills (GitHub web pages weren't fetched)",
          "Whether 429 responses carry a Retry-After header. None is documented",
          "The subprocessor list and data hosting locations are in the Dashboard and weren't read",
          "Whether the SLA in Annex 1 carries service credits, which weren't found in the text reviewed"
        ]
      },
      "negative": 0,
      "verdict": "Per-token permissions, an IP allowlist, HMAC-signed requests and a public OpenAPI spec with Markdown docs suit an agent working on verification cases. No idempotency keys or Retry-After guidance were found, there is no server SDK, and production access needs a browser signup, a bank card and Sumsub's review of the integration.",
      "bestFor": "An agent that starts verifications, sends links, reads results and AML cases, and works case queues for a regulated business, with one token limited to those permissions.",
      "strengths": [
        "App tokens carry per-token permissions, an optional IP allowlist and expiry date, and can be disabled with a recorded reason",
        "Requests are signed with HMAC-SHA256 over timestamp, method, path and body, so the secret key never travels",
        "Public OpenAPI 3.0.1 spec with 157 operations, llms.txt, and every docs page served as Markdown",
        "Hosted MCP server with OAuth, PKCE and dynamic client registration, gated by a Use MCP server role permission",
        "Terms publish a 99.5 per cent monthly uptime commitment, and the status page lists API, WebSDK and MobileSDK for three regions"
      ],
      "weaknesses": [
        "No idempotency keys and no Retry-After or backoff guidance found in the reviewed documentation",
        "Only 24 of 157 operations in the OpenAPI spec carry a summary or description, and 154 declare only a default response",
        "No official server-side SDK. Sumsub publishes request-signing examples in seven languages instead",
        "The 14-day trial of 50 real checks needs a bank card, and production opens after Sumsub checks the integration",
        "Terms clause 6.9 permits Sumsub to use customers' personal data to develop fraud detection, including machine learning models",
        "The subprocessor list is published in the Dashboard, not on a public page"
      ],
      "agentNotes": [
        "Sign every request. X-App-Access-Sig is the lowercase hex HMAC-SHA256 of timestamp, uppercase method, path with query and raw body, and the timestamp must be within one minute of server time",
        "Use a sandbox token (prefix sbx) for agent work. Sandbox and production tokens are separate, and Sumsub's own skills refuse any other prefix",
        "Stay under 300 GET and 50 POST requests per 5 seconds, and under 500 new applicants per 24 hours in Sandbox",
        "Token permissions can't be edited after creation. Generate a new token with the narrower set and delete the old one",
        "Subscribe to the applicantReviewed webhook for results and verify x-payload-digest against the raw body before trusting it"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "B",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 68.5
        }
      ],
      "editorialScores": {
        "ergonomics": 60,
        "maintenance": 74,
        "payments": 25,
        "reliability": 80,
        "schema": 78,
        "security": 80,
        "transparency": 52
      },
      "provenanceScore": 96
    },
    "connect": {
      "install": "npx skills add sumsub/agent-skills --all -g",
      "http": "curl -X GET \\\n  'https://api.sumsub.com/resources/auditTrailEvents/list?from=2024-06-01+00:00:00\u0026to=2024-06-30+23:59:59\u0026limit=100' \\\n  -H 'X-App-Token: \u003cyour-app-token\u003e' \\\n  -H 'X-App-Access-Sig: \u003cyour-signature\u003e' \\\n  -H 'X-App-Access-Ts: \u003cunix-timestamp\u003e'",
      "claudeCode": "claude mcp add --transport http sumsub https://api.sumsub.com/mcp/",
      "config": {
        "mcpServers": {
          "sumsub": {
            "args": [
              "mcp-remote",
              "https://api.sumsub.com/mcp/"
            ],
            "command": "npx"
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/kyc.identity",
      "tool": "https://letme.dev/sumsub"
    },
    "notable": [
      "The hosted MCP server at https://api.sumsub.com/mcp/ acts with the signed-in user's role permissions and needs the Use MCP server permission. Named tools include applicant_create_individual, verification_link_create, applicant_get, transaction_list and verification_level_list (https://docs.sumsub.com/docs/mcp-server)",
      "A public OpenAPI 3.0.1 spec lists 157 operations on 134 paths, and every docs page is served as Markdown by adding .md to its URL (https://docs.sumsub.com/docs/build-on-sumsub-with-ai)",
      "Default rate limits are 300 GET requests and 50 POST requests per 5 seconds, raised on request to support (https://docs.sumsub.com/reference/rate-limits)",
      "Annex 1 of the terms commits to 99.5 per cent availability in each calendar month, measured by a third-party check every minute (https://sumsub.com/terms-and-conditions/)",
      "The status page records a complete service outage from 08:15 to 08:28 UTC on 31 August 2026, caused by a bug on the path handling all API requests (https://status.sumsub.com/history)",
      "Sumsub's agent skills repository holds 28 skills at version 1.5.0 (3 October 2026) and tells agents to use sandbox tokens only (https://github.com/sumsub/agent-skills)",
      "security.txt names security@sumsub.com and a Bugcrowd engagement and expires on 31 December 2027 (https://sumsub.com/.well-known/security.txt)"
    ],
    "area": "domain-data",
    "details": [
      {
        "label": "API",
        "value": "REST at https://api.sumsub.com for both Production and Sandbox. OpenAPI 3.0.1 at https://api.sumsub.com/openapi.json with 157 operations on 134 paths (74 POST, 53 GET, 15 PATCH, 12 DELETE, 3 PUT)"
      },
      {
        "label": "MCP server",
        "value": "Hosted at https://api.sumsub.com/mcp/, OAuth authorisation code grant with PKCE (S256), dynamic client registration and refresh tokens, issuer cockpit.sumsub.com. Connectors listed for Claude and ChatGPT. The tool list needs a signed-in account and wasn't read"
      },
      {
        "label": "Credentials",
        "value": "App token plus secret key, shown once. Per-token permissions, IP allowlist, optional expiry, source keys, enable and disable with a reason. An email goes to token managers when a token is created"
      },
      {
        "label": "Request signing",
        "value": "HMAC-SHA256 over timestamp, method, path with query and body, sent as X-App-Access-Sig with X-App-Access-Ts. The timestamp must be within 1 minute of server time"
      },
      {
        "label": "Rate limits",
        "value": "300 GET and 50 POST requests per 5 seconds by default. Sandbox allows 500 new applicants and 1,000 transactions per 24 hours"
      },
      {
        "label": "Errors",
        "value": "JSON with code, description and correlationId, plus errorCode and errorName on some. The reference lists 139 error codes with their HTTP status. 429 on rate limits, with no Retry-After documented"
      },
      {
        "label": "Sandbox",
        "value": "A mode of the same account and host, with its own tokens. Presets force approve or reject per check, and document templates return fixed results. Level settings made in Sandbox mirror to production"
      },
      {
        "label": "Webhooks",
        "value": "HTTP, Slack, Telegram or email. Six delivery attempts over up to 24 hours, HMAC digest in x-payload-digest (SHA256 default, SHA512 optional), delivery logs with manual resend"
      },
      {
        "label": "Audit",
        "value": "Audit trail events API with cursor paging, filters by user and activity, IP and user agent on each event. The App Tokens page shows requests per token for the last 30 days"
      },
      {
        "label": "SLA",
        "value": "99.5 per cent availability per calendar month in Annex 1 of the public terms, excluding up to 5 hours of scheduled maintenance a month"
      },
      {
        "label": "Status",
        "value": "status.sumsub.com on Statuspage, with API, MobileSDK and WebSDK components for EU, UAE and SGP regions, and Support Systems"
      },
      {
        "label": "Certifications",
        "value": "SOC 2 Type 2, ISO/IEC 27001, 27017 and 27018, ISO 22301, PCI DSS and iBeta Level 1 and 2 per the trust centre page. Reports are sent on request"
      },
      {
        "label": "Data handling",
        "value": "Sumsub is processor and the customer sets retention. Data is deleted after one year of account inactivity following cancellation. Terms clause 6.9 permits use of personal data to develop fraud detection, including machine learning"
      }
    ],
    "unitPrices": [
      {
        "item": "Basic plan, user verification",
        "unit": "tx",
        "usd": 1.35,
        "note": "per completed verification; $149 monthly minimum"
      },
      {
        "item": "Compliance plan, user verification with AML screening and address check",
        "unit": "tx",
        "usd": 1.85,
        "note": "per completed verification; $299 monthly minimum"
      }
    ],
    "provenance": {
      "legalEntity": "Sum and Substance Ltd",
      "domain": "sumsub.com",
      "domainRegistered": "2015-05-01",
      "endpointOnVendorDomain": true,
      "terms": "https://sumsub.com/terms-and-conditions/",
      "privacy": "https://sumsub.com/privacy-notice-service/",
      "statusPage": "https://status.sumsub.com",
      "changelog": "https://docs.sumsub.com/changelog",
      "securityTxt": "valid",
      "checked": "2026-10-08",
      "notes": [
        "The terms (version of 21 May 2026) name Sum and Substance Ltd, England, company number 09688671, 30 St. Mary Axe, London EC3A 8BF, with contracting entities in the UAE, Delaware, Singapore and Cyprus depending on where the customer is registered.",
        "The API and the MCP server answer at api.sumsub.com, and the Dashboard and OAuth issuer at cockpit.sumsub.com.",
        "sumsub.com/.well-known/security.txt gives security@sumsub.com and a Bugcrowd engagement as contacts and expires on 2027-12-31.",
        "The service privacy notice was last updated on 19 March 2026. The data processing agreement is Annex 3 of the terms.",
        "RDAP for sumsub.com gives a registration date of 2015-05-01."
      ],
      "score": 96,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Sum and Substance Ltd",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "sumsub.com, registered 2015-05-01 (11 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "api.sumsub.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 7 of the 7 things a reader expects, and has 2 clauses that cost points",
          "points": 6,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 8 of the 8 things a reader expects",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Status page",
          "value": "status.sumsub.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "valid",
          "points": 10,
          "max": 10,
          "state": "ok"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://sumsub.com/terms-and-conditions/",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-05-21",
          "words": 23828,
          "points": 6,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Version of 21 May 2026",
              "says": "Last updated 2026-05-21"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "This Agreement and all disputes and claims arising out of or in connection with it are governed by the laws of the State of New York.",
              "says": "The law of the State of New York"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "…PERFORMANCE OF THESE TERMS AND CONDITIONS OR ANY COLLATERAL CONTRACT SHALL IN ALL CIRCUMSTANCES BE LIMITED TO: (i) 100% OF THE TOTAL FEES PAID BY THE CUSTOMER TO THE SERVICE PROVIDER DURING THE 3-MONTH PERIOD IMMEDIATELY PRECEDING THE DATE ON WHICH THE CAUSE OF ACTION FIRST AROSE;",
              "says": "Capped at the fees paid in the 3 months before the claim"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "The Service Provider shall be entitled, at its sole discretion, to suspend or limit the Customer’s access to the System and/or the Services and/or terminate the Terms and Conditions as between itself and the Customer where (i) the Customer fails to timely provide the requested information (in full or in part);"
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "1.4 A reference to writing or written includes faxes, email and electronic messaging services, which the parties typically use to exchange information in order to execute the Terms and Conditions.",
              "says": "Says it gives notice of a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "The Customer shall not upload any personal data (except that of the individual uploading it, unless that individual is also an Applicant) into the System before the Billing Start Date."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": true,
              "quote": "1.4 “Uptime Commitment” means the Service Availability shall be at least ninety-nine and five tenths percent (99.5%) in each calendar month.",
              "says": "Names 99.5% availability"
            }
          ],
          "toKnow": [
            {
              "key": "training",
              "label": "Says it may use customer content to train or improve models, and no opt-out was found",
              "found": true,
              "quote": "6.9 The Customer grants the Service Provider permission to use personal data transferred to the Service Provider under these Terms and Conditions for: (i) developing and testing the Services and/or the System to improve their capabilities for detection and prevention of fraud, including by means of artificial intellig…",
              "costsPoints": true
            },
            {
              "key": "terms.nonotice",
              "label": "Says the terms or the service can change without notice",
              "found": true,
              "quote": "3.4 The Customer acknowledges that for any reason, at any time, and without prior notice, the Service Provider may issue New Releases, and agrees to implement such New Releases promptly.",
              "costsPoints": true
            },
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "In this scenario the Service Provider may immediately and without notice suspend the Customer’s access to the Services and the System until the outstanding amount has been paid in full (without prejudice to the Service Provider’s right to suspend or limit the Customer’s access to the System and/or the Services as may…"
            },
            {
              "key": "terms.arbitration",
              "label": "Requires arbitration or waives class actions",
              "found": true,
              "quote": "The parties agree, pursuant to Article 30(2)(b) of the Rules of Arbitration of the International Chamber of Commerce, that the Expedited Procedure Rules shall apply irrespective of the amount in dispute."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Liability is capped at the lesser of the fees paid in the three months before the claim arose and 5,000 US dollars.",
              "quote": "SHALL IN ALL CIRCUMSTANCES BE LIMITED TO: (i) 100% OF THE TOTAL FEES PAID BY THE CUSTOMER TO THE SERVICE PROVIDER DURING THE 3-MONTH PERIOD IMMEDIATELY PRECEDING THE DATE ON WHICH THE CAUSE OF ACTION FIRST AROSE; OR (ii) 5,000 (FIVE THOUSAND) USD, WHICHEVER IS LESS."
            },
            {
              "date": "2026-10-08",
              "text": "Access may be limited, suspended or ended with immediate effect where usage exceeds 1,000 Checks or 1,000 Applicants in a calendar day.",
              "quote": "(vii) the Customer’s usage of the Services exceeds 1000 Checks or 1000 Applicants within any given calendar day."
            },
            {
              "date": "2026-10-08",
              "text": "After the customer relationship ends, Sumsub may keep personal data and related inferences for its own purposes where it has a lawful basis.",
              "quote": "Even after the Customer’s relationship with Sumsub is terminated, Sumsub may retain the Personal Data and related inferences where it has a lawful basis for doing so"
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://sumsub.com/privacy-notice-service/",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-03-19",
          "words": 13536,
          "points": 10,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated: 19 March 2026",
              "says": "Last updated 2026-03-19"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "We collect personal data as necessary to fulfill the purposes mentioned in this Privacy Notice"
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "Any request to delete all or any Personal data related to a User is fulfilled within 30 days.",
              "says": "Names a period of 30 days"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "third-party service providers or public authorities used to collect additional information necessary for the provision of the Services;"
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "Sumsub does not sell personal information and does not share personal information for cross-context behavioural advertising in connection with the Services provided to the Clients.",
              "says": "Says it does not sell personal data"
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "Sumsub ID allows Applicants to use their Personal data for identity verification with multiple Clients, including to be able to execute your right to data portability and obtain necessary Personal data based on your instructions using Sumsub ID."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "Our Data Protection Officer can be contacted via the following e-mail address: [email protected].",
              "says": "Names a data protection officer"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "Whenever a transfer of Personal data outside the EEA or the UK is carried out, Sumsub implements appropriate safeguards as set out in Chapter V of the EU GDPR or UK GDPR by transferring based on an EU Adequacy Decision (or UK Adequacy Regulations) or by concluding Standard Contractual Clauses.",
              "says": "Relies on standard contractual clauses"
            }
          ],
          "toKnow": [
            {
              "key": "training.optout",
              "label": "Says it may use customer content to train or improve models, and gives an opt-out",
              "found": true,
              "quote": "You have the right to object to the processing of your Personal data for this purpose at any time."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Sumsub may amend the notice at any time and for any reason, with amendments effective on posting to its website.",
              "quote": "Any amendments will be effective immediately upon us posting the updated Privacy Notice on our Website."
            },
            {
              "date": "2026-10-08",
              "text": "Sumsub may analyse fraud patterns and indicators across different clients, sessions, services, datasets and third-party sources.",
              "quote": "To strengthen fraud prevention, Sumsub may also analyse fraud patterns and indicators across different sessions, services, Clients, datasets and third-party sources, where permitted by applicable law and our contractual arrangements."
            },
            {
              "date": "2026-10-08",
              "text": "The notice states it will be rare that Sumsub has no overriding grounds to keep using personal data after an objection.",
              "quote": "it will be rare that we have no compelling, overriding grounds to continue using the Personal data following an objection."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/sumsub.json",
    "live": {
      "slug": "sumsub",
      "probe": {
        "target": "https://api.sumsub.com",
        "method": "get",
        "lastAt": "2026-10-08T17:36:46.485189738Z",
        "lastOk": true,
        "lastStatus": 200,
        "lastMs": 225,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 221,
        "p95ms24h": 274,
        "samples24h": 25,
        "samples30d": 25,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 25,
            "ok": 25
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.sumsub.com",
        "indicator": "none",
        "summary": "All Systems Operational",
        "checkedAt": "2026-10-08T17:25:51.177341215Z"
      },
      "versions": [
        {
          "registry": "npm",
          "name": "@sumsub/websdk",
          "version": "2.9.0",
          "seenAt": "2026-10-08T16:31:00.353997894Z"
        }
      ],
      "githubStars": 7,
      "npmWeekly": 172226,
      "securityTxt": {
        "url": "https://sumsub.com/.well-known/security.txt",
        "state": "valid",
        "expires": "2027-12-31T11:59:00Z",
        "checkedAt": "2026-10-08T15:38:36.412722848Z"
      },
      "updatedAt": "2026-10-08T17:36:46.485189738Z"
    }
  }
}
