{
  "data": {
    "category": {
      "area": "domain-data",
      "capabilities": [
        "kyc.identity",
        "kyc.business",
        "kyc.documents",
        "kyc.screening",
        "kyc.cases"
      ],
      "description": "Services that verify a person from an identity document and a selfie, or a business from registry records, and screen both against sanctions and watchlists. Compared on the checks covered, how a verification is started and read, webhooks and data retention.",
      "json": "https://www.anchorterminal.com/categories/identity-verification.json",
      "name": "Identity \u0026 business verification",
      "slug": "identity-verification",
      "test": "One test person and one test business run through each listing's sandbox. A verification is started, completed with the vendor's test documents and read back, with a watchlist screen. We check the result fields, status events, retention controls and redaction. In this run listings are graded from public evidence against the published checklist.",
      "title": "Identity and business verification APIs for AI agents",
      "toolCount": 11,
      "tools": [
        "didit",
        "persona",
        "sumsub",
        "complycube",
        "socure-riskos",
        "veriff",
        "middesk",
        "trulioo",
        "shufti",
        "jumio",
        "complyadvantage"
      ],
      "url": "https://www.anchorterminal.com/categories/identity-verification"
    },
    "faq": [
      {
        "answer": "Didit has the highest benchmark score of the 11 ranked identity and business verification APIs, 75 (BB). Persona is second with 69.5 (B).",
        "question": "What are the highest-rated identity and business verification APIs for AI agents?"
      },
      {
        "answer": "1 of the 11 ranked here grade BB or better, the bar for agent-ready on the Anchor benchmark.",
        "question": "How many identity and business verification APIs are agent-ready?"
      },
      {
        "answer": "None of the ranked listings here accepts x402 for its main call yet.",
        "question": "Which identity and business verification APIs accept x402 payments?"
      },
      {
        "answer": "By the Anchor benchmark score out of 100, a weighted mean of the scored categories minus deductions for negative events, from public evidence re-checked as vendors change. Listings cannot pay for a place. The latest assessment behind this page is from 9 October 2026.",
        "question": "How is this list ranked?"
      }
    ],
    "howToChoose": [
      {
        "label": "Identity, business and screening checks",
        "detail": "Check whether identity, business registry and watchlist screening are all covered, since a listing that covers only one leaves a gap the agent cannot close itself."
      },
      {
        "label": "Status events and callbacks",
        "detail": "Check whether status changes arrive by callback, since an agent that polls for a result wastes calls and may read a stale status."
      },
      {
        "label": "Retention, deletion and redaction",
        "detail": "Check how long documents and selfies are kept, whether they can be deleted, and if results are redacted, so stored personal data stays minimal."
      },
      {
        "label": "Result fields for each check",
        "detail": "Check which result fields come back for a person and a business, and whether a sandbox run returns the same fields as live, so tests reflect production decisions."
      }
    ],
    "picks": [
      {
        "also": {
          "name": "Persona",
          "slug": "persona",
          "why": "B, 69.5/100"
        },
        "name": "Didit",
        "need": "Highest score overall",
        "slug": "didit",
        "why": "BB, 75/100 on the benchmark"
      },
      {
        "name": "ComplyCube",
        "need": "Reliability",
        "slug": "complycube",
        "why": "84/100 on reliability, against 80 for the overall leader"
      },
      {
        "name": "Trulioo",
        "need": "Agent ergonomics",
        "slug": "trulioo",
        "why": "78/100 on agent ergonomics, against 69 for the overall leader"
      },
      {
        "name": "Sumsub",
        "need": "Security \u0026 auth",
        "slug": "sumsub",
        "why": "80/100 on security \u0026 auth, against 76 for the overall leader"
      },
      {
        "name": "Sumsub",
        "need": "Transparency \u0026 trust",
        "slug": "sumsub",
        "why": "74/100 on transparency \u0026 trust, against 63 for the overall leader"
      }
    ],
    "ranked": 11,
    "shortlist": [
      {
        "bestFor": "A team that wants document, liveness, screening and business registry checks from one API with public prices and no sales step, and an agent that has to set itself up.",
        "grade": "BB",
        "name": "Didit",
        "position": 1,
        "price": "$0.15 / tx",
        "score": 75,
        "slug": "didit",
        "strengths": [
          "An account and API key can be created by API at `apx.didit.me/auth/v2/programmatic/register/`, with an emailed code and no browser step",
          "Public OpenAPI 3.0.0 spec with 256 operations, plus llms.txt and a Markdown copy of every docs page",
          "Named API keys take read or write access per resource, workflow limits, an IP allowlist and an expiry date, and rotation keeps the old secret for 24 hours"
        ],
        "url": "https://www.anchorterminal.com/tools/didit",
        "verdict": "A self-serve verification API with public per-check prices, key registration by API, scoped keys and a 365-day audit log. The status page shows three incidents marked major between 22 July and 4 September 2026, each a partial outage of the core APIs, and the sub-processor list isn't public.",
        "weaknesses": [
          "Three incidents marked major on status.didit.me from 22 July to 4 September 2026, each a partial outage of the core APIs traced to the primary database",
          "No server-side SDK in any language. The published SDKs are capture clients for web, iOS, Android, React Native and Flutter",
          "The data processing addendum says the sub-processor list is published at `/terms/sub-processors`, but that address shows the legal index, which says the list is sent after a signed NDA"
        ],
        "where": "both",
        "x402": "no"
      },
      {
        "bestFor": "A company that already runs Persona and wants an agent to create inquiries from templates, read verification and report results, screen against watchlists and work review cases with a permission-limited key.",
        "grade": "B",
        "name": "Persona",
        "position": 2,
        "price": "$250 / mo",
        "score": 69.5,
        "slug": "persona",
        "strengths": [
          "Public OpenAPI 3.1 file with 231 operations and 141 webhook definitions, plus llms.txt and a Markdown copy of every docs page",
          "API keys take about 50 read and write permissions per resource, an IP allowlist, their own rate limit and an expiry endpoint",
          "`Idempotency-Key` on every POST, cursor pagination, and `fields` and `include` parameters that trim responses"
        ],
        "url": "https://www.anchorterminal.com/tools/persona",
        "verdict": "The REST API has a public OpenAPI 3.1 file, llms.txt, API keys with per-resource permissions, idempotency keys on every POST and a 60-day sandbox trial with no card. Production needs a business review and a 12-month plan from $250 a month. The status page lists 11 incidents since 10 July 2026, including 70 minutes of timeouts across all products.",
        "weaknesses": [
          "Production access needs Persona's approval and a 12-month plan from $250 a month, and API-only integration is limited to Enterprise plans",
          "Eleven incidents on the status page since 10 July 2026, five marked partial outage, most on document and government ID verifications",
          "The MCP server lists all 190 tools whatever the key allows, with no annotations, toolsets or read-only subset, and OAuth isn't available yet"
        ],
        "where": "hosted",
        "x402": "no"
      },
      {
        "bestFor": "An agent that starts verifications, sends links, reads results and AML cases, and works case queues for a regulated business, with one token limited to those permissions.",
        "grade": "B",
        "name": "Sumsub",
        "position": 3,
        "price": "$1.35 / tx",
        "score": 68.5,
        "slug": "sumsub",
        "strengths": [
          "App tokens carry per-token permissions, an optional IP allowlist and expiry date, and can be disabled with a recorded reason",
          "Requests are signed with HMAC-SHA256 over timestamp, method, path and body, so the secret key never travels",
          "Public OpenAPI 3.0.1 spec with 157 operations, llms.txt, and every docs page served as Markdown"
        ],
        "url": "https://www.anchorterminal.com/tools/sumsub",
        "verdict": "Per-token permissions, an IP allowlist, HMAC-signed requests and a public OpenAPI spec with Markdown docs suit an agent working on verification cases. No idempotency keys or Retry-After guidance were found, there is no server SDK, and production access needs a browser signup, a bank card and Sumsub's review of the integration.",
        "weaknesses": [
          "No idempotency keys and no Retry-After or backoff guidance found in the reviewed documentation",
          "Only 24 of 157 operations in the OpenAPI spec carry a summary or description, and 154 declare only a default response",
          "No official server-side SDK. Sumsub publishes request-signing examples in seven languages instead"
        ],
        "where": "hosted",
        "x402": "no"
      },
      {
        "bestFor": "An agent that creates clients, uploads documents, starts document, identity and AML screening checks and reads results for a regulated business, with low entry cost ($99 a month) and a scripted sandbox.",
        "grade": "B",
        "name": "ComplyCube",
        "position": 4,
        "price": "$99 / mo",
        "score": 63.7,
        "slug": "complycube",
        "strengths": [
          "Test and live environments have separate keys, and sandbox outcomes are set by test data such as a client last name of attention or failed",
          "Public OpenAPI 3.0.0 spec (version 1.7.3, 52 operations), `llms.txt`, and every docs page served as Markdown",
          "Audit log API records the team member, trigger, action and a field-level diff of old and new values"
        ],
        "url": "https://www.anchorterminal.com/tools/complycube",
        "verdict": "A sandbox with its own key and scripted outcomes, a public OpenAPI spec, Markdown docs and an audit log API suit an agent running verification checks. Each environment has one unscoped key, no idempotency keys were found, and the only published terms are undated and read as website terms.",
        "weaknesses": [
          "One API key per environment with no scopes. The docs say keys carry many privileges",
          "No idempotency keys, and no Retry-After header documented for 429 responses",
          "The only published terms are undated, read as website terms and cite the Data Protection Act 1998. No service agreement or DPA was found on a public page"
        ],
        "where": "hosted",
        "x402": "no"
      },
      {
        "bestFor": "A company in the United States that wants one decision from combined KYC, document, fraud and watchlist checks through a single evaluation call.",
        "grade": "B",
        "name": "Socure RiskOS",
        "position": 5,
        "price": "$0.80 / tx",
        "score": 63.5,
        "slug": "socure-riskos",
        "strengths": [
          "OpenAPI 3.0.3 file for ten operations and a 3.1 webhook file in a public GitHub repository, last synced 5 October 2026",
          "llms.txt indexes for every docs section and a Markdown copy of each page, with a robots.txt signal that allows AI input",
          "Socure Launch publishes four solutions at $0.80 to $1.30 per evaluation, with a free sandbox and $1,000 of monthly production credits"
        ],
        "url": "https://www.anchorterminal.com/tools/socure-riskos",
        "verdict": "A public OpenAPI file, llms.txt, 15 documented error codes and dated release notes cover a ten-operation REST API, and Socure Launch publishes prices from $0.80 an evaluation with a free sandbox. API keys carry no scopes, no idempotency header is defined, no service terms are published, and production stays at zero requests until Socure activates it.",
        "weaknesses": [
          "No service agreement or API terms are published. The only terms pages are website terms of use and end-user terms for document capture",
          "Each API key reaches every workflow, with no scopes or read-only keys, and an additional key has to be requested from Support",
          "The rate limit page advises idempotency keys, but neither the docs nor the OpenAPI file define an idempotency header"
        ],
        "where": "hosted",
        "x402": "no"
      },
      {
        "bestFor": "A team that needs document and selfie verification with public per-verification prices and a trial, and that can run a webhook receiver and HMAC signing.",
        "grade": "C",
        "name": "Veriff",
        "position": 6,
        "price": "$0.80 / tx",
        "score": 61.1,
        "slug": "veriff",
        "strengths": [
          "Public prices of $0.80, $1.39 and $1.89 a verification, with a 15-day trial of up to 50 sessions and no card",
          "llms.txt index and Markdown pages, each API endpoint with an OpenAPI 3.0.0 fragment, examples and error schemas",
          "Up to five shared secret keys per integration, shown once, with documented rotation and deletion"
        ],
        "url": "https://www.anchorterminal.com/tools/veriff",
        "verdict": "Per-verification prices are public from $0.80, with a 15-day trial of 50 sessions and no card. Each endpoint page is Markdown with an OpenAPI 3.0 fragment. There is no server SDK, MCP server or idempotency key, most calls need an HMAC signature, and the status page shows nine incidents between 20 July and 7 October 2026.",
        "weaknesses": [
          "No server-side SDK and no MCP server. Official packages cover only browser and mobile capture",
          "No idempotency key on POST /v1/sessions, and no Retry-After or backoff guidance for the documented 429",
          "Nine status-page incidents between 20 July and 7 October 2026, mostly delayed decisions in the US region"
        ],
        "where": "local",
        "x402": "no"
      },
      {
        "bestFor": "An agent onboarding or re-checking US businesses for a bank, lender or marketplace that already holds a Middesk contract, with registry, TIN, sanctions and lien data in one object.",
        "grade": "C",
        "name": "Middesk",
        "position": 7,
        "price": "Paid",
        "score": 59,
        "slug": "middesk",
        "strengths": [
          "Public OpenAPI 3.1 spec with 87 operations and 373 schemas, plus llms.txt and a Markdown copy of every docs page",
          "Dated changelog with nine entries between 20 July and 5 October 2026, breaking changes labelled as such",
          "OAuth 2.0 with `read_only` and `read_write` scopes and a revoke endpoint. The MCP server adds PKCE and dynamic client registration"
        ],
        "url": "https://www.anchorterminal.com/tools/middesk",
        "verdict": "A public OpenAPI 3.1 contract for 87 operations, llms.txt, Markdown docs and a dated weekly changelog make the REST API readable to an agent, and OAuth has a read-only scope. Access is sales-led. No price, self-serve signup or official SDK was found, and the hosted MCP server rejects sandbox keys.",
        "weaknesses": [
          "No public price. Fees are set in an order form, and every docs page ends with a prompt to contact sales",
          "No official SDK found on npm, PyPI or RubyGems, and none in the vendor's GitHub organisation",
          "The hosted MCP server runs against production only, so a sandbox key fails on every call"
        ],
        "where": "hosted",
        "x402": "no"
      },
      {
        "bestFor": "An agent doing business due diligence (search, verification, ownership, reports) or person checks across many countries for a company that already has a Trulioo contract, and for teams that want to test verification flows against synthetic data first.",
        "grade": "C",
        "name": "Trulioo",
        "position": 8,
        "price": "Paid",
        "score": 58.2,
        "slug": "trulioo",
        "strengths": [
          "Hosted MCP server at mcp.trulioo.com/mcp with OAuth 2.1, PKCE and dynamic client registration, so no key is copied into the client",
          "An anonymous mock endpoint and an unbilled sandbox mode return synthetic results without Trulioo credentials",
          "All 18 listed tools carry read-only, destructive and idempotent annotations, with 35 more loaded on demand"
        ],
        "url": "https://www.anchorterminal.com/tools/trulioo",
        "verdict": "The hosted MCP server has OAuth 2.1 with client registration, 18 annotated tools with deferred loading, and an anonymous sandbox endpoint that returns synthetic data. Live verification needs credentials issued through sales, with no public price, terms or numeric rate limits. The MCP server is in early access and the status page requires a login.",
        "weaknesses": [
          "No public prices, terms of service or SLA. Live credentials come from Trulioo's sales and support teams",
          "status.trulioo.com requires an account requested from support, so incident history isn't public",
          "No rate limits with numbers on either surface, and an account over its limit gets a 409"
        ],
        "where": "hosted",
        "x402": "no"
      },
      {
        "bestFor": "A team that wants document, face, address, AML and KYB checks behind one endpoint, a free plan for low volume, and an MCP server that hands the person a hosted verification link.",
        "grade": "C",
        "name": "Shufti",
        "position": 9,
        "price": "$1.50 / tx",
        "score": 57.8,
        "slug": "shufti",
        "strengths": [
          "Free Forever plan of 10 verifications a month with no card, on the production environment, per the pricing page",
          "Hosted MCP server at `https://ai.shuftipro.com/mcp` with 25 tools, OAuth 2.1 with PKCE and three scopes enforced on every call",
          "Docs published as llms.txt, a 2.9 MB llms-full.txt and a Markdown twin of each page, with samples in nine languages"
        ],
        "url": "https://www.anchorterminal.com/tools/shufti",
        "verdict": "One endpoint covers document, face, address, AML and KYB checks, with a free plan of 10 verifications a month, and a hosted MCP server adds OAuth with three scopes. No OpenAPI file, server SDK or idempotency key was found, and the status page history could not be read.",
        "weaknesses": [
          "No OpenAPI file or other machine-readable contract was found. The reference is prose tables plus Postman collections",
          "The REST credential is one Client ID and Secret Key pair with no scopes, sent as Basic auth on every call",
          "No idempotency key, Retry-After header or backoff guidance was found for the documented 429"
        ],
        "where": "hosted",
        "x402": "no"
      },
      {
        "bestFor": "An enterprise with a Jumio contract that wants document, selfie and liveness checks, watchlist screening and Latin American, Thai and Australian database checks behind OpenAPI-described endpoints.",
        "grade": "C",
        "name": "Jumio",
        "position": 10,
        "price": "Paid",
        "score": 55,
        "slug": "jumio",
        "strengths": [
          "Five downloadable OpenAPI 3.0 files covering 25 operations, plus llms.txt and a 2.2 MB llms-full.txt of the docs in Markdown",
          "OAuth2 client credentials with 60-minute bearer tokens. Each client is limited to initiate, to retrieve and delete, or both, and can be deactivated",
          "Rate limits are published per tenant. Token requests 10 a second, new transactions 1 a second, retrievals 15 a second"
        ],
        "url": "https://www.anchorterminal.com/tools/jumio",
        "verdict": "Five OpenAPI 3.0 files, an llms.txt index and OAuth2 clients limited to initiating or to retrieving and deleting make the API readable and containable. Access starts with an account manager, with no public price, trial or service agreement, and the status page shows four processing degradations and a 35-minute Singapore outage between 14 August and 2 October 2026.",
        "weaknesses": [
          "No public price, free tier or trial. OAuth2 and workflow keys are activated by a Jumio account manager",
          "No service agreement or DPA is published. The public terms of use cover end users in the United States",
          "Four processing degradations and a 35-minute Singapore outage on the status page between 14 August and 2 October 2026"
        ],
        "where": "local",
        "x402": "no"
      }
    ],
    "updated": "2026-10-09"
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/best/identity-verification/",
    "json": "https://www.anchorterminal.com/best/identity-verification/index.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/best/identity-verification/index.md",
    "slim": "https://www.anchorterminal.com/best/identity-verification/index.min.md"
  },
  "markdown": "The 10 highest-scoring of 11 identity and business verification APIs on the Anchor benchmark, with a pick for each need and where each one falls short. Scores come from public evidence, re-checked as vendors change.\n\n- Ranked: 11 · agent-ready (BB or better): 1 · accept x402: 0 · hosted endpoints: 9\n- Full ranked table: https://www.anchorterminal.com/categories/identity-verification.md\n- Head-to-head comparisons: https://www.anchorterminal.com/compare/identity-verification/index.md (55)\n- Methodology: https://www.anchorterminal.com/benchmark/index.md\n\n## The shortlist\n\n| # | Tool | Grade | Score | Best for | Price | Where |\n| --- | --- | --- | --- | --- | --- | --- |\n| 1 | [Didit](https://www.anchorterminal.com/tools/didit.md) | BB | 75 | A team that wants document, liveness, screening and business registry checks from one API with public prices and no sales step, and an agent that has to set itself up. | $0.15 / tx | hosted and local |\n| 2 | [Persona](https://www.anchorterminal.com/tools/persona.md) | B | 69.5 | A company that already runs Persona and wants an agent to create inquiries from templates, read verification and report results, screen against watchlists and work review cases with a permission-limited key. | $250 / mo | hosted |\n| 3 | [Sumsub](https://www.anchorterminal.com/tools/sumsub.md) | B | 68.5 | An agent that starts verifications, sends links, reads results and AML cases, and works case queues for a regulated business, with one token limited to those permissions. | $1.35 / tx | hosted |\n| 4 | [ComplyCube](https://www.anchorterminal.com/tools/complycube.md) | B | 63.7 | An agent that creates clients, uploads documents, starts document, identity and AML screening checks and reads results for a regulated business, with low entry cost ($99 a month) and a scripted sandbox. | $99 / mo | hosted |\n| 5 | [Socure RiskOS](https://www.anchorterminal.com/tools/socure-riskos.md) | B | 63.5 | A company in the United States that wants one decision from combined KYC, document, fraud and watchlist checks through a single evaluation call. | $0.80 / tx | hosted |\n| 6 | [Veriff](https://www.anchorterminal.com/tools/veriff.md) | C | 61.1 | A team that needs document and selfie verification with public per-verification prices and a trial, and that can run a webhook receiver and HMAC signing. | $0.80 / tx | local |\n| 7 | [Middesk](https://www.anchorterminal.com/tools/middesk.md) | C | 59 | An agent onboarding or re-checking US businesses for a bank, lender or marketplace that already holds a Middesk contract, with registry, TIN, sanctions and lien data in one object. | Paid | hosted |\n| 8 | [Trulioo](https://www.anchorterminal.com/tools/trulioo.md) | C | 58.2 | An agent doing business due diligence (search, verification, ownership, reports) or person checks across many countries for a company that already has a Trulioo contract, and for teams that want to test verification flows against synthetic data first. | Paid | hosted |\n| 9 | [Shufti](https://www.anchorterminal.com/tools/shufti.md) | C | 57.8 | A team that wants document, face, address, AML and KYB checks behind one endpoint, a free plan for low volume, and an MCP server that hands the person a hosted verification link. | $1.50 / tx | hosted |\n| 10 | [Jumio](https://www.anchorterminal.com/tools/jumio.md) | C | 55 | An enterprise with a Jumio contract that wants document, selfie and liveness checks, watchlist screening and Latin American, Thai and Australian database checks behind OpenAPI-described endpoints. | Paid | local |\n\n## Picks by need\n\n- Highest score overall: [Didit](https://www.anchorterminal.com/tools/didit.md), BB, 75/100 on the benchmark. Also [Persona](https://www.anchorterminal.com/tools/persona.md), B, 69.5/100.\n- Reliability: [ComplyCube](https://www.anchorterminal.com/tools/complycube.md), 84/100 on reliability, against 80 for the overall leader.\n- Agent ergonomics: [Trulioo](https://www.anchorterminal.com/tools/trulioo.md), 78/100 on agent ergonomics, against 69 for the overall leader.\n- Security \u0026 auth: [Sumsub](https://www.anchorterminal.com/tools/sumsub.md), 80/100 on security \u0026 auth, against 76 for the overall leader.\n- Transparency \u0026 trust: [Sumsub](https://www.anchorterminal.com/tools/sumsub.md), 74/100 on transparency \u0026 trust, against 63 for the overall leader.\n\n## How to choose\n\n- Identity, business and screening checks: Check whether identity, business registry and watchlist screening are all covered, since a listing that covers only one leaves a gap the agent cannot close itself.\n- Status events and callbacks: Check whether status changes arrive by callback, since an agent that polls for a result wastes calls and may read a stale status.\n- Retention, deletion and redaction: Check how long documents and selfies are kept, whether they can be deleted, and if results are redacted, so stored personal data stays minimal.\n- Result fields for each check: Check which result fields come back for a person and a business, and whether a sandbox run returns the same fields as live, so tests reflect production decisions.\n\n- How the benchmark tests this category: One test person and one test business run through each listing's sandbox. A verification is started, completed with the vendor's test documents and read back, with a watchlist screen. We check the result fields, status events, retention controls and redaction. In this run listings are graded from public evidence against the published checklist.\n\n## Each one in detail\n\n### 1. Didit, BB 75/100\n\nDidit is a hosted identity verification service for document, liveness, face match, sanctions screening and business registry checks. Developers reach it through a REST API with an OpenAPI spec, a hosted MCP server and client SDKs.\n\n- Verdict: A self-serve verification API with public per-check prices, key registration by API, scoped keys and a 365-day audit log. The status page shows three incidents marked major between 22 July and 4 September 2026, each a partial outage of the core APIs, and the sub-processor list isn't public.\n- Choose it for: A team that wants document, liveness, screening and business registry checks from one API with public prices and no sales step, and an agent that has to set itself up.\n- Strength: An account and API key can be created by API at `apx.didit.me/auth/v2/programmatic/register/`, with an emailed code and no browser step\n- Strength: Public OpenAPI 3.0.0 spec with 256 operations, plus llms.txt and a Markdown copy of every docs page\n- Strength: Named API keys take read or write access per resource, workflow limits, an IP allowlist and an expiry date, and rotation keeps the old secret for 24 hours\n- Weakness: Three incidents marked major on status.didit.me from 22 July to 4 September 2026, each a partial outage of the core APIs traced to the primary database\n- Weakness: No server-side SDK in any language. The published SDKs are capture clients for web, iOS, Android, React Native and Flutter\n- Weakness: The data processing addendum says the sub-processor list is published at `/terms/sub-processors`, but that address shows the legal index, which says the list is sent after a signed NDA\n- Price: $0.15 / tx · Auth: OAuth or key · x402: no · Where: hosted and local\n- Full assessment: https://www.anchorterminal.com/tools/didit.md\n\n### 2. Persona, B 69.5/100\n\nPersona is an identity verification platform from Persona Identities, Inc. Its REST API and hosted MCP server create inquiries, run government ID, selfie, document and database verifications, screen people and businesses against watchlists, and manage review cases.\n\n- Verdict: The REST API has a public OpenAPI 3.1 file, llms.txt, API keys with per-resource permissions, idempotency keys on every POST and a 60-day sandbox trial with no card. Production needs a business review and a 12-month plan from $250 a month. The status page lists 11 incidents since 10 July 2026, including 70 minutes of timeouts across all products.\n- Choose it for: A company that already runs Persona and wants an agent to create inquiries from templates, read verification and report results, screen against watchlists and work review cases with a permission-limited key.\n- Strength: Public OpenAPI 3.1 file with 231 operations and 141 webhook definitions, plus llms.txt and a Markdown copy of every docs page\n- Strength: API keys take about 50 read and write permissions per resource, an IP allowlist, their own rate limit and an expiry endpoint\n- Strength: `Idempotency-Key` on every POST, cursor pagination, and `fields` and `include` parameters that trim responses\n- Weakness: Production access needs Persona's approval and a 12-month plan from $250 a month, and API-only integration is limited to Enterprise plans\n- Weakness: Eleven incidents on the status page since 10 July 2026, five marked partial outage, most on document and government ID verifications\n- Weakness: The MCP server lists all 190 tools whatever the key allows, with no annotations, toolsets or read-only subset, and OAuth isn't available yet\n- Price: $250 / mo · Auth: API key · x402: no · Where: hosted\n- Full assessment: https://www.anchorterminal.com/tools/persona.md\n- Against #1: https://www.anchorterminal.com/compare/didit-vs-persona.md\n\n### 3. Sumsub, B 68.5/100\n\nSumsub verifies people from identity documents and a liveness check, verifies businesses against registries, and screens both against sanctions and watchlists. Agents reach it through a signed REST API and a hosted MCP server.\n\n- Verdict: Per-token permissions, an IP allowlist, HMAC-signed requests and a public OpenAPI spec with Markdown docs suit an agent working on verification cases. No idempotency keys or Retry-After guidance were found, there is no server SDK, and production access needs a browser signup, a bank card and Sumsub's review of the integration.\n- Choose it for: An agent that starts verifications, sends links, reads results and AML cases, and works case queues for a regulated business, with one token limited to those permissions.\n- Strength: App tokens carry per-token permissions, an optional IP allowlist and expiry date, and can be disabled with a recorded reason\n- Strength: Requests are signed with HMAC-SHA256 over timestamp, method, path and body, so the secret key never travels\n- Strength: Public OpenAPI 3.0.1 spec with 157 operations, llms.txt, and every docs page served as Markdown\n- Weakness: No idempotency keys and no Retry-After or backoff guidance found in the reviewed documentation\n- Weakness: Only 24 of 157 operations in the OpenAPI spec carry a summary or description, and 154 declare only a default response\n- Weakness: No official server-side SDK. Sumsub publishes request-signing examples in seven languages instead\n- Price: $1.35 / tx · Auth: OAuth or key · x402: no · Where: hosted\n- Full assessment: https://www.anchorterminal.com/tools/sumsub.md\n- Against #1: https://www.anchorterminal.com/compare/didit-vs-sumsub.md\n\n### 4. ComplyCube, B 63.7/100\n\nComplyCube verifies people from identity documents and a liveness check, screens people and companies against sanctions, PEP and adverse media lists, and runs address and bureau checks. Agents reach it through a REST API with separate test and live keys.\n\n- Verdict: A sandbox with its own key and scripted outcomes, a public OpenAPI spec, Markdown docs and an audit log API suit an agent running verification checks. Each environment has one unscoped key, no idempotency keys were found, and the only published terms are undated and read as website terms.\n- Choose it for: An agent that creates clients, uploads documents, starts document, identity and AML screening checks and reads results for a regulated business, with low entry cost ($99 a month) and a scripted sandbox.\n- Strength: Test and live environments have separate keys, and sandbox outcomes are set by test data such as a client last name of attention or failed\n- Strength: Public OpenAPI 3.0.0 spec (version 1.7.3, 52 operations), `llms.txt`, and every docs page served as Markdown\n- Strength: Audit log API records the team member, trigger, action and a field-level diff of old and new values\n- Weakness: One API key per environment with no scopes. The docs say keys carry many privileges\n- Weakness: No idempotency keys, and no Retry-After header documented for 429 responses\n- Weakness: The only published terms are undated, read as website terms and cite the Data Protection Act 1998. No service agreement or DPA was found on a public page\n- Price: $99 / mo · Auth: API key · x402: no · Where: hosted\n- Full assessment: https://www.anchorterminal.com/tools/complycube.md\n- Against #1: https://www.anchorterminal.com/compare/complycube-vs-didit.md\n\n### 5. Socure RiskOS, B 63.5/100\n\nSocure RiskOS is an identity verification and risk decisioning platform from Socure Inc. Its Evaluation API runs configured workflows for KYC, document and selfie checks, fraud scoring and watchlist screening, and returns a decision with reason codes.\n\n- Verdict: A public OpenAPI file, llms.txt, 15 documented error codes and dated release notes cover a ten-operation REST API, and Socure Launch publishes prices from $0.80 an evaluation with a free sandbox. API keys carry no scopes, no idempotency header is defined, no service terms are published, and production stays at zero requests until Socure activates it.\n- Choose it for: A company in the United States that wants one decision from combined KYC, document, fraud and watchlist checks through a single evaluation call.\n- Strength: OpenAPI 3.0.3 file for ten operations and a 3.1 webhook file in a public GitHub repository, last synced 5 October 2026\n- Strength: llms.txt indexes for every docs section and a Markdown copy of each page, with a robots.txt signal that allows AI input\n- Strength: Socure Launch publishes four solutions at $0.80 to $1.30 per evaluation, with a free sandbox and $1,000 of monthly production credits\n- Weakness: No service agreement or API terms are published. The only terms pages are website terms of use and end-user terms for document capture\n- Weakness: Each API key reaches every workflow, with no scopes or read-only keys, and an additional key has to be requested from Support\n- Weakness: The rate limit page advises idempotency keys, but neither the docs nor the OpenAPI file define an idempotency header\n- Price: $0.80 / tx · Auth: API key · x402: no · Where: hosted\n- Full assessment: https://www.anchorterminal.com/tools/socure-riskos.md\n- Against #1: https://www.anchorterminal.com/compare/didit-vs-socure-riskos.md\n\n### 6. Veriff, C 61.1/100\n\nIdentity verification service from Veriff in Tallinn. It checks an identity document and a selfie, with liveness, database checks and PEP and sanctions screening. Sessions are created and read through the Public API v1, with results sent by webhook.\n\n- Verdict: Per-verification prices are public from $0.80, with a 15-day trial of 50 sessions and no card. Each endpoint page is Markdown with an OpenAPI 3.0 fragment. There is no server SDK, MCP server or idempotency key, most calls need an HMAC signature, and the status page shows nine incidents between 20 July and 7 October 2026.\n- Choose it for: A team that needs document and selfie verification with public per-verification prices and a trial, and that can run a webhook receiver and HMAC signing.\n- Strength: Public prices of $0.80, $1.39 and $1.89 a verification, with a 15-day trial of up to 50 sessions and no card\n- Strength: llms.txt index and Markdown pages, each API endpoint with an OpenAPI 3.0.0 fragment, examples and error schemas\n- Strength: Up to five shared secret keys per integration, shown once, with documented rotation and deletion\n- Weakness: No server-side SDK and no MCP server. Official packages cover only browser and mobile capture\n- Weakness: No idempotency key on POST /v1/sessions, and no Retry-After or backoff guidance for the documented 429\n- Weakness: Nine status-page incidents between 20 July and 7 October 2026, mostly delayed decisions in the US region\n- Price: $0.80 / tx · Auth: API key · x402: no · Where: local\n- Full assessment: https://www.anchorterminal.com/tools/veriff.md\n- Against #1: https://www.anchorterminal.com/compare/didit-vs-veriff.md\n\n### 7. Middesk, C 59/100\n\nBusiness verification API from Middesk in San Francisco. It checks US and international businesses against registry, tax ID, sanctions and watchlist records, monitors them for changes, and files liens and state tax registrations, over REST and a hosted MCP server.\n\n- Verdict: A public OpenAPI 3.1 contract for 87 operations, llms.txt, Markdown docs and a dated weekly changelog make the REST API readable to an agent, and OAuth has a read-only scope. Access is sales-led. No price, self-serve signup or official SDK was found, and the hosted MCP server rejects sandbox keys.\n- Choose it for: An agent onboarding or re-checking US businesses for a bank, lender or marketplace that already holds a Middesk contract, with registry, TIN, sanctions and lien data in one object.\n- Strength: Public OpenAPI 3.1 spec with 87 operations and 373 schemas, plus llms.txt and a Markdown copy of every docs page\n- Strength: Dated changelog with nine entries between 20 July and 5 October 2026, breaking changes labelled as such\n- Strength: OAuth 2.0 with `read_only` and `read_write` scopes and a revoke endpoint. The MCP server adds PKCE and dynamic client registration\n- Weakness: No public price. Fees are set in an order form, and every docs page ends with a prompt to contact sales\n- Weakness: No official SDK found on npm, PyPI or RubyGems, and none in the vendor's GitHub organisation\n- Weakness: The hosted MCP server runs against production only, so a sandbox key fails on every call\n- Price: Paid · Auth: OAuth or key · x402: no · Where: hosted\n- Full assessment: https://www.anchorterminal.com/tools/middesk.md\n- Against #1: https://www.anchorterminal.com/compare/didit-vs-middesk.md\n\n### 8. Trulioo, C 58.2/100\n\nTrulioo verifies people and businesses against registry and bureau data, checks identity documents and screens watchlists. Agents reach it through REST APIs with OAuth client credentials or a hosted MCP server, which is in early access.\n\n- Verdict: The hosted MCP server has OAuth 2.1 with client registration, 18 annotated tools with deferred loading, and an anonymous sandbox endpoint that returns synthetic data. Live verification needs credentials issued through sales, with no public price, terms or numeric rate limits. The MCP server is in early access and the status page requires a login.\n- Choose it for: An agent doing business due diligence (search, verification, ownership, reports) or person checks across many countries for a company that already has a Trulioo contract, and for teams that want to test verification flows against synthetic data first.\n- Strength: Hosted MCP server at mcp.trulioo.com/mcp with OAuth 2.1, PKCE and dynamic client registration, so no key is copied into the client\n- Strength: An anonymous mock endpoint and an unbilled sandbox mode return synthetic results without Trulioo credentials\n- Strength: All 18 listed tools carry read-only, destructive and idempotent annotations, with 35 more loaded on demand\n- Weakness: No public prices, terms of service or SLA. Live credentials come from Trulioo's sales and support teams\n- Weakness: status.trulioo.com requires an account requested from support, so incident history isn't public\n- Weakness: No rate limits with numbers on either surface, and an account over its limit gets a 409\n- Price: Paid · Auth: OAuth · x402: no · Where: hosted\n- Full assessment: https://www.anchorterminal.com/tools/trulioo.md\n- Against #1: https://www.anchorterminal.com/compare/didit-vs-trulioo.md\n\n### 9. Shufti, C 57.8/100\n\nIdentity and business verification service from Shufti Pro Limited in London. One REST endpoint runs document, face, address, AML screening and KYB checks chosen in the request body, with results by callback. A hosted MCP server exposes 25 tools.\n\n- Verdict: One endpoint covers document, face, address, AML and KYB checks, with a free plan of 10 verifications a month, and a hosted MCP server adds OAuth with three scopes. No OpenAPI file, server SDK or idempotency key was found, and the status page history could not be read.\n- Choose it for: A team that wants document, face, address, AML and KYB checks behind one endpoint, a free plan for low volume, and an MCP server that hands the person a hosted verification link.\n- Strength: Free Forever plan of 10 verifications a month with no card, on the production environment, per the pricing page\n- Strength: Hosted MCP server at `https://ai.shuftipro.com/mcp` with 25 tools, OAuth 2.1 with PKCE and three scopes enforced on every call\n- Strength: Docs published as llms.txt, a 2.9 MB llms-full.txt and a Markdown twin of each page, with samples in nine languages\n- Weakness: No OpenAPI file or other machine-readable contract was found. The reference is prose tables plus Postman collections\n- Weakness: The REST credential is one Client ID and Secret Key pair with no scopes, sent as Basic auth on every call\n- Weakness: No idempotency key, Retry-After header or backoff guidance was found for the documented 429\n- Price: $1.50 / tx · Auth: OAuth or key · x402: no · Where: hosted\n- Full assessment: https://www.anchorterminal.com/tools/shufti.md\n- Against #1: https://www.anchorterminal.com/compare/didit-vs-shufti.md\n\n### 10. Jumio, C 55/100\n\nIdentity verification service from Jumio Corporation in Sunnyvale. It checks identity documents and selfies with liveness, screens against sanctions and PEP lists, and runs government database checks. Transactions are started and read through regional REST APIs with OAuth2.\n\n- Verdict: Five OpenAPI 3.0 files, an llms.txt index and OAuth2 clients limited to initiating or to retrieving and deleting make the API readable and containable. Access starts with an account manager, with no public price, trial or service agreement, and the status page shows four processing degradations and a 35-minute Singapore outage between 14 August and 2 October 2026.\n- Choose it for: An enterprise with a Jumio contract that wants document, selfie and liveness checks, watchlist screening and Latin American, Thai and Australian database checks behind OpenAPI-described endpoints.\n- Strength: Five downloadable OpenAPI 3.0 files covering 25 operations, plus llms.txt and a 2.2 MB llms-full.txt of the docs in Markdown\n- Strength: OAuth2 client credentials with 60-minute bearer tokens. Each client is limited to initiate, to retrieve and delete, or both, and can be deactivated\n- Strength: Rate limits are published per tenant. Token requests 10 a second, new transactions 1 a second, retrievals 15 a second\n- Weakness: No public price, free tier or trial. OAuth2 and workflow keys are activated by a Jumio account manager\n- Weakness: No service agreement or DPA is published. The public terms of use cover end users in the United States\n- Weakness: Four processing degradations and a 35-minute Singapore outage on the status page between 14 August and 2 October 2026\n- Price: Paid · Auth: OAuth · x402: no · Where: local\n- Full assessment: https://www.anchorterminal.com/tools/jumio.md\n- Against #1: https://www.anchorterminal.com/compare/didit-vs-jumio.md\n\n1 more are ranked in the full table: https://www.anchorterminal.com/categories/identity-verification.md\n\n## Head to head\n\n- [Didit vs Persona](https://www.anchorterminal.com/compare/didit-vs-persona.md)\n- [Didit vs Sumsub](https://www.anchorterminal.com/compare/didit-vs-sumsub.md)\n- [ComplyCube vs Didit](https://www.anchorterminal.com/compare/complycube-vs-didit.md)\n- [Didit vs Socure RiskOS](https://www.anchorterminal.com/compare/didit-vs-socure-riskos.md)\n- [Persona vs Sumsub](https://www.anchorterminal.com/compare/persona-vs-sumsub.md)\n- [ComplyCube vs Persona](https://www.anchorterminal.com/compare/complycube-vs-persona.md)\n- [Persona vs Socure RiskOS](https://www.anchorterminal.com/compare/persona-vs-socure-riskos.md)\n- [ComplyCube vs Sumsub](https://www.anchorterminal.com/compare/complycube-vs-sumsub.md)\n- [Socure RiskOS vs Sumsub](https://www.anchorterminal.com/compare/socure-riskos-vs-sumsub.md)\n- [ComplyCube vs Socure RiskOS](https://www.anchorterminal.com/compare/complycube-vs-socure-riskos.md)\n\n## Questions\n\n### What are the highest-rated identity and business verification APIs for AI agents?\n\nDidit has the highest benchmark score of the 11 ranked identity and business verification APIs, 75 (BB). Persona is second with 69.5 (B).\n\n### How many identity and business verification APIs are agent-ready?\n\n1 of the 11 ranked here grade BB or better, the bar for agent-ready on the Anchor benchmark.\n\n### Which identity and business verification APIs accept x402 payments?\n\nNone of the ranked listings here accepts x402 for its main call yet.\n\n### How is this list ranked?\n\nBy the Anchor benchmark score out of 100, a weighted mean of the scored categories minus deductions for negative events, from public evidence re-checked as vendors change. Listings cannot pay for a place. The latest assessment behind this page is from 9 October 2026.\n\n## How this list is made\n\nThe order is the Anchor benchmark score, the same number as on each listing. Each listing is graded from public evidence against the benchmark checklist, and the picks are worked out from those grades, prices and facts. No listing pays for its place, and paid audits or listing help never change a score.\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Best of",
        "url": "https://www.anchorterminal.com/best/"
      },
      {
        "name": "Identity \u0026 business verification",
        "url": ""
      }
    ],
    "description": "Didit (BB), Persona (B) and Sumsub (B) lead the 11 ranked identity and business verification APIs. Picks by need, strengths, weaknesses and prices from the Anchor benchmark.",
    "facts": [
      "Didit BB",
      "Persona B",
      "Sumsub B"
    ],
    "h1": "Best identity and business verification APIs for AI agents",
    "image": "https://www.anchorterminal.com/assets/og/best-identity-verification.png",
    "path": "/best/identity-verification/",
    "published": "",
    "section": "tools",
    "title": "Best identity and business verification APIs for AI agents in 2026",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/best/identity-verification/"
  },
  "tokens": {
    "markdown": 6550,
    "slim": 1480
  },
  "version": 1
}
