{
  "data": {
    "a": {
      "slug": "complyadvantage",
      "name": "ComplyAdvantage",
      "vendor": "IVXS UK Limited (trading as ComplyAdvantage)",
      "vendorUrl": "https://complyadvantage.com",
      "kind": "http-api",
      "category": "identity-verification",
      "summary": "ComplyAdvantage screens people and companies against sanctions lists, watchlists, politically exposed person registers and adverse media, with ongoing monitoring and case management. Agents reach its Mesh platform through a REST API with a public OpenAPI spec.",
      "url": "https://www.anchorterminal.com/tools/complyadvantage",
      "markdownUrl": "https://www.anchorterminal.com/tools/complyadvantage.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/complyadvantage.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/complyadvantage.json",
      "license": "Proprietary service. No service agreement is published, and the terms page on complyadvantage.com covers the website only",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://api.mesh.complyadvantage.com",
      "packages": [],
      "auth": "oauth",
      "authNotes": "The Mesh API uses the OAuth2 client credentials flow. A Mesh admin, or a custom role with the API credential permissions, creates a credential in the web application under Settings, Access Management, API Credentials, choosing its permissions and an optional expiry date. The integration sends the access key and secret to `POST /v3/token` and receives a bearer token valid for 24 hours, with no refresh. A credential can't be edited, its secret is shown once, and deactivating it invalidates tokens already issued. The older username and password flow at `POST /v2/token` remains supported for existing integrations. Accounts are opened by ComplyAdvantage after a Starter Plan purchase or a sales contract, so there is no self-serve key (https://docs.mesh.complyadvantage.com/docs/getting-started, https://support.complyadvantage.com/articles/5045588818-creating-api-credentials, checked 2026-10-08).",
      "pricing": "paid",
      "pricingNotes": "The Starter Plan is priced by monitored entities a month. Essentials runs from $119 a month for up to 100 entities to $383 for up to 2,000 on monthly billing ($99 to $319 on annual billing), and the Agentic version from $179 to $575. Entities over the allowance are charged at 1.5 times the unit rate. Enterprise, which adds transaction monitoring and payment screening, is priced on application. No free tier or trial was found. Sandbox and production logins come with a paid account, set up by staff within one working day, and the pricing page says the API is included. ComplyLaunch gives early-stage start-ups free access on application (https://complyadvantage.com/pricing/, https://complyadvantage.com/starter-plan/, checked 2026-10-08).",
      "priceSummary": "$119 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the Mesh API docs, the OpenAPI spec or the pricing pages (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.mesh.complyadvantage.com",
      "llmsTxt": "https://docs.mesh.complyadvantage.com/llms.txt",
      "openapi": "https://docs.mesh.complyadvantage.com/openapi/mesh-api.json",
      "capabilities": [
        "kyc.screening",
        "kyc.cases"
      ],
      "tags": [
        "hosted",
        "paid",
        "sandbox",
        "oauth",
        "openapi",
        "llms-txt",
        "webhooks",
        "aml",
        "sanctions",
        "audit-log",
        "iso27001",
        "soc2"
      ],
      "lastRelease": "2026-09-16",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 52.6,
        "grade": "D",
        "agentReady": false,
        "rank": 653,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 11,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 67,
          "maintenance": 28,
          "payments": 10,
          "reliability": 42,
          "schema": 82,
          "security": 68,
          "transparency": 50
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "The Mesh API has a public OpenAPI 3.0.3 spec with 165 described operations, per-credential permissions and audit log endpoints, which suits an agent screening customers and working alerts. No status page, changelog, SDK, service agreement or subprocessor list was found in public, and access starts with a paid plan bought by a person.",
        "bestFor": "An agent that screens customers and companies against sanctions, politically exposed person and adverse media data, keeps them under monitoring and works the resulting alerts and cases.",
        "strengths": [
          "Public OpenAPI 3.0.3 spec with 165 operations, each with a summary and description, and 124 naming the permission the call needs",
          "API credentials carry their own permissions and optional expiry, and deactivation invalidates tokens already issued",
          "Six audit log endpoints cover the account, cases, customers, roles, transactions and users",
          "Rate limits are published (1,000 requests a minute in production, 300 in Sandbox) with `Ratelimit-Limit`, `Ratelimit-Remaining` and `Ratelimit-Reset` headers",
          "`llms.txt` on the docs site, and every guide and reference page is served as Markdown"
        ],
        "weaknesses": [
          "No public status page or incident history was found. `status.complyadvantage.com` does not resolve",
          "No changelog or release notes were found for the Mesh API",
          "No service agreement, data processing agreement or subprocessor list is published. The terms page covers the website only",
          "No free tier or self-serve trial. The Starter Plan starts at $119 a month and accounts are set up by staff within a working day",
          "No official SDK was found. Access tokens last 24 hours with no refresh",
          "Screening results carry third-party adverse media text, and no prompt-injection guidance was found"
        ],
        "agentNotes": [
          "Exchange the access key and secret at `POST /v3/token` for a bearer token. It lasts 24 hours and can't be refreshed, so request a new one before expiry",
          "Ask for a credential with only the permissions the task needs. Permissions can't be edited later, and each reference page names the ones a call requires",
          "Create a screening configuration first and keep its `configuration_identifier`. Creating and screening a customer needs it",
          "Give each customer a unique external identifier. A concurrent request for the same identifier returns 409 with a pointer to the first workflow",
          "Read `Ratelimit-Remaining` and `Ratelimit-Reset` on every response. A 429 body is only `API rate limit exceeded`"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "D",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 52.6
          }
        ],
        "editorialScores": {
          "ergonomics": 67,
          "maintenance": 28,
          "payments": 10,
          "reliability": 42,
          "schema": 82,
          "security": 68,
          "transparency": 40
        },
        "provenanceScore": 59
      },
      "connect": {
        "http": "curl -X POST https://api.mesh.complyadvantage.com/v3/token \\\n  -H 'Content-Type: application/json' \\\n  -d '{\"access_key\": \"\u003cyour access key\u003e\", \"secret\": \"\u003cyour secret\u003e\"}'"
      },
      "letme": {
        "capability": "https://letme.dev/kyc.screening",
        "tool": "https://letme.dev/complyadvantage"
      },
      "area": "domain-data",
      "unitPrices": [
        {
          "item": "Essentials Starter Plan, up to 100 monitored entities",
          "unit": "month",
          "usd": 119,
          "note": "monthly billing; $99 a month on annual billing"
        },
        {
          "item": "Essentials Starter Plan, up to 1,000 monitored entities",
          "unit": "month",
          "usd": 323,
          "note": "monthly billing; $269 a month on annual billing"
        },
        {
          "item": "Essentials Starter Plan, up to 2,000 monitored entities",
          "unit": "month",
          "usd": 383,
          "note": "monthly billing; $319 a month on annual billing"
        },
        {
          "item": "Agentic Starter Plan, up to 100 monitored entities",
          "unit": "month",
          "usd": 179,
          "note": "monthly billing; $149 a month on annual billing"
        }
      ],
      "provenance": {
        "legalEntity": "IVXS UK Limited (trading as ComplyAdvantage)",
        "domain": "complyadvantage.com",
        "domainRegistered": "2014-07-05",
        "endpointOnVendorDomain": true,
        "terms": "",
        "privacy": "https://complyadvantage.com/privacy-notice/",
        "statusPage": "",
        "changelog": "",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The privacy notice (last updated 12 June 2026) names IVXS UK Limited, trading as ComplyAdvantage, 86-90 Paul Street, London EC2A 4NE, registered with the UK Information Commissioner under ZA054290, and covers its products and services as well as the website.",
          "No `terms` is given. https://complyadvantage.com/terms-and-conditions/ is the website's terms of use, and no service agreement, API terms or data processing agreement was found on the site, the docs or the help centre.",
          "The Mesh API answers at api.mesh.complyadvantage.com and regional hosts under mesh.complyadvantage.com.",
          "https://complyadvantage.com/.well-known/security.txt and /security.txt return 404.",
          "status.complyadvantage.com does not resolve, and no status page is linked from the site, the docs or the help centre. docs.mesh.complyadvantage.com/changelog returns 404.",
          "RDAP for complyadvantage.com gives a registration date of 2014-07-05."
        ],
        "score": 59
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/complyadvantage.json",
      "live": {
        "slug": "complyadvantage",
        "probe": {
          "target": "https://api.mesh.complyadvantage.com",
          "method": "get",
          "lastAt": "2026-10-09T11:46:25.812195931Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 40,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 48,
          "p95ms24h": 123,
          "samples24h": 175,
          "samples30d": 175,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 50,
              "ok": 50
            },
            {
              "date": "2026-10-09",
              "probes": 125,
              "ok": 125
            }
          ]
        },
        "updatedAt": "2026-10-09T11:46:25.812195931Z"
      }
    },
    "answer": "Shufti scores 57.8 (C) on agent readiness against ComplyAdvantage's 52.6 (D), and leads in 4 of 7 scored categories. ComplyAdvantage leads on schema \u0026 documentation, agent ergonomics and security \u0026 auth.",
    "b": {
      "slug": "shufti",
      "name": "Shufti",
      "vendor": "Shufti Pro Limited",
      "vendorUrl": "https://shuftipro.com",
      "kind": "http-api",
      "category": "identity-verification",
      "summary": "Identity and business verification service from Shufti Pro Limited in London. One REST endpoint runs document, face, address, AML screening and KYB checks chosen in the request body, with results by callback. A hosted MCP server exposes 25 tools.",
      "url": "https://www.anchorterminal.com/tools/shufti",
      "markdownUrl": "https://www.anchorterminal.com/tools/shufti.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/shufti.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/shufti.json",
      "repo": "https://github.com/shuftipro/iOS-SDK",
      "license": "Proprietary service under Shufti's Terms and Conditions. The licences of the mobile capture SDKs were not checked",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.shuftipro.com",
      "packages": [
        {
          "registry": "npm",
          "name": "shuftipro-onsite-mobilesdk"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve. Signing up creates a back office account, and the Client ID and Secret Key come from Settings, API Configuration, API Keys. The REST API takes them as HTTP Basic auth, or a Bearer access token from `/get/access/token` that lasts one hour. The key pair has no scopes, and the Secret Key is shown once and replaced by generating a new one. The MCP server uses OAuth 2.1 with PKCE and dynamic client registration. Its login page asks for the same Client ID and Secret Key, and it issues tokens with the scopes `knowledge:read`, `verification:read` and `verification:write`. Callback and redirect domains must be registered in the back office.",
      "pricing": "freemium",
      "pricingNotes": "Free Forever covers up to 10 verifications a month with no card, on the production environment. Essentials starts from $1.50 a verification, pay as you go with no monthly minimum, up to 20,000 verifications. Enterprise is quoted by sales and adds e-IDV, Travel Rule, video KYC and other services. The pricing page says only successful verification attempts are billed and resubmissions are free. Trial accounts accept test ID samples (https://shuftipro.com/pricing/, checked 2026-10-09).",
      "priceSummary": "$1.50 / tx",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the developer docs (llms-full.txt), the pricing page or the terms (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": 25,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 673,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://developers.shuftipro.com/docs/get_started",
      "llmsTxt": "https://developers.shuftipro.com/llms.txt",
      "capabilities": [
        "kyc.identity",
        "kyc.documents",
        "kyc.business",
        "kyc.screening"
      ],
      "tags": [
        "hosted",
        "api-key",
        "oauth",
        "mcp",
        "webhooks",
        "llms-txt",
        "free-tier",
        "no-card",
        "status-page",
        "sla",
        "soc2",
        "iso27001"
      ],
      "lastRelease": "2026-10-06",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 57.8,
        "grade": "C",
        "agentReady": false,
        "rank": 538,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 9,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 47,
          "maintenance": 72,
          "payments": 35,
          "reliability": 65,
          "schema": 58,
          "security": 62,
          "transparency": 71
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": 0,
        "verdict": "One endpoint covers document, face, address, AML and KYB checks, with a free plan of 10 verifications a month, and a hosted MCP server adds OAuth with three scopes. No OpenAPI file, server SDK or idempotency key was found, and the status page history could not be read.",
        "bestFor": "A team that wants document, face, address, AML and KYB checks behind one endpoint, a free plan for low volume, and an MCP server that hands the person a hosted verification link.",
        "strengths": [
          "Free Forever plan of 10 verifications a month with no card, on the production environment, per the pricing page",
          "Hosted MCP server at `https://ai.shuftipro.com/mcp` with 25 tools, OAuth 2.1 with PKCE and three scopes enforced on every call",
          "Docs published as llms.txt, a 2.9 MB llms-full.txt and a Markdown twin of each page, with samples in nine languages",
          "Public terms (version 11.1, 13 May 2026) include an availability schedule targeting 99 per cent monthly uptime",
          "Revision history with 19 dated entries between 24 July and 6 October 2026"
        ],
        "weaknesses": [
          "No OpenAPI file or other machine-readable contract was found. The reference is prose tables plus Postman collections",
          "The REST credential is one Client ID and Secret Key pair with no scopes, sent as Basic auth on every call",
          "No idempotency key, Retry-After header or backoff guidance was found for the documented 429",
          "No server-side SDK. Official packages cover Android, iOS, Flutter, React Native and Cordova capture only",
          "Standard KYB was deprecated on 6 October 2026 and its pages removed the same day, with no notice period stated",
          "The sub-processor list is available to clients on request only, and security.txt returns 404"
        ],
        "agentNotes": [
          "POST every verification to `https://api.shuftipro.com/` with a unique `reference` of 6 to 250 characters and one object per service. Read results from `/status` with that reference",
          "Register the callback domain in the back office first. An unregistered `callback_url` is rejected",
          "Stay under 60 requests a minute per IP on a production account and 20 on a trial account",
          "Check the `Signature` response header. Accounts created after 15 March 2023 hash the Secret Key with SHA-256 before appending it to the raw response",
          "Through MCP, identity checks return a `verification_url` for the person to open. No tool accepts an image, so use the REST API for offsite proofs"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 57.8
          }
        ],
        "editorialScores": {
          "ergonomics": 47,
          "maintenance": 72,
          "payments": 35,
          "reliability": 65,
          "schema": 58,
          "security": 62,
          "transparency": 51
        },
        "provenanceScore": 90
      },
      "connect": {
        "http": "curl --location --request POST 'https://api.shuftipro.com' \\\n--header 'Content-Type: application/json' \\\n--header 'Authorization: Basic \u003cbase64 of CLIENT_ID:SECRET_KEY\u003e' \\\n--data-raw '{\n    \"reference\"    : \"1234567\",\n    \"callback_url\" : \"https://yourdomain.com/profile/notifyCallback\",\n    \"country\"      : \"GB\",\n    \"language\"     : \"EN\",\n    \"verification_mode\" : \"any\",\n    \"face\" : {\n        \"proof\"            : \"\"\n    }\n}'",
        "claudeCode": "claude mcp add --transport http shufti https://ai.shuftipro.com/mcp",
        "config": {
          "mcpServers": {
            "shufti": {
              "args": [
                "mcp-remote",
                "https://ai.shuftipro.com/mcp"
              ],
              "command": "npx"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/kyc.identity",
        "tool": "https://letme.dev/shufti"
      },
      "area": "domain-data",
      "unitPrices": [
        {
          "item": "Verification, Free Forever plan (document and face checks)",
          "unit": "tx",
          "usd": 0,
          "note": "up to 10 verifications a month, no card"
        },
        {
          "item": "Verification, Essentials plan, starting price",
          "unit": "tx",
          "usd": 1.5,
          "note": "rate depends on volume and the services chosen, up to 20,000 verifications"
        }
      ],
      "provenance": {
        "legalEntity": "Shufti Pro Limited",
        "domain": "shuftipro.com",
        "domainRegistered": "2016-06-28",
        "endpointOnVendorDomain": true,
        "terms": "https://shuftipro.com/wp-content/uploads/Version-11.1-w.e.f.-May-13th-2026.pdf",
        "privacy": "https://shuftipro.com/services-privacy-notice/",
        "statusPage": "https://status.shuftipro.com",
        "changelog": "https://developers.shuftipro.com/docs/revision_history",
        "securityTxt": "none",
        "checked": "2026-10-09",
        "notes": [
          "The terms and the MCP privacy notice name Shufti Pro Limited, Office 408 Coppergate House, 10 Whites Row, London E1 7NF.",
          "The governing terms are a PDF, version 11.1, linked from shuftipro.com/terms-and-conditions/, which itself carries only a summary and links to every earlier version. The page labels the file 12 May 2026 and the file name says 13 May.",
          "The privacy link is the Services Privacy Notice, version 1.2, last updated September 2026, which covers verification data. A separate notice covers the website.",
          "shuftipro.com/.well-known/security.txt answered 502 on the first request and 404 on the second.",
          "RDAP for shuftipro.com gives a registration date of 2016-06-28.",
          "The API answers at api.shuftipro.com and the MCP server at ai.shuftipro.com. The lead's shufti.ai is a parked domain for sale and unrelated to the vendor.",
          "status.shuftipro.com is an UptimeRobot page whose data loads from /api/, a path its robots.txt disallows, so the incident history was not read."
        ],
        "score": 90
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/shufti.json",
      "live": {
        "slug": "shufti",
        "probe": {
          "target": "https://api.shuftipro.com",
          "method": "get",
          "lastAt": "2026-10-09T11:46:40.498968542Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 347,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 321,
          "p95ms24h": 367,
          "samples24h": 44,
          "samples30d": 44,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 44,
              "ok": 44
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.shuftipro.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-09T07:58:32.112017753Z"
        },
        "updatedAt": "2026-10-09T11:46:40.498968542Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "IVXS UK Limited (trading as ComplyAdvantage)",
        "b": "Shufti Pro Limited",
        "name": "Vendor"
      },
      {
        "a": "https://api.mesh.complyadvantage.com",
        "b": "https://api.shuftipro.com",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Paid",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service. No service agreement is published, and the terms page on complyadvantage.com covers the website only",
        "b": "Proprietary service under Shufti's Terms and Conditions. The licences of the mobile capture SDKs were not checked",
        "name": "Licence"
      },
      {
        "a": "none",
        "b": "25",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-16",
        "b": "2026-10-06",
        "name": "Last release"
      },
      {
        "a": "no document linked",
        "b": "",
        "name": "Terms last updated"
      },
      {
        "a": "2026-06-12",
        "b": "2026-09-01",
        "name": "Privacy policy last updated"
      },
      {
        "a": "",
        "b": "yes, with an opt-out",
        "name": "Customer content may train models"
      },
      {
        "a": "",
        "b": "",
        "name": "Terms restrict automated access"
      },
      {
        "a": "",
        "b": "",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "",
        "b": "",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "",
        "b": "",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "none",
        "b": "673 npm/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Shufti scores 57.8 (C) on agent readiness against ComplyAdvantage's 52.6 (D), and leads in 4 of 7 scored categories. ComplyAdvantage leads on schema \u0026 documentation, agent ergonomics and security \u0026 auth.",
        "question": "Which is better for AI agents, ComplyAdvantage or Shufti?"
      },
      {
        "answer": "ComplyAdvantage uses an OAuth sign-in. Shufti takes an API key or an OAuth sign-in.",
        "question": "Do ComplyAdvantage and Shufti need an API key?"
      },
      {
        "answer": "Yes. ComplyAdvantage has a hosted endpoint at https://api.mesh.complyadvantage.com and Shufti at https://api.shuftipro.com.",
        "question": "Can an agent call ComplyAdvantage and Shufti without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Schema \u0026 documentation, 82 against 58",
          "Agent ergonomics, 67 against 47",
          "Security \u0026 auth, 68 against 62"
        ],
        "also": null,
        "goodFor": "An agent that screens customers and companies against sanctions, politically exposed person and adverse media data, keeps them under monitoring and works the resulting alerts and cases.",
        "slug": "complyadvantage",
        "watchFor": "No public status page or incident history was found. `status.complyadvantage.com` does not resolve"
      },
      {
        "aheadOn": [
          "Reliability, 65 against 42",
          "Payments \u0026 pricing, 35 against 10",
          "Maintenance \u0026 community, 72 against 28",
          "Transparency \u0026 trust, 71 against 50"
        ],
        "also": [
          "Free to start without a card"
        ],
        "goodFor": "A team that wants document, face, address, AML and KYB checks behind one endpoint, a free plan for low volume, and an MCP server that hands the person a hosted verification link.",
        "slug": "shufti",
        "watchFor": "No OpenAPI file or other machine-readable contract was found. The reference is prose tables plus Postman collections"
      }
    ],
    "job": {
      "capability": "kyc.screening",
      "name": "Kyc screening"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/complycube-vs-shufti.json",
        "title": "ComplyCube vs Shufti",
        "url": "https://www.anchorterminal.com/compare/complycube-vs-shufti"
      },
      {
        "json": "https://www.anchorterminal.com/compare/didit-vs-shufti.json",
        "title": "Didit vs Shufti",
        "url": "https://www.anchorterminal.com/compare/didit-vs-shufti"
      },
      {
        "json": "https://www.anchorterminal.com/compare/jumio-vs-shufti.json",
        "title": "Jumio vs Shufti",
        "url": "https://www.anchorterminal.com/compare/jumio-vs-shufti"
      },
      {
        "json": "https://www.anchorterminal.com/compare/persona-vs-shufti.json",
        "title": "Persona vs Shufti",
        "url": "https://www.anchorterminal.com/compare/persona-vs-shufti"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shufti-vs-socure-riskos.json",
        "title": "Shufti vs Socure RiskOS",
        "url": "https://www.anchorterminal.com/compare/shufti-vs-socure-riskos"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shufti-vs-sumsub.json",
        "title": "Shufti vs Sumsub",
        "url": "https://www.anchorterminal.com/compare/shufti-vs-sumsub"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shufti-vs-trulioo.json",
        "title": "Shufti vs Trulioo",
        "url": "https://www.anchorterminal.com/compare/shufti-vs-trulioo"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shufti-vs-veriff.json",
        "title": "Shufti vs Veriff",
        "url": "https://www.anchorterminal.com/compare/shufti-vs-veriff"
      },
      {
        "json": "https://www.anchorterminal.com/compare/complyadvantage-vs-complycube.json",
        "title": "ComplyAdvantage vs ComplyCube",
        "url": "https://www.anchorterminal.com/compare/complyadvantage-vs-complycube"
      },
      {
        "json": "https://www.anchorterminal.com/compare/complyadvantage-vs-didit.json",
        "title": "ComplyAdvantage vs Didit",
        "url": "https://www.anchorterminal.com/compare/complyadvantage-vs-didit"
      },
      {
        "json": "https://www.anchorterminal.com/compare/complyadvantage-vs-jumio.json",
        "title": "ComplyAdvantage vs Jumio",
        "url": "https://www.anchorterminal.com/compare/complyadvantage-vs-jumio"
      },
      {
        "json": "https://www.anchorterminal.com/compare/complyadvantage-vs-middesk.json",
        "title": "ComplyAdvantage vs Middesk",
        "url": "https://www.anchorterminal.com/compare/complyadvantage-vs-middesk"
      },
      {
        "json": "https://www.anchorterminal.com/compare/complyadvantage-vs-persona.json",
        "title": "ComplyAdvantage vs Persona",
        "url": "https://www.anchorterminal.com/compare/complyadvantage-vs-persona"
      },
      {
        "json": "https://www.anchorterminal.com/compare/complyadvantage-vs-socure-riskos.json",
        "title": "ComplyAdvantage vs Socure RiskOS",
        "url": "https://www.anchorterminal.com/compare/complyadvantage-vs-socure-riskos"
      },
      {
        "json": "https://www.anchorterminal.com/compare/complyadvantage-vs-sumsub.json",
        "title": "ComplyAdvantage vs Sumsub",
        "url": "https://www.anchorterminal.com/compare/complyadvantage-vs-sumsub"
      },
      {
        "json": "https://www.anchorterminal.com/compare/complyadvantage-vs-trulioo.json",
        "title": "ComplyAdvantage vs Trulioo",
        "url": "https://www.anchorterminal.com/compare/complyadvantage-vs-trulioo"
      },
      {
        "json": "https://www.anchorterminal.com/compare/complyadvantage-vs-veriff.json",
        "title": "ComplyAdvantage vs Veriff",
        "url": "https://www.anchorterminal.com/compare/complyadvantage-vs-veriff"
      },
      {
        "json": "https://www.anchorterminal.com/compare/middesk-vs-shufti.json",
        "title": "Middesk vs Shufti",
        "url": "https://www.anchorterminal.com/compare/middesk-vs-shufti"
      }
    ],
    "scores": [
      {
        "by": 23,
        "complyadvantage": 42,
        "edge": "shufti",
        "key": "reliability",
        "name": "Reliability",
        "shufti": 65,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 24,
        "complyadvantage": 82,
        "edge": "complyadvantage",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "shufti": 58,
        "weight": 13
      },
      {
        "by": 20,
        "complyadvantage": 67,
        "edge": "complyadvantage",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "shufti": 47,
        "weight": 13
      },
      {
        "by": 6,
        "complyadvantage": 68,
        "edge": "complyadvantage",
        "key": "security",
        "name": "Security \u0026 auth",
        "shufti": 62,
        "weight": 14
      },
      {
        "by": 25,
        "complyadvantage": 10,
        "edge": "shufti",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "shufti": 35,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 44,
        "complyadvantage": 28,
        "edge": "shufti",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "shufti": 72,
        "weight": 7
      },
      {
        "by": 21,
        "complyadvantage": 50,
        "edge": "shufti",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "shufti": 71,
        "weight": 7
      }
    ],
    "summary": "Shufti scores 57.8 (C) on agent readiness against ComplyAdvantage's 52.6 (D), and leads in 4 of 7 scored categories. ComplyAdvantage leads on schema \u0026 documentation, agent ergonomics and security \u0026 auth. Both do kyc screening.",
    "verdicts": {
      "complyadvantage": "The Mesh API has a public OpenAPI 3.0.3 spec with 165 described operations, per-credential permissions and audit log endpoints, which suits an agent screening customers and working alerts. No status page, changelog, SDK, service agreement or subprocessor list was found in public, and access starts with a paid plan bought by a person.",
      "shufti": "One endpoint covers document, face, address, AML and KYB checks, with a free plan of 10 verifications a month, and a hosted MCP server adds OAuth with three scopes. No OpenAPI file, server SDK or idempotency key was found, and the status page history could not be read."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/complyadvantage-vs-shufti",
    "json": "https://www.anchorterminal.com/compare/complyadvantage-vs-shufti.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/complyadvantage-vs-shufti.md",
    "slim": "https://www.anchorterminal.com/compare/complyadvantage-vs-shufti.min.md"
  },
  "markdown": "Shufti scores 57.8 (C) on agent readiness against ComplyAdvantage's 52.6 (D), and leads in 4 of 7 scored categories. ComplyAdvantage leads on schema \u0026 documentation, agent ergonomics and security \u0026 auth. Both do kyc screening.\n\n- ComplyAdvantage: grade D, 52.6/100, rank #653 of 842. Markdown https://www.anchorterminal.com/tools/complyadvantage.md · JSON https://www.anchorterminal.com/api/v1/tools/complyadvantage.json\n- Shufti: grade C, 57.8/100, rank #538 of 842. Markdown https://www.anchorterminal.com/tools/shufti.md · JSON https://www.anchorterminal.com/api/v1/tools/shufti.json\n\n## Which one, for what\n\n### ComplyAdvantage (D)\n\nGood for: An agent that screens customers and companies against sanctions, politically exposed person and adverse media data, keeps them under monitoring and works the resulting alerts and cases.\n\nAhead on:\n- Schema \u0026 documentation, 82 against 58\n- Agent ergonomics, 67 against 47\n- Security \u0026 auth, 68 against 62\n\nWatch for: No public status page or incident history was found. `status.complyadvantage.com` does not resolve\n\n### Shufti (C)\n\nGood for: A team that wants document, face, address, AML and KYB checks behind one endpoint, a free plan for low volume, and an MCP server that hands the person a hosted verification link.\n\nAhead on:\n- Reliability, 65 against 42\n- Payments \u0026 pricing, 35 against 10\n- Maintenance \u0026 community, 72 against 28\n- Transparency \u0026 trust, 71 against 50\n\nAlso in its favour:\n- Free to start without a card\n\nWatch for: No OpenAPI file or other machine-readable contract was found. The reference is prose tables plus Postman collections\n\n\n## Score by category\n\n| Category | Weight | ComplyAdvantage | Shufti | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 42 | 65 | Shufti +23 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 82 | 58 | ComplyAdvantage +24 |\n| Agent ergonomics | 13% (16.2 this run) | 67 | 47 | ComplyAdvantage +20 |\n| Security \u0026 auth | 14% (17.5 this run) | 68 | 62 | ComplyAdvantage +6 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 10 | 35 | Shufti +25 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 28 | 72 | Shufti +44 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 50 | 71 | Shufti +21 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **52.6 · D** | **57.8 · C** | |\n\n## Facts side by side\n\n| Fact | ComplyAdvantage | Shufti |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | IVXS UK Limited (trading as ComplyAdvantage) | Shufti Pro Limited |\n| Hosted endpoint | `https://api.mesh.complyadvantage.com` | `https://api.shuftipro.com` |\n| Transports | HTTP | HTTP, Streamable HTTP |\n| Auth | OAuth | OAuth or key |\n| Pricing | Paid | Freemium |\n| x402 | no | no |\n| Licence | Proprietary service. No service agreement is published, and the terms page on complyadvantage.com covers the website only | Proprietary service under Shufti's Terms and Conditions. The licences of the mobile capture SDKs were not checked |\n| Tools exposed | none | 25 |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| Last release | 2026-09-16 | 2026-10-06 |\n| Terms last updated | no document linked |  |\n| Privacy policy last updated | 2026-06-12 | 2026-09-01 |\n| Customer content may train models |  | yes, with an opt-out |\n| Terms restrict automated access |  |  |\n| Terms restrict benchmarking |  |  |\n| Terms or service can change without notice |  |  |\n| Arbitration or class-action waiver |  |  |\n| Popularity | none | 673 npm/wk |\n\n## Verdicts\n\n**ComplyAdvantage.** The Mesh API has a public OpenAPI 3.0.3 spec with 165 described operations, per-credential permissions and audit log endpoints, which suits an agent screening customers and working alerts. No status page, changelog, SDK, service agreement or subprocessor list was found in public, and access starts with a paid plan bought by a person.\n\n**Shufti.** One endpoint covers document, face, address, AML and KYB checks, with a free plan of 10 verifications a month, and a hosted MCP server adds OAuth with three scopes. No OpenAPI file, server SDK or idempotency key was found, and the status page history could not be read.\n\n## Before you call either\n\n### ComplyAdvantage\n\n1. Exchange the access key and secret at `POST /v3/token` for a bearer token. It lasts 24 hours and can't be refreshed, so request a new one before expiry\n2. Ask for a credential with only the permissions the task needs. Permissions can't be edited later, and each reference page names the ones a call requires\n3. Create a screening configuration first and keep its `configuration_identifier`. Creating and screening a customer needs it\n4. Give each customer a unique external identifier. A concurrent request for the same identifier returns 409 with a pointer to the first workflow\n5. Read `Ratelimit-Remaining` and `Ratelimit-Reset` on every response. A 429 body is only `API rate limit exceeded`\n\n### Shufti\n\n1. POST every verification to `https://api.shuftipro.com/` with a unique `reference` of 6 to 250 characters and one object per service. Read results from `/status` with that reference\n2. Register the callback domain in the back office first. An unregistered `callback_url` is rejected\n3. Stay under 60 requests a minute per IP on a production account and 20 on a trial account\n4. Check the `Signature` response header. Accounts created after 15 March 2023 hash the Secret Key with SHA-256 before appending it to the raw response\n5. Through MCP, identity checks return a `verification_url` for the person to open. No tool accepts an image, so use the REST API for offsite proofs\n\n## Questions\n\n### Which is better for AI agents, ComplyAdvantage or Shufti?\n\nShufti scores 57.8 (C) on agent readiness against ComplyAdvantage's 52.6 (D), and leads in 4 of 7 scored categories. ComplyAdvantage leads on schema \u0026 documentation, agent ergonomics and security \u0026 auth.\n\n### Do ComplyAdvantage and Shufti need an API key?\n\nComplyAdvantage uses an OAuth sign-in. Shufti takes an API key or an OAuth sign-in.\n\n### Can an agent call ComplyAdvantage and Shufti without installing anything?\n\nYes. ComplyAdvantage has a hosted endpoint at https://api.mesh.complyadvantage.com and Shufti at https://api.shuftipro.com.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/complyadvantage-vs-shufti.json, and with the fewest tokens: https://www.anchorterminal.com/compare/complyadvantage-vs-shufti.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"complyadvantage\", \"b\": \"shufti\"}`. From a terminal: `anchor compare complyadvantage shufti`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/complyadvantage.json and https://www.anchorterminal.com/api/v1/tools/shufti.json\n\n## Other comparisons with ComplyAdvantage or Shufti\n\n- [ComplyCube vs Shufti](https://www.anchorterminal.com/compare/complycube-vs-shufti.md)\n- [Didit vs Shufti](https://www.anchorterminal.com/compare/didit-vs-shufti.md)\n- [Jumio vs Shufti](https://www.anchorterminal.com/compare/jumio-vs-shufti.md)\n- [Persona vs Shufti](https://www.anchorterminal.com/compare/persona-vs-shufti.md)\n- [Shufti vs Socure RiskOS](https://www.anchorterminal.com/compare/shufti-vs-socure-riskos.md)\n- [Shufti vs Sumsub](https://www.anchorterminal.com/compare/shufti-vs-sumsub.md)\n- [Shufti vs Trulioo](https://www.anchorterminal.com/compare/shufti-vs-trulioo.md)\n- [Shufti vs Veriff](https://www.anchorterminal.com/compare/shufti-vs-veriff.md)\n- [ComplyAdvantage vs ComplyCube](https://www.anchorterminal.com/compare/complyadvantage-vs-complycube.md)\n- [ComplyAdvantage vs Didit](https://www.anchorterminal.com/compare/complyadvantage-vs-didit.md)\n- [ComplyAdvantage vs Jumio](https://www.anchorterminal.com/compare/complyadvantage-vs-jumio.md)\n- [ComplyAdvantage vs Middesk](https://www.anchorterminal.com/compare/complyadvantage-vs-middesk.md)\n- [ComplyAdvantage vs Persona](https://www.anchorterminal.com/compare/complyadvantage-vs-persona.md)\n- [ComplyAdvantage vs Socure RiskOS](https://www.anchorterminal.com/compare/complyadvantage-vs-socure-riskos.md)\n- [ComplyAdvantage vs Sumsub](https://www.anchorterminal.com/compare/complyadvantage-vs-sumsub.md)\n- [ComplyAdvantage vs Trulioo](https://www.anchorterminal.com/compare/complyadvantage-vs-trulioo.md)\n- [ComplyAdvantage vs Veriff](https://www.anchorterminal.com/compare/complyadvantage-vs-veriff.md)\n- [Middesk vs Shufti](https://www.anchorterminal.com/compare/middesk-vs-shufti.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "ComplyAdvantage vs Shufti",
        "url": ""
      }
    ],
    "description": "Shufti scores 57.8 (C) on agent readiness against ComplyAdvantage's 52.6 (D), and leads in 4 of 7 scored categories. ComplyAdvantage leads on schema \u0026 documentation, agent ergonomics and security \u0026 auth. Both do kyc screening. Category scores, facts, verdicts and agent notes…",
    "facts": [
      "ComplyAdvantage D 52.6",
      "Shufti C 57.8",
      "scores"
    ],
    "h1": "ComplyAdvantage vs Shufti",
    "image": "https://www.anchorterminal.com/assets/og/compare-complyadvantage-vs-shufti.png",
    "path": "/compare/complyadvantage-vs-shufti",
    "published": "2026-10-01",
    "section": "tools",
    "title": "ComplyAdvantage vs Shufti for AI agents, D 52.6 vs C 57.8",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/complyadvantage-vs-shufti"
  },
  "tokens": {
    "markdown": 2350,
    "slim": 730
  },
  "version": 1
}
