Head to head · Kyc identity · October 2026 research run

ComplyCube vs Didit

Didit scores 75 (BB) on agent readiness against ComplyCube's 63.7 (B), and leads in 5 of 7 scored categories. Both do kyc identity.

Which one, for what

ComplyCube B

Good for An agent that creates clients, uploads documents, starts document, identity and AML screening checks and reads results for a regulated business, with low entry cost ($99 a month) and a scripted sandbox.

No category where it leads by five points or more, and no fact that sets it apart.

Watch for

One API key per environment with no scopes. The docs say keys carry many privileges

Didit BB

Good for A team that wants document, liveness, screening and business registry checks from one API with public prices and no sales step, and an agent that has to set itself up.

Ahead on

  • Schema & documentation, 88 against 78
  • Agent ergonomics, 69 against 60
  • Security & auth, 76 against 52
  • Payments & pricing, 60 against 27
  • Maintenance & community, 82 against 74

Also in its favour

  • Agent-ready, a grade of BB or better
  • Runs on your own machine
  • Free to start without a card

Watch for

Three incidents marked major on status.didit.me from 22 July to 4 September 2026, each a partial outage of the core APIs traced to the primary database

Score by category

CategoryWeight this runComplyCubeDiditEdge
Reliability16%208480ComplyCube +4
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.27888Didit +10
Agent ergonomics13%16.26069Didit +9
Security & auth14%17.55276Didit +24
Payments & pricing10%12.52760Didit +33
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87482Didit +8
Transparency & trust7%8.86363even
Negative events≤1500
Total63.7 · B75 · BB

Facts side by side

FactComplyCubeDidit
KindHTTP APIHTTP API
VendorComplyCube (Teemo Technology Ltd)Didit Identity Spain, S.L.
Hosted endpointhttps://api.complycube.comhttps://verification.didit.me
TransportsHTTPHTTP, Streamable HTTP, stdio
AuthAPI keyOAuth or key
PricingPay per usePay per use
x402nono
LicenceProprietary service under ComplyCube's terms of service. The PHP library and the web, iOS and Android SDK repositories are MIT, and @complycube/api on npm is MITProprietary service under Didit's Business Terms and Conditions. The MCP server in didit-protocol/mcp is MIT
Tools exposednone156
Read-only variant documentednono
llms.txtyesyes
MCP registrynot listedme.didit/mcp
Last release2026-10-062026-10-08
Terms last updatedno date given2026-09-23
Privacy policy last updatedno date given2026-10-07
Customer content may train modelsnot found in the textyes, with an opt-out
Terms restrict automated accessnot found in the textnot found in the text
Terms restrict benchmarkingnot found in the textyes
Terms or service can change without noticenot found in the textnot found in the text
Arbitration or class-action waivernot found in the textnot found in the text
Popularity6.2k npm/wk, 292 PyPI/wk0 stars, 27k npm/wk

Verdicts

ComplyCube

A sandbox with its own key and scripted outcomes, a public OpenAPI spec, Markdown docs and an audit log API suit an agent running verification checks. Each environment has one unscoped key, no idempotency keys were found, and the only published terms are undated and read as website terms.

Didit

A self-serve verification API with public per-check prices, key registration by API, scoped keys and a 365-day audit log. The status page shows three incidents marked major between 22 July and 4 September 2026, each a partial outage of the core APIs, and the sub-processor list isn't public.

Before you call either

ComplyCube

  1. Send the key bare in the Authorization header, with no Bearer prefix. Keys start test_ or live_
  2. Create a client first, then documents or live photos for it, then POST /v1/checks with the client and upload IDs
  3. Stay under 10 requests a second live and 5 in the sandbox. On 429, back off exponentially with jitter, starting at 30 seconds
  4. A badly formed filter returns 200 with no results, so check filter names before trusting an empty list
  5. Checks are asynchronous. Subscribe to webhooks, verify the ComplyCube-Signature HMAC-SHA256 header, and expect duplicate and out-of-order events

Didit

  1. Register with POST https://apx.didit.me/auth/v2/programmatic/register/, then verify-email with the emailed 6-character code. Use a real inbox, because reserved test domains return 500.
  2. Send the key as x-api-key to https://verification.didit.me/v3/. The JWT from registration works only on apx.didit.me.
  3. Create a workflow before POST /v3/session/. workflow_id is the only required field, and an unfinished session with the same vendor_data is returned again.
  4. Read results from webhooks and use GET /v3/session/{sessionId}/decision/ for back-fill. Every per-feature result is a plural array.
  5. The MCP server at https://mcp.didit.me/mcp takes OAuth sign-in only, never an API key. Approve didit:verification alone when the task doesn't change workflows or keys.

Questions

Which is better for AI agents, ComplyCube or Didit?

Didit scores 75 (BB) on agent readiness against ComplyCube's 63.7 (B), and leads in 5 of 7 scored categories.

Do ComplyCube and Didit need an API key?

ComplyCube needs an API key. Didit takes an API key or an OAuth sign-in.

Can an agent call ComplyCube and Didit without installing anything?

Yes. ComplyCube has a hosted endpoint at https://api.complycube.com and Didit at https://verification.didit.me.

Other comparisons with ComplyCube or Didit

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.