Head to head · Kyc identity · October 2026 research run

ComplyCube vs Shufti

ComplyCube scores 63.7 (B) on agent readiness against Shufti's 57.8 (C), and leads in 4 of 7 scored categories. Shufti leads on security & auth, payments & pricing and transparency & trust. Both do kyc identity.

Which one, for what

ComplyCube B

Good for An agent that creates clients, uploads documents, starts document, identity and AML screening checks and reads results for a regulated business, with low entry cost ($99 a month) and a scripted sandbox.

Ahead on

  • Reliability, 84 against 65
  • Schema & documentation, 78 against 58
  • Agent ergonomics, 60 against 47

Watch for

One API key per environment with no scopes. The docs say keys carry many privileges

Shufti C

Good for A team that wants document, face, address, AML and KYB checks behind one endpoint, a free plan for low volume, and an MCP server that hands the person a hosted verification link.

Ahead on

  • Security & auth, 62 against 52
  • Payments & pricing, 35 against 27
  • Transparency & trust, 71 against 63

Also in its favour

  • Free to start without a card

Watch for

No OpenAPI file or other machine-readable contract was found. The reference is prose tables plus Postman collections

Score by category

CategoryWeight this runComplyCubeShuftiEdge
Reliability16%208465ComplyCube +19
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.27858ComplyCube +20
Agent ergonomics13%16.26047ComplyCube +13
Security & auth14%17.55262Shufti +10
Payments & pricing10%12.52735Shufti +8
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87472ComplyCube +2
Transparency & trust7%8.86371Shufti +8
Negative events≤1500
Total63.7 · B57.8 · C

Facts side by side

FactComplyCubeShufti
KindHTTP APIHTTP API
VendorComplyCube (Teemo Technology Ltd)Shufti Pro Limited
Hosted endpointhttps://api.complycube.comhttps://api.shuftipro.com
TransportsHTTPHTTP, Streamable HTTP
AuthAPI keyOAuth or key
PricingPay per useFreemium
x402nono
LicenceProprietary service under ComplyCube's terms of service. The PHP library and the web, iOS and Android SDK repositories are MIT, and @complycube/api on npm is MITProprietary service under Shufti's Terms and Conditions. The licences of the mobile capture SDKs were not checked
Tools exposednone25
Read-only variant documentednono
llms.txtyesyes
Last release2026-10-062026-10-06
Terms last updatedno date given
Privacy policy last updatedno date given2026-09-01
Customer content may train modelsnot found in the textyes, with an opt-out
Terms restrict automated accessnot found in the text
Terms restrict benchmarkingnot found in the text
Terms or service can change without noticenot found in the text
Arbitration or class-action waivernot found in the text
Popularity6.2k npm/wk, 292 PyPI/wk673 npm/wk

Verdicts

ComplyCube

A sandbox with its own key and scripted outcomes, a public OpenAPI spec, Markdown docs and an audit log API suit an agent running verification checks. Each environment has one unscoped key, no idempotency keys were found, and the only published terms are undated and read as website terms.

Shufti

One endpoint covers document, face, address, AML and KYB checks, with a free plan of 10 verifications a month, and a hosted MCP server adds OAuth with three scopes. No OpenAPI file, server SDK or idempotency key was found, and the status page history could not be read.

Before you call either

ComplyCube

  1. Send the key bare in the Authorization header, with no Bearer prefix. Keys start test_ or live_
  2. Create a client first, then documents or live photos for it, then POST /v1/checks with the client and upload IDs
  3. Stay under 10 requests a second live and 5 in the sandbox. On 429, back off exponentially with jitter, starting at 30 seconds
  4. A badly formed filter returns 200 with no results, so check filter names before trusting an empty list
  5. Checks are asynchronous. Subscribe to webhooks, verify the ComplyCube-Signature HMAC-SHA256 header, and expect duplicate and out-of-order events

Shufti

  1. POST every verification to https://api.shuftipro.com/ with a unique reference of 6 to 250 characters and one object per service. Read results from /status with that reference
  2. Register the callback domain in the back office first. An unregistered callback_url is rejected
  3. Stay under 60 requests a minute per IP on a production account and 20 on a trial account
  4. Check the Signature response header. Accounts created after 15 March 2023 hash the Secret Key with SHA-256 before appending it to the raw response
  5. Through MCP, identity checks return a verification_url for the person to open. No tool accepts an image, so use the REST API for offsite proofs

Questions

Which is better for AI agents, ComplyCube or Shufti?

ComplyCube scores 63.7 (B) on agent readiness against Shufti's 57.8 (C), and leads in 4 of 7 scored categories. Shufti leads on security & auth, payments & pricing and transparency & trust.

Do ComplyCube and Shufti need an API key?

ComplyCube needs an API key. Shufti takes an API key or an OAuth sign-in.

Can an agent call ComplyCube and Shufti without installing anything?

Yes. ComplyCube has a hosted endpoint at https://api.complycube.com and Shufti at https://api.shuftipro.com.

Other comparisons with ComplyCube or Shufti

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.