{
  "data": {
    "a": {
      "slug": "complycube",
      "name": "ComplyCube",
      "vendor": "ComplyCube (Teemo Technology Ltd)",
      "vendorUrl": "https://www.complycube.com",
      "kind": "http-api",
      "category": "identity-verification",
      "summary": "ComplyCube verifies people from identity documents and a liveness check, screens people and companies against sanctions, PEP and adverse media lists, and runs address and bureau checks. Agents reach it through a REST API with separate test and live keys.",
      "url": "https://www.anchorterminal.com/tools/complycube",
      "markdownUrl": "https://www.anchorterminal.com/tools/complycube.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/complycube.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/complycube.json",
      "repo": "https://github.com/complycube/complycube-php",
      "license": "Proprietary service under ComplyCube's terms of service. The PHP library and the web, iOS and Android SDK repositories are MIT, and `@complycube/api` on npm is MIT",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://api.complycube.com",
      "packages": [
        {
          "registry": "npm",
          "name": "@complycube/api"
        },
        {
          "registry": "pypi",
          "name": "complycube"
        }
      ],
      "auth": "api-key",
      "authNotes": "Every request carries an API key in the `Authorization` header, with no Bearer prefix. Each account has a test key (prefix `test_`) and a live key (prefix `live_`), created and rotated on the API keys page of the Web Portal by a signed-in Owner, Administrator or Developer. Keys have no scopes, and the docs say they carry many privileges. The live key opens when the account is activated from Test to Live in the portal. Client-side SDKs use short-lived tokens from `POST /v1/tokens` (https://docs.complycube.com/documentation/api-reference/authentication).",
      "pricing": "usage",
      "pricingNotes": "Starter is $99 a month and Core $299, each converted to credits spent per check, with further checks billed at plan rates. On Starter a document check is $1.05, standard AML screening $0.50 and a photo liveness check $0.35. Growth and Enterprise are quoted by sales. Only completed verifications are charged. The sandbox is free with a test key, and a 14-day trial of 50 checks starts on activation to Live (https://www.complycube.com/en/pricing/, checked 2026-10-08).",
      "priceSummary": "$99 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the API reference, the OpenAPI spec or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 6182,
        "pypiWeekly": 292,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.complycube.com/documentation",
      "llmsTxt": "https://docs.complycube.com/documentation/llms.txt",
      "openapi": "https://2245032618-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FkAhgmUKSf8CFUFVL3GEe%2Fuploads%2FcpxxltxmYAxOotxgEkmP%2Fcomplycube-openapi.yaml?alt=media\u0026token=aa988fe0-8ce8-431c-a69a-6657f5eacf28",
      "capabilities": [
        "kyc.identity",
        "kyc.documents",
        "kyc.screening",
        "kyc.business"
      ],
      "tags": [
        "hosted",
        "usage-based",
        "sandbox",
        "api-key",
        "openapi",
        "llms-txt",
        "webhooks",
        "status-page",
        "python",
        "typescript",
        "php",
        "dotnet",
        "iso27001",
        "soc2"
      ],
      "lastRelease": "2026-10-06",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 63.7,
        "grade": "B",
        "agentReady": false,
        "rank": 343,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 4,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 60,
          "maintenance": 74,
          "payments": 27,
          "reliability": 84,
          "schema": 78,
          "security": 52,
          "transparency": 63
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "A sandbox with its own key and scripted outcomes, a public OpenAPI spec, Markdown docs and an audit log API suit an agent running verification checks. Each environment has one unscoped key, no idempotency keys were found, and the only published terms are undated and read as website terms.",
        "bestFor": "An agent that creates clients, uploads documents, starts document, identity and AML screening checks and reads results for a regulated business, with low entry cost ($99 a month) and a scripted sandbox.",
        "strengths": [
          "Test and live environments have separate keys, and sandbox outcomes are set by test data such as a client last name of attention or failed",
          "Public OpenAPI 3.0.0 spec (version 1.7.3, 52 operations), `llms.txt`, and every docs page served as Markdown",
          "Audit log API records the team member, trigger, action and a field-level diff of old and new values",
          "Per-check prices are public for the Starter and Core plans, and failed or incomplete verifications are not charged",
          "Statuspage lists API, Web Portal and each check type for four regions, with no incident recorded since August 2022"
        ],
        "weaknesses": [
          "One API key per environment with no scopes. The docs say keys carry many privileges",
          "No idempotency keys, and no Retry-After header documented for 429 responses",
          "The only published terms are undated, read as website terms and cite the Data Protection Act 1998. No service agreement or DPA was found on a public page",
          "No `security.txt`, disclosure policy or bug bounty found, and the trust centre is drawn by script",
          "Company search, address search and redaction endpoints are in the API reference but not in the OpenAPI spec",
          "The ComplyCube MCP server serves documentation only and cannot reach account data"
        ],
        "agentNotes": [
          "Send the key bare in the `Authorization` header, with no Bearer prefix. Keys start `test_` or `live_`",
          "Create a client first, then documents or live photos for it, then `POST /v1/checks` with the client and upload IDs",
          "Stay under 10 requests a second live and 5 in the sandbox. On 429, back off exponentially with jitter, starting at 30 seconds",
          "A badly formed filter returns 200 with no results, so check filter names before trusting an empty list",
          "Checks are asynchronous. Subscribe to webhooks, verify the `ComplyCube-Signature` HMAC-SHA256 header, and expect duplicate and out-of-order events"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 63.7
          }
        ],
        "editorialScores": {
          "ergonomics": 60,
          "maintenance": 74,
          "payments": 27,
          "reliability": 84,
          "schema": 78,
          "security": 52,
          "transparency": 43
        },
        "provenanceScore": 82
      },
      "connect": {
        "install": "npm install --save @complycube/api",
        "http": "curl -X GET https://api.complycube.com/v1/clients \\\n     -H 'Authorization: \u003cYOUR_API_KEY\u003e'"
      },
      "letme": {
        "capability": "https://letme.dev/kyc.identity",
        "tool": "https://letme.dev/complycube"
      },
      "area": "domain-data",
      "unitPrices": [
        {
          "item": "Starter plan",
          "unit": "month",
          "usd": 99,
          "note": "converted to usage credits; 1,000 checks a month quota"
        },
        {
          "item": "Core plan",
          "unit": "month",
          "usd": 299,
          "note": "converted to usage credits; 8,000 checks a month quota"
        },
        {
          "item": "Document verification check, Starter",
          "unit": "tx",
          "usd": 1.05,
          "note": "per completed check; $0.75 on Core"
        },
        {
          "item": "Standard AML screening, Starter",
          "unit": "tx",
          "usd": 0.5,
          "note": "per completed check; $0.35 on Core"
        },
        {
          "item": "Extensive AML screening, Starter",
          "unit": "tx",
          "usd": 1.05,
          "note": "per completed check; $0.85 on Core"
        },
        {
          "item": "Liveness and facial similarity check (photo), Starter",
          "unit": "tx",
          "usd": 0.35,
          "note": "per completed check; $0.20 on Core"
        }
      ],
      "provenance": {
        "legalEntity": "Teemo Technology Ltd",
        "domain": "complycube.com",
        "domainRegistered": "2018-05-24",
        "endpointOnVendorDomain": true,
        "terms": "https://www.complycube.com/en/terms-of-service/",
        "privacy": "https://www.complycube.com/en/privacy-policy/",
        "statusPage": "https://status.complycube.com",
        "changelog": "https://docs.complycube.com/documentation/changelog",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The privacy policy gives ComplyCube as the trading name of TEEMO TECHNOLOGY LTD, company number 12392069, Crown House, 27 Old Gloucester Street, London WC1N 3AX. The terms of service name only ComplyCube, registered in England and Wales, at that address.",
          "The terms of service are the only terms published. They define the Services to include ComplyCube's data and software services, but are written around website use, carry no date and cite the Data Protection Act 1998. No separate service agreement or DPA was found on a public page.",
          "The privacy policy covers the website and the Service and carries no date.",
          "The API answers at api.complycube.com, the Web Portal at portal.complycube.com and the docs at docs.complycube.com.",
          "www.complycube.com/.well-known/security.txt redirects to a 404 page, and api.complycube.com returns 403 for the same path.",
          "RDAP for complycube.com gives a registration date of 2018-05-24."
        ],
        "score": 82
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/complycube.json",
      "live": {
        "slug": "complycube",
        "probe": {
          "target": "https://api.complycube.com",
          "method": "get",
          "lastAt": "2026-10-09T11:46:25.821386733Z",
          "lastOk": true,
          "lastStatus": 403,
          "lastMs": 33,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 32,
          "p95ms24h": 64,
          "samples24h": 175,
          "samples30d": 175,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 50,
              "ok": 50
            },
            {
              "date": "2026-10-09",
              "probes": 125,
              "ok": 125
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.complycube.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-09T09:58:36.217074829Z"
        },
        "updatedAt": "2026-10-09T11:46:25.821386733Z"
      }
    },
    "answer": "ComplyCube scores 63.7 (B) on agent readiness against Shufti's 57.8 (C), and leads in 4 of 7 scored categories. Shufti leads on security \u0026 auth, payments \u0026 pricing and transparency \u0026 trust.",
    "b": {
      "slug": "shufti",
      "name": "Shufti",
      "vendor": "Shufti Pro Limited",
      "vendorUrl": "https://shuftipro.com",
      "kind": "http-api",
      "category": "identity-verification",
      "summary": "Identity and business verification service from Shufti Pro Limited in London. One REST endpoint runs document, face, address, AML screening and KYB checks chosen in the request body, with results by callback. A hosted MCP server exposes 25 tools.",
      "url": "https://www.anchorterminal.com/tools/shufti",
      "markdownUrl": "https://www.anchorterminal.com/tools/shufti.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/shufti.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/shufti.json",
      "repo": "https://github.com/shuftipro/iOS-SDK",
      "license": "Proprietary service under Shufti's Terms and Conditions. The licences of the mobile capture SDKs were not checked",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.shuftipro.com",
      "packages": [
        {
          "registry": "npm",
          "name": "shuftipro-onsite-mobilesdk"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve. Signing up creates a back office account, and the Client ID and Secret Key come from Settings, API Configuration, API Keys. The REST API takes them as HTTP Basic auth, or a Bearer access token from `/get/access/token` that lasts one hour. The key pair has no scopes, and the Secret Key is shown once and replaced by generating a new one. The MCP server uses OAuth 2.1 with PKCE and dynamic client registration. Its login page asks for the same Client ID and Secret Key, and it issues tokens with the scopes `knowledge:read`, `verification:read` and `verification:write`. Callback and redirect domains must be registered in the back office.",
      "pricing": "freemium",
      "pricingNotes": "Free Forever covers up to 10 verifications a month with no card, on the production environment. Essentials starts from $1.50 a verification, pay as you go with no monthly minimum, up to 20,000 verifications. Enterprise is quoted by sales and adds e-IDV, Travel Rule, video KYC and other services. The pricing page says only successful verification attempts are billed and resubmissions are free. Trial accounts accept test ID samples (https://shuftipro.com/pricing/, checked 2026-10-09).",
      "priceSummary": "$1.50 / tx",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the developer docs (llms-full.txt), the pricing page or the terms (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": 25,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 673,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://developers.shuftipro.com/docs/get_started",
      "llmsTxt": "https://developers.shuftipro.com/llms.txt",
      "capabilities": [
        "kyc.identity",
        "kyc.documents",
        "kyc.business",
        "kyc.screening"
      ],
      "tags": [
        "hosted",
        "api-key",
        "oauth",
        "mcp",
        "webhooks",
        "llms-txt",
        "free-tier",
        "no-card",
        "status-page",
        "sla",
        "soc2",
        "iso27001"
      ],
      "lastRelease": "2026-10-06",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 57.8,
        "grade": "C",
        "agentReady": false,
        "rank": 538,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 9,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 47,
          "maintenance": 72,
          "payments": 35,
          "reliability": 65,
          "schema": 58,
          "security": 62,
          "transparency": 71
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": 0,
        "verdict": "One endpoint covers document, face, address, AML and KYB checks, with a free plan of 10 verifications a month, and a hosted MCP server adds OAuth with three scopes. No OpenAPI file, server SDK or idempotency key was found, and the status page history could not be read.",
        "bestFor": "A team that wants document, face, address, AML and KYB checks behind one endpoint, a free plan for low volume, and an MCP server that hands the person a hosted verification link.",
        "strengths": [
          "Free Forever plan of 10 verifications a month with no card, on the production environment, per the pricing page",
          "Hosted MCP server at `https://ai.shuftipro.com/mcp` with 25 tools, OAuth 2.1 with PKCE and three scopes enforced on every call",
          "Docs published as llms.txt, a 2.9 MB llms-full.txt and a Markdown twin of each page, with samples in nine languages",
          "Public terms (version 11.1, 13 May 2026) include an availability schedule targeting 99 per cent monthly uptime",
          "Revision history with 19 dated entries between 24 July and 6 October 2026"
        ],
        "weaknesses": [
          "No OpenAPI file or other machine-readable contract was found. The reference is prose tables plus Postman collections",
          "The REST credential is one Client ID and Secret Key pair with no scopes, sent as Basic auth on every call",
          "No idempotency key, Retry-After header or backoff guidance was found for the documented 429",
          "No server-side SDK. Official packages cover Android, iOS, Flutter, React Native and Cordova capture only",
          "Standard KYB was deprecated on 6 October 2026 and its pages removed the same day, with no notice period stated",
          "The sub-processor list is available to clients on request only, and security.txt returns 404"
        ],
        "agentNotes": [
          "POST every verification to `https://api.shuftipro.com/` with a unique `reference` of 6 to 250 characters and one object per service. Read results from `/status` with that reference",
          "Register the callback domain in the back office first. An unregistered `callback_url` is rejected",
          "Stay under 60 requests a minute per IP on a production account and 20 on a trial account",
          "Check the `Signature` response header. Accounts created after 15 March 2023 hash the Secret Key with SHA-256 before appending it to the raw response",
          "Through MCP, identity checks return a `verification_url` for the person to open. No tool accepts an image, so use the REST API for offsite proofs"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 57.8
          }
        ],
        "editorialScores": {
          "ergonomics": 47,
          "maintenance": 72,
          "payments": 35,
          "reliability": 65,
          "schema": 58,
          "security": 62,
          "transparency": 51
        },
        "provenanceScore": 90
      },
      "connect": {
        "http": "curl --location --request POST 'https://api.shuftipro.com' \\\n--header 'Content-Type: application/json' \\\n--header 'Authorization: Basic \u003cbase64 of CLIENT_ID:SECRET_KEY\u003e' \\\n--data-raw '{\n    \"reference\"    : \"1234567\",\n    \"callback_url\" : \"https://yourdomain.com/profile/notifyCallback\",\n    \"country\"      : \"GB\",\n    \"language\"     : \"EN\",\n    \"verification_mode\" : \"any\",\n    \"face\" : {\n        \"proof\"            : \"\"\n    }\n}'",
        "claudeCode": "claude mcp add --transport http shufti https://ai.shuftipro.com/mcp",
        "config": {
          "mcpServers": {
            "shufti": {
              "args": [
                "mcp-remote",
                "https://ai.shuftipro.com/mcp"
              ],
              "command": "npx"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/kyc.identity",
        "tool": "https://letme.dev/shufti"
      },
      "area": "domain-data",
      "unitPrices": [
        {
          "item": "Verification, Free Forever plan (document and face checks)",
          "unit": "tx",
          "usd": 0,
          "note": "up to 10 verifications a month, no card"
        },
        {
          "item": "Verification, Essentials plan, starting price",
          "unit": "tx",
          "usd": 1.5,
          "note": "rate depends on volume and the services chosen, up to 20,000 verifications"
        }
      ],
      "provenance": {
        "legalEntity": "Shufti Pro Limited",
        "domain": "shuftipro.com",
        "domainRegistered": "2016-06-28",
        "endpointOnVendorDomain": true,
        "terms": "https://shuftipro.com/wp-content/uploads/Version-11.1-w.e.f.-May-13th-2026.pdf",
        "privacy": "https://shuftipro.com/services-privacy-notice/",
        "statusPage": "https://status.shuftipro.com",
        "changelog": "https://developers.shuftipro.com/docs/revision_history",
        "securityTxt": "none",
        "checked": "2026-10-09",
        "notes": [
          "The terms and the MCP privacy notice name Shufti Pro Limited, Office 408 Coppergate House, 10 Whites Row, London E1 7NF.",
          "The governing terms are a PDF, version 11.1, linked from shuftipro.com/terms-and-conditions/, which itself carries only a summary and links to every earlier version. The page labels the file 12 May 2026 and the file name says 13 May.",
          "The privacy link is the Services Privacy Notice, version 1.2, last updated September 2026, which covers verification data. A separate notice covers the website.",
          "shuftipro.com/.well-known/security.txt answered 502 on the first request and 404 on the second.",
          "RDAP for shuftipro.com gives a registration date of 2016-06-28.",
          "The API answers at api.shuftipro.com and the MCP server at ai.shuftipro.com. The lead's shufti.ai is a parked domain for sale and unrelated to the vendor.",
          "status.shuftipro.com is an UptimeRobot page whose data loads from /api/, a path its robots.txt disallows, so the incident history was not read."
        ],
        "score": 90
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/shufti.json",
      "live": {
        "slug": "shufti",
        "probe": {
          "target": "https://api.shuftipro.com",
          "method": "get",
          "lastAt": "2026-10-09T11:46:40.498968542Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 347,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 321,
          "p95ms24h": 367,
          "samples24h": 44,
          "samples30d": 44,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 44,
              "ok": 44
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.shuftipro.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-09T07:58:32.112017753Z"
        },
        "updatedAt": "2026-10-09T11:46:40.498968542Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "ComplyCube (Teemo Technology Ltd)",
        "b": "Shufti Pro Limited",
        "name": "Vendor"
      },
      {
        "a": "https://api.complycube.com",
        "b": "https://api.shuftipro.com",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "API key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Pay per use",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under ComplyCube's terms of service. The PHP library and the web, iOS and Android SDK repositories are MIT, and `@complycube/api` on npm is MIT",
        "b": "Proprietary service under Shufti's Terms and Conditions. The licences of the mobile capture SDKs were not checked",
        "name": "Licence"
      },
      {
        "a": "none",
        "b": "25",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-06",
        "b": "2026-10-06",
        "name": "Last release"
      },
      {
        "a": "no date given",
        "b": "",
        "name": "Terms last updated"
      },
      {
        "a": "no date given",
        "b": "2026-09-01",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "yes, with an opt-out",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Terms restrict automated access"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "6.2k npm/wk, 292 PyPI/wk",
        "b": "673 npm/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "ComplyCube scores 63.7 (B) on agent readiness against Shufti's 57.8 (C), and leads in 4 of 7 scored categories. Shufti leads on security \u0026 auth, payments \u0026 pricing and transparency \u0026 trust.",
        "question": "Which is better for AI agents, ComplyCube or Shufti?"
      },
      {
        "answer": "ComplyCube needs an API key. Shufti takes an API key or an OAuth sign-in.",
        "question": "Do ComplyCube and Shufti need an API key?"
      },
      {
        "answer": "Yes. ComplyCube has a hosted endpoint at https://api.complycube.com and Shufti at https://api.shuftipro.com.",
        "question": "Can an agent call ComplyCube and Shufti without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 84 against 65",
          "Schema \u0026 documentation, 78 against 58",
          "Agent ergonomics, 60 against 47"
        ],
        "also": null,
        "goodFor": "An agent that creates clients, uploads documents, starts document, identity and AML screening checks and reads results for a regulated business, with low entry cost ($99 a month) and a scripted sandbox.",
        "slug": "complycube",
        "watchFor": "One API key per environment with no scopes. The docs say keys carry many privileges"
      },
      {
        "aheadOn": [
          "Security \u0026 auth, 62 against 52",
          "Payments \u0026 pricing, 35 against 27",
          "Transparency \u0026 trust, 71 against 63"
        ],
        "also": [
          "Free to start without a card"
        ],
        "goodFor": "A team that wants document, face, address, AML and KYB checks behind one endpoint, a free plan for low volume, and an MCP server that hands the person a hosted verification link.",
        "slug": "shufti",
        "watchFor": "No OpenAPI file or other machine-readable contract was found. The reference is prose tables plus Postman collections"
      }
    ],
    "job": {
      "capability": "kyc.identity",
      "name": "Kyc identity"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/complycube-vs-didit.json",
        "title": "ComplyCube vs Didit",
        "url": "https://www.anchorterminal.com/compare/complycube-vs-didit"
      },
      {
        "json": "https://www.anchorterminal.com/compare/complycube-vs-jumio.json",
        "title": "ComplyCube vs Jumio",
        "url": "https://www.anchorterminal.com/compare/complycube-vs-jumio"
      },
      {
        "json": "https://www.anchorterminal.com/compare/complycube-vs-middesk.json",
        "title": "ComplyCube vs Middesk",
        "url": "https://www.anchorterminal.com/compare/complycube-vs-middesk"
      },
      {
        "json": "https://www.anchorterminal.com/compare/complycube-vs-persona.json",
        "title": "ComplyCube vs Persona",
        "url": "https://www.anchorterminal.com/compare/complycube-vs-persona"
      },
      {
        "json": "https://www.anchorterminal.com/compare/complycube-vs-socure-riskos.json",
        "title": "ComplyCube vs Socure RiskOS",
        "url": "https://www.anchorterminal.com/compare/complycube-vs-socure-riskos"
      },
      {
        "json": "https://www.anchorterminal.com/compare/complycube-vs-sumsub.json",
        "title": "ComplyCube vs Sumsub",
        "url": "https://www.anchorterminal.com/compare/complycube-vs-sumsub"
      },
      {
        "json": "https://www.anchorterminal.com/compare/complycube-vs-trulioo.json",
        "title": "ComplyCube vs Trulioo",
        "url": "https://www.anchorterminal.com/compare/complycube-vs-trulioo"
      },
      {
        "json": "https://www.anchorterminal.com/compare/complycube-vs-veriff.json",
        "title": "ComplyCube vs Veriff",
        "url": "https://www.anchorterminal.com/compare/complycube-vs-veriff"
      },
      {
        "json": "https://www.anchorterminal.com/compare/didit-vs-shufti.json",
        "title": "Didit vs Shufti",
        "url": "https://www.anchorterminal.com/compare/didit-vs-shufti"
      },
      {
        "json": "https://www.anchorterminal.com/compare/jumio-vs-shufti.json",
        "title": "Jumio vs Shufti",
        "url": "https://www.anchorterminal.com/compare/jumio-vs-shufti"
      },
      {
        "json": "https://www.anchorterminal.com/compare/persona-vs-shufti.json",
        "title": "Persona vs Shufti",
        "url": "https://www.anchorterminal.com/compare/persona-vs-shufti"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shufti-vs-socure-riskos.json",
        "title": "Shufti vs Socure RiskOS",
        "url": "https://www.anchorterminal.com/compare/shufti-vs-socure-riskos"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shufti-vs-sumsub.json",
        "title": "Shufti vs Sumsub",
        "url": "https://www.anchorterminal.com/compare/shufti-vs-sumsub"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shufti-vs-trulioo.json",
        "title": "Shufti vs Trulioo",
        "url": "https://www.anchorterminal.com/compare/shufti-vs-trulioo"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shufti-vs-veriff.json",
        "title": "Shufti vs Veriff",
        "url": "https://www.anchorterminal.com/compare/shufti-vs-veriff"
      },
      {
        "json": "https://www.anchorterminal.com/compare/complyadvantage-vs-complycube.json",
        "title": "ComplyAdvantage vs ComplyCube",
        "url": "https://www.anchorterminal.com/compare/complyadvantage-vs-complycube"
      },
      {
        "json": "https://www.anchorterminal.com/compare/complyadvantage-vs-shufti.json",
        "title": "ComplyAdvantage vs Shufti",
        "url": "https://www.anchorterminal.com/compare/complyadvantage-vs-shufti"
      },
      {
        "json": "https://www.anchorterminal.com/compare/middesk-vs-shufti.json",
        "title": "Middesk vs Shufti",
        "url": "https://www.anchorterminal.com/compare/middesk-vs-shufti"
      }
    ],
    "scores": [
      {
        "by": 19,
        "complycube": 84,
        "edge": "complycube",
        "key": "reliability",
        "name": "Reliability",
        "shufti": 65,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 20,
        "complycube": 78,
        "edge": "complycube",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "shufti": 58,
        "weight": 13
      },
      {
        "by": 13,
        "complycube": 60,
        "edge": "complycube",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "shufti": 47,
        "weight": 13
      },
      {
        "by": 10,
        "complycube": 52,
        "edge": "shufti",
        "key": "security",
        "name": "Security \u0026 auth",
        "shufti": 62,
        "weight": 14
      },
      {
        "by": 8,
        "complycube": 27,
        "edge": "shufti",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "shufti": 35,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 2,
        "complycube": 74,
        "edge": "complycube",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "shufti": 72,
        "weight": 7
      },
      {
        "by": 8,
        "complycube": 63,
        "edge": "shufti",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "shufti": 71,
        "weight": 7
      }
    ],
    "summary": "ComplyCube scores 63.7 (B) on agent readiness against Shufti's 57.8 (C), and leads in 4 of 7 scored categories. Shufti leads on security \u0026 auth, payments \u0026 pricing and transparency \u0026 trust. Both do kyc identity.",
    "verdicts": {
      "complycube": "A sandbox with its own key and scripted outcomes, a public OpenAPI spec, Markdown docs and an audit log API suit an agent running verification checks. Each environment has one unscoped key, no idempotency keys were found, and the only published terms are undated and read as website terms.",
      "shufti": "One endpoint covers document, face, address, AML and KYB checks, with a free plan of 10 verifications a month, and a hosted MCP server adds OAuth with three scopes. No OpenAPI file, server SDK or idempotency key was found, and the status page history could not be read."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/complycube-vs-shufti",
    "json": "https://www.anchorterminal.com/compare/complycube-vs-shufti.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/complycube-vs-shufti.md",
    "slim": "https://www.anchorterminal.com/compare/complycube-vs-shufti.min.md"
  },
  "markdown": "ComplyCube scores 63.7 (B) on agent readiness against Shufti's 57.8 (C), and leads in 4 of 7 scored categories. Shufti leads on security \u0026 auth, payments \u0026 pricing and transparency \u0026 trust. Both do kyc identity.\n\n- ComplyCube: grade B, 63.7/100, rank #343 of 842. Markdown https://www.anchorterminal.com/tools/complycube.md · JSON https://www.anchorterminal.com/api/v1/tools/complycube.json\n- Shufti: grade C, 57.8/100, rank #538 of 842. Markdown https://www.anchorterminal.com/tools/shufti.md · JSON https://www.anchorterminal.com/api/v1/tools/shufti.json\n\n## Which one, for what\n\n### ComplyCube (B)\n\nGood for: An agent that creates clients, uploads documents, starts document, identity and AML screening checks and reads results for a regulated business, with low entry cost ($99 a month) and a scripted sandbox.\n\nAhead on:\n- Reliability, 84 against 65\n- Schema \u0026 documentation, 78 against 58\n- Agent ergonomics, 60 against 47\n\nWatch for: One API key per environment with no scopes. The docs say keys carry many privileges\n\n### Shufti (C)\n\nGood for: A team that wants document, face, address, AML and KYB checks behind one endpoint, a free plan for low volume, and an MCP server that hands the person a hosted verification link.\n\nAhead on:\n- Security \u0026 auth, 62 against 52\n- Payments \u0026 pricing, 35 against 27\n- Transparency \u0026 trust, 71 against 63\n\nAlso in its favour:\n- Free to start without a card\n\nWatch for: No OpenAPI file or other machine-readable contract was found. The reference is prose tables plus Postman collections\n\n\n## Score by category\n\n| Category | Weight | ComplyCube | Shufti | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 84 | 65 | ComplyCube +19 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 78 | 58 | ComplyCube +20 |\n| Agent ergonomics | 13% (16.2 this run) | 60 | 47 | ComplyCube +13 |\n| Security \u0026 auth | 14% (17.5 this run) | 52 | 62 | Shufti +10 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 27 | 35 | Shufti +8 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 74 | 72 | ComplyCube +2 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 63 | 71 | Shufti +8 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **63.7 · B** | **57.8 · C** | |\n\n## Facts side by side\n\n| Fact | ComplyCube | Shufti |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | ComplyCube (Teemo Technology Ltd) | Shufti Pro Limited |\n| Hosted endpoint | `https://api.complycube.com` | `https://api.shuftipro.com` |\n| Transports | HTTP | HTTP, Streamable HTTP |\n| Auth | API key | OAuth or key |\n| Pricing | Pay per use | Freemium |\n| x402 | no | no |\n| Licence | Proprietary service under ComplyCube's terms of service. The PHP library and the web, iOS and Android SDK repositories are MIT, and `@complycube/api` on npm is MIT | Proprietary service under Shufti's Terms and Conditions. The licences of the mobile capture SDKs were not checked |\n| Tools exposed | none | 25 |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| Last release | 2026-10-06 | 2026-10-06 |\n| Terms last updated | no date given |  |\n| Privacy policy last updated | no date given | 2026-09-01 |\n| Customer content may train models | not found in the text | yes, with an opt-out |\n| Terms restrict automated access | not found in the text |  |\n| Terms restrict benchmarking | not found in the text |  |\n| Terms or service can change without notice | not found in the text |  |\n| Arbitration or class-action waiver | not found in the text |  |\n| Popularity | 6.2k npm/wk, 292 PyPI/wk | 673 npm/wk |\n\n## Verdicts\n\n**ComplyCube.** A sandbox with its own key and scripted outcomes, a public OpenAPI spec, Markdown docs and an audit log API suit an agent running verification checks. Each environment has one unscoped key, no idempotency keys were found, and the only published terms are undated and read as website terms.\n\n**Shufti.** One endpoint covers document, face, address, AML and KYB checks, with a free plan of 10 verifications a month, and a hosted MCP server adds OAuth with three scopes. No OpenAPI file, server SDK or idempotency key was found, and the status page history could not be read.\n\n## Before you call either\n\n### ComplyCube\n\n1. Send the key bare in the `Authorization` header, with no Bearer prefix. Keys start `test_` or `live_`\n2. Create a client first, then documents or live photos for it, then `POST /v1/checks` with the client and upload IDs\n3. Stay under 10 requests a second live and 5 in the sandbox. On 429, back off exponentially with jitter, starting at 30 seconds\n4. A badly formed filter returns 200 with no results, so check filter names before trusting an empty list\n5. Checks are asynchronous. Subscribe to webhooks, verify the `ComplyCube-Signature` HMAC-SHA256 header, and expect duplicate and out-of-order events\n\n### Shufti\n\n1. POST every verification to `https://api.shuftipro.com/` with a unique `reference` of 6 to 250 characters and one object per service. Read results from `/status` with that reference\n2. Register the callback domain in the back office first. An unregistered `callback_url` is rejected\n3. Stay under 60 requests a minute per IP on a production account and 20 on a trial account\n4. Check the `Signature` response header. Accounts created after 15 March 2023 hash the Secret Key with SHA-256 before appending it to the raw response\n5. Through MCP, identity checks return a `verification_url` for the person to open. No tool accepts an image, so use the REST API for offsite proofs\n\n## Questions\n\n### Which is better for AI agents, ComplyCube or Shufti?\n\nComplyCube scores 63.7 (B) on agent readiness against Shufti's 57.8 (C), and leads in 4 of 7 scored categories. Shufti leads on security \u0026 auth, payments \u0026 pricing and transparency \u0026 trust.\n\n### Do ComplyCube and Shufti need an API key?\n\nComplyCube needs an API key. Shufti takes an API key or an OAuth sign-in.\n\n### Can an agent call ComplyCube and Shufti without installing anything?\n\nYes. ComplyCube has a hosted endpoint at https://api.complycube.com and Shufti at https://api.shuftipro.com.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/complycube-vs-shufti.json, and with the fewest tokens: https://www.anchorterminal.com/compare/complycube-vs-shufti.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"complycube\", \"b\": \"shufti\"}`. From a terminal: `anchor compare complycube shufti`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/complycube.json and https://www.anchorterminal.com/api/v1/tools/shufti.json\n\n## Other comparisons with ComplyCube or Shufti\n\n- [ComplyCube vs Didit](https://www.anchorterminal.com/compare/complycube-vs-didit.md)\n- [ComplyCube vs Jumio](https://www.anchorterminal.com/compare/complycube-vs-jumio.md)\n- [ComplyCube vs Middesk](https://www.anchorterminal.com/compare/complycube-vs-middesk.md)\n- [ComplyCube vs Persona](https://www.anchorterminal.com/compare/complycube-vs-persona.md)\n- [ComplyCube vs Socure RiskOS](https://www.anchorterminal.com/compare/complycube-vs-socure-riskos.md)\n- [ComplyCube vs Sumsub](https://www.anchorterminal.com/compare/complycube-vs-sumsub.md)\n- [ComplyCube vs Trulioo](https://www.anchorterminal.com/compare/complycube-vs-trulioo.md)\n- [ComplyCube vs Veriff](https://www.anchorterminal.com/compare/complycube-vs-veriff.md)\n- [Didit vs Shufti](https://www.anchorterminal.com/compare/didit-vs-shufti.md)\n- [Jumio vs Shufti](https://www.anchorterminal.com/compare/jumio-vs-shufti.md)\n- [Persona vs Shufti](https://www.anchorterminal.com/compare/persona-vs-shufti.md)\n- [Shufti vs Socure RiskOS](https://www.anchorterminal.com/compare/shufti-vs-socure-riskos.md)\n- [Shufti vs Sumsub](https://www.anchorterminal.com/compare/shufti-vs-sumsub.md)\n- [Shufti vs Trulioo](https://www.anchorterminal.com/compare/shufti-vs-trulioo.md)\n- [Shufti vs Veriff](https://www.anchorterminal.com/compare/shufti-vs-veriff.md)\n- [ComplyAdvantage vs ComplyCube](https://www.anchorterminal.com/compare/complyadvantage-vs-complycube.md)\n- [ComplyAdvantage vs Shufti](https://www.anchorterminal.com/compare/complyadvantage-vs-shufti.md)\n- [Middesk vs Shufti](https://www.anchorterminal.com/compare/middesk-vs-shufti.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "ComplyCube vs Shufti",
        "url": ""
      }
    ],
    "description": "ComplyCube scores 63.7 (B) on agent readiness against Shufti's 57.8 (C), and leads in 4 of 7 scored categories. Shufti leads on security \u0026 auth, payments \u0026 pricing and transparency \u0026 trust. Both do kyc identity. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "ComplyCube B 63.7",
      "Shufti C 57.8",
      "scores"
    ],
    "h1": "ComplyCube vs Shufti",
    "image": "https://www.anchorterminal.com/assets/og/compare-complycube-vs-shufti.png",
    "path": "/compare/complycube-vs-shufti",
    "published": "2026-10-01",
    "section": "tools",
    "title": "ComplyCube vs Shufti for AI agents, B 63.7 vs C 57.8 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/complycube-vs-shufti"
  },
  "tokens": {
    "markdown": 2250,
    "slim": 780
  },
  "version": 1
}
