Head to head · Kyc identity · October 2026 research run

ComplyCube vs Veriff

ComplyCube scores 63.7 (B) on agent readiness against Veriff's 61.1 (C), and leads in 2 of 7 scored categories. Veriff leads on security & auth and payments & pricing. Both do kyc identity.

Which one, for what

ComplyCube B

Good for An agent that creates clients, uploads documents, starts document, identity and AML screening checks and reads results for a regulated business, with low entry cost ($99 a month) and a scripted sandbox.

Ahead on

  • Reliability, 84 against 62
  • Agent ergonomics, 60 against 43

Also in its favour

  • A hosted endpoint, with nothing to install

Watch for

One API key per environment with no scopes. The docs say keys carry many privileges

Veriff C

Good for A team that needs document and selfie verification with public per-verification prices and a trial, and that can run a webhook receiver and HMAC signing.

Ahead on

  • Security & auth, 63 against 52
  • Payments & pricing, 40 against 27

Watch for

No server-side SDK and no MCP server. Official packages cover only browser and mobile capture

Score by category

CategoryWeight this runComplyCubeVeriffEdge
Reliability16%208462ComplyCube +22
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.27882Veriff +4
Agent ergonomics13%16.26043ComplyCube +17
Security & auth14%17.55263Veriff +11
Payments & pricing10%12.52740Veriff +13
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87474even
Transparency & trust7%8.86367Veriff +4
Negative events≤1500
Total63.7 · B61.1 · C

Facts side by side

FactComplyCubeVeriff
KindHTTP APIHTTP API
VendorComplyCube (Teemo Technology Ltd)Veriff OÜ
Hosted endpointhttps://api.complycube.comno (local only)
TransportsHTTPHTTP
AuthAPI keyAPI key
PricingPay per usePay per use
x402nono
LicenceProprietary service under ComplyCube's terms of service. The PHP library and the web, iOS and Android SDK repositories are MIT, and @complycube/api on npm is MITProprietary service. The npm capture SDKs are ISC (@veriff/js-sdk, @veriff/incontext-sdk) and MIT (@veriff/react-native-sdk)
Read-only variant documentednono
llms.txtyesyes
Last release2026-10-062026-10-02
Terms last updatedno date givencouldn't be read
Privacy policy last updatedno date given2026-04-16
Customer content may train modelsnot found in the textyes
Terms restrict automated accessnot found in the textcouldn't be read
Terms restrict benchmarkingnot found in the textcouldn't be read
Terms or service can change without noticenot found in the textcouldn't be read
Arbitration or class-action waivernot found in the textcouldn't be read
Popularity6.2k npm/wk, 292 PyPI/wk32 stars, 110k npm/wk

Verdicts

ComplyCube

A sandbox with its own key and scripted outcomes, a public OpenAPI spec, Markdown docs and an audit log API suit an agent running verification checks. Each environment has one unscoped key, no idempotency keys were found, and the only published terms are undated and read as website terms.

Veriff

Per-verification prices are public from $0.80, with a 15-day trial of 50 sessions and no card. Each endpoint page is Markdown with an OpenAPI 3.0 fragment. There is no server SDK, MCP server or idempotency key, most calls need an HMAC signature, and the status page shows nine incidents between 20 July and 7 October 2026.

Before you call either

ComplyCube

  1. Send the key bare in the Authorization header, with no Bearer prefix. Keys start test_ or live_
  2. Create a client first, then documents or live photos for it, then POST /v1/checks with the client and upload IDs
  3. Stay under 10 requests a second live and 5 in the sandbox. On 429, back off exponentially with jitter, starting at 30 seconds
  4. A badly formed filter returns 200 with no results, so check filter names before trusting an empty list
  5. Checks are asynchronous. Subscribe to webhooks, verify the ComplyCube-Signature HMAC-SHA256 header, and expect duplicate and out-of-order events

Veriff

  1. Take the base URL from the integration's API keys page. Send X-AUTH-CLIENT on every call and store verification.id from POST /v1/sessions
  2. Sign POST and PATCH bodies, and the session ID on GET and DELETE, with HMAC-SHA256 in X-HMAC-SIGNATURE. POST /v1/sessions needs no signature
  3. Stay under 30 session creations a minute on Self-Serve, 600 on Enterprise. A 429 carries code 1004
  4. Don't blindly retry POST /v1/sessions. Each call makes a new session, which is billed on a live integration
  5. Poll GET /v1/sessions/{id}/decision until verification is not null, or accept webhooks within 5 seconds and treat duplicates as normal

Questions

Which is better for AI agents, ComplyCube or Veriff?

ComplyCube scores 63.7 (B) on agent readiness against Veriff's 61.1 (C), and leads in 2 of 7 scored categories. Veriff leads on security & auth and payments & pricing.

Do ComplyCube and Veriff need an API key?

Both need an API key.

Can an agent call ComplyCube and Veriff without installing anything?

ComplyCube has a hosted endpoint at https://api.complycube.com. No hosted endpoint is listed for Veriff.

Other comparisons with ComplyCube or Veriff

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.