Head to head · Kyc identity · October 2026 research run

Didit vs Jumio

Didit scores 75 (BB) on agent readiness against Jumio's 55 (C), and leads in every scored category. Both do kyc identity.

Which one, for what

Didit BB

Good for A team that wants document, liveness, screening and business registry checks from one API with public prices and no sales step, and an agent that has to set itself up.

Ahead on

  • Reliability, 80 against 65
  • Schema & documentation, 88 against 73
  • Agent ergonomics, 69 against 45
  • Security & auth, 76 against 63
  • Payments & pricing, 60 against 0
  • Maintenance & community, 82 against 75

Also in its favour

  • Agent-ready, a grade of BB or better
  • A hosted endpoint, with nothing to install
  • Runs on your own machine
  • Free to start without a card

Watch for

Three incidents marked major on status.didit.me from 22 July to 4 September 2026, each a partial outage of the core APIs traced to the primary database

Jumio C

Good for An enterprise with a Jumio contract that wants document, selfie and liveness checks, watchlist screening and Latin American, Thai and Australian database checks behind OpenAPI-described endpoints.

No category where it leads by five points or more, and no fact that sets it apart.

Watch for

No public price, free tier or trial. OAuth2 and workflow keys are activated by a Jumio account manager

Score by category

CategoryWeight this runDiditJumioEdge
Reliability16%208065Didit +15
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28873Didit +15
Agent ergonomics13%16.26945Didit +24
Security & auth14%17.57663Didit +13
Payments & pricing10%12.5600Didit +60
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88275Didit +7
Transparency & trust7%8.86360Didit +3
Negative events≤1500
Total75 · BB55 · C

Facts side by side

FactDiditJumio
KindHTTP APIHTTP API
VendorDidit Identity Spain, S.L.Jumio Corporation
Hosted endpointhttps://verification.didit.meno (local only)
TransportsHTTP, Streamable HTTP, stdioHTTP
AuthOAuth or keyOAuth
PricingPay per usePaid
x402nono
LicenceProprietary service under Didit's Business Terms and Conditions. The MCP server in didit-protocol/mcp is MITProprietary service. No public service agreement was found. The @jumio/websdk npm package is marked UNLICENSED
Tools exposed156none
Read-only variant documentednono
llms.txtyesyes
MCP registryme.didit/mcpnot listed
Last release2026-10-082026-09-28
Terms last updated2026-09-23no document linked
Privacy policy last updated2026-10-072026-08-04
Customer content may train modelsyes, with an opt-outyes
Terms restrict automated accessnot found in the text
Terms restrict benchmarkingyes
Terms or service can change without noticenot found in the text
Arbitration or class-action waivernot found in the text
Popularity0 stars, 27k npm/wk72 stars, 2.1k npm/wk

Verdicts

Didit

A self-serve verification API with public per-check prices, key registration by API, scoped keys and a 365-day audit log. The status page shows three incidents marked major between 22 July and 4 September 2026, each a partial outage of the core APIs, and the sub-processor list isn't public.

Jumio

Five OpenAPI 3.0 files, an llms.txt index and OAuth2 clients limited to initiating or to retrieving and deleting make the API readable and containable. Access starts with an account manager, with no public price, trial or service agreement, and the status page shows four processing degradations and a 35-minute Singapore outage between 14 August and 2 October 2026.

Before you call either

Didit

  1. Register with POST https://apx.didit.me/auth/v2/programmatic/register/, then verify-email with the emailed 6-character code. Use a real inbox, because reserved test domains return 500.
  2. Send the key as x-api-key to https://verification.didit.me/v3/. The JWT from registration works only on apx.didit.me.
  3. Create a workflow before POST /v3/session/. workflow_id is the only required field, and an unfinished session with the same vendor_data is returned again.
  4. Read results from webhooks and use GET /v3/session/{sessionId}/decision/ for back-fill. Every per-feature result is a plural array.
  5. The MCP server at https://mcp.didit.me/mcp takes OAuth sign-in only, never an API key. Approve didit:verification alone when the task doesn't change workflows or keys.

Jumio

  1. Use the host for the tenant's region (amer-1, emea-1 or apac-1). Tokens come from auth.<region>.jumio.ai/oauth2/token with the client ID and secret as Basic credentials
  2. Reuse the bearer token for its 60 minutes. Token requests are limited to 10 a second and new transactions to 1 a second per tenant
  3. Send a User-Agent header on every call. The Account API marks it required
  4. Don't blindly retry POST /api/v1/accounts. Each call creates an account and a transaction, and no idempotency key exists
  5. Wait for the callback or poll the status endpoint until PROCESSED before retrieving. Jumio's retry schedule starts at 40 seconds and stops after 940

Questions

Which is better for AI agents, Didit or Jumio?

Didit scores 75 (BB) on agent readiness against Jumio's 55 (C), and leads in every scored category.

Do Didit and Jumio need an API key?

Didit takes an API key or an OAuth sign-in. Jumio uses an OAuth sign-in.

Can an agent call Didit and Jumio without installing anything?

Didit has a hosted endpoint at https://verification.didit.me. No hosted endpoint is listed for Jumio.

Other comparisons with Didit or Jumio

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.