Head to head · Kyc identity · October 2026 research run

Didit vs Middesk

Didit scores 75 (BB) on agent readiness against Middesk's 59 (C), and leads in every scored category. Both do kyc identity.

Which one, for what

Didit BB

Good for A team that wants document, liveness, screening and business registry checks from one API with public prices and no sales step, and an agent that has to set itself up.

Ahead on

  • Reliability, 80 against 73
  • Schema & documentation, 88 against 82
  • Agent ergonomics, 69 against 56
  • Security & auth, 76 against 56
  • Payments & pricing, 60 against 10
  • Maintenance & community, 82 against 64

Also in its favour

  • Agent-ready, a grade of BB or better
  • Runs on your own machine
  • Free to start without a card

Watch for

Three incidents marked major on status.didit.me from 22 July to 4 September 2026, each a partial outage of the core APIs traced to the primary database

Middesk C

Good for An agent onboarding or re-checking US businesses for a bank, lender or marketplace that already holds a Middesk contract, with registry, TIN, sanctions and lien data in one object.

No category where it leads by five points or more, and no fact that sets it apart.

Watch for

No public price. Fees are set in an order form, and every docs page ends with a prompt to contact sales

Score by category

CategoryWeight this runDiditMiddeskEdge
Reliability16%208073Didit +7
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28882Didit +6
Agent ergonomics13%16.26956Didit +13
Security & auth14%17.57656Didit +20
Payments & pricing10%12.56010Didit +50
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88264Didit +18
Transparency & trust7%8.86361Didit +2
Negative events≤1500
Total75 · BB59 · C

Facts side by side

FactDiditMiddesk
KindHTTP APIHTTP API
VendorDidit Identity Spain, S.L.Middesk, Inc.
Hosted endpointhttps://verification.didit.mehttps://api.middesk.com/v1
TransportsHTTP, Streamable HTTP, stdioHTTP
AuthOAuth or keyOAuth or key
PricingPay per usePaid
x402nono
LicenceProprietary service under Didit's Business Terms and Conditions. The MCP server in didit-protocol/mcp is MITProprietary service under Middesk's Business Verification Terms and Conditions. The Claude Code and Codex plugins on GitHub are MIT
Tools exposed15611
Read-only variant documentednono
llms.txtyesyes
MCP registryme.didit/mcpnot listed
Last release2026-10-082026-10-05
Terms last updated2026-09-23no date given
Privacy policy last updated2026-10-07no date given
Customer content may train modelsyes, with an opt-outyes
Terms restrict automated accessnot found in the textnot found in the text
Terms restrict benchmarkingyesyes
Terms or service can change without noticenot found in the textnot found in the text
Arbitration or class-action waivernot found in the textyes
Popularity0 stars, 27k npm/wk2 stars

Verdicts

Didit

A self-serve verification API with public per-check prices, key registration by API, scoped keys and a 365-day audit log. The status page shows three incidents marked major between 22 July and 4 September 2026, each a partial outage of the core APIs, and the sub-processor list isn't public.

Middesk

A public OpenAPI 3.1 contract for 87 operations, llms.txt, Markdown docs and a dated weekly changelog make the REST API readable to an agent, and OAuth has a read-only scope. Access is sales-led. No price, self-serve signup or official SDK was found, and the hosted MCP server rejects sandbox keys.

Before you call either

Didit

  1. Register with POST https://apx.didit.me/auth/v2/programmatic/register/, then verify-email with the emailed 6-character code. Use a real inbox, because reserved test domains return 500.
  2. Send the key as x-api-key to https://verification.didit.me/v3/. The JWT from registration works only on apx.didit.me.
  3. Create a workflow before POST /v3/session/. workflow_id is the only required field, and an unfinished session with the same vendor_data is returned again.
  4. Read results from webhooks and use GET /v3/session/{sessionId}/decision/ for back-fill. Every per-feature result is a plural array.
  5. The MCP server at https://mcp.didit.me/mcp takes OAuth sign-in only, never an API key. Approve didit:verification alone when the task doesn't change workflows or keys.

Middesk

  1. Match the key to the host. mk_test keys work only at https://api-sandbox.middesk.com/v1 and mk_live keys only at https://api.middesk.com/v1
  2. Name the orders on POST /v1/businesses. Omitting them places a verification order plus every package the account runs automatically, all billed
  3. Send address_line1 and address_line2. The API ignores address_line_1 without an error
  4. A 201 means the business was created, not verified. Wait for the business.updated webhook or poll until status leaves pending
  5. Stay under 20 requests a second per account, and in sandbox wait the seconds in Retry-After after a 429 on business creation

Questions

Which is better for AI agents, Didit or Middesk?

Didit scores 75 (BB) on agent readiness against Middesk's 59 (C), and leads in every scored category.

Do Didit and Middesk need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call Didit and Middesk without installing anything?

Yes. Didit has a hosted endpoint at https://verification.didit.me and Middesk at https://api.middesk.com/v1.

Other comparisons with Didit or Middesk

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.