Head to head · Kyc identity · October 2026 research run

Didit vs Shufti

Didit scores 75 (BB) on agent readiness against Shufti's 57.8 (C), and leads in 6 of 7 scored categories. Shufti leads on transparency & trust. Both do kyc identity.

Which one, for what

Didit BB

Good for A team that wants document, liveness, screening and business registry checks from one API with public prices and no sales step, and an agent that has to set itself up.

Ahead on

  • Reliability, 80 against 65
  • Schema & documentation, 88 against 58
  • Agent ergonomics, 69 against 47
  • Security & auth, 76 against 62
  • Payments & pricing, 60 against 35
  • Maintenance & community, 82 against 72

Also in its favour

  • Agent-ready, a grade of BB or better
  • Runs on your own machine

Watch for

Three incidents marked major on status.didit.me from 22 July to 4 September 2026, each a partial outage of the core APIs traced to the primary database

Shufti C

Good for A team that wants document, face, address, AML and KYB checks behind one endpoint, a free plan for low volume, and an MCP server that hands the person a hosted verification link.

Ahead on

  • Transparency & trust, 71 against 63

Watch for

No OpenAPI file or other machine-readable contract was found. The reference is prose tables plus Postman collections

Score by category

CategoryWeight this runDiditShuftiEdge
Reliability16%208065Didit +15
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28858Didit +30
Agent ergonomics13%16.26947Didit +22
Security & auth14%17.57662Didit +14
Payments & pricing10%12.56035Didit +25
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88272Didit +10
Transparency & trust7%8.86371Shufti +8
Negative events≤1500
Total75 · BB57.8 · C

Facts side by side

FactDiditShufti
KindHTTP APIHTTP API
VendorDidit Identity Spain, S.L.Shufti Pro Limited
Hosted endpointhttps://verification.didit.mehttps://api.shuftipro.com
TransportsHTTP, Streamable HTTP, stdioHTTP, Streamable HTTP
AuthOAuth or keyOAuth or key
PricingPay per useFreemium
x402nono
LicenceProprietary service under Didit's Business Terms and Conditions. The MCP server in didit-protocol/mcp is MITProprietary service under Shufti's Terms and Conditions. The licences of the mobile capture SDKs were not checked
Tools exposed15625
Read-only variant documentednono
llms.txtyesyes
MCP registryme.didit/mcpnot listed
Last release2026-10-082026-10-06
Terms last updated2026-09-23
Privacy policy last updated2026-10-072026-09-01
Customer content may train modelsyes, with an opt-outyes, with an opt-out
Terms restrict automated accessnot found in the text
Terms restrict benchmarkingyes
Terms or service can change without noticenot found in the text
Arbitration or class-action waivernot found in the text
Popularity0 stars, 27k npm/wk673 npm/wk

Verdicts

Didit

A self-serve verification API with public per-check prices, key registration by API, scoped keys and a 365-day audit log. The status page shows three incidents marked major between 22 July and 4 September 2026, each a partial outage of the core APIs, and the sub-processor list isn't public.

Shufti

One endpoint covers document, face, address, AML and KYB checks, with a free plan of 10 verifications a month, and a hosted MCP server adds OAuth with three scopes. No OpenAPI file, server SDK or idempotency key was found, and the status page history could not be read.

Before you call either

Didit

  1. Register with POST https://apx.didit.me/auth/v2/programmatic/register/, then verify-email with the emailed 6-character code. Use a real inbox, because reserved test domains return 500.
  2. Send the key as x-api-key to https://verification.didit.me/v3/. The JWT from registration works only on apx.didit.me.
  3. Create a workflow before POST /v3/session/. workflow_id is the only required field, and an unfinished session with the same vendor_data is returned again.
  4. Read results from webhooks and use GET /v3/session/{sessionId}/decision/ for back-fill. Every per-feature result is a plural array.
  5. The MCP server at https://mcp.didit.me/mcp takes OAuth sign-in only, never an API key. Approve didit:verification alone when the task doesn't change workflows or keys.

Shufti

  1. POST every verification to https://api.shuftipro.com/ with a unique reference of 6 to 250 characters and one object per service. Read results from /status with that reference
  2. Register the callback domain in the back office first. An unregistered callback_url is rejected
  3. Stay under 60 requests a minute per IP on a production account and 20 on a trial account
  4. Check the Signature response header. Accounts created after 15 March 2023 hash the Secret Key with SHA-256 before appending it to the raw response
  5. Through MCP, identity checks return a verification_url for the person to open. No tool accepts an image, so use the REST API for offsite proofs

Questions

Which is better for AI agents, Didit or Shufti?

Didit scores 75 (BB) on agent readiness against Shufti's 57.8 (C), and leads in 6 of 7 scored categories. Shufti leads on transparency & trust.

Do Didit and Shufti need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call Didit and Shufti without installing anything?

Yes. Didit has a hosted endpoint at https://verification.didit.me and Shufti at https://api.shuftipro.com.

Other comparisons with Didit or Shufti

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.