Head to head · Kyc identity · October 2026 research run
Didit vs Shufti
Didit scores 75 (BB) on agent readiness against Shufti's 57.8 (C), and leads in 6 of 7 scored categories. Shufti leads on transparency & trust. Both do kyc identity.
Which one, for what
Didit BB
Good for A team that wants document, liveness, screening and business registry checks from one API with public prices and no sales step, and an agent that has to set itself up.
Ahead on
- Reliability, 80 against 65
- Schema & documentation, 88 against 58
- Agent ergonomics, 69 against 47
- Security & auth, 76 against 62
- Payments & pricing, 60 against 35
- Maintenance & community, 82 against 72
Also in its favour
- Agent-ready, a grade of BB or better
- Runs on your own machine
Watch for
Three incidents marked major on status.didit.me from 22 July to 4 September 2026, each a partial outage of the core APIs traced to the primary database
Shufti C
Good for A team that wants document, face, address, AML and KYB checks behind one endpoint, a free plan for low volume, and an MCP server that hands the person a hosted verification link.
Ahead on
- Transparency & trust, 71 against 63
Watch for
No OpenAPI file or other machine-readable contract was found. The reference is prose tables plus Postman collections
Score by category
| Category | Weight this run | Didit | Shufti | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 80 | 65 | Didit +15 |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 88 | 58 | Didit +30 |
| Agent ergonomics | 13%16.2 | 69 | 47 | Didit +22 |
| Security & auth | 14%17.5 | 76 | 62 | Didit +14 |
| Payments & pricing | 10%12.5 | 60 | 35 | Didit +25 |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 82 | 72 | Didit +10 |
| Transparency & trust | 7%8.8 | 63 | 71 | Shufti +8 |
| Negative events | ≤15 | 0 | 0 | |
| Total | 75 · BB | 57.8 · C |
Facts side by side
| Fact | Didit | Shufti |
|---|---|---|
| Kind | HTTP API | HTTP API |
| Vendor | Didit Identity Spain, S.L. | Shufti Pro Limited |
| Hosted endpoint | https://verification.didit.me | https://api.shuftipro.com |
| Transports | HTTP, Streamable HTTP, stdio | HTTP, Streamable HTTP |
| Auth | OAuth or key | OAuth or key |
| Pricing | Pay per use | Freemium |
| x402 | no | no |
| Licence | Proprietary service under Didit's Business Terms and Conditions. The MCP server in didit-protocol/mcp is MIT | Proprietary service under Shufti's Terms and Conditions. The licences of the mobile capture SDKs were not checked |
| Tools exposed | 156 | 25 |
| Read-only variant documented | no | no |
| llms.txt | yes | yes |
| MCP registry | me.didit/mcp | not listed |
| Last release | 2026-10-08 | 2026-10-06 |
| Terms last updated | 2026-09-23 | |
| Privacy policy last updated | 2026-10-07 | 2026-09-01 |
| Customer content may train models | yes, with an opt-out | yes, with an opt-out |
| Terms restrict automated access | not found in the text | |
| Terms restrict benchmarking | yes | |
| Terms or service can change without notice | not found in the text | |
| Arbitration or class-action waiver | not found in the text | |
| Popularity | 0 stars, 27k npm/wk | 673 npm/wk |
Verdicts
Didit
A self-serve verification API with public per-check prices, key registration by API, scoped keys and a 365-day audit log. The status page shows three incidents marked major between 22 July and 4 September 2026, each a partial outage of the core APIs, and the sub-processor list isn't public.
Shufti
One endpoint covers document, face, address, AML and KYB checks, with a free plan of 10 verifications a month, and a hosted MCP server adds OAuth with three scopes. No OpenAPI file, server SDK or idempotency key was found, and the status page history could not be read.
Before you call either
Didit
- Register with
POST https://apx.didit.me/auth/v2/programmatic/register/, thenverify-emailwith the emailed 6-character code. Use a real inbox, because reserved test domains return 500. - Send the key as
x-api-keytohttps://verification.didit.me/v3/. The JWT from registration works only onapx.didit.me. - Create a workflow before
POST /v3/session/.workflow_idis the only required field, and an unfinished session with the samevendor_datais returned again. - Read results from webhooks and use
GET /v3/session/{sessionId}/decision/for back-fill. Every per-feature result is a plural array. - The MCP server at
https://mcp.didit.me/mcptakes OAuth sign-in only, never an API key. Approvedidit:verificationalone when the task doesn't change workflows or keys.
Shufti
- POST every verification to
https://api.shuftipro.com/with a uniquereferenceof 6 to 250 characters and one object per service. Read results from/statuswith that reference - Register the callback domain in the back office first. An unregistered
callback_urlis rejected - Stay under 60 requests a minute per IP on a production account and 20 on a trial account
- Check the
Signatureresponse header. Accounts created after 15 March 2023 hash the Secret Key with SHA-256 before appending it to the raw response - Through MCP, identity checks return a
verification_urlfor the person to open. No tool accepts an image, so use the REST API for offsite proofs
Questions
Which is better for AI agents, Didit or Shufti?
Didit scores 75 (BB) on agent readiness against Shufti's 57.8 (C), and leads in 6 of 7 scored categories. Shufti leads on transparency & trust.
Do Didit and Shufti need an API key?
Both take an API key or an OAuth sign-in.
Can an agent call Didit and Shufti without installing anything?
Yes. Didit has a hosted endpoint at https://verification.didit.me and Shufti at https://api.shuftipro.com.
Other comparisons with Didit or Shufti
- ComplyCube vs Didit
- ComplyCube vs Shufti
- Didit vs Jumio
- Didit vs Middesk
- Didit vs Persona
- Didit vs Socure RiskOS
- Didit vs Sumsub
- Didit vs Trulioo
- Didit vs Veriff
- Jumio vs Shufti
- Persona vs Shufti
- Shufti vs Socure RiskOS
- Shufti vs Sumsub
- Shufti vs Trulioo
- Shufti vs Veriff
- ComplyAdvantage vs Didit
- ComplyAdvantage vs Shufti
- Middesk vs Shufti
Machine-readable
- This page as Markdown
/compare/didit-vs-shufti.md· slim.min.md· JSON.json(or sendAccept: text/markdown) - Each listing in full
/api/v1/tools/didit.json·/api/v1/tools/shufti.json - From a terminal
anchor compare didit shufti(the CLI) - Over MCP
compare_tools {"a": "didit", "b": "shufti"}at/mcp, no key