Head to head · Kyc identity · October 2026 research run

Didit vs Socure RiskOS

Didit scores 75 (BB) on agent readiness against Socure RiskOS's 63.5 (B), and leads in 6 of 7 scored categories. Socure RiskOS leads on transparency & trust. Both do kyc identity.

Which one, for what

Didit BB

Good for A team that wants document, liveness, screening and business registry checks from one API with public prices and no sales step, and an agent that has to set itself up.

Ahead on

  • Reliability, 80 against 75
  • Agent ergonomics, 69 against 46
  • Security & auth, 76 against 60
  • Payments & pricing, 60 against 35
  • Maintenance & community, 82 against 75

Also in its favour

  • Agent-ready, a grade of BB or better
  • Runs on your own machine
  • Free to start without a card

Watch for

Three incidents marked major on status.didit.me from 22 July to 4 September 2026, each a partial outage of the core APIs traced to the primary database

Socure RiskOS B

Good for A company in the United States that wants one decision from combined KYC, document, fraud and watchlist checks through a single evaluation call.

Ahead on

  • Transparency & trust, 68 against 63

Watch for

No service agreement or API terms are published. The only terms pages are website terms of use and end-user terms for document capture

Score by category

CategoryWeight this runDiditSocure RiskOSEdge
Reliability16%208075Didit +5
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28884Didit +4
Agent ergonomics13%16.26946Didit +23
Security & auth14%17.57660Didit +16
Payments & pricing10%12.56035Didit +25
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88275Didit +7
Transparency & trust7%8.86368Socure RiskOS +5
Negative events≤1500
Total75 · BB63.5 · B

Facts side by side

FactDiditSocure RiskOS
KindHTTP APIHTTP API
VendorDidit Identity Spain, S.L.Socure Inc.
Hosted endpointhttps://verification.didit.mehttps://mcp.riskos.socure.com/sandbox
TransportsHTTP, Streamable HTTP, stdioHTTP
AuthOAuth or keyAPI key
PricingPay per usePay per use
x402nono
LicenceProprietary service under Didit's Business Terms and Conditions. The MCP server in didit-protocol/mcp is MITProprietary service. No service agreement is published, and the OpenAPI file states its licence as Proprietary
Tools exposed1569
Read-only variant documentednono
llms.txtyesyes
MCP registryme.didit/mcpnot listed
Last release2026-10-082026-10-06
Terms last updated2026-09-23no document linked
Privacy policy last updated2026-10-07no date given
Customer content may train modelsyes, with an opt-outyes
Terms restrict automated accessnot found in the text
Terms restrict benchmarkingyes
Terms or service can change without noticenot found in the text
Arbitration or class-action waivernot found in the text
Popularity0 stars, 27k npm/wk35k npm/wk

Verdicts

Didit

A self-serve verification API with public per-check prices, key registration by API, scoped keys and a 365-day audit log. The status page shows three incidents marked major between 22 July and 4 September 2026, each a partial outage of the core APIs, and the sub-processor list isn't public.

Socure RiskOS

A public OpenAPI file, llms.txt, 15 documented error codes and dated release notes cover a ten-operation REST API, and Socure Launch publishes prices from $0.80 an evaluation with a free sandbox. API keys carry no scopes, no idempotency header is defined, no service terms are published, and production stays at zero requests until Socure activates it.

Before you call either

Didit

  1. Register with POST https://apx.didit.me/auth/v2/programmatic/register/, then verify-email with the emailed 6-character code. Use a real inbox, because reserved test domains return 500.
  2. Send the key as x-api-key to https://verification.didit.me/v3/. The JWT from registration works only on apx.didit.me.
  3. Create a workflow before POST /v3/session/. workflow_id is the only required field, and an unfinished session with the same vendor_data is returned again.
  4. Read results from webhooks and use GET /v3/session/{sessionId}/decision/ for back-fill. Every per-feature result is a plural array.
  5. The MCP server at https://mcp.didit.me/mcp takes OAuth sign-in only, never an API key. Approve didit:verification alone when the task doesn't change workflows or keys.

Socure RiskOS

  1. Send Authorization: Bearer <key> to https://riskos.sandbox.socure.com/api/evaluation for tests and https://riskos.socure.com/api/evaluation for live checks. The two environments use separate keys.
  2. Use dummy data only in the sandbox. It returns predefined results, connects to no live data source and expects the documented test values.
  3. Store the eval_id from every POST /api/evaluation response. No list or search endpoint exists to find it later.
  4. On 429 wait the seconds given in X-Retry-After. Do not blindly resend a failed POST /api/evaluation, because no idempotency header is documented and Launch bills each initiated evaluation.
  5. The MCP server at https://mcp.riskos.socure.com/sandbox reads docs, workflows and webhooks with its own MCP Server Key. It cannot run evaluations or read results.

Questions

Which is better for AI agents, Didit or Socure RiskOS?

Didit scores 75 (BB) on agent readiness against Socure RiskOS's 63.5 (B), and leads in 6 of 7 scored categories. Socure RiskOS leads on transparency & trust.

Do Didit and Socure RiskOS need an API key?

Didit takes an API key or an OAuth sign-in. Socure RiskOS needs an API key.

Can an agent call Didit and Socure RiskOS without installing anything?

Yes. Didit has a hosted endpoint at https://verification.didit.me and Socure RiskOS at https://mcp.riskos.socure.com/sandbox.

Other comparisons with Didit or Socure RiskOS

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.