Head to head · Kyc identity · October 2026 research run
Didit vs Sumsub
Didit scores 75 (BB) on agent readiness against Sumsub's 68.5 (B), and leads in 4 of 7 scored categories. Sumsub leads on transparency & trust. Both do kyc identity.
Which one, for what
Didit BB
Good for A team that wants document, liveness, screening and business registry checks from one API with public prices and no sales step, and an agent that has to set itself up.
Ahead on
- Schema & documentation, 88 against 78
- Agent ergonomics, 69 against 60
- Payments & pricing, 60 against 25
- Maintenance & community, 82 against 74
Also in its favour
- Agent-ready, a grade of BB or better
- Runs on your own machine
- Free to start without a card
Watch for
Three incidents marked major on status.didit.me from 22 July to 4 September 2026, each a partial outage of the core APIs traced to the primary database
Sumsub B
Good for An agent that starts verifications, sends links, reads results and AML cases, and works case queues for a regulated business, with one token limited to those permissions.
Ahead on
- Transparency & trust, 74 against 63
Watch for
No idempotency keys and no Retry-After or backoff guidance found in the reviewed documentation
Score by category
| Category | Weight this run | Didit | Sumsub | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 80 | 80 | even |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 88 | 78 | Didit +10 |
| Agent ergonomics | 13%16.2 | 69 | 60 | Didit +9 |
| Security & auth | 14%17.5 | 76 | 80 | Sumsub +4 |
| Payments & pricing | 10%12.5 | 60 | 25 | Didit +35 |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 82 | 74 | Didit +8 |
| Transparency & trust | 7%8.8 | 63 | 74 | Sumsub +11 |
| Negative events | ≤15 | 0 | 0 | |
| Total | 75 · BB | 68.5 · B |
Facts side by side
| Fact | Didit | Sumsub |
|---|---|---|
| Kind | HTTP API | HTTP API |
| Vendor | Didit Identity Spain, S.L. | Sum and Substance Ltd |
| Hosted endpoint | https://verification.didit.me | https://api.sumsub.com |
| Transports | HTTP, Streamable HTTP, stdio | HTTP |
| Auth | OAuth or key | OAuth or key |
| Pricing | Pay per use | Pay per use |
| x402 | no | no |
| Licence | Proprietary service under Didit's Business Terms and Conditions. The MCP server in didit-protocol/mcp is MIT | Proprietary service under Sumsub's terms and conditions. The agent skills repository and the @sumsub/websdk npm package are MIT |
| Tools exposed | 156 | none |
| Read-only variant documented | no | no |
| llms.txt | yes | yes |
| MCP registry | me.didit/mcp | not listed |
| Last release | 2026-10-08 | 2026-10-03 |
| Terms last updated | 2026-09-23 | 2026-05-21 |
| Privacy policy last updated | 2026-10-07 | 2026-03-19 |
| Customer content may train models | yes, with an opt-out | yes |
| Terms restrict automated access | not found in the text | not found in the text |
| Terms restrict benchmarking | yes | not found in the text |
| Terms or service can change without notice | not found in the text | yes |
| Arbitration or class-action waiver | not found in the text | yes |
| Popularity | 0 stars, 27k npm/wk | 172k npm/wk |
Verdicts
Didit
A self-serve verification API with public per-check prices, key registration by API, scoped keys and a 365-day audit log. The status page shows three incidents marked major between 22 July and 4 September 2026, each a partial outage of the core APIs, and the sub-processor list isn't public.
Sumsub
Per-token permissions, an IP allowlist, HMAC-signed requests and a public OpenAPI spec with Markdown docs suit an agent working on verification cases. No idempotency keys or Retry-After guidance were found, there is no server SDK, and production access needs a browser signup, a bank card and Sumsub's review of the integration.
Before you call either
Didit
- Register with
POST https://apx.didit.me/auth/v2/programmatic/register/, thenverify-emailwith the emailed 6-character code. Use a real inbox, because reserved test domains return 500. - Send the key as
x-api-keytohttps://verification.didit.me/v3/. The JWT from registration works only onapx.didit.me. - Create a workflow before
POST /v3/session/.workflow_idis the only required field, and an unfinished session with the samevendor_datais returned again. - Read results from webhooks and use
GET /v3/session/{sessionId}/decision/for back-fill. Every per-feature result is a plural array. - The MCP server at
https://mcp.didit.me/mcptakes OAuth sign-in only, never an API key. Approvedidit:verificationalone when the task doesn't change workflows or keys.
Sumsub
- Sign every request. X-App-Access-Sig is the lowercase hex HMAC-SHA256 of timestamp, uppercase method, path with query and raw body, and the timestamp must be within one minute of server time
- Use a sandbox token (prefix sbx) for agent work. Sandbox and production tokens are separate, and Sumsub's own skills refuse any other prefix
- Stay under 300 GET and 50 POST requests per 5 seconds, and under 500 new applicants per 24 hours in Sandbox
- Token permissions can't be edited after creation. Generate a new token with the narrower set and delete the old one
- Subscribe to the applicantReviewed webhook for results and verify x-payload-digest against the raw body before trusting it
Questions
Which is better for AI agents, Didit or Sumsub?
Didit scores 75 (BB) on agent readiness against Sumsub's 68.5 (B), and leads in 4 of 7 scored categories. Sumsub leads on transparency & trust.
Do Didit and Sumsub need an API key?
Both take an API key or an OAuth sign-in.
Can an agent call Didit and Sumsub without installing anything?
Yes. Didit has a hosted endpoint at https://verification.didit.me and Sumsub at https://api.sumsub.com.
Other comparisons with Didit or Sumsub
Machine-readable
- This page as Markdown
/compare/didit-vs-sumsub.md· slim.min.md· JSON.json(or sendAccept: text/markdown) - Each listing in full
/api/v1/tools/didit.json·/api/v1/tools/sumsub.json - From a terminal
anchor compare didit sumsub(the CLI) - Over MCP
compare_tools {"a": "didit", "b": "sumsub"}at/mcp, no key