Head to head · Kyc identity · October 2026 research run

Didit vs Veriff

Didit scores 75 (BB) on agent readiness against Veriff's 61.1 (C), and leads in 6 of 7 scored categories. Both do kyc identity.

Which one, for what

Didit BB

Good for A team that wants document, liveness, screening and business registry checks from one API with public prices and no sales step, and an agent that has to set itself up.

Ahead on

  • Reliability, 80 against 62
  • Schema & documentation, 88 against 82
  • Agent ergonomics, 69 against 43
  • Security & auth, 76 against 63
  • Payments & pricing, 60 against 40
  • Maintenance & community, 82 against 74

Also in its favour

  • Agent-ready, a grade of BB or better
  • A hosted endpoint, with nothing to install
  • Runs on your own machine
  • Free to start without a card

Watch for

Three incidents marked major on status.didit.me from 22 July to 4 September 2026, each a partial outage of the core APIs traced to the primary database

Veriff C

Good for A team that needs document and selfie verification with public per-verification prices and a trial, and that can run a webhook receiver and HMAC signing.

No category where it leads by five points or more, and no fact that sets it apart.

Watch for

No server-side SDK and no MCP server. Official packages cover only browser and mobile capture

Score by category

CategoryWeight this runDiditVeriffEdge
Reliability16%208062Didit +18
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28882Didit +6
Agent ergonomics13%16.26943Didit +26
Security & auth14%17.57663Didit +13
Payments & pricing10%12.56040Didit +20
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88274Didit +8
Transparency & trust7%8.86367Veriff +4
Negative events≤1500
Total75 · BB61.1 · C

Facts side by side

FactDiditVeriff
KindHTTP APIHTTP API
VendorDidit Identity Spain, S.L.Veriff OÜ
Hosted endpointhttps://verification.didit.meno (local only)
TransportsHTTP, Streamable HTTP, stdioHTTP
AuthOAuth or keyAPI key
PricingPay per usePay per use
x402nono
LicenceProprietary service under Didit's Business Terms and Conditions. The MCP server in didit-protocol/mcp is MITProprietary service. The npm capture SDKs are ISC (@veriff/js-sdk, @veriff/incontext-sdk) and MIT (@veriff/react-native-sdk)
Tools exposed156none
Read-only variant documentednono
llms.txtyesyes
MCP registryme.didit/mcpnot listed
Last release2026-10-082026-10-02
Terms last updated2026-09-23couldn't be read
Privacy policy last updated2026-10-072026-04-16
Customer content may train modelsyes, with an opt-outyes
Terms restrict automated accessnot found in the textcouldn't be read
Terms restrict benchmarkingyescouldn't be read
Terms or service can change without noticenot found in the textcouldn't be read
Arbitration or class-action waivernot found in the textcouldn't be read
Popularity0 stars, 27k npm/wk32 stars, 110k npm/wk

Verdicts

Didit

A self-serve verification API with public per-check prices, key registration by API, scoped keys and a 365-day audit log. The status page shows three incidents marked major between 22 July and 4 September 2026, each a partial outage of the core APIs, and the sub-processor list isn't public.

Veriff

Per-verification prices are public from $0.80, with a 15-day trial of 50 sessions and no card. Each endpoint page is Markdown with an OpenAPI 3.0 fragment. There is no server SDK, MCP server or idempotency key, most calls need an HMAC signature, and the status page shows nine incidents between 20 July and 7 October 2026.

Before you call either

Didit

  1. Register with POST https://apx.didit.me/auth/v2/programmatic/register/, then verify-email with the emailed 6-character code. Use a real inbox, because reserved test domains return 500.
  2. Send the key as x-api-key to https://verification.didit.me/v3/. The JWT from registration works only on apx.didit.me.
  3. Create a workflow before POST /v3/session/. workflow_id is the only required field, and an unfinished session with the same vendor_data is returned again.
  4. Read results from webhooks and use GET /v3/session/{sessionId}/decision/ for back-fill. Every per-feature result is a plural array.
  5. The MCP server at https://mcp.didit.me/mcp takes OAuth sign-in only, never an API key. Approve didit:verification alone when the task doesn't change workflows or keys.

Veriff

  1. Take the base URL from the integration's API keys page. Send X-AUTH-CLIENT on every call and store verification.id from POST /v1/sessions
  2. Sign POST and PATCH bodies, and the session ID on GET and DELETE, with HMAC-SHA256 in X-HMAC-SIGNATURE. POST /v1/sessions needs no signature
  3. Stay under 30 session creations a minute on Self-Serve, 600 on Enterprise. A 429 carries code 1004
  4. Don't blindly retry POST /v1/sessions. Each call makes a new session, which is billed on a live integration
  5. Poll GET /v1/sessions/{id}/decision until verification is not null, or accept webhooks within 5 seconds and treat duplicates as normal

Questions

Which is better for AI agents, Didit or Veriff?

Didit scores 75 (BB) on agent readiness against Veriff's 61.1 (C), and leads in 6 of 7 scored categories.

Do Didit and Veriff need an API key?

Didit takes an API key or an OAuth sign-in. Veriff needs an API key.

Can an agent call Didit and Veriff without installing anything?

Didit has a hosted endpoint at https://verification.didit.me. No hosted endpoint is listed for Veriff.

Other comparisons with Didit or Veriff

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.