{
  "data": {
    "a": {
      "slug": "jumio",
      "name": "Jumio",
      "vendor": "Jumio Corporation",
      "vendorUrl": "https://www.jumio.com",
      "kind": "http-api",
      "category": "identity-verification",
      "summary": "Identity verification service from Jumio Corporation in Sunnyvale. It checks identity documents and selfies with liveness, screens against sanctions and PEP lists, and runs government database checks. Transactions are started and read through regional REST APIs with OAuth2.",
      "url": "https://www.anchorterminal.com/tools/jumio",
      "markdownUrl": "https://www.anchorterminal.com/tools/jumio.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/jumio.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/jumio.json",
      "repo": "https://github.com/Jumio/mobile-sdk-android",
      "license": "Proprietary service. No public service agreement was found. The @jumio/websdk npm package is marked UNLICENSED",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "@jumio/websdk"
        },
        {
          "registry": "npm",
          "name": "react-native-jumio-mobilesdk"
        }
      ],
      "auth": "oauth",
      "authNotes": "Sales approval. A Jumio account manager activates OAuth2 for the tenant and supplies the workflow keys. An admin then generates client ID and secret pairs in the Jumio Portal, each limited to initiating transactions, to retrieving and deleting them, or both, and each can be deactivated. The pair is sent as Basic credentials to the regional token URL with `grant_type=client_credentials`, and the bearer token lasts 60 minutes. Basic authentication on the REST APIs themselves is marked deprecated. Account creation also returns per-transaction tokens for uploads and the capture SDKs.",
      "pricing": "paid",
      "pricingNotes": "No public prices. www.jumio.com/pricing/ returns 404 and the site's Get Started button opens a sales enquiry form. No free tier, trial or self-serve signup was found. The mock service for synthetic test transactions needs a dedicated tenant that Jumio Support or the account manager sets up (checked 2026-10-08).",
      "priceSummary": "Paid",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in llms-full.txt, the five OpenAPI files or the Jumio website (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 72,
        "npmWeekly": 2122,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://documentation.jumio.ai",
      "llmsTxt": "https://documentation.jumio.ai/llms.txt",
      "openapi": "https://documentation.jumio.ai/redocusaurus/account.yaml",
      "capabilities": [
        "kyc.identity",
        "kyc.documents",
        "kyc.screening"
      ],
      "tags": [
        "hosted",
        "enterprise",
        "oauth",
        "openapi",
        "llms-txt",
        "callbacks",
        "sales-led",
        "status-page",
        "soc2",
        "iso27001",
        "java",
        "dotnet"
      ],
      "lastRelease": "2026-09-28",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 55,
        "grade": "C",
        "agentReady": false,
        "rank": 603,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 10,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 45,
          "maintenance": 75,
          "payments": 0,
          "reliability": 65,
          "schema": 73,
          "security": 63,
          "transparency": 60
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "Five OpenAPI 3.0 files, an llms.txt index and OAuth2 clients limited to initiating or to retrieving and deleting make the API readable and containable. Access starts with an account manager, with no public price, trial or service agreement, and the status page shows four processing degradations and a 35-minute Singapore outage between 14 August and 2 October 2026.",
        "bestFor": "An enterprise with a Jumio contract that wants document, selfie and liveness checks, watchlist screening and Latin American, Thai and Australian database checks behind OpenAPI-described endpoints.",
        "strengths": [
          "Five downloadable OpenAPI 3.0 files covering 25 operations, plus llms.txt and a 2.2 MB llms-full.txt of the docs in Markdown",
          "OAuth2 client credentials with 60-minute bearer tokens. Each client is limited to initiate, to retrieve and delete, or both, and can be deactivated",
          "Rate limits are published per tenant. Token requests 10 a second, new transactions 1 a second, retrievals 15 a second",
          "Statuspage at monitor.jumio.com by data centre, and an unauthenticated health endpoint per region that answers UP, DEGRADED or DOWN",
          "SOC 2, ISO 27001 and PCI DSS 4.0.1 listed on the Trust Centre, and a vulnerability disclosure programme at vdp.jumio.com"
        ],
        "weaknesses": [
          "No public price, free tier or trial. OAuth2 and workflow keys are activated by a Jumio account manager",
          "No service agreement or DPA is published. The public terms of use cover end users in the United States",
          "Four processing degradations and a 35-minute Singapore outage on the status page between 14 August and 2 October 2026",
          "No idempotency key. A repeated POST or PUT on accounts starts another transaction",
          "GET /api/v1/workflow-executions takes no paging or filter parameters, and the specs document only 401, 403 and 404 errors",
          "Retention periods and the sub-processor list are available on request only, and security.txt returns 404"
        ],
        "agentNotes": [
          "Use the host for the tenant's region (amer-1, emea-1 or apac-1). Tokens come from auth.\u003cregion\u003e.jumio.ai/oauth2/token with the client ID and secret as Basic credentials",
          "Reuse the bearer token for its 60 minutes. Token requests are limited to 10 a second and new transactions to 1 a second per tenant",
          "Send a User-Agent header on every call. The Account API marks it required",
          "Don't blindly retry POST /api/v1/accounts. Each call creates an account and a transaction, and no idempotency key exists",
          "Wait for the callback or poll the status endpoint until PROCESSED before retrieving. Jumio's retry schedule starts at 40 seconds and stops after 940"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 55
          }
        ],
        "editorialScores": {
          "ergonomics": 45,
          "maintenance": 75,
          "payments": 0,
          "reliability": 65,
          "schema": 73,
          "security": 63,
          "transparency": 41
        },
        "provenanceScore": 78
      },
      "connect": {
        "http": "curl --location 'https://auth.amer-1.jumio.ai/oauth2/token' \\\n  -u CLIENT_ID:CLIENT_SECRET \\\n  --header 'Accept: application/json' \\\n  --data-urlencode 'grant_type=client_credentials'"
      },
      "letme": {
        "capability": "https://letme.dev/kyc.identity",
        "tool": "https://letme.dev/jumio"
      },
      "area": "domain-data",
      "provenance": {
        "legalEntity": "Jumio Corporation",
        "domain": "jumio.com",
        "domainRegistered": "2004-03-30",
        "endpointOnVendorDomain": true,
        "terms": "",
        "privacy": "https://www.jumio.com/privacy-center/privacy-notices/online-services-notice/",
        "statusPage": "https://monitor.jumio.com",
        "changelog": "https://documentation.jumio.ai/docs/developer-resources/SDKs/mobile-sdk/mobile-sdk-android-master/docs/changelog",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The Online Services Privacy Notice (last updated 4 August 2026) names Jumio Corporation, 100 Mathilda Place, Suite 100, Sunnyvale, CA 94086, with Jumio Software Development GmbH in Linz as EU representative.",
          "No terms field. Jumio publishes no service agreement or API terms for customers. www.jumio.com/terms-of-use/ (last updated 18 June 2026) is addressed to end users in the United States, so it isn't recorded as the governing document.",
          "The APIs answer on jumio.ai hosts (auth, account, api, retrieval, kyx and status under amer-1, emea-1 and apac-1), a second domain used throughout Jumio's own documentation at documentation.jumio.ai.",
          "www.jumio.com/.well-known/security.txt and /security.txt return 404. Reports go to the vulnerability disclosure programme at https://vdp.jumio.com, which pays nothing.",
          "The changelog linked is the Android SDK's. No changelog for the REST APIs was found.",
          "RDAP for jumio.com gives a registration date of 2004-03-30."
        ],
        "score": 78
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/jumio.json",
      "live": {
        "slug": "jumio",
        "vendorStatus": {
          "page": "https://monitor.jumio.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-09T10:41:46.211525155Z"
        },
        "pages": [
          {
            "url": "https://documentation.jumio.ai/docs/developer-resources/SDKs/mobile-sdk/mobile-sdk-android-master/docs/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:19:56.339175642Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "4e0b13492ecb"
          },
          {
            "url": "https://www.jumio.com/privacy-center/privacy-notices/online-services-notice/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:28:35.8188334Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "47ddc34e8761"
          }
        ],
        "updatedAt": "2026-10-09T10:41:46.211525155Z"
      }
    },
    "answer": "Shufti scores 57.8 (C) on agent readiness against Jumio's 55 (C), and leads in 3 of 7 scored categories. Jumio leads on schema \u0026 documentation.",
    "b": {
      "slug": "shufti",
      "name": "Shufti",
      "vendor": "Shufti Pro Limited",
      "vendorUrl": "https://shuftipro.com",
      "kind": "http-api",
      "category": "identity-verification",
      "summary": "Identity and business verification service from Shufti Pro Limited in London. One REST endpoint runs document, face, address, AML screening and KYB checks chosen in the request body, with results by callback. A hosted MCP server exposes 25 tools.",
      "url": "https://www.anchorterminal.com/tools/shufti",
      "markdownUrl": "https://www.anchorterminal.com/tools/shufti.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/shufti.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/shufti.json",
      "repo": "https://github.com/shuftipro/iOS-SDK",
      "license": "Proprietary service under Shufti's Terms and Conditions. The licences of the mobile capture SDKs were not checked",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.shuftipro.com",
      "packages": [
        {
          "registry": "npm",
          "name": "shuftipro-onsite-mobilesdk"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve. Signing up creates a back office account, and the Client ID and Secret Key come from Settings, API Configuration, API Keys. The REST API takes them as HTTP Basic auth, or a Bearer access token from `/get/access/token` that lasts one hour. The key pair has no scopes, and the Secret Key is shown once and replaced by generating a new one. The MCP server uses OAuth 2.1 with PKCE and dynamic client registration. Its login page asks for the same Client ID and Secret Key, and it issues tokens with the scopes `knowledge:read`, `verification:read` and `verification:write`. Callback and redirect domains must be registered in the back office.",
      "pricing": "freemium",
      "pricingNotes": "Free Forever covers up to 10 verifications a month with no card, on the production environment. Essentials starts from $1.50 a verification, pay as you go with no monthly minimum, up to 20,000 verifications. Enterprise is quoted by sales and adds e-IDV, Travel Rule, video KYC and other services. The pricing page says only successful verification attempts are billed and resubmissions are free. Trial accounts accept test ID samples (https://shuftipro.com/pricing/, checked 2026-10-09).",
      "priceSummary": "$1.50 / tx",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the developer docs (llms-full.txt), the pricing page or the terms (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": 25,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 673,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://developers.shuftipro.com/docs/get_started",
      "llmsTxt": "https://developers.shuftipro.com/llms.txt",
      "capabilities": [
        "kyc.identity",
        "kyc.documents",
        "kyc.business",
        "kyc.screening"
      ],
      "tags": [
        "hosted",
        "api-key",
        "oauth",
        "mcp",
        "webhooks",
        "llms-txt",
        "free-tier",
        "no-card",
        "status-page",
        "sla",
        "soc2",
        "iso27001"
      ],
      "lastRelease": "2026-10-06",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 57.8,
        "grade": "C",
        "agentReady": false,
        "rank": 538,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 9,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 47,
          "maintenance": 72,
          "payments": 35,
          "reliability": 65,
          "schema": 58,
          "security": 62,
          "transparency": 71
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": 0,
        "verdict": "One endpoint covers document, face, address, AML and KYB checks, with a free plan of 10 verifications a month, and a hosted MCP server adds OAuth with three scopes. No OpenAPI file, server SDK or idempotency key was found, and the status page history could not be read.",
        "bestFor": "A team that wants document, face, address, AML and KYB checks behind one endpoint, a free plan for low volume, and an MCP server that hands the person a hosted verification link.",
        "strengths": [
          "Free Forever plan of 10 verifications a month with no card, on the production environment, per the pricing page",
          "Hosted MCP server at `https://ai.shuftipro.com/mcp` with 25 tools, OAuth 2.1 with PKCE and three scopes enforced on every call",
          "Docs published as llms.txt, a 2.9 MB llms-full.txt and a Markdown twin of each page, with samples in nine languages",
          "Public terms (version 11.1, 13 May 2026) include an availability schedule targeting 99 per cent monthly uptime",
          "Revision history with 19 dated entries between 24 July and 6 October 2026"
        ],
        "weaknesses": [
          "No OpenAPI file or other machine-readable contract was found. The reference is prose tables plus Postman collections",
          "The REST credential is one Client ID and Secret Key pair with no scopes, sent as Basic auth on every call",
          "No idempotency key, Retry-After header or backoff guidance was found for the documented 429",
          "No server-side SDK. Official packages cover Android, iOS, Flutter, React Native and Cordova capture only",
          "Standard KYB was deprecated on 6 October 2026 and its pages removed the same day, with no notice period stated",
          "The sub-processor list is available to clients on request only, and security.txt returns 404"
        ],
        "agentNotes": [
          "POST every verification to `https://api.shuftipro.com/` with a unique `reference` of 6 to 250 characters and one object per service. Read results from `/status` with that reference",
          "Register the callback domain in the back office first. An unregistered `callback_url` is rejected",
          "Stay under 60 requests a minute per IP on a production account and 20 on a trial account",
          "Check the `Signature` response header. Accounts created after 15 March 2023 hash the Secret Key with SHA-256 before appending it to the raw response",
          "Through MCP, identity checks return a `verification_url` for the person to open. No tool accepts an image, so use the REST API for offsite proofs"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 57.8
          }
        ],
        "editorialScores": {
          "ergonomics": 47,
          "maintenance": 72,
          "payments": 35,
          "reliability": 65,
          "schema": 58,
          "security": 62,
          "transparency": 51
        },
        "provenanceScore": 90
      },
      "connect": {
        "http": "curl --location --request POST 'https://api.shuftipro.com' \\\n--header 'Content-Type: application/json' \\\n--header 'Authorization: Basic \u003cbase64 of CLIENT_ID:SECRET_KEY\u003e' \\\n--data-raw '{\n    \"reference\"    : \"1234567\",\n    \"callback_url\" : \"https://yourdomain.com/profile/notifyCallback\",\n    \"country\"      : \"GB\",\n    \"language\"     : \"EN\",\n    \"verification_mode\" : \"any\",\n    \"face\" : {\n        \"proof\"            : \"\"\n    }\n}'",
        "claudeCode": "claude mcp add --transport http shufti https://ai.shuftipro.com/mcp",
        "config": {
          "mcpServers": {
            "shufti": {
              "args": [
                "mcp-remote",
                "https://ai.shuftipro.com/mcp"
              ],
              "command": "npx"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/kyc.identity",
        "tool": "https://letme.dev/shufti"
      },
      "area": "domain-data",
      "unitPrices": [
        {
          "item": "Verification, Free Forever plan (document and face checks)",
          "unit": "tx",
          "usd": 0,
          "note": "up to 10 verifications a month, no card"
        },
        {
          "item": "Verification, Essentials plan, starting price",
          "unit": "tx",
          "usd": 1.5,
          "note": "rate depends on volume and the services chosen, up to 20,000 verifications"
        }
      ],
      "provenance": {
        "legalEntity": "Shufti Pro Limited",
        "domain": "shuftipro.com",
        "domainRegistered": "2016-06-28",
        "endpointOnVendorDomain": true,
        "terms": "https://shuftipro.com/wp-content/uploads/Version-11.1-w.e.f.-May-13th-2026.pdf",
        "privacy": "https://shuftipro.com/services-privacy-notice/",
        "statusPage": "https://status.shuftipro.com",
        "changelog": "https://developers.shuftipro.com/docs/revision_history",
        "securityTxt": "none",
        "checked": "2026-10-09",
        "notes": [
          "The terms and the MCP privacy notice name Shufti Pro Limited, Office 408 Coppergate House, 10 Whites Row, London E1 7NF.",
          "The governing terms are a PDF, version 11.1, linked from shuftipro.com/terms-and-conditions/, which itself carries only a summary and links to every earlier version. The page labels the file 12 May 2026 and the file name says 13 May.",
          "The privacy link is the Services Privacy Notice, version 1.2, last updated September 2026, which covers verification data. A separate notice covers the website.",
          "shuftipro.com/.well-known/security.txt answered 502 on the first request and 404 on the second.",
          "RDAP for shuftipro.com gives a registration date of 2016-06-28.",
          "The API answers at api.shuftipro.com and the MCP server at ai.shuftipro.com. The lead's shufti.ai is a parked domain for sale and unrelated to the vendor.",
          "status.shuftipro.com is an UptimeRobot page whose data loads from /api/, a path its robots.txt disallows, so the incident history was not read."
        ],
        "score": 90
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/shufti.json",
      "live": {
        "slug": "shufti",
        "probe": {
          "target": "https://api.shuftipro.com",
          "method": "get",
          "lastAt": "2026-10-09T10:42:56.447659113Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 384,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 324,
          "p95ms24h": 384,
          "samples24h": 33,
          "samples30d": 33,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 33,
              "ok": 33
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.shuftipro.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-09T07:58:32.112017753Z"
        },
        "updatedAt": "2026-10-09T10:42:56.447659113Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Jumio Corporation",
        "b": "Shufti Pro Limited",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "https://api.shuftipro.com",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Paid",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service. No public service agreement was found. The @jumio/websdk npm package is marked UNLICENSED",
        "b": "Proprietary service under Shufti's Terms and Conditions. The licences of the mobile capture SDKs were not checked",
        "name": "Licence"
      },
      {
        "a": "none",
        "b": "25",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-28",
        "b": "2026-10-06",
        "name": "Last release"
      },
      {
        "a": "no document linked",
        "b": "",
        "name": "Terms last updated"
      },
      {
        "a": "2026-08-04",
        "b": "2026-09-01",
        "name": "Privacy policy last updated"
      },
      {
        "a": "yes",
        "b": "yes, with an opt-out",
        "name": "Customer content may train models"
      },
      {
        "a": "",
        "b": "",
        "name": "Terms restrict automated access"
      },
      {
        "a": "",
        "b": "",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "",
        "b": "",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "",
        "b": "",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "72 stars, 2.1k npm/wk",
        "b": "673 npm/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Shufti scores 57.8 (C) on agent readiness against Jumio's 55 (C), and leads in 3 of 7 scored categories. Jumio leads on schema \u0026 documentation.",
        "question": "Which is better for AI agents, Jumio or Shufti?"
      },
      {
        "answer": "Jumio uses an OAuth sign-in. Shufti takes an API key or an OAuth sign-in.",
        "question": "Do Jumio and Shufti need an API key?"
      },
      {
        "answer": "No hosted endpoint is listed for Jumio. Shufti has a hosted endpoint at https://api.shuftipro.com.",
        "question": "Can an agent call Jumio and Shufti without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Schema \u0026 documentation, 73 against 58"
        ],
        "also": null,
        "goodFor": "An enterprise with a Jumio contract that wants document, selfie and liveness checks, watchlist screening and Latin American, Thai and Australian database checks behind OpenAPI-described endpoints.",
        "slug": "jumio",
        "watchFor": "No public price, free tier or trial. OAuth2 and workflow keys are activated by a Jumio account manager"
      },
      {
        "aheadOn": [
          "Payments \u0026 pricing, 35 against 0",
          "Transparency \u0026 trust, 71 against 60"
        ],
        "also": [
          "A hosted endpoint, with nothing to install",
          "Free to start without a card"
        ],
        "goodFor": "A team that wants document, face, address, AML and KYB checks behind one endpoint, a free plan for low volume, and an MCP server that hands the person a hosted verification link.",
        "slug": "shufti",
        "watchFor": "No OpenAPI file or other machine-readable contract was found. The reference is prose tables plus Postman collections"
      }
    ],
    "job": {
      "capability": "kyc.identity",
      "name": "Kyc identity"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/complycube-vs-jumio.json",
        "title": "ComplyCube vs Jumio",
        "url": "https://www.anchorterminal.com/compare/complycube-vs-jumio"
      },
      {
        "json": "https://www.anchorterminal.com/compare/complycube-vs-shufti.json",
        "title": "ComplyCube vs Shufti",
        "url": "https://www.anchorterminal.com/compare/complycube-vs-shufti"
      },
      {
        "json": "https://www.anchorterminal.com/compare/didit-vs-jumio.json",
        "title": "Didit vs Jumio",
        "url": "https://www.anchorterminal.com/compare/didit-vs-jumio"
      },
      {
        "json": "https://www.anchorterminal.com/compare/didit-vs-shufti.json",
        "title": "Didit vs Shufti",
        "url": "https://www.anchorterminal.com/compare/didit-vs-shufti"
      },
      {
        "json": "https://www.anchorterminal.com/compare/jumio-vs-middesk.json",
        "title": "Jumio vs Middesk",
        "url": "https://www.anchorterminal.com/compare/jumio-vs-middesk"
      },
      {
        "json": "https://www.anchorterminal.com/compare/jumio-vs-persona.json",
        "title": "Jumio vs Persona",
        "url": "https://www.anchorterminal.com/compare/jumio-vs-persona"
      },
      {
        "json": "https://www.anchorterminal.com/compare/jumio-vs-socure-riskos.json",
        "title": "Jumio vs Socure RiskOS",
        "url": "https://www.anchorterminal.com/compare/jumio-vs-socure-riskos"
      },
      {
        "json": "https://www.anchorterminal.com/compare/jumio-vs-sumsub.json",
        "title": "Jumio vs Sumsub",
        "url": "https://www.anchorterminal.com/compare/jumio-vs-sumsub"
      },
      {
        "json": "https://www.anchorterminal.com/compare/jumio-vs-trulioo.json",
        "title": "Jumio vs Trulioo",
        "url": "https://www.anchorterminal.com/compare/jumio-vs-trulioo"
      },
      {
        "json": "https://www.anchorterminal.com/compare/jumio-vs-veriff.json",
        "title": "Jumio vs Veriff",
        "url": "https://www.anchorterminal.com/compare/jumio-vs-veriff"
      },
      {
        "json": "https://www.anchorterminal.com/compare/persona-vs-shufti.json",
        "title": "Persona vs Shufti",
        "url": "https://www.anchorterminal.com/compare/persona-vs-shufti"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shufti-vs-socure-riskos.json",
        "title": "Shufti vs Socure RiskOS",
        "url": "https://www.anchorterminal.com/compare/shufti-vs-socure-riskos"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shufti-vs-sumsub.json",
        "title": "Shufti vs Sumsub",
        "url": "https://www.anchorterminal.com/compare/shufti-vs-sumsub"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shufti-vs-trulioo.json",
        "title": "Shufti vs Trulioo",
        "url": "https://www.anchorterminal.com/compare/shufti-vs-trulioo"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shufti-vs-veriff.json",
        "title": "Shufti vs Veriff",
        "url": "https://www.anchorterminal.com/compare/shufti-vs-veriff"
      },
      {
        "json": "https://www.anchorterminal.com/compare/complyadvantage-vs-jumio.json",
        "title": "ComplyAdvantage vs Jumio",
        "url": "https://www.anchorterminal.com/compare/complyadvantage-vs-jumio"
      },
      {
        "json": "https://www.anchorterminal.com/compare/complyadvantage-vs-shufti.json",
        "title": "ComplyAdvantage vs Shufti",
        "url": "https://www.anchorterminal.com/compare/complyadvantage-vs-shufti"
      },
      {
        "json": "https://www.anchorterminal.com/compare/middesk-vs-shufti.json",
        "title": "Middesk vs Shufti",
        "url": "https://www.anchorterminal.com/compare/middesk-vs-shufti"
      }
    ],
    "scores": [
      {
        "by": 0,
        "edge": "",
        "jumio": 65,
        "key": "reliability",
        "name": "Reliability",
        "shufti": 65,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 15,
        "edge": "jumio",
        "jumio": 73,
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "shufti": 58,
        "weight": 13
      },
      {
        "by": 2,
        "edge": "shufti",
        "jumio": 45,
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "shufti": 47,
        "weight": 13
      },
      {
        "by": 1,
        "edge": "jumio",
        "jumio": 63,
        "key": "security",
        "name": "Security \u0026 auth",
        "shufti": 62,
        "weight": 14
      },
      {
        "by": 35,
        "edge": "shufti",
        "jumio": 0,
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "shufti": 35,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 3,
        "edge": "jumio",
        "jumio": 75,
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "shufti": 72,
        "weight": 7
      },
      {
        "by": 11,
        "edge": "shufti",
        "jumio": 60,
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "shufti": 71,
        "weight": 7
      }
    ],
    "summary": "Shufti scores 57.8 (C) on agent readiness against Jumio's 55 (C), and leads in 3 of 7 scored categories. Jumio leads on schema \u0026 documentation. Both do kyc identity.",
    "verdicts": {
      "jumio": "Five OpenAPI 3.0 files, an llms.txt index and OAuth2 clients limited to initiating or to retrieving and deleting make the API readable and containable. Access starts with an account manager, with no public price, trial or service agreement, and the status page shows four processing degradations and a 35-minute Singapore outage between 14 August and 2 October 2026.",
      "shufti": "One endpoint covers document, face, address, AML and KYB checks, with a free plan of 10 verifications a month, and a hosted MCP server adds OAuth with three scopes. No OpenAPI file, server SDK or idempotency key was found, and the status page history could not be read."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/jumio-vs-shufti",
    "json": "https://www.anchorterminal.com/compare/jumio-vs-shufti.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/jumio-vs-shufti.md",
    "slim": "https://www.anchorterminal.com/compare/jumio-vs-shufti.min.md"
  },
  "markdown": "Shufti scores 57.8 (C) on agent readiness against Jumio's 55 (C), and leads in 3 of 7 scored categories. Jumio leads on schema \u0026 documentation. Both do kyc identity.\n\n- Jumio: grade C, 55/100, rank #603 of 842. Markdown https://www.anchorterminal.com/tools/jumio.md · JSON https://www.anchorterminal.com/api/v1/tools/jumio.json\n- Shufti: grade C, 57.8/100, rank #538 of 842. Markdown https://www.anchorterminal.com/tools/shufti.md · JSON https://www.anchorterminal.com/api/v1/tools/shufti.json\n\n## Which one, for what\n\n### Jumio (C)\n\nGood for: An enterprise with a Jumio contract that wants document, selfie and liveness checks, watchlist screening and Latin American, Thai and Australian database checks behind OpenAPI-described endpoints.\n\nAhead on:\n- Schema \u0026 documentation, 73 against 58\n\nWatch for: No public price, free tier or trial. OAuth2 and workflow keys are activated by a Jumio account manager\n\n### Shufti (C)\n\nGood for: A team that wants document, face, address, AML and KYB checks behind one endpoint, a free plan for low volume, and an MCP server that hands the person a hosted verification link.\n\nAhead on:\n- Payments \u0026 pricing, 35 against 0\n- Transparency \u0026 trust, 71 against 60\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n- Free to start without a card\n\nWatch for: No OpenAPI file or other machine-readable contract was found. The reference is prose tables plus Postman collections\n\n\n## Score by category\n\n| Category | Weight | Jumio | Shufti | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 65 | 65 | even |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 73 | 58 | Jumio +15 |\n| Agent ergonomics | 13% (16.2 this run) | 45 | 47 | Shufti +2 |\n| Security \u0026 auth | 14% (17.5 this run) | 63 | 62 | Jumio +1 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 0 | 35 | Shufti +35 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 75 | 72 | Jumio +3 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 60 | 71 | Shufti +11 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **55 · C** | **57.8 · C** | |\n\n## Facts side by side\n\n| Fact | Jumio | Shufti |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Jumio Corporation | Shufti Pro Limited |\n| Hosted endpoint | no (local only) | `https://api.shuftipro.com` |\n| Transports | HTTP | HTTP, Streamable HTTP |\n| Auth | OAuth | OAuth or key |\n| Pricing | Paid | Freemium |\n| x402 | no | no |\n| Licence | Proprietary service. No public service agreement was found. The @jumio/websdk npm package is marked UNLICENSED | Proprietary service under Shufti's Terms and Conditions. The licences of the mobile capture SDKs were not checked |\n| Tools exposed | none | 25 |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| Last release | 2026-09-28 | 2026-10-06 |\n| Terms last updated | no document linked |  |\n| Privacy policy last updated | 2026-08-04 | 2026-09-01 |\n| Customer content may train models | yes | yes, with an opt-out |\n| Terms restrict automated access |  |  |\n| Terms restrict benchmarking |  |  |\n| Terms or service can change without notice |  |  |\n| Arbitration or class-action waiver |  |  |\n| Popularity | 72 stars, 2.1k npm/wk | 673 npm/wk |\n\n## Verdicts\n\n**Jumio.** Five OpenAPI 3.0 files, an llms.txt index and OAuth2 clients limited to initiating or to retrieving and deleting make the API readable and containable. Access starts with an account manager, with no public price, trial or service agreement, and the status page shows four processing degradations and a 35-minute Singapore outage between 14 August and 2 October 2026.\n\n**Shufti.** One endpoint covers document, face, address, AML and KYB checks, with a free plan of 10 verifications a month, and a hosted MCP server adds OAuth with three scopes. No OpenAPI file, server SDK or idempotency key was found, and the status page history could not be read.\n\n## Before you call either\n\n### Jumio\n\n1. Use the host for the tenant's region (amer-1, emea-1 or apac-1). Tokens come from auth.\u003cregion\u003e.jumio.ai/oauth2/token with the client ID and secret as Basic credentials\n2. Reuse the bearer token for its 60 minutes. Token requests are limited to 10 a second and new transactions to 1 a second per tenant\n3. Send a User-Agent header on every call. The Account API marks it required\n4. Don't blindly retry POST /api/v1/accounts. Each call creates an account and a transaction, and no idempotency key exists\n5. Wait for the callback or poll the status endpoint until PROCESSED before retrieving. Jumio's retry schedule starts at 40 seconds and stops after 940\n\n### Shufti\n\n1. POST every verification to `https://api.shuftipro.com/` with a unique `reference` of 6 to 250 characters and one object per service. Read results from `/status` with that reference\n2. Register the callback domain in the back office first. An unregistered `callback_url` is rejected\n3. Stay under 60 requests a minute per IP on a production account and 20 on a trial account\n4. Check the `Signature` response header. Accounts created after 15 March 2023 hash the Secret Key with SHA-256 before appending it to the raw response\n5. Through MCP, identity checks return a `verification_url` for the person to open. No tool accepts an image, so use the REST API for offsite proofs\n\n## Questions\n\n### Which is better for AI agents, Jumio or Shufti?\n\nShufti scores 57.8 (C) on agent readiness against Jumio's 55 (C), and leads in 3 of 7 scored categories. Jumio leads on schema \u0026 documentation.\n\n### Do Jumio and Shufti need an API key?\n\nJumio uses an OAuth sign-in. Shufti takes an API key or an OAuth sign-in.\n\n### Can an agent call Jumio and Shufti without installing anything?\n\nNo hosted endpoint is listed for Jumio. Shufti has a hosted endpoint at https://api.shuftipro.com.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/jumio-vs-shufti.json, and with the fewest tokens: https://www.anchorterminal.com/compare/jumio-vs-shufti.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"jumio\", \"b\": \"shufti\"}`. From a terminal: `anchor compare jumio shufti`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/jumio.json and https://www.anchorterminal.com/api/v1/tools/shufti.json\n\n## Other comparisons with Jumio or Shufti\n\n- [ComplyCube vs Jumio](https://www.anchorterminal.com/compare/complycube-vs-jumio.md)\n- [ComplyCube vs Shufti](https://www.anchorterminal.com/compare/complycube-vs-shufti.md)\n- [Didit vs Jumio](https://www.anchorterminal.com/compare/didit-vs-jumio.md)\n- [Didit vs Shufti](https://www.anchorterminal.com/compare/didit-vs-shufti.md)\n- [Jumio vs Middesk](https://www.anchorterminal.com/compare/jumio-vs-middesk.md)\n- [Jumio vs Persona](https://www.anchorterminal.com/compare/jumio-vs-persona.md)\n- [Jumio vs Socure RiskOS](https://www.anchorterminal.com/compare/jumio-vs-socure-riskos.md)\n- [Jumio vs Sumsub](https://www.anchorterminal.com/compare/jumio-vs-sumsub.md)\n- [Jumio vs Trulioo](https://www.anchorterminal.com/compare/jumio-vs-trulioo.md)\n- [Jumio vs Veriff](https://www.anchorterminal.com/compare/jumio-vs-veriff.md)\n- [Persona vs Shufti](https://www.anchorterminal.com/compare/persona-vs-shufti.md)\n- [Shufti vs Socure RiskOS](https://www.anchorterminal.com/compare/shufti-vs-socure-riskos.md)\n- [Shufti vs Sumsub](https://www.anchorterminal.com/compare/shufti-vs-sumsub.md)\n- [Shufti vs Trulioo](https://www.anchorterminal.com/compare/shufti-vs-trulioo.md)\n- [Shufti vs Veriff](https://www.anchorterminal.com/compare/shufti-vs-veriff.md)\n- [ComplyAdvantage vs Jumio](https://www.anchorterminal.com/compare/complyadvantage-vs-jumio.md)\n- [ComplyAdvantage vs Shufti](https://www.anchorterminal.com/compare/complyadvantage-vs-shufti.md)\n- [Middesk vs Shufti](https://www.anchorterminal.com/compare/middesk-vs-shufti.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Jumio vs Shufti",
        "url": ""
      }
    ],
    "description": "Shufti scores 57.8 (C) on agent readiness against Jumio's 55 (C), and leads in 3 of 7 scored categories. Jumio leads on schema \u0026 documentation. Both do kyc identity. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Jumio C 55",
      "Shufti C 57.8",
      "scores"
    ],
    "h1": "Jumio vs Shufti",
    "image": "https://www.anchorterminal.com/assets/og/compare-jumio-vs-shufti.png",
    "path": "/compare/jumio-vs-shufti",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Jumio vs Shufti for AI agents, C 55 vs C 57.8 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/jumio-vs-shufti"
  },
  "tokens": {
    "markdown": 2150,
    "slim": 630
  },
  "version": 1
}
