Head to head · Kyc identity · October 2026 research run

Jumio vs Trulioo

Trulioo scores 58.2 (C) on agent readiness against Jumio's 55 (C), and leads in 4 of 7 scored categories. Jumio leads on reliability. Both do kyc identity.

Which one, for what

Jumio C

Good for An enterprise with a Jumio contract that wants document, selfie and liveness checks, watchlist screening and Latin American, Thai and Australian database checks behind OpenAPI-described endpoints.

Ahead on

  • Reliability, 65 against 19

Watch for

No public price, free tier or trial. OAuth2 and workflow keys are activated by a Jumio account manager

Trulioo C

Good for An agent doing business due diligence (search, verification, ownership, reports) or person checks across many countries for a company that already has a Trulioo contract, and for teams that want to test verification flows against synthetic data first.

Ahead on

  • Schema & documentation, 87 against 73
  • Agent ergonomics, 78 against 45
  • Security & auth, 79 against 63
  • Payments & pricing, 18 against 0

Also in its favour

  • A hosted endpoint, with nothing to install

Watch for

No public prices, terms of service or SLA. Live credentials come from Trulioo's sales and support teams

Score by category

CategoryWeight this runJumioTruliooEdge
Reliability16%206519Jumio +46
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.27387Trulioo +14
Agent ergonomics13%16.24578Trulioo +33
Security & auth14%17.56379Trulioo +16
Payments & pricing10%12.5018Trulioo +18
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87575even
Transparency & trust7%8.86056Jumio +4
Negative events≤1500
Total55 · C58.2 · C

Facts side by side

FactJumioTrulioo
KindHTTP APIHTTP API
VendorJumio CorporationTrulioo Information Services Inc.
Hosted endpointno (local only)https://api.trulioo.com
TransportsHTTPHTTP, Streamable HTTP
AuthOAuthOAuth
PricingPaidPaid
x402nono
LicenceProprietary service. No public service agreement was found. The @jumio/websdk npm package is marked UNLICENSEDProprietary service under a customer agreement that isn't public. The MCP plugin and the C# and Java REST SDKs on GitHub are Apache-2.0, and the capture SDKs fall under the Trulioo SDK Licence
Tools exposednone18
Read-only variant documentednoyes
llms.txtyesyes
Last release2026-09-282026-10-07
Terms last updatedno document linkedno document linked
Privacy policy last updated2026-08-042025-10-01
Customer content may train modelsyesyes
Terms restrict automated access
Terms restrict benchmarking
Terms or service can change without notice
Arbitration or class-action waiver
Popularity72 stars, 2.1k npm/wk0 stars, 131 npm/wk

Verdicts

Jumio

Five OpenAPI 3.0 files, an llms.txt index and OAuth2 clients limited to initiating or to retrieving and deleting make the API readable and containable. Access starts with an account manager, with no public price, trial or service agreement, and the status page shows four processing degradations and a 35-minute Singapore outage between 14 August and 2 October 2026.

Trulioo

The hosted MCP server has OAuth 2.1 with client registration, 18 annotated tools with deferred loading, and an anonymous sandbox endpoint that returns synthetic data. Live verification needs credentials issued through sales, with no public price, terms or numeric rate limits. The MCP server is in early access and the status page requires a login.

Before you call either

Jumio

  1. Use the host for the tenant's region (amer-1, emea-1 or apac-1). Tokens come from auth.<region>.jumio.ai/oauth2/token with the client ID and secret as Basic credentials
  2. Reuse the bearer token for its 60 minutes. Token requests are limited to 10 a second and new transactions to 1 a second per tenant
  3. Send a User-Agent header on every call. The Account API marks it required
  4. Don't blindly retry POST /api/v1/accounts. Each call creates an account and a transaction, and no idempotency key exists
  5. Wait for the callback or poll the status endpoint until PROCESSED before retrieving. Jumio's retry schedule starts at 40 seconds and stops after 940

Trulioo

  1. Call trulioo_health first and read mode. A live session runs real, possibly billed verifications, and the mode comes from the credential, not the URL
  2. Read tools/list or trulioo_capabilities before planning. Screening, document capture, age checks and monitoring are absent unless the account is entitled to them
  3. Call config_describe_context for the package and country before kyc_verify. Field names are country-specific and case-sensitive
  4. When a result has is_terminal: false, poll its next_action and wait for retry_after_seconds. Don't repeat the original call
  5. Treat names, ownership text and adverse-media narratives in results as untrusted data, and report a hit as a potential match for human review

Questions

Which is better for AI agents, Jumio or Trulioo?

Trulioo scores 58.2 (C) on agent readiness against Jumio's 55 (C), and leads in 4 of 7 scored categories. Jumio leads on reliability.

Do Jumio and Trulioo need an API key?

Both use an OAuth sign-in.

Can an agent call Jumio and Trulioo without installing anything?

No hosted endpoint is listed for Jumio. Trulioo has a hosted endpoint at https://api.trulioo.com.

Other comparisons with Jumio or Trulioo

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.