Head to head · Kyc identity · October 2026 research run

Jumio vs Veriff

Veriff scores 61.1 (C) on agent readiness against Jumio's 55 (C), and leads in 3 of 7 scored categories. Both do kyc identity.

Which one, for what

Jumio C

Good for An enterprise with a Jumio contract that wants document, selfie and liveness checks, watchlist screening and Latin American, Thai and Australian database checks behind OpenAPI-described endpoints.

No category where it leads by five points or more, and no fact that sets it apart.

Watch for

No public price, free tier or trial. OAuth2 and workflow keys are activated by a Jumio account manager

Veriff C

Good for A team that needs document and selfie verification with public per-verification prices and a trial, and that can run a webhook receiver and HMAC signing.

Ahead on

  • Schema & documentation, 82 against 73
  • Payments & pricing, 40 against 0
  • Transparency & trust, 67 against 60

Watch for

No server-side SDK and no MCP server. Official packages cover only browser and mobile capture

Score by category

CategoryWeight this runJumioVeriffEdge
Reliability16%206562Jumio +3
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.27382Veriff +9
Agent ergonomics13%16.24543Jumio +2
Security & auth14%17.56363even
Payments & pricing10%12.5040Veriff +40
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87574Jumio +1
Transparency & trust7%8.86067Veriff +7
Negative events≤1500
Total55 · C61.1 · C

Facts side by side

FactJumioVeriff
KindHTTP APIHTTP API
VendorJumio CorporationVeriff OÜ
Hosted endpointno (local only)no (local only)
TransportsHTTPHTTP
AuthOAuthAPI key
PricingPaidPay per use
x402nono
LicenceProprietary service. No public service agreement was found. The @jumio/websdk npm package is marked UNLICENSEDProprietary service. The npm capture SDKs are ISC (@veriff/js-sdk, @veriff/incontext-sdk) and MIT (@veriff/react-native-sdk)
Read-only variant documentednono
llms.txtyesyes
Last release2026-09-282026-10-02
Terms last updatedno document linkedcouldn't be read
Privacy policy last updated2026-08-042026-04-16
Customer content may train modelsyesyes
Terms restrict automated accesscouldn't be read
Terms restrict benchmarkingcouldn't be read
Terms or service can change without noticecouldn't be read
Arbitration or class-action waivercouldn't be read
Popularity72 stars, 2.1k npm/wk32 stars, 110k npm/wk

Verdicts

Jumio

Five OpenAPI 3.0 files, an llms.txt index and OAuth2 clients limited to initiating or to retrieving and deleting make the API readable and containable. Access starts with an account manager, with no public price, trial or service agreement, and the status page shows four processing degradations and a 35-minute Singapore outage between 14 August and 2 October 2026.

Veriff

Per-verification prices are public from $0.80, with a 15-day trial of 50 sessions and no card. Each endpoint page is Markdown with an OpenAPI 3.0 fragment. There is no server SDK, MCP server or idempotency key, most calls need an HMAC signature, and the status page shows nine incidents between 20 July and 7 October 2026.

Before you call either

Jumio

  1. Use the host for the tenant's region (amer-1, emea-1 or apac-1). Tokens come from auth.<region>.jumio.ai/oauth2/token with the client ID and secret as Basic credentials
  2. Reuse the bearer token for its 60 minutes. Token requests are limited to 10 a second and new transactions to 1 a second per tenant
  3. Send a User-Agent header on every call. The Account API marks it required
  4. Don't blindly retry POST /api/v1/accounts. Each call creates an account and a transaction, and no idempotency key exists
  5. Wait for the callback or poll the status endpoint until PROCESSED before retrieving. Jumio's retry schedule starts at 40 seconds and stops after 940

Veriff

  1. Take the base URL from the integration's API keys page. Send X-AUTH-CLIENT on every call and store verification.id from POST /v1/sessions
  2. Sign POST and PATCH bodies, and the session ID on GET and DELETE, with HMAC-SHA256 in X-HMAC-SIGNATURE. POST /v1/sessions needs no signature
  3. Stay under 30 session creations a minute on Self-Serve, 600 on Enterprise. A 429 carries code 1004
  4. Don't blindly retry POST /v1/sessions. Each call makes a new session, which is billed on a live integration
  5. Poll GET /v1/sessions/{id}/decision until verification is not null, or accept webhooks within 5 seconds and treat duplicates as normal

Questions

Which is better for AI agents, Jumio or Veriff?

Veriff scores 61.1 (C) on agent readiness against Jumio's 55 (C), and leads in 3 of 7 scored categories.

Do Jumio and Veriff need an API key?

Jumio uses an OAuth sign-in. Veriff needs an API key.

Can an agent call Jumio and Veriff without installing anything?

No hosted endpoint is listed for Jumio. No hosted endpoint is listed for Veriff.

Other comparisons with Jumio or Veriff

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.