Head to head · Kyc business · October 2026 research run

Middesk vs Shufti

Middesk scores 59 (C) on agent readiness against Shufti's 57.8 (C), and leads in 3 of 7 scored categories. Shufti leads on security & auth, payments & pricing, maintenance & community and transparency & trust. Both do kyc business.

Which one, for what

Middesk C

Good for An agent onboarding or re-checking US businesses for a bank, lender or marketplace that already holds a Middesk contract, with registry, TIN, sanctions and lien data in one object.

Ahead on

  • Reliability, 73 against 65
  • Schema & documentation, 82 against 58
  • Agent ergonomics, 56 against 47

Watch for

No public price. Fees are set in an order form, and every docs page ends with a prompt to contact sales

Shufti C

Good for A team that wants document, face, address, AML and KYB checks behind one endpoint, a free plan for low volume, and an MCP server that hands the person a hosted verification link.

Ahead on

  • Security & auth, 62 against 56
  • Payments & pricing, 35 against 10
  • Maintenance & community, 72 against 64
  • Transparency & trust, 71 against 61

Also in its favour

  • Free to start without a card

Watch for

No OpenAPI file or other machine-readable contract was found. The reference is prose tables plus Postman collections

Score by category

CategoryWeight this runMiddeskShuftiEdge
Reliability16%207365Middesk +8
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28258Middesk +24
Agent ergonomics13%16.25647Middesk +9
Security & auth14%17.55662Shufti +6
Payments & pricing10%12.51035Shufti +25
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.86472Shufti +8
Transparency & trust7%8.86171Shufti +10
Negative events≤1500
Total59 · C57.8 · C

Facts side by side

FactMiddeskShufti
KindHTTP APIHTTP API
VendorMiddesk, Inc.Shufti Pro Limited
Hosted endpointhttps://api.middesk.com/v1https://api.shuftipro.com
TransportsHTTPHTTP, Streamable HTTP
AuthOAuth or keyOAuth or key
PricingPaidFreemium
x402nono
LicenceProprietary service under Middesk's Business Verification Terms and Conditions. The Claude Code and Codex plugins on GitHub are MITProprietary service under Shufti's Terms and Conditions. The licences of the mobile capture SDKs were not checked
Tools exposed1125
Read-only variant documentednono
llms.txtyesyes
Last release2026-10-052026-10-06
Terms last updatedno date given
Privacy policy last updatedno date given2026-09-01
Customer content may train modelsyesyes, with an opt-out
Terms restrict automated accessnot found in the text
Terms restrict benchmarkingyes
Terms or service can change without noticenot found in the text
Arbitration or class-action waiveryes
Popularity2 stars673 npm/wk

Verdicts

Middesk

A public OpenAPI 3.1 contract for 87 operations, llms.txt, Markdown docs and a dated weekly changelog make the REST API readable to an agent, and OAuth has a read-only scope. Access is sales-led. No price, self-serve signup or official SDK was found, and the hosted MCP server rejects sandbox keys.

Shufti

One endpoint covers document, face, address, AML and KYB checks, with a free plan of 10 verifications a month, and a hosted MCP server adds OAuth with three scopes. No OpenAPI file, server SDK or idempotency key was found, and the status page history could not be read.

Before you call either

Middesk

  1. Match the key to the host. mk_test keys work only at https://api-sandbox.middesk.com/v1 and mk_live keys only at https://api.middesk.com/v1
  2. Name the orders on POST /v1/businesses. Omitting them places a verification order plus every package the account runs automatically, all billed
  3. Send address_line1 and address_line2. The API ignores address_line_1 without an error
  4. A 201 means the business was created, not verified. Wait for the business.updated webhook or poll until status leaves pending
  5. Stay under 20 requests a second per account, and in sandbox wait the seconds in Retry-After after a 429 on business creation

Shufti

  1. POST every verification to https://api.shuftipro.com/ with a unique reference of 6 to 250 characters and one object per service. Read results from /status with that reference
  2. Register the callback domain in the back office first. An unregistered callback_url is rejected
  3. Stay under 60 requests a minute per IP on a production account and 20 on a trial account
  4. Check the Signature response header. Accounts created after 15 March 2023 hash the Secret Key with SHA-256 before appending it to the raw response
  5. Through MCP, identity checks return a verification_url for the person to open. No tool accepts an image, so use the REST API for offsite proofs

Questions

Which is better for AI agents, Middesk or Shufti?

Middesk scores 59 (C) on agent readiness against Shufti's 57.8 (C), and leads in 3 of 7 scored categories. Shufti leads on security & auth, payments & pricing, maintenance & community and transparency & trust.

Do Middesk and Shufti need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call Middesk and Shufti without installing anything?

Yes. Middesk has a hosted endpoint at https://api.middesk.com/v1 and Shufti at https://api.shuftipro.com.

Other comparisons with Middesk or Shufti

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.