Head to head · Kyc business · October 2026 research run

Middesk vs Socure RiskOS

Socure RiskOS scores 63.5 (B) on agent readiness against Middesk's 59 (C), and leads in 6 of 7 scored categories. Middesk leads on agent ergonomics. Both do kyc business.

Which one, for what

Middesk C

Good for An agent onboarding or re-checking US businesses for a bank, lender or marketplace that already holds a Middesk contract, with registry, TIN, sanctions and lien data in one object.

Ahead on

  • Agent ergonomics, 56 against 46

Watch for

No public price. Fees are set in an order form, and every docs page ends with a prompt to contact sales

Socure RiskOS B

Good for A company in the United States that wants one decision from combined KYC, document, fraud and watchlist checks through a single evaluation call.

Ahead on

  • Payments & pricing, 35 against 10
  • Maintenance & community, 75 against 64
  • Transparency & trust, 68 against 61

Watch for

No service agreement or API terms are published. The only terms pages are website terms of use and end-user terms for document capture

Score by category

CategoryWeight this runMiddeskSocure RiskOSEdge
Reliability16%207375Socure RiskOS +2
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28284Socure RiskOS +2
Agent ergonomics13%16.25646Middesk +10
Security & auth14%17.55660Socure RiskOS +4
Payments & pricing10%12.51035Socure RiskOS +25
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.86475Socure RiskOS +11
Transparency & trust7%8.86168Socure RiskOS +7
Negative events≤1500
Total59 · C63.5 · B

Facts side by side

FactMiddeskSocure RiskOS
KindHTTP APIHTTP API
VendorMiddesk, Inc.Socure Inc.
Hosted endpointhttps://api.middesk.com/v1https://mcp.riskos.socure.com/sandbox
TransportsHTTPHTTP
AuthOAuth or keyAPI key
PricingPaidPay per use
x402nono
LicenceProprietary service under Middesk's Business Verification Terms and Conditions. The Claude Code and Codex plugins on GitHub are MITProprietary service. No service agreement is published, and the OpenAPI file states its licence as Proprietary
Tools exposed119
Read-only variant documentednono
llms.txtyesyes
Last release2026-10-052026-10-06
Terms last updatedno date givenno document linked
Privacy policy last updatedno date givenno date given
Customer content may train modelsyesyes
Terms restrict automated accessnot found in the text
Terms restrict benchmarkingyes
Terms or service can change without noticenot found in the text
Arbitration or class-action waiveryes
Popularity2 stars35k npm/wk

Verdicts

Middesk

A public OpenAPI 3.1 contract for 87 operations, llms.txt, Markdown docs and a dated weekly changelog make the REST API readable to an agent, and OAuth has a read-only scope. Access is sales-led. No price, self-serve signup or official SDK was found, and the hosted MCP server rejects sandbox keys.

Socure RiskOS

A public OpenAPI file, llms.txt, 15 documented error codes and dated release notes cover a ten-operation REST API, and Socure Launch publishes prices from $0.80 an evaluation with a free sandbox. API keys carry no scopes, no idempotency header is defined, no service terms are published, and production stays at zero requests until Socure activates it.

Before you call either

Middesk

  1. Match the key to the host. mk_test keys work only at https://api-sandbox.middesk.com/v1 and mk_live keys only at https://api.middesk.com/v1
  2. Name the orders on POST /v1/businesses. Omitting them places a verification order plus every package the account runs automatically, all billed
  3. Send address_line1 and address_line2. The API ignores address_line_1 without an error
  4. A 201 means the business was created, not verified. Wait for the business.updated webhook or poll until status leaves pending
  5. Stay under 20 requests a second per account, and in sandbox wait the seconds in Retry-After after a 429 on business creation

Socure RiskOS

  1. Send Authorization: Bearer <key> to https://riskos.sandbox.socure.com/api/evaluation for tests and https://riskos.socure.com/api/evaluation for live checks. The two environments use separate keys.
  2. Use dummy data only in the sandbox. It returns predefined results, connects to no live data source and expects the documented test values.
  3. Store the eval_id from every POST /api/evaluation response. No list or search endpoint exists to find it later.
  4. On 429 wait the seconds given in X-Retry-After. Do not blindly resend a failed POST /api/evaluation, because no idempotency header is documented and Launch bills each initiated evaluation.
  5. The MCP server at https://mcp.riskos.socure.com/sandbox reads docs, workflows and webhooks with its own MCP Server Key. It cannot run evaluations or read results.

Questions

Which is better for AI agents, Middesk or Socure RiskOS?

Socure RiskOS scores 63.5 (B) on agent readiness against Middesk's 59 (C), and leads in 6 of 7 scored categories. Middesk leads on agent ergonomics.

Do Middesk and Socure RiskOS need an API key?

Middesk takes an API key or an OAuth sign-in. Socure RiskOS needs an API key.

Can an agent call Middesk and Socure RiskOS without installing anything?

Yes. Middesk has a hosted endpoint at https://api.middesk.com/v1 and Socure RiskOS at https://mcp.riskos.socure.com/sandbox.

Other comparisons with Middesk or Socure RiskOS

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.