Head to head · Kyc business · October 2026 research run

Middesk vs Sumsub

Sumsub scores 68.5 (B) on agent readiness against Middesk's 59 (C), and leads in 6 of 7 scored categories. Both do kyc business.

Which one, for what

Middesk C

Good for An agent onboarding or re-checking US businesses for a bank, lender or marketplace that already holds a Middesk contract, with registry, TIN, sanctions and lien data in one object.

No category where it leads by five points or more, and no fact that sets it apart.

Watch for

No public price. Fees are set in an order form, and every docs page ends with a prompt to contact sales

Sumsub B

Good for An agent that starts verifications, sends links, reads results and AML cases, and works case queues for a regulated business, with one token limited to those permissions.

Ahead on

  • Reliability, 80 against 73
  • Security & auth, 80 against 56
  • Payments & pricing, 25 against 10
  • Maintenance & community, 74 against 64
  • Transparency & trust, 74 against 61

Watch for

No idempotency keys and no Retry-After or backoff guidance found in the reviewed documentation

Score by category

CategoryWeight this runMiddeskSumsubEdge
Reliability16%207380Sumsub +7
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28278Middesk +4
Agent ergonomics13%16.25660Sumsub +4
Security & auth14%17.55680Sumsub +24
Payments & pricing10%12.51025Sumsub +15
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.86474Sumsub +10
Transparency & trust7%8.86174Sumsub +13
Negative events≤1500
Total59 · C68.5 · B

Facts side by side

FactMiddeskSumsub
KindHTTP APIHTTP API
VendorMiddesk, Inc.Sum and Substance Ltd
Hosted endpointhttps://api.middesk.com/v1https://api.sumsub.com
TransportsHTTPHTTP
AuthOAuth or keyOAuth or key
PricingPaidPay per use
x402nono
LicenceProprietary service under Middesk's Business Verification Terms and Conditions. The Claude Code and Codex plugins on GitHub are MITProprietary service under Sumsub's terms and conditions. The agent skills repository and the @sumsub/websdk npm package are MIT
Tools exposed11none
Read-only variant documentednono
llms.txtyesyes
Last release2026-10-052026-10-03
Terms last updatedno date given2026-05-21
Privacy policy last updatedno date given2026-03-19
Customer content may train modelsyesyes
Terms restrict automated accessnot found in the textnot found in the text
Terms restrict benchmarkingyesnot found in the text
Terms or service can change without noticenot found in the textyes
Arbitration or class-action waiveryesyes
Popularity2 stars172k npm/wk

Verdicts

Middesk

A public OpenAPI 3.1 contract for 87 operations, llms.txt, Markdown docs and a dated weekly changelog make the REST API readable to an agent, and OAuth has a read-only scope. Access is sales-led. No price, self-serve signup or official SDK was found, and the hosted MCP server rejects sandbox keys.

Sumsub

Per-token permissions, an IP allowlist, HMAC-signed requests and a public OpenAPI spec with Markdown docs suit an agent working on verification cases. No idempotency keys or Retry-After guidance were found, there is no server SDK, and production access needs a browser signup, a bank card and Sumsub's review of the integration.

Before you call either

Middesk

  1. Match the key to the host. mk_test keys work only at https://api-sandbox.middesk.com/v1 and mk_live keys only at https://api.middesk.com/v1
  2. Name the orders on POST /v1/businesses. Omitting them places a verification order plus every package the account runs automatically, all billed
  3. Send address_line1 and address_line2. The API ignores address_line_1 without an error
  4. A 201 means the business was created, not verified. Wait for the business.updated webhook or poll until status leaves pending
  5. Stay under 20 requests a second per account, and in sandbox wait the seconds in Retry-After after a 429 on business creation

Sumsub

  1. Sign every request. X-App-Access-Sig is the lowercase hex HMAC-SHA256 of timestamp, uppercase method, path with query and raw body, and the timestamp must be within one minute of server time
  2. Use a sandbox token (prefix sbx) for agent work. Sandbox and production tokens are separate, and Sumsub's own skills refuse any other prefix
  3. Stay under 300 GET and 50 POST requests per 5 seconds, and under 500 new applicants per 24 hours in Sandbox
  4. Token permissions can't be edited after creation. Generate a new token with the narrower set and delete the old one
  5. Subscribe to the applicantReviewed webhook for results and verify x-payload-digest against the raw body before trusting it

Questions

Which is better for AI agents, Middesk or Sumsub?

Sumsub scores 68.5 (B) on agent readiness against Middesk's 59 (C), and leads in 6 of 7 scored categories.

Do Middesk and Sumsub need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call Middesk and Sumsub without installing anything?

Yes. Middesk has a hosted endpoint at https://api.middesk.com/v1 and Sumsub at https://api.sumsub.com.

Other comparisons with Middesk or Sumsub

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.