Head to head · Kyc business · October 2026 research run
Middesk vs Sumsub
Sumsub scores 68.5 (B) on agent readiness against Middesk's 59 (C), and leads in 6 of 7 scored categories. Both do kyc business.
Which one, for what
Middesk C
Good for An agent onboarding or re-checking US businesses for a bank, lender or marketplace that already holds a Middesk contract, with registry, TIN, sanctions and lien data in one object.
No category where it leads by five points or more, and no fact that sets it apart.
Watch for
No public price. Fees are set in an order form, and every docs page ends with a prompt to contact sales
Sumsub B
Good for An agent that starts verifications, sends links, reads results and AML cases, and works case queues for a regulated business, with one token limited to those permissions.
Ahead on
- Reliability, 80 against 73
- Security & auth, 80 against 56
- Payments & pricing, 25 against 10
- Maintenance & community, 74 against 64
- Transparency & trust, 74 against 61
Watch for
No idempotency keys and no Retry-After or backoff guidance found in the reviewed documentation
Score by category
| Category | Weight this run | Middesk | Sumsub | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 73 | 80 | Sumsub +7 |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 82 | 78 | Middesk +4 |
| Agent ergonomics | 13%16.2 | 56 | 60 | Sumsub +4 |
| Security & auth | 14%17.5 | 56 | 80 | Sumsub +24 |
| Payments & pricing | 10%12.5 | 10 | 25 | Sumsub +15 |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 64 | 74 | Sumsub +10 |
| Transparency & trust | 7%8.8 | 61 | 74 | Sumsub +13 |
| Negative events | ≤15 | 0 | 0 | |
| Total | 59 · C | 68.5 · B |
Facts side by side
| Fact | Middesk | Sumsub |
|---|---|---|
| Kind | HTTP API | HTTP API |
| Vendor | Middesk, Inc. | Sum and Substance Ltd |
| Hosted endpoint | https://api.middesk.com/v1 | https://api.sumsub.com |
| Transports | HTTP | HTTP |
| Auth | OAuth or key | OAuth or key |
| Pricing | Paid | Pay per use |
| x402 | no | no |
| Licence | Proprietary service under Middesk's Business Verification Terms and Conditions. The Claude Code and Codex plugins on GitHub are MIT | Proprietary service under Sumsub's terms and conditions. The agent skills repository and the @sumsub/websdk npm package are MIT |
| Tools exposed | 11 | none |
| Read-only variant documented | no | no |
| llms.txt | yes | yes |
| Last release | 2026-10-05 | 2026-10-03 |
| Terms last updated | no date given | 2026-05-21 |
| Privacy policy last updated | no date given | 2026-03-19 |
| Customer content may train models | yes | yes |
| Terms restrict automated access | not found in the text | not found in the text |
| Terms restrict benchmarking | yes | not found in the text |
| Terms or service can change without notice | not found in the text | yes |
| Arbitration or class-action waiver | yes | yes |
| Popularity | 2 stars | 172k npm/wk |
Verdicts
Middesk
A public OpenAPI 3.1 contract for 87 operations, llms.txt, Markdown docs and a dated weekly changelog make the REST API readable to an agent, and OAuth has a read-only scope. Access is sales-led. No price, self-serve signup or official SDK was found, and the hosted MCP server rejects sandbox keys.
Sumsub
Per-token permissions, an IP allowlist, HMAC-signed requests and a public OpenAPI spec with Markdown docs suit an agent working on verification cases. No idempotency keys or Retry-After guidance were found, there is no server SDK, and production access needs a browser signup, a bank card and Sumsub's review of the integration.
Before you call either
Middesk
- Match the key to the host.
mk_testkeys work only at https://api-sandbox.middesk.com/v1 andmk_livekeys only at https://api.middesk.com/v1 - Name the
ordersonPOST /v1/businesses. Omitting them places a verification order plus every package the account runs automatically, all billed - Send
address_line1andaddress_line2. The API ignoresaddress_line_1without an error - A 201 means the business was created, not verified. Wait for the
business.updatedwebhook or poll untilstatusleavespending - Stay under 20 requests a second per account, and in sandbox wait the seconds in
Retry-Afterafter a 429 on business creation
Sumsub
- Sign every request. X-App-Access-Sig is the lowercase hex HMAC-SHA256 of timestamp, uppercase method, path with query and raw body, and the timestamp must be within one minute of server time
- Use a sandbox token (prefix sbx) for agent work. Sandbox and production tokens are separate, and Sumsub's own skills refuse any other prefix
- Stay under 300 GET and 50 POST requests per 5 seconds, and under 500 new applicants per 24 hours in Sandbox
- Token permissions can't be edited after creation. Generate a new token with the narrower set and delete the old one
- Subscribe to the applicantReviewed webhook for results and verify x-payload-digest against the raw body before trusting it
Questions
Which is better for AI agents, Middesk or Sumsub?
Sumsub scores 68.5 (B) on agent readiness against Middesk's 59 (C), and leads in 6 of 7 scored categories.
Do Middesk and Sumsub need an API key?
Both take an API key or an OAuth sign-in.
Can an agent call Middesk and Sumsub without installing anything?
Yes. Middesk has a hosted endpoint at https://api.middesk.com/v1 and Sumsub at https://api.sumsub.com.
Other comparisons with Middesk or Sumsub
Machine-readable
- This page as Markdown
/compare/middesk-vs-sumsub.md· slim.min.md· JSON.json(or sendAccept: text/markdown) - Each listing in full
/api/v1/tools/middesk.json·/api/v1/tools/sumsub.json - From a terminal
anchor compare middesk sumsub(the CLI) - Over MCP
compare_tools {"a": "middesk", "b": "sumsub"}at/mcp, no key