Head to head · Kyc identity · October 2026 research run

Persona vs Shufti

Persona scores 69.5 (B) on agent readiness against Shufti's 57.8 (C), and leads in 5 of 7 scored categories. Both do kyc identity.

Which one, for what

Persona B

Good for A company that already runs Persona and wants an agent to create inquiries from templates, read verification and report results, screen against watchlists and work review cases with a permission-limited key.

Ahead on

  • Reliability, 70 against 65
  • Schema & documentation, 85 against 58
  • Agent ergonomics, 74 against 47
  • Security & auth, 73 against 62

Watch for

Production access needs Persona's approval and a 12-month plan from $250 a month, and API-only integration is limited to Enterprise plans

Shufti C

Good for A team that wants document, face, address, AML and KYB checks behind one endpoint, a free plan for low volume, and an MCP server that hands the person a hosted verification link.

Also in its favour

  • Free to start without a card

Watch for

No OpenAPI file or other machine-readable contract was found. The reference is prose tables plus Postman collections

Score by category

CategoryWeight this runPersonaShuftiEdge
Reliability16%207065Persona +5
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28558Persona +27
Agent ergonomics13%16.27447Persona +27
Security & auth14%17.57362Persona +11
Payments & pricing10%12.53535even
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87572Persona +3
Transparency & trust7%8.86871Shufti +3
Negative events≤1500
Total69.5 · B57.8 · C

Facts side by side

FactPersonaShufti
KindHTTP APIHTTP API
VendorPersona Identities, Inc.Shufti Pro Limited
Hosted endpointhttps://mcp.withpersona.comhttps://api.shuftipro.com
TransportsHTTPHTTP, Streamable HTTP
AuthAPI keyOAuth or key
PricingPaidFreemium
x402nono
LicenceProprietary service under Persona's terms of service. The persona JavaScript client on npm is MITProprietary service under Shufti's Terms and Conditions. The licences of the mobile capture SDKs were not checked
Tools exposed19025
Read-only variant documentednono
llms.txtyesyes
Last release2026-09-292026-10-06
Terms last updatedcouldn't be read
Privacy policy last updatedcouldn't be read2026-09-01
Customer content may train modelscouldn't be readyes, with an opt-out
Terms restrict automated accesscouldn't be read
Terms restrict benchmarkingcouldn't be read
Terms or service can change without noticecouldn't be read
Arbitration or class-action waivercouldn't be read
Popularity570k npm/wk673 npm/wk

Verdicts

Persona

The REST API has a public OpenAPI 3.1 file, llms.txt, API keys with per-resource permissions, idempotency keys on every POST and a 60-day sandbox trial with no card. Production needs a business review and a 12-month plan from $250 a month. The status page lists 11 incidents since 10 July 2026, including 70 minutes of timeouts across all products.

Shufti

One endpoint covers document, face, address, AML and KYB checks, with a free plan of 10 verifications a month, and a hosted MCP server adds OAuth with three scopes. No OpenAPI file, server SDK or idempotency key was found, and the status page history could not be read.

Before you call either

Persona

  1. Ask for a dedicated key limited to the permissions the task needs. A new key has every standard permission until it's limited
  2. Send Persona-Version on every call and an Idempotency-Key on every POST. A replayed key returns the first result, including a 500
  3. Treat redact calls as irreversible. They permanently delete personal data and cascade to downstream objects
  4. Stay under 300 requests a minute in production, read RateLimit-Remaining and Quota-Remaining, and back off on 429 because rejected requests still count
  5. Use fields and include to cut response size. Through MCP these parameters aren't exposed, and only 14 tools take filter

Shufti

  1. POST every verification to https://api.shuftipro.com/ with a unique reference of 6 to 250 characters and one object per service. Read results from /status with that reference
  2. Register the callback domain in the back office first. An unregistered callback_url is rejected
  3. Stay under 60 requests a minute per IP on a production account and 20 on a trial account
  4. Check the Signature response header. Accounts created after 15 March 2023 hash the Secret Key with SHA-256 before appending it to the raw response
  5. Through MCP, identity checks return a verification_url for the person to open. No tool accepts an image, so use the REST API for offsite proofs

Questions

Which is better for AI agents, Persona or Shufti?

Persona scores 69.5 (B) on agent readiness against Shufti's 57.8 (C), and leads in 5 of 7 scored categories.

Do Persona and Shufti need an API key?

Persona needs an API key. Shufti takes an API key or an OAuth sign-in.

Can an agent call Persona and Shufti without installing anything?

Yes. Persona has a hosted endpoint at https://mcp.withpersona.com and Shufti at https://api.shuftipro.com.

Other comparisons with Persona or Shufti

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.