Head to head · Kyc identity · October 2026 research run
Persona vs Shufti
Persona scores 69.5 (B) on agent readiness against Shufti's 57.8 (C), and leads in 5 of 7 scored categories. Both do kyc identity.
Which one, for what
Persona B
Good for A company that already runs Persona and wants an agent to create inquiries from templates, read verification and report results, screen against watchlists and work review cases with a permission-limited key.
Ahead on
- Reliability, 70 against 65
- Schema & documentation, 85 against 58
- Agent ergonomics, 74 against 47
- Security & auth, 73 against 62
Watch for
Production access needs Persona's approval and a 12-month plan from $250 a month, and API-only integration is limited to Enterprise plans
Shufti C
Good for A team that wants document, face, address, AML and KYB checks behind one endpoint, a free plan for low volume, and an MCP server that hands the person a hosted verification link.
Also in its favour
- Free to start without a card
Watch for
No OpenAPI file or other machine-readable contract was found. The reference is prose tables plus Postman collections
Score by category
| Category | Weight this run | Persona | Shufti | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 70 | 65 | Persona +5 |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 85 | 58 | Persona +27 |
| Agent ergonomics | 13%16.2 | 74 | 47 | Persona +27 |
| Security & auth | 14%17.5 | 73 | 62 | Persona +11 |
| Payments & pricing | 10%12.5 | 35 | 35 | even |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 75 | 72 | Persona +3 |
| Transparency & trust | 7%8.8 | 68 | 71 | Shufti +3 |
| Negative events | ≤15 | 0 | 0 | |
| Total | 69.5 · B | 57.8 · C |
Facts side by side
| Fact | Persona | Shufti |
|---|---|---|
| Kind | HTTP API | HTTP API |
| Vendor | Persona Identities, Inc. | Shufti Pro Limited |
| Hosted endpoint | https://mcp.withpersona.com | https://api.shuftipro.com |
| Transports | HTTP | HTTP, Streamable HTTP |
| Auth | API key | OAuth or key |
| Pricing | Paid | Freemium |
| x402 | no | no |
| Licence | Proprietary service under Persona's terms of service. The persona JavaScript client on npm is MIT | Proprietary service under Shufti's Terms and Conditions. The licences of the mobile capture SDKs were not checked |
| Tools exposed | 190 | 25 |
| Read-only variant documented | no | no |
| llms.txt | yes | yes |
| Last release | 2026-09-29 | 2026-10-06 |
| Terms last updated | couldn't be read | |
| Privacy policy last updated | couldn't be read | 2026-09-01 |
| Customer content may train models | couldn't be read | yes, with an opt-out |
| Terms restrict automated access | couldn't be read | |
| Terms restrict benchmarking | couldn't be read | |
| Terms or service can change without notice | couldn't be read | |
| Arbitration or class-action waiver | couldn't be read | |
| Popularity | 570k npm/wk | 673 npm/wk |
Verdicts
Persona
The REST API has a public OpenAPI 3.1 file, llms.txt, API keys with per-resource permissions, idempotency keys on every POST and a 60-day sandbox trial with no card. Production needs a business review and a 12-month plan from $250 a month. The status page lists 11 incidents since 10 July 2026, including 70 minutes of timeouts across all products.
Shufti
One endpoint covers document, face, address, AML and KYB checks, with a free plan of 10 verifications a month, and a hosted MCP server adds OAuth with three scopes. No OpenAPI file, server SDK or idempotency key was found, and the status page history could not be read.
Before you call either
Persona
- Ask for a dedicated key limited to the permissions the task needs. A new key has every standard permission until it's limited
- Send
Persona-Versionon every call and anIdempotency-Keyon every POST. A replayed key returns the first result, including a 500 - Treat redact calls as irreversible. They permanently delete personal data and cascade to downstream objects
- Stay under 300 requests a minute in production, read
RateLimit-RemainingandQuota-Remaining, and back off on 429 because rejected requests still count - Use
fieldsandincludeto cut response size. Through MCP these parameters aren't exposed, and only 14 tools takefilter
Shufti
- POST every verification to
https://api.shuftipro.com/with a uniquereferenceof 6 to 250 characters and one object per service. Read results from/statuswith that reference - Register the callback domain in the back office first. An unregistered
callback_urlis rejected - Stay under 60 requests a minute per IP on a production account and 20 on a trial account
- Check the
Signatureresponse header. Accounts created after 15 March 2023 hash the Secret Key with SHA-256 before appending it to the raw response - Through MCP, identity checks return a
verification_urlfor the person to open. No tool accepts an image, so use the REST API for offsite proofs
Questions
Which is better for AI agents, Persona or Shufti?
Persona scores 69.5 (B) on agent readiness against Shufti's 57.8 (C), and leads in 5 of 7 scored categories.
Do Persona and Shufti need an API key?
Persona needs an API key. Shufti takes an API key or an OAuth sign-in.
Can an agent call Persona and Shufti without installing anything?
Yes. Persona has a hosted endpoint at https://mcp.withpersona.com and Shufti at https://api.shuftipro.com.
Other comparisons with Persona or Shufti
- ComplyCube vs Persona
- ComplyCube vs Shufti
- Didit vs Persona
- Didit vs Shufti
- Jumio vs Persona
- Jumio vs Shufti
- Persona vs Socure RiskOS
- Persona vs Sumsub
- Persona vs Trulioo
- Persona vs Veriff
- Shufti vs Socure RiskOS
- Shufti vs Sumsub
- Shufti vs Trulioo
- Shufti vs Veriff
- ComplyAdvantage vs Persona
- ComplyAdvantage vs Shufti
- Middesk vs Persona
- Middesk vs Shufti
Machine-readable
- This page as Markdown
/compare/persona-vs-shufti.md· slim.min.md· JSON.json(or sendAccept: text/markdown) - Each listing in full
/api/v1/tools/persona.json·/api/v1/tools/shufti.json - From a terminal
anchor compare persona shufti(the CLI) - Over MCP
compare_tools {"a": "persona", "b": "shufti"}at/mcp, no key