{
  "data": {
    "a": {
      "slug": "persona",
      "name": "Persona",
      "vendor": "Persona Identities, Inc.",
      "vendorUrl": "https://withpersona.com",
      "kind": "http-api",
      "category": "identity-verification",
      "summary": "Persona is an identity verification platform from Persona Identities, Inc. Its REST API and hosted MCP server create inquiries, run government ID, selfie, document and database verifications, screen people and businesses against watchlists, and manage review cases.",
      "url": "https://www.anchorterminal.com/tools/persona",
      "markdownUrl": "https://www.anchorterminal.com/tools/persona.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/persona.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/persona.json",
      "license": "Proprietary service under Persona's terms of service. The `persona` JavaScript client on npm is MIT",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://mcp.withpersona.com",
      "packages": [
        {
          "registry": "npm",
          "name": "persona"
        }
      ],
      "auth": "api-key",
      "authNotes": "Self-serve API key, sent as `Authorization: Bearer \u003ckey\u003e` to https://api.withpersona.com/api/v1. A browser sign-up with a business email gives a sandbox key (`persona_sandbox_...`) at once. A production key (`persona_production_...`) needs a plan and Persona's approval of the organisation. Each key can be limited to about 50 read and write permissions per resource, given its own rate limit and an IP allowlist, and expired through the dashboard or the API. A new key has every standard permission until someone limits it. The MCP server at https://mcp.withpersona.com takes the same key. Its help article says OAuth is coming and isn't available yet (checked 2026-10-08).",
      "pricing": "paid",
      "pricingNotes": "The Essential plan starts at $250 a month on a 12-month contract with 500 verifications or reports a month included, then $1.50 for each further one, per the help centre. Growth and Enterprise are priced through sales. A 60-day trial with no card gives sandbox access and up to 50 services, so an agent can build and test without a contract, but the sandbox performs no real verifications. A Startup Programme gives eligible small companies 500 free verifications a month for a year. The pricing page itself refused our reader (checked 2026-10-08).",
      "priceSummary": "$250 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the API docs, the OpenAPI file, the MCP tool list or the help centre's plan articles (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 190,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 570188,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.withpersona.com/getting-started",
      "llmsTxt": "https://docs.withpersona.com/llms.txt",
      "openapi": "https://docs.withpersona.com/openapi/api-reference.json",
      "capabilities": [
        "kyc.identity",
        "kyc.business",
        "kyc.documents",
        "kyc.screening",
        "kyc.cases"
      ],
      "tags": [
        "hosted",
        "paid",
        "sandbox",
        "api-key",
        "mcp",
        "openapi",
        "llms-txt",
        "webhooks",
        "json-api",
        "status-page",
        "soc2",
        "iso27001"
      ],
      "lastRelease": "2026-09-29",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 69.5,
        "grade": "B",
        "agentReady": false,
        "rank": 176,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 2,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 74,
          "maintenance": 75,
          "payments": 35,
          "reliability": 70,
          "schema": 85,
          "security": 73,
          "transparency": 68
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "The REST API has a public OpenAPI 3.1 file, llms.txt, API keys with per-resource permissions, idempotency keys on every POST and a 60-day sandbox trial with no card. Production needs a business review and a 12-month plan from $250 a month. The status page lists 11 incidents since 10 July 2026, including 70 minutes of timeouts across all products.",
        "bestFor": "A company that already runs Persona and wants an agent to create inquiries from templates, read verification and report results, screen against watchlists and work review cases with a permission-limited key.",
        "strengths": [
          "Public OpenAPI 3.1 file with 231 operations and 141 webhook definitions, plus llms.txt and a Markdown copy of every docs page",
          "API keys take about 50 read and write permissions per resource, an IP allowlist, their own rate limit and an expiry endpoint",
          "`Idempotency-Key` on every POST, cursor pagination, and `fields` and `include` parameters that trim responses",
          "API logs kept for two weeks and user audit logs for six months, both readable through the API",
          "Dated API versions selected per key or per request with `Persona-Version`, and a changelog with an RSS feed"
        ],
        "weaknesses": [
          "Production access needs Persona's approval and a 12-month plan from $250 a month, and API-only integration is limited to Enterprise plans",
          "Eleven incidents on the status page since 10 July 2026, five marked partial outage, most on document and government ID verifications",
          "The MCP server lists all 190 tools whatever the key allows, with no annotations, toolsets or read-only subset, and OAuth isn't available yet",
          "No official server-side SDK was found. The npm, iOS, Android and React Native packages are clients for the end-user flow",
          "The marketing site, terms, privacy policy and pricing page answered our reader with a bot check, and no SLA was found in the docs or help centre"
        ],
        "agentNotes": [
          "Ask for a dedicated key limited to the permissions the task needs. A new key has every standard permission until it's limited",
          "Send `Persona-Version` on every call and an `Idempotency-Key` on every POST. A replayed key returns the first result, including a 500",
          "Treat redact calls as irreversible. They permanently delete personal data and cascade to downstream objects",
          "Stay under 300 requests a minute in production, read `RateLimit-Remaining` and `Quota-Remaining`, and back off on 429 because rejected requests still count",
          "Use `fields` and `include` to cut response size. Through MCP these parameters aren't exposed, and only 14 tools take `filter`"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 69.5
          }
        ],
        "editorialScores": {
          "ergonomics": 74,
          "maintenance": 75,
          "payments": 35,
          "reliability": 70,
          "schema": 85,
          "security": 73,
          "transparency": 46
        },
        "provenanceScore": 90
      },
      "connect": {
        "http": "curl --request POST \\\n     --url https://api.withpersona.com/api/v1/inquiries \\\n     --header 'Persona-Version: 2023-01-05' \\\n     --header 'accept: application/json' \\\n     --header 'authorization: Bearer persona_sandbox_YOURAPIKEY' \\\n     --header 'content-type: application/json' \\\n     --data '{\"data\":{\"attributes\":{\"inquiry-template-id\":\"itmpl_YOURTEMPLATEID\",\"fields\":{\"name-first\":\"Jane\",\"name-last\":\"Doe\",\"birthdate\":\"1994-04-12\"}}}}'"
      },
      "letme": {
        "capability": "https://letme.dev/kyc.identity",
        "tool": "https://letme.dev/persona"
      },
      "area": "domain-data",
      "unitPrices": [
        {
          "item": "Essential plan",
          "unit": "month",
          "usd": 250,
          "note": "12-month contract, 500 verifications or reports a month included, unused ones don't roll over"
        },
        {
          "item": "Additional verification or report on the Essential plan",
          "unit": "tx",
          "usd": 1.5,
          "note": "Each service beyond the 500 included a month"
        }
      ],
      "provenance": {
        "legalEntity": "Persona Identities, Inc.",
        "domain": "withpersona.com",
        "domainRegistered": "2018-09-24",
        "endpointOnVendorDomain": true,
        "terms": "https://withpersona.com/legal/terms-of-service",
        "privacy": "https://withpersona.com/legal/privacy-policy",
        "statusPage": "https://status.withpersona.com",
        "changelog": "https://docs.withpersona.com/api-reference/versioning/changelog",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "The help centre footer reads \"2026 Persona Identities, Inc.\", and the `persona` npm package names Persona Identities, Inc. as author.",
          "The API answers at api.withpersona.com and the MCP server at mcp.withpersona.com, both withpersona.com subdomains.",
          "withpersona.com/.well-known/security.txt gives security@withpersona.com, an expiry of 17 February 2027 and a note that disclosure runs through Bugcrowd.",
          "The terms and privacy URLs are the ones the status page links to. Both pages, and the rest of withpersona.com, answered our reader with a bot check (HTTP 403), so their text wasn't read.",
          "RDAP for withpersona.com gives a registration date of 2018-09-24 and MarkMonitor Inc. as registrar."
        ],
        "score": 90
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/persona.json",
      "live": {
        "slug": "persona",
        "probe": {
          "target": "https://mcp.withpersona.com",
          "method": "get",
          "lastAt": "2026-10-09T10:42:52.467979059Z",
          "lastOk": true,
          "lastStatus": 405,
          "lastMs": 176,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 149,
          "p95ms24h": 404,
          "samples24h": 207,
          "samples30d": 207,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 93,
              "ok": 93
            },
            {
              "date": "2026-10-09",
              "probes": 114,
              "ok": 114
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.withpersona.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-09T07:58:25.314745809Z"
        },
        "versions": [
          {
            "registry": "npm",
            "name": "persona",
            "version": "5.9.0",
            "seenAt": "2026-10-08T16:25:07.765894859Z"
          }
        ],
        "npmWeekly": 570188,
        "securityTxt": {
          "url": "https://withpersona.com/.well-known/security.txt",
          "state": "valid",
          "expires": "2027-02-17T08:00:00.000Z",
          "checkedAt": "2026-10-08T15:39:00.840131962Z"
        },
        "pages": [
          {
            "url": "https://docs.withpersona.com/api-reference/versioning/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:19:46.701685957Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "6f0e8de3c16e"
          },
          {
            "url": "https://withpersona.com/legal/privacy-policy",
            "kind": "privacy",
            "status": 403,
            "checkedAt": "2026-10-08T18:25:46.538922013Z",
            "changedAt": "0001-01-01T00:00:00Z"
          },
          {
            "url": "https://withpersona.com/legal/terms-of-service",
            "kind": "terms",
            "status": 403,
            "checkedAt": "2026-10-08T18:25:48.548892401Z",
            "changedAt": "0001-01-01T00:00:00Z"
          }
        ],
        "updatedAt": "2026-10-09T10:42:52.467979059Z"
      }
    },
    "answer": "Persona scores 69.5 (B) on agent readiness against Shufti's 57.8 (C), and leads in 5 of 7 scored categories.",
    "b": {
      "slug": "shufti",
      "name": "Shufti",
      "vendor": "Shufti Pro Limited",
      "vendorUrl": "https://shuftipro.com",
      "kind": "http-api",
      "category": "identity-verification",
      "summary": "Identity and business verification service from Shufti Pro Limited in London. One REST endpoint runs document, face, address, AML screening and KYB checks chosen in the request body, with results by callback. A hosted MCP server exposes 25 tools.",
      "url": "https://www.anchorterminal.com/tools/shufti",
      "markdownUrl": "https://www.anchorterminal.com/tools/shufti.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/shufti.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/shufti.json",
      "repo": "https://github.com/shuftipro/iOS-SDK",
      "license": "Proprietary service under Shufti's Terms and Conditions. The licences of the mobile capture SDKs were not checked",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.shuftipro.com",
      "packages": [
        {
          "registry": "npm",
          "name": "shuftipro-onsite-mobilesdk"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve. Signing up creates a back office account, and the Client ID and Secret Key come from Settings, API Configuration, API Keys. The REST API takes them as HTTP Basic auth, or a Bearer access token from `/get/access/token` that lasts one hour. The key pair has no scopes, and the Secret Key is shown once and replaced by generating a new one. The MCP server uses OAuth 2.1 with PKCE and dynamic client registration. Its login page asks for the same Client ID and Secret Key, and it issues tokens with the scopes `knowledge:read`, `verification:read` and `verification:write`. Callback and redirect domains must be registered in the back office.",
      "pricing": "freemium",
      "pricingNotes": "Free Forever covers up to 10 verifications a month with no card, on the production environment. Essentials starts from $1.50 a verification, pay as you go with no monthly minimum, up to 20,000 verifications. Enterprise is quoted by sales and adds e-IDV, Travel Rule, video KYC and other services. The pricing page says only successful verification attempts are billed and resubmissions are free. Trial accounts accept test ID samples (https://shuftipro.com/pricing/, checked 2026-10-09).",
      "priceSummary": "$1.50 / tx",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the developer docs (llms-full.txt), the pricing page or the terms (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": 25,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 673,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://developers.shuftipro.com/docs/get_started",
      "llmsTxt": "https://developers.shuftipro.com/llms.txt",
      "capabilities": [
        "kyc.identity",
        "kyc.documents",
        "kyc.business",
        "kyc.screening"
      ],
      "tags": [
        "hosted",
        "api-key",
        "oauth",
        "mcp",
        "webhooks",
        "llms-txt",
        "free-tier",
        "no-card",
        "status-page",
        "sla",
        "soc2",
        "iso27001"
      ],
      "lastRelease": "2026-10-06",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 57.8,
        "grade": "C",
        "agentReady": false,
        "rank": 538,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 9,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 47,
          "maintenance": 72,
          "payments": 35,
          "reliability": 65,
          "schema": 58,
          "security": 62,
          "transparency": 71
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": 0,
        "verdict": "One endpoint covers document, face, address, AML and KYB checks, with a free plan of 10 verifications a month, and a hosted MCP server adds OAuth with three scopes. No OpenAPI file, server SDK or idempotency key was found, and the status page history could not be read.",
        "bestFor": "A team that wants document, face, address, AML and KYB checks behind one endpoint, a free plan for low volume, and an MCP server that hands the person a hosted verification link.",
        "strengths": [
          "Free Forever plan of 10 verifications a month with no card, on the production environment, per the pricing page",
          "Hosted MCP server at `https://ai.shuftipro.com/mcp` with 25 tools, OAuth 2.1 with PKCE and three scopes enforced on every call",
          "Docs published as llms.txt, a 2.9 MB llms-full.txt and a Markdown twin of each page, with samples in nine languages",
          "Public terms (version 11.1, 13 May 2026) include an availability schedule targeting 99 per cent monthly uptime",
          "Revision history with 19 dated entries between 24 July and 6 October 2026"
        ],
        "weaknesses": [
          "No OpenAPI file or other machine-readable contract was found. The reference is prose tables plus Postman collections",
          "The REST credential is one Client ID and Secret Key pair with no scopes, sent as Basic auth on every call",
          "No idempotency key, Retry-After header or backoff guidance was found for the documented 429",
          "No server-side SDK. Official packages cover Android, iOS, Flutter, React Native and Cordova capture only",
          "Standard KYB was deprecated on 6 October 2026 and its pages removed the same day, with no notice period stated",
          "The sub-processor list is available to clients on request only, and security.txt returns 404"
        ],
        "agentNotes": [
          "POST every verification to `https://api.shuftipro.com/` with a unique `reference` of 6 to 250 characters and one object per service. Read results from `/status` with that reference",
          "Register the callback domain in the back office first. An unregistered `callback_url` is rejected",
          "Stay under 60 requests a minute per IP on a production account and 20 on a trial account",
          "Check the `Signature` response header. Accounts created after 15 March 2023 hash the Secret Key with SHA-256 before appending it to the raw response",
          "Through MCP, identity checks return a `verification_url` for the person to open. No tool accepts an image, so use the REST API for offsite proofs"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 57.8
          }
        ],
        "editorialScores": {
          "ergonomics": 47,
          "maintenance": 72,
          "payments": 35,
          "reliability": 65,
          "schema": 58,
          "security": 62,
          "transparency": 51
        },
        "provenanceScore": 90
      },
      "connect": {
        "http": "curl --location --request POST 'https://api.shuftipro.com' \\\n--header 'Content-Type: application/json' \\\n--header 'Authorization: Basic \u003cbase64 of CLIENT_ID:SECRET_KEY\u003e' \\\n--data-raw '{\n    \"reference\"    : \"1234567\",\n    \"callback_url\" : \"https://yourdomain.com/profile/notifyCallback\",\n    \"country\"      : \"GB\",\n    \"language\"     : \"EN\",\n    \"verification_mode\" : \"any\",\n    \"face\" : {\n        \"proof\"            : \"\"\n    }\n}'",
        "claudeCode": "claude mcp add --transport http shufti https://ai.shuftipro.com/mcp",
        "config": {
          "mcpServers": {
            "shufti": {
              "args": [
                "mcp-remote",
                "https://ai.shuftipro.com/mcp"
              ],
              "command": "npx"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/kyc.identity",
        "tool": "https://letme.dev/shufti"
      },
      "area": "domain-data",
      "unitPrices": [
        {
          "item": "Verification, Free Forever plan (document and face checks)",
          "unit": "tx",
          "usd": 0,
          "note": "up to 10 verifications a month, no card"
        },
        {
          "item": "Verification, Essentials plan, starting price",
          "unit": "tx",
          "usd": 1.5,
          "note": "rate depends on volume and the services chosen, up to 20,000 verifications"
        }
      ],
      "provenance": {
        "legalEntity": "Shufti Pro Limited",
        "domain": "shuftipro.com",
        "domainRegistered": "2016-06-28",
        "endpointOnVendorDomain": true,
        "terms": "https://shuftipro.com/wp-content/uploads/Version-11.1-w.e.f.-May-13th-2026.pdf",
        "privacy": "https://shuftipro.com/services-privacy-notice/",
        "statusPage": "https://status.shuftipro.com",
        "changelog": "https://developers.shuftipro.com/docs/revision_history",
        "securityTxt": "none",
        "checked": "2026-10-09",
        "notes": [
          "The terms and the MCP privacy notice name Shufti Pro Limited, Office 408 Coppergate House, 10 Whites Row, London E1 7NF.",
          "The governing terms are a PDF, version 11.1, linked from shuftipro.com/terms-and-conditions/, which itself carries only a summary and links to every earlier version. The page labels the file 12 May 2026 and the file name says 13 May.",
          "The privacy link is the Services Privacy Notice, version 1.2, last updated September 2026, which covers verification data. A separate notice covers the website.",
          "shuftipro.com/.well-known/security.txt answered 502 on the first request and 404 on the second.",
          "RDAP for shuftipro.com gives a registration date of 2016-06-28.",
          "The API answers at api.shuftipro.com and the MCP server at ai.shuftipro.com. The lead's shufti.ai is a parked domain for sale and unrelated to the vendor.",
          "status.shuftipro.com is an UptimeRobot page whose data loads from /api/, a path its robots.txt disallows, so the incident history was not read."
        ],
        "score": 90
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/shufti.json",
      "live": {
        "slug": "shufti",
        "probe": {
          "target": "https://api.shuftipro.com",
          "method": "get",
          "lastAt": "2026-10-09T10:42:56.447659113Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 384,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 324,
          "p95ms24h": 384,
          "samples24h": 33,
          "samples30d": 33,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 33,
              "ok": 33
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.shuftipro.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-09T07:58:32.112017753Z"
        },
        "updatedAt": "2026-10-09T10:42:56.447659113Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Persona Identities, Inc.",
        "b": "Shufti Pro Limited",
        "name": "Vendor"
      },
      {
        "a": "https://mcp.withpersona.com",
        "b": "https://api.shuftipro.com",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "API key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Paid",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under Persona's terms of service. The `persona` JavaScript client on npm is MIT",
        "b": "Proprietary service under Shufti's Terms and Conditions. The licences of the mobile capture SDKs were not checked",
        "name": "Licence"
      },
      {
        "a": "190",
        "b": "25",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-29",
        "b": "2026-10-06",
        "name": "Last release"
      },
      {
        "a": "couldn't be read",
        "b": "",
        "name": "Terms last updated"
      },
      {
        "a": "couldn't be read",
        "b": "2026-09-01",
        "name": "Privacy policy last updated"
      },
      {
        "a": "couldn't be read",
        "b": "yes, with an opt-out",
        "name": "Customer content may train models"
      },
      {
        "a": "couldn't be read",
        "b": "",
        "name": "Terms restrict automated access"
      },
      {
        "a": "couldn't be read",
        "b": "",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "couldn't be read",
        "b": "",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "couldn't be read",
        "b": "",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "570k npm/wk",
        "b": "673 npm/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Persona scores 69.5 (B) on agent readiness against Shufti's 57.8 (C), and leads in 5 of 7 scored categories.",
        "question": "Which is better for AI agents, Persona or Shufti?"
      },
      {
        "answer": "Persona needs an API key. Shufti takes an API key or an OAuth sign-in.",
        "question": "Do Persona and Shufti need an API key?"
      },
      {
        "answer": "Yes. Persona has a hosted endpoint at https://mcp.withpersona.com and Shufti at https://api.shuftipro.com.",
        "question": "Can an agent call Persona and Shufti without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 70 against 65",
          "Schema \u0026 documentation, 85 against 58",
          "Agent ergonomics, 74 against 47",
          "Security \u0026 auth, 73 against 62"
        ],
        "also": null,
        "goodFor": "A company that already runs Persona and wants an agent to create inquiries from templates, read verification and report results, screen against watchlists and work review cases with a permission-limited key.",
        "slug": "persona",
        "watchFor": "Production access needs Persona's approval and a 12-month plan from $250 a month, and API-only integration is limited to Enterprise plans"
      },
      {
        "aheadOn": null,
        "also": [
          "Free to start without a card"
        ],
        "goodFor": "A team that wants document, face, address, AML and KYB checks behind one endpoint, a free plan for low volume, and an MCP server that hands the person a hosted verification link.",
        "slug": "shufti",
        "watchFor": "No OpenAPI file or other machine-readable contract was found. The reference is prose tables plus Postman collections"
      }
    ],
    "job": {
      "capability": "kyc.identity",
      "name": "Kyc identity"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/complycube-vs-persona.json",
        "title": "ComplyCube vs Persona",
        "url": "https://www.anchorterminal.com/compare/complycube-vs-persona"
      },
      {
        "json": "https://www.anchorterminal.com/compare/complycube-vs-shufti.json",
        "title": "ComplyCube vs Shufti",
        "url": "https://www.anchorterminal.com/compare/complycube-vs-shufti"
      },
      {
        "json": "https://www.anchorterminal.com/compare/didit-vs-persona.json",
        "title": "Didit vs Persona",
        "url": "https://www.anchorterminal.com/compare/didit-vs-persona"
      },
      {
        "json": "https://www.anchorterminal.com/compare/didit-vs-shufti.json",
        "title": "Didit vs Shufti",
        "url": "https://www.anchorterminal.com/compare/didit-vs-shufti"
      },
      {
        "json": "https://www.anchorterminal.com/compare/jumio-vs-persona.json",
        "title": "Jumio vs Persona",
        "url": "https://www.anchorterminal.com/compare/jumio-vs-persona"
      },
      {
        "json": "https://www.anchorterminal.com/compare/jumio-vs-shufti.json",
        "title": "Jumio vs Shufti",
        "url": "https://www.anchorterminal.com/compare/jumio-vs-shufti"
      },
      {
        "json": "https://www.anchorterminal.com/compare/persona-vs-socure-riskos.json",
        "title": "Persona vs Socure RiskOS",
        "url": "https://www.anchorterminal.com/compare/persona-vs-socure-riskos"
      },
      {
        "json": "https://www.anchorterminal.com/compare/persona-vs-sumsub.json",
        "title": "Persona vs Sumsub",
        "url": "https://www.anchorterminal.com/compare/persona-vs-sumsub"
      },
      {
        "json": "https://www.anchorterminal.com/compare/persona-vs-trulioo.json",
        "title": "Persona vs Trulioo",
        "url": "https://www.anchorterminal.com/compare/persona-vs-trulioo"
      },
      {
        "json": "https://www.anchorterminal.com/compare/persona-vs-veriff.json",
        "title": "Persona vs Veriff",
        "url": "https://www.anchorterminal.com/compare/persona-vs-veriff"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shufti-vs-socure-riskos.json",
        "title": "Shufti vs Socure RiskOS",
        "url": "https://www.anchorterminal.com/compare/shufti-vs-socure-riskos"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shufti-vs-sumsub.json",
        "title": "Shufti vs Sumsub",
        "url": "https://www.anchorterminal.com/compare/shufti-vs-sumsub"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shufti-vs-trulioo.json",
        "title": "Shufti vs Trulioo",
        "url": "https://www.anchorterminal.com/compare/shufti-vs-trulioo"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shufti-vs-veriff.json",
        "title": "Shufti vs Veriff",
        "url": "https://www.anchorterminal.com/compare/shufti-vs-veriff"
      },
      {
        "json": "https://www.anchorterminal.com/compare/complyadvantage-vs-persona.json",
        "title": "ComplyAdvantage vs Persona",
        "url": "https://www.anchorterminal.com/compare/complyadvantage-vs-persona"
      },
      {
        "json": "https://www.anchorterminal.com/compare/complyadvantage-vs-shufti.json",
        "title": "ComplyAdvantage vs Shufti",
        "url": "https://www.anchorterminal.com/compare/complyadvantage-vs-shufti"
      },
      {
        "json": "https://www.anchorterminal.com/compare/middesk-vs-persona.json",
        "title": "Middesk vs Persona",
        "url": "https://www.anchorterminal.com/compare/middesk-vs-persona"
      },
      {
        "json": "https://www.anchorterminal.com/compare/middesk-vs-shufti.json",
        "title": "Middesk vs Shufti",
        "url": "https://www.anchorterminal.com/compare/middesk-vs-shufti"
      }
    ],
    "scores": [
      {
        "by": 5,
        "edge": "persona",
        "key": "reliability",
        "name": "Reliability",
        "persona": 70,
        "shufti": 65,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 27,
        "edge": "persona",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "persona": 85,
        "shufti": 58,
        "weight": 13
      },
      {
        "by": 27,
        "edge": "persona",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "persona": 74,
        "shufti": 47,
        "weight": 13
      },
      {
        "by": 11,
        "edge": "persona",
        "key": "security",
        "name": "Security \u0026 auth",
        "persona": 73,
        "shufti": 62,
        "weight": 14
      },
      {
        "by": 0,
        "edge": "",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "persona": 35,
        "shufti": 35,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 3,
        "edge": "persona",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "persona": 75,
        "shufti": 72,
        "weight": 7
      },
      {
        "by": 3,
        "edge": "shufti",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "persona": 68,
        "shufti": 71,
        "weight": 7
      }
    ],
    "summary": "Persona scores 69.5 (B) on agent readiness against Shufti's 57.8 (C), and leads in 5 of 7 scored categories. Both do kyc identity.",
    "verdicts": {
      "persona": "The REST API has a public OpenAPI 3.1 file, llms.txt, API keys with per-resource permissions, idempotency keys on every POST and a 60-day sandbox trial with no card. Production needs a business review and a 12-month plan from $250 a month. The status page lists 11 incidents since 10 July 2026, including 70 minutes of timeouts across all products.",
      "shufti": "One endpoint covers document, face, address, AML and KYB checks, with a free plan of 10 verifications a month, and a hosted MCP server adds OAuth with three scopes. No OpenAPI file, server SDK or idempotency key was found, and the status page history could not be read."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/persona-vs-shufti",
    "json": "https://www.anchorterminal.com/compare/persona-vs-shufti.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/persona-vs-shufti.md",
    "slim": "https://www.anchorterminal.com/compare/persona-vs-shufti.min.md"
  },
  "markdown": "Persona scores 69.5 (B) on agent readiness against Shufti's 57.8 (C), and leads in 5 of 7 scored categories. Both do kyc identity.\n\n- Persona: grade B, 69.5/100, rank #176 of 842. Markdown https://www.anchorterminal.com/tools/persona.md · JSON https://www.anchorterminal.com/api/v1/tools/persona.json\n- Shufti: grade C, 57.8/100, rank #538 of 842. Markdown https://www.anchorterminal.com/tools/shufti.md · JSON https://www.anchorterminal.com/api/v1/tools/shufti.json\n\n## Which one, for what\n\n### Persona (B)\n\nGood for: A company that already runs Persona and wants an agent to create inquiries from templates, read verification and report results, screen against watchlists and work review cases with a permission-limited key.\n\nAhead on:\n- Reliability, 70 against 65\n- Schema \u0026 documentation, 85 against 58\n- Agent ergonomics, 74 against 47\n- Security \u0026 auth, 73 against 62\n\nWatch for: Production access needs Persona's approval and a 12-month plan from $250 a month, and API-only integration is limited to Enterprise plans\n\n### Shufti (C)\n\nGood for: A team that wants document, face, address, AML and KYB checks behind one endpoint, a free plan for low volume, and an MCP server that hands the person a hosted verification link.\n\nAlso in its favour:\n- Free to start without a card\n\nWatch for: No OpenAPI file or other machine-readable contract was found. The reference is prose tables plus Postman collections\n\n\n## Score by category\n\n| Category | Weight | Persona | Shufti | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 70 | 65 | Persona +5 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 85 | 58 | Persona +27 |\n| Agent ergonomics | 13% (16.2 this run) | 74 | 47 | Persona +27 |\n| Security \u0026 auth | 14% (17.5 this run) | 73 | 62 | Persona +11 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 35 | 35 | even |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 75 | 72 | Persona +3 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 68 | 71 | Shufti +3 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **69.5 · B** | **57.8 · C** | |\n\n## Facts side by side\n\n| Fact | Persona | Shufti |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Persona Identities, Inc. | Shufti Pro Limited |\n| Hosted endpoint | `https://mcp.withpersona.com` | `https://api.shuftipro.com` |\n| Transports | HTTP | HTTP, Streamable HTTP |\n| Auth | API key | OAuth or key |\n| Pricing | Paid | Freemium |\n| x402 | no | no |\n| Licence | Proprietary service under Persona's terms of service. The `persona` JavaScript client on npm is MIT | Proprietary service under Shufti's Terms and Conditions. The licences of the mobile capture SDKs were not checked |\n| Tools exposed | 190 | 25 |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| Last release | 2026-09-29 | 2026-10-06 |\n| Terms last updated | couldn't be read |  |\n| Privacy policy last updated | couldn't be read | 2026-09-01 |\n| Customer content may train models | couldn't be read | yes, with an opt-out |\n| Terms restrict automated access | couldn't be read |  |\n| Terms restrict benchmarking | couldn't be read |  |\n| Terms or service can change without notice | couldn't be read |  |\n| Arbitration or class-action waiver | couldn't be read |  |\n| Popularity | 570k npm/wk | 673 npm/wk |\n\n## Verdicts\n\n**Persona.** The REST API has a public OpenAPI 3.1 file, llms.txt, API keys with per-resource permissions, idempotency keys on every POST and a 60-day sandbox trial with no card. Production needs a business review and a 12-month plan from $250 a month. The status page lists 11 incidents since 10 July 2026, including 70 minutes of timeouts across all products.\n\n**Shufti.** One endpoint covers document, face, address, AML and KYB checks, with a free plan of 10 verifications a month, and a hosted MCP server adds OAuth with three scopes. No OpenAPI file, server SDK or idempotency key was found, and the status page history could not be read.\n\n## Before you call either\n\n### Persona\n\n1. Ask for a dedicated key limited to the permissions the task needs. A new key has every standard permission until it's limited\n2. Send `Persona-Version` on every call and an `Idempotency-Key` on every POST. A replayed key returns the first result, including a 500\n3. Treat redact calls as irreversible. They permanently delete personal data and cascade to downstream objects\n4. Stay under 300 requests a minute in production, read `RateLimit-Remaining` and `Quota-Remaining`, and back off on 429 because rejected requests still count\n5. Use `fields` and `include` to cut response size. Through MCP these parameters aren't exposed, and only 14 tools take `filter`\n\n### Shufti\n\n1. POST every verification to `https://api.shuftipro.com/` with a unique `reference` of 6 to 250 characters and one object per service. Read results from `/status` with that reference\n2. Register the callback domain in the back office first. An unregistered `callback_url` is rejected\n3. Stay under 60 requests a minute per IP on a production account and 20 on a trial account\n4. Check the `Signature` response header. Accounts created after 15 March 2023 hash the Secret Key with SHA-256 before appending it to the raw response\n5. Through MCP, identity checks return a `verification_url` for the person to open. No tool accepts an image, so use the REST API for offsite proofs\n\n## Questions\n\n### Which is better for AI agents, Persona or Shufti?\n\nPersona scores 69.5 (B) on agent readiness against Shufti's 57.8 (C), and leads in 5 of 7 scored categories.\n\n### Do Persona and Shufti need an API key?\n\nPersona needs an API key. Shufti takes an API key or an OAuth sign-in.\n\n### Can an agent call Persona and Shufti without installing anything?\n\nYes. Persona has a hosted endpoint at https://mcp.withpersona.com and Shufti at https://api.shuftipro.com.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/persona-vs-shufti.json, and with the fewest tokens: https://www.anchorterminal.com/compare/persona-vs-shufti.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"persona\", \"b\": \"shufti\"}`. From a terminal: `anchor compare persona shufti`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/persona.json and https://www.anchorterminal.com/api/v1/tools/shufti.json\n\n## Other comparisons with Persona or Shufti\n\n- [ComplyCube vs Persona](https://www.anchorterminal.com/compare/complycube-vs-persona.md)\n- [ComplyCube vs Shufti](https://www.anchorterminal.com/compare/complycube-vs-shufti.md)\n- [Didit vs Persona](https://www.anchorterminal.com/compare/didit-vs-persona.md)\n- [Didit vs Shufti](https://www.anchorterminal.com/compare/didit-vs-shufti.md)\n- [Jumio vs Persona](https://www.anchorterminal.com/compare/jumio-vs-persona.md)\n- [Jumio vs Shufti](https://www.anchorterminal.com/compare/jumio-vs-shufti.md)\n- [Persona vs Socure RiskOS](https://www.anchorterminal.com/compare/persona-vs-socure-riskos.md)\n- [Persona vs Sumsub](https://www.anchorterminal.com/compare/persona-vs-sumsub.md)\n- [Persona vs Trulioo](https://www.anchorterminal.com/compare/persona-vs-trulioo.md)\n- [Persona vs Veriff](https://www.anchorterminal.com/compare/persona-vs-veriff.md)\n- [Shufti vs Socure RiskOS](https://www.anchorterminal.com/compare/shufti-vs-socure-riskos.md)\n- [Shufti vs Sumsub](https://www.anchorterminal.com/compare/shufti-vs-sumsub.md)\n- [Shufti vs Trulioo](https://www.anchorterminal.com/compare/shufti-vs-trulioo.md)\n- [Shufti vs Veriff](https://www.anchorterminal.com/compare/shufti-vs-veriff.md)\n- [ComplyAdvantage vs Persona](https://www.anchorterminal.com/compare/complyadvantage-vs-persona.md)\n- [ComplyAdvantage vs Shufti](https://www.anchorterminal.com/compare/complyadvantage-vs-shufti.md)\n- [Middesk vs Persona](https://www.anchorterminal.com/compare/middesk-vs-persona.md)\n- [Middesk vs Shufti](https://www.anchorterminal.com/compare/middesk-vs-shufti.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Persona vs Shufti",
        "url": ""
      }
    ],
    "description": "Persona scores 69.5 (B) on agent readiness against Shufti's 57.8 (C), and leads in 5 of 7 scored categories. Both do kyc identity. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Persona B 69.5",
      "Shufti C 57.8",
      "scores"
    ],
    "h1": "Persona vs Shufti",
    "image": "https://www.anchorterminal.com/assets/og/compare-persona-vs-shufti.png",
    "path": "/compare/persona-vs-shufti",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Persona vs Shufti for AI agents, B 69.5 vs C 57.8 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/persona-vs-shufti"
  },
  "tokens": {
    "markdown": 2200,
    "slim": 730
  },
  "version": 1
}
