Head to head · Kyc identity · October 2026 research run

Shufti vs Socure RiskOS

Socure RiskOS scores 63.5 (B) on agent readiness against Shufti's 57.8 (C), and leads in 3 of 7 scored categories. Both do kyc identity.

Which one, for what

Shufti C

Good for A team that wants document, face, address, AML and KYB checks behind one endpoint, a free plan for low volume, and an MCP server that hands the person a hosted verification link.

Also in its favour

  • Free to start without a card

Watch for

No OpenAPI file or other machine-readable contract was found. The reference is prose tables plus Postman collections

Socure RiskOS B

Good for A company in the United States that wants one decision from combined KYC, document, fraud and watchlist checks through a single evaluation call.

Ahead on

  • Reliability, 75 against 65
  • Schema & documentation, 84 against 58

Watch for

No service agreement or API terms are published. The only terms pages are website terms of use and end-user terms for document capture

Score by category

CategoryWeight this runShuftiSocure RiskOSEdge
Reliability16%206575Socure RiskOS +10
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.25884Socure RiskOS +26
Agent ergonomics13%16.24746Shufti +1
Security & auth14%17.56260Shufti +2
Payments & pricing10%12.53535even
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87275Socure RiskOS +3
Transparency & trust7%8.87168Shufti +3
Negative events≤1500
Total57.8 · C63.5 · B

Facts side by side

FactShuftiSocure RiskOS
KindHTTP APIHTTP API
VendorShufti Pro LimitedSocure Inc.
Hosted endpointhttps://api.shuftipro.comhttps://mcp.riskos.socure.com/sandbox
TransportsHTTP, Streamable HTTPHTTP
AuthOAuth or keyAPI key
PricingFreemiumPay per use
x402nono
LicenceProprietary service under Shufti's Terms and Conditions. The licences of the mobile capture SDKs were not checkedProprietary service. No service agreement is published, and the OpenAPI file states its licence as Proprietary
Tools exposed259
Read-only variant documentednono
llms.txtyesyes
Last release2026-10-062026-10-06
Terms last updatedno document linked
Privacy policy last updated2026-09-01no date given
Customer content may train modelsyes, with an opt-outyes
Terms restrict automated access
Terms restrict benchmarking
Terms or service can change without notice
Arbitration or class-action waiver
Popularity673 npm/wk35k npm/wk

Verdicts

Shufti

One endpoint covers document, face, address, AML and KYB checks, with a free plan of 10 verifications a month, and a hosted MCP server adds OAuth with three scopes. No OpenAPI file, server SDK or idempotency key was found, and the status page history could not be read.

Socure RiskOS

A public OpenAPI file, llms.txt, 15 documented error codes and dated release notes cover a ten-operation REST API, and Socure Launch publishes prices from $0.80 an evaluation with a free sandbox. API keys carry no scopes, no idempotency header is defined, no service terms are published, and production stays at zero requests until Socure activates it.

Before you call either

Shufti

  1. POST every verification to https://api.shuftipro.com/ with a unique reference of 6 to 250 characters and one object per service. Read results from /status with that reference
  2. Register the callback domain in the back office first. An unregistered callback_url is rejected
  3. Stay under 60 requests a minute per IP on a production account and 20 on a trial account
  4. Check the Signature response header. Accounts created after 15 March 2023 hash the Secret Key with SHA-256 before appending it to the raw response
  5. Through MCP, identity checks return a verification_url for the person to open. No tool accepts an image, so use the REST API for offsite proofs

Socure RiskOS

  1. Send Authorization: Bearer <key> to https://riskos.sandbox.socure.com/api/evaluation for tests and https://riskos.socure.com/api/evaluation for live checks. The two environments use separate keys.
  2. Use dummy data only in the sandbox. It returns predefined results, connects to no live data source and expects the documented test values.
  3. Store the eval_id from every POST /api/evaluation response. No list or search endpoint exists to find it later.
  4. On 429 wait the seconds given in X-Retry-After. Do not blindly resend a failed POST /api/evaluation, because no idempotency header is documented and Launch bills each initiated evaluation.
  5. The MCP server at https://mcp.riskos.socure.com/sandbox reads docs, workflows and webhooks with its own MCP Server Key. It cannot run evaluations or read results.

Questions

Which is better for AI agents, Shufti or Socure RiskOS?

Socure RiskOS scores 63.5 (B) on agent readiness against Shufti's 57.8 (C), and leads in 3 of 7 scored categories.

Do Shufti and Socure RiskOS need an API key?

Shufti takes an API key or an OAuth sign-in. Socure RiskOS needs an API key.

Can an agent call Shufti and Socure RiskOS without installing anything?

Yes. Shufti has a hosted endpoint at https://api.shuftipro.com and Socure RiskOS at https://mcp.riskos.socure.com/sandbox.

Other comparisons with Shufti or Socure RiskOS

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.