{
  "data": {
    "a": {
      "slug": "shufti",
      "name": "Shufti",
      "vendor": "Shufti Pro Limited",
      "vendorUrl": "https://shuftipro.com",
      "kind": "http-api",
      "category": "identity-verification",
      "summary": "Identity and business verification service from Shufti Pro Limited in London. One REST endpoint runs document, face, address, AML screening and KYB checks chosen in the request body, with results by callback. A hosted MCP server exposes 25 tools.",
      "url": "https://www.anchorterminal.com/tools/shufti",
      "markdownUrl": "https://www.anchorterminal.com/tools/shufti.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/shufti.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/shufti.json",
      "repo": "https://github.com/shuftipro/iOS-SDK",
      "license": "Proprietary service under Shufti's Terms and Conditions. The licences of the mobile capture SDKs were not checked",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.shuftipro.com",
      "packages": [
        {
          "registry": "npm",
          "name": "shuftipro-onsite-mobilesdk"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve. Signing up creates a back office account, and the Client ID and Secret Key come from Settings, API Configuration, API Keys. The REST API takes them as HTTP Basic auth, or a Bearer access token from `/get/access/token` that lasts one hour. The key pair has no scopes, and the Secret Key is shown once and replaced by generating a new one. The MCP server uses OAuth 2.1 with PKCE and dynamic client registration. Its login page asks for the same Client ID and Secret Key, and it issues tokens with the scopes `knowledge:read`, `verification:read` and `verification:write`. Callback and redirect domains must be registered in the back office.",
      "pricing": "freemium",
      "pricingNotes": "Free Forever covers up to 10 verifications a month with no card, on the production environment. Essentials starts from $1.50 a verification, pay as you go with no monthly minimum, up to 20,000 verifications. Enterprise is quoted by sales and adds e-IDV, Travel Rule, video KYC and other services. The pricing page says only successful verification attempts are billed and resubmissions are free. Trial accounts accept test ID samples (https://shuftipro.com/pricing/, checked 2026-10-09).",
      "priceSummary": "$1.50 / tx",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the developer docs (llms-full.txt), the pricing page or the terms (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": 25,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 673,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://developers.shuftipro.com/docs/get_started",
      "llmsTxt": "https://developers.shuftipro.com/llms.txt",
      "capabilities": [
        "kyc.identity",
        "kyc.documents",
        "kyc.business",
        "kyc.screening"
      ],
      "tags": [
        "hosted",
        "api-key",
        "oauth",
        "mcp",
        "webhooks",
        "llms-txt",
        "free-tier",
        "no-card",
        "status-page",
        "sla",
        "soc2",
        "iso27001"
      ],
      "lastRelease": "2026-10-06",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 57.8,
        "grade": "C",
        "agentReady": false,
        "rank": 538,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 9,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 47,
          "maintenance": 72,
          "payments": 35,
          "reliability": 65,
          "schema": 58,
          "security": 62,
          "transparency": 71
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": 0,
        "verdict": "One endpoint covers document, face, address, AML and KYB checks, with a free plan of 10 verifications a month, and a hosted MCP server adds OAuth with three scopes. No OpenAPI file, server SDK or idempotency key was found, and the status page history could not be read.",
        "bestFor": "A team that wants document, face, address, AML and KYB checks behind one endpoint, a free plan for low volume, and an MCP server that hands the person a hosted verification link.",
        "strengths": [
          "Free Forever plan of 10 verifications a month with no card, on the production environment, per the pricing page",
          "Hosted MCP server at `https://ai.shuftipro.com/mcp` with 25 tools, OAuth 2.1 with PKCE and three scopes enforced on every call",
          "Docs published as llms.txt, a 2.9 MB llms-full.txt and a Markdown twin of each page, with samples in nine languages",
          "Public terms (version 11.1, 13 May 2026) include an availability schedule targeting 99 per cent monthly uptime",
          "Revision history with 19 dated entries between 24 July and 6 October 2026"
        ],
        "weaknesses": [
          "No OpenAPI file or other machine-readable contract was found. The reference is prose tables plus Postman collections",
          "The REST credential is one Client ID and Secret Key pair with no scopes, sent as Basic auth on every call",
          "No idempotency key, Retry-After header or backoff guidance was found for the documented 429",
          "No server-side SDK. Official packages cover Android, iOS, Flutter, React Native and Cordova capture only",
          "Standard KYB was deprecated on 6 October 2026 and its pages removed the same day, with no notice period stated",
          "The sub-processor list is available to clients on request only, and security.txt returns 404"
        ],
        "agentNotes": [
          "POST every verification to `https://api.shuftipro.com/` with a unique `reference` of 6 to 250 characters and one object per service. Read results from `/status` with that reference",
          "Register the callback domain in the back office first. An unregistered `callback_url` is rejected",
          "Stay under 60 requests a minute per IP on a production account and 20 on a trial account",
          "Check the `Signature` response header. Accounts created after 15 March 2023 hash the Secret Key with SHA-256 before appending it to the raw response",
          "Through MCP, identity checks return a `verification_url` for the person to open. No tool accepts an image, so use the REST API for offsite proofs"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 57.8
          }
        ],
        "editorialScores": {
          "ergonomics": 47,
          "maintenance": 72,
          "payments": 35,
          "reliability": 65,
          "schema": 58,
          "security": 62,
          "transparency": 51
        },
        "provenanceScore": 90
      },
      "connect": {
        "http": "curl --location --request POST 'https://api.shuftipro.com' \\\n--header 'Content-Type: application/json' \\\n--header 'Authorization: Basic \u003cbase64 of CLIENT_ID:SECRET_KEY\u003e' \\\n--data-raw '{\n    \"reference\"    : \"1234567\",\n    \"callback_url\" : \"https://yourdomain.com/profile/notifyCallback\",\n    \"country\"      : \"GB\",\n    \"language\"     : \"EN\",\n    \"verification_mode\" : \"any\",\n    \"face\" : {\n        \"proof\"            : \"\"\n    }\n}'",
        "claudeCode": "claude mcp add --transport http shufti https://ai.shuftipro.com/mcp",
        "config": {
          "mcpServers": {
            "shufti": {
              "args": [
                "mcp-remote",
                "https://ai.shuftipro.com/mcp"
              ],
              "command": "npx"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/kyc.identity",
        "tool": "https://letme.dev/shufti"
      },
      "area": "domain-data",
      "unitPrices": [
        {
          "item": "Verification, Free Forever plan (document and face checks)",
          "unit": "tx",
          "usd": 0,
          "note": "up to 10 verifications a month, no card"
        },
        {
          "item": "Verification, Essentials plan, starting price",
          "unit": "tx",
          "usd": 1.5,
          "note": "rate depends on volume and the services chosen, up to 20,000 verifications"
        }
      ],
      "provenance": {
        "legalEntity": "Shufti Pro Limited",
        "domain": "shuftipro.com",
        "domainRegistered": "2016-06-28",
        "endpointOnVendorDomain": true,
        "terms": "https://shuftipro.com/wp-content/uploads/Version-11.1-w.e.f.-May-13th-2026.pdf",
        "privacy": "https://shuftipro.com/services-privacy-notice/",
        "statusPage": "https://status.shuftipro.com",
        "changelog": "https://developers.shuftipro.com/docs/revision_history",
        "securityTxt": "none",
        "checked": "2026-10-09",
        "notes": [
          "The terms and the MCP privacy notice name Shufti Pro Limited, Office 408 Coppergate House, 10 Whites Row, London E1 7NF.",
          "The governing terms are a PDF, version 11.1, linked from shuftipro.com/terms-and-conditions/, which itself carries only a summary and links to every earlier version. The page labels the file 12 May 2026 and the file name says 13 May.",
          "The privacy link is the Services Privacy Notice, version 1.2, last updated September 2026, which covers verification data. A separate notice covers the website.",
          "shuftipro.com/.well-known/security.txt answered 502 on the first request and 404 on the second.",
          "RDAP for shuftipro.com gives a registration date of 2016-06-28.",
          "The API answers at api.shuftipro.com and the MCP server at ai.shuftipro.com. The lead's shufti.ai is a parked domain for sale and unrelated to the vendor.",
          "status.shuftipro.com is an UptimeRobot page whose data loads from /api/, a path its robots.txt disallows, so the incident history was not read."
        ],
        "score": 90
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/shufti.json",
      "live": {
        "slug": "shufti",
        "probe": {
          "target": "https://api.shuftipro.com",
          "method": "get",
          "lastAt": "2026-10-09T10:14:27.35074698Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 319,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 320,
          "p95ms24h": 342,
          "samples24h": 28,
          "samples30d": 28,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 28,
              "ok": 28
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.shuftipro.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-09T07:58:32.112017753Z"
        },
        "updatedAt": "2026-10-09T10:14:27.35074698Z"
      }
    },
    "answer": "Socure RiskOS scores 63.5 (B) on agent readiness against Shufti's 57.8 (C), and leads in 3 of 7 scored categories.",
    "b": {
      "slug": "socure-riskos",
      "name": "Socure RiskOS",
      "vendor": "Socure Inc.",
      "vendorUrl": "https://www.socure.com",
      "kind": "http-api",
      "category": "identity-verification",
      "summary": "Socure RiskOS is an identity verification and risk decisioning platform from Socure Inc. Its Evaluation API runs configured workflows for KYC, document and selfie checks, fraud scoring and watchlist screening, and returns a decision with reason codes.",
      "url": "https://www.anchorterminal.com/tools/socure-riskos",
      "markdownUrl": "https://www.anchorterminal.com/tools/socure-riskos.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/socure-riskos.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/socure-riskos.json",
      "repo": "https://github.com/socure-inc/.github",
      "license": "Proprietary service. No service agreement is published, and the OpenAPI file states its licence as Proprietary",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://mcp.riskos.socure.com/sandbox",
      "packages": [
        {
          "registry": "npm",
          "name": "@socure-inc/device-risk-sdk"
        }
      ],
      "auth": "api-key",
      "authNotes": "Self-serve API key for the sandbox, sent as `Authorization: Bearer \u003ckey\u003e`. A person signs up in a browser for a Socure Launch sandbox account and copies the key from the Developer Workbench. Sandbox and production use separate keys and hosts. Production starts at 0 requests a second and needs Socure Support to activate it, and Enterprise accounts go through sandbox certification with Socure staff. Each key reaches every workflow, with no scopes. Regenerating a key keeps the old one working until it is deleted, and an additional key is requested from Support. The MCP server takes its own MCP Server Key. IP allowlisting, mutual TLS and payload encryption are optional (checked 2026-10-08).",
      "pricing": "usage",
      "pricingNotes": "Socure Launch charges per evaluation started in production, at $0.80 for document verification, $0.90 with watchlist screening, $1.00 for KYC, fraud and watchlist with a document step-up, and $1.30 with prefill. Launch accounts receive $1,000 in production credits each month. The sandbox is free, so an agent can build and test without a contract, but it returns predefined results. Evaluations an end user abandons are still charged. Socure Enterprise is priced through sales. Whether sign-up or the move to production asks for a card was not established (checked 2026-10-08).",
      "priceSummary": "$0.80 / tx",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the API reference, the OpenAPI file, the MCP server page or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 9,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 35395,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://help.socure.com/riskos/docs",
      "llmsTxt": "https://help.socure.com/riskos/llms.txt",
      "openapi": "https://raw.githubusercontent.com/socure-inc/.github/main/openapi-spec/riskos-api-spec.json",
      "capabilities": [
        "kyc.identity",
        "kyc.documents",
        "kyc.screening",
        "kyc.business",
        "kyc.cases"
      ],
      "tags": [
        "hosted",
        "usage",
        "sandbox",
        "api-key",
        "mcp",
        "openapi",
        "llms-txt",
        "webhooks",
        "status-page",
        "soc2",
        "iso27001",
        "fedramp"
      ],
      "lastRelease": "2026-10-06",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 63.5,
        "grade": "B",
        "agentReady": false,
        "rank": 357,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 5,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 46,
          "maintenance": 75,
          "payments": 35,
          "reliability": 75,
          "schema": 84,
          "security": 60,
          "transparency": 68
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "A public OpenAPI file, llms.txt, 15 documented error codes and dated release notes cover a ten-operation REST API, and Socure Launch publishes prices from $0.80 an evaluation with a free sandbox. API keys carry no scopes, no idempotency header is defined, no service terms are published, and production stays at zero requests until Socure activates it.",
        "bestFor": "A company in the United States that wants one decision from combined KYC, document, fraud and watchlist checks through a single evaluation call.",
        "strengths": [
          "OpenAPI 3.0.3 file for ten operations and a 3.1 webhook file in a public GitHub repository, last synced 5 October 2026",
          "llms.txt indexes for every docs section and a Markdown copy of each page, with a robots.txt signal that allows AI input",
          "Socure Launch publishes four solutions at $0.80 to $1.30 per evaluation, with a free sandbox and $1,000 of monthly production credits",
          "Errors return one of 15 machine-readable codes with field-level `invalid_args`, and 429 responses carry `X-Retry-After`",
          "Release notes show entries on 5 and 6 October 2026 and more than 20 dated entries since 10 July"
        ],
        "weaknesses": [
          "No service agreement or API terms are published. The only terms pages are website terms of use and end-user terms for document capture",
          "Each API key reaches every workflow, with no scopes or read-only keys, and an additional key has to be requested from Support",
          "The rate limit page advises idempotency keys, but neither the docs nor the OpenAPI file define an idempotency header",
          "No endpoint lists or searches evaluations. A caller needs the `eval_id` from the original response or a webhook",
          "Enrichment request and response schemas, reason codes and signal definitions sit in the dashboard, not in the public docs",
          "Production starts at 0 requests a second until Socure approves it, and Launch accounts are capped at 1 evaluation a second and 500 a day"
        ],
        "agentNotes": [
          "Send `Authorization: Bearer \u003ckey\u003e` to `https://riskos.sandbox.socure.com/api/evaluation` for tests and `https://riskos.socure.com/api/evaluation` for live checks. The two environments use separate keys.",
          "Use dummy data only in the sandbox. It returns predefined results, connects to no live data source and expects the documented test values.",
          "Store the `eval_id` from every `POST /api/evaluation` response. No list or search endpoint exists to find it later.",
          "On 429 wait the seconds given in `X-Retry-After`. Do not blindly resend a failed `POST /api/evaluation`, because no idempotency header is documented and Launch bills each initiated evaluation.",
          "The MCP server at `https://mcp.riskos.socure.com/sandbox` reads docs, workflows and webhooks with its own MCP Server Key. It cannot run evaluations or read results."
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 63.5
          }
        ],
        "editorialScores": {
          "ergonomics": 46,
          "maintenance": 75,
          "payments": 35,
          "reliability": 75,
          "schema": 84,
          "security": 60,
          "transparency": 53
        },
        "provenanceScore": 82
      },
      "connect": {
        "http": "curl --request POST \\\n  --url \"https://riskos.sandbox.socure.com/api/evaluation\" \\\n  --header \"Authorization: Bearer YOUR_API_KEY\" \\\n  --header \"Content-Type: application/json\" \\\n  --header \"Accept: application/json\" \\\n  --data '{\"id\":\"customer-onb-12345\",\"timestamp\":\"2024-12-01T08:15:30.456Z\",\"workflow\":\"consumer_onboarding\",\"data\":{\"individual\":{\"given_name\":\"Jane\",\"family_name\":\"Doe\",\"email\":\"jane.doe@example.com\",\"phone_number\":\"+1-555-123-4567\",\"address\":{\"line_1\":\"123 Main St\",\"locality\":\"San Francisco\",\"major_admin_division\":\"CA\",\"postal_code\":\"94105\",\"country\":\"US\"}}}}'",
        "claudeCode": "claude mcp add --transport http socure-dev-assist https://mcp.riskos.socure.com/sandbox --header \"Authorization: Bearer $RISKOS_MCP_KEY\"",
        "config": {
          "mcpServers": {
            "socure-dev-assist": {
              "args": [
                "-y",
                "mcp-remote",
                "https://mcp.riskos.socure.com/sandbox",
                "--header",
                "Authorization: Bearer YOUR_MCP_SERVER_KEY"
              ],
              "command": "npx"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/kyc.identity",
        "tool": "https://letme.dev/socure-riskos"
      },
      "area": "domain-data",
      "unitPrices": [
        {
          "item": "Socure Launch, Document Verification (DocV)",
          "unit": "tx",
          "usd": 0.8,
          "note": "Per evaluation started in production, after $1,000 of monthly credits"
        },
        {
          "item": "Socure Launch, DocV + Watchlist",
          "unit": "tx",
          "usd": 0.9,
          "note": "Per evaluation started in production"
        },
        {
          "item": "Socure Launch, KYC + Fraud + Watchlist with DocV step-up",
          "unit": "tx",
          "usd": 1,
          "note": "Per evaluation started in production"
        },
        {
          "item": "Socure Launch, Prefill, KYC + Fraud + Watchlist with DocV step-up",
          "unit": "tx",
          "usd": 1.3,
          "note": "Per evaluation started in production"
        }
      ],
      "provenance": {
        "legalEntity": "Socure Inc.",
        "domain": "socure.com",
        "domainRegistered": "2003-06-20",
        "endpointOnVendorDomain": true,
        "terms": "",
        "privacy": "https://www.socure.com/privacy-en",
        "statusPage": "https://status.socure.com",
        "changelog": "https://help.socure.com/riskos/page/release-notes",
        "securityTxt": "expired",
        "checked": "2026-10-08",
        "notes": [
          "The Global Services Privacy Notice (effective 1 October 2026) names Socure Inc. and covers the verification services. A separate Website Privacy Notice covers the marketing site.",
          "No service agreement or API terms are published. www.socure.com/terms-of-service is the Website Terms of Use, and the policies page lists only privacy notices, the DocV Terms of Use for end users and a text messaging notice, so the terms field is left out.",
          "The API answers at riskos.socure.com and riskos.sandbox.socure.com, and the MCP server at mcp.riskos.socure.com, all socure.com subdomains.",
          "www.socure.com/.well-known/security.txt gives security@socure.com and an `Expires` value of 15 July 2026, which has passed.",
          "RDAP for socure.com gives a registration date of 2003-06-20."
        ],
        "score": 82
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/socure-riskos.json",
      "live": {
        "slug": "socure-riskos",
        "probe": {
          "target": "https://mcp.riskos.socure.com/sandbox",
          "method": "get",
          "lastAt": "2026-10-09T10:14:28.252018465Z",
          "lastOk": true,
          "lastStatus": 403,
          "lastMs": 326,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 333,
          "p95ms24h": 351,
          "samples24h": 28,
          "samples30d": 28,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 28,
              "ok": 28
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.socure.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-09T10:11:19.572503783Z"
        },
        "updatedAt": "2026-10-09T10:14:28.252018465Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Shufti Pro Limited",
        "b": "Socure Inc.",
        "name": "Vendor"
      },
      {
        "a": "https://api.shuftipro.com",
        "b": "https://mcp.riskos.socure.com/sandbox",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "API key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Pay per use",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under Shufti's Terms and Conditions. The licences of the mobile capture SDKs were not checked",
        "b": "Proprietary service. No service agreement is published, and the OpenAPI file states its licence as Proprietary",
        "name": "Licence"
      },
      {
        "a": "25",
        "b": "9",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-06",
        "b": "2026-10-06",
        "name": "Last release"
      },
      {
        "a": "",
        "b": "no document linked",
        "name": "Terms last updated"
      },
      {
        "a": "2026-09-01",
        "b": "no date given",
        "name": "Privacy policy last updated"
      },
      {
        "a": "yes, with an opt-out",
        "b": "yes",
        "name": "Customer content may train models"
      },
      {
        "a": "",
        "b": "",
        "name": "Terms restrict automated access"
      },
      {
        "a": "",
        "b": "",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "",
        "b": "",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "",
        "b": "",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "673 npm/wk",
        "b": "35k npm/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Socure RiskOS scores 63.5 (B) on agent readiness against Shufti's 57.8 (C), and leads in 3 of 7 scored categories.",
        "question": "Which is better for AI agents, Shufti or Socure RiskOS?"
      },
      {
        "answer": "Shufti takes an API key or an OAuth sign-in. Socure RiskOS needs an API key.",
        "question": "Do Shufti and Socure RiskOS need an API key?"
      },
      {
        "answer": "Yes. Shufti has a hosted endpoint at https://api.shuftipro.com and Socure RiskOS at https://mcp.riskos.socure.com/sandbox.",
        "question": "Can an agent call Shufti and Socure RiskOS without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": null,
        "also": [
          "Free to start without a card"
        ],
        "goodFor": "A team that wants document, face, address, AML and KYB checks behind one endpoint, a free plan for low volume, and an MCP server that hands the person a hosted verification link.",
        "slug": "shufti",
        "watchFor": "No OpenAPI file or other machine-readable contract was found. The reference is prose tables plus Postman collections"
      },
      {
        "aheadOn": [
          "Reliability, 75 against 65",
          "Schema \u0026 documentation, 84 against 58"
        ],
        "also": null,
        "goodFor": "A company in the United States that wants one decision from combined KYC, document, fraud and watchlist checks through a single evaluation call.",
        "slug": "socure-riskos",
        "watchFor": "No service agreement or API terms are published. The only terms pages are website terms of use and end-user terms for document capture"
      }
    ],
    "job": {
      "capability": "kyc.identity",
      "name": "Kyc identity"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/complycube-vs-shufti.json",
        "title": "ComplyCube vs Shufti",
        "url": "https://www.anchorterminal.com/compare/complycube-vs-shufti"
      },
      {
        "json": "https://www.anchorterminal.com/compare/complycube-vs-socure-riskos.json",
        "title": "ComplyCube vs Socure RiskOS",
        "url": "https://www.anchorterminal.com/compare/complycube-vs-socure-riskos"
      },
      {
        "json": "https://www.anchorterminal.com/compare/didit-vs-shufti.json",
        "title": "Didit vs Shufti",
        "url": "https://www.anchorterminal.com/compare/didit-vs-shufti"
      },
      {
        "json": "https://www.anchorterminal.com/compare/didit-vs-socure-riskos.json",
        "title": "Didit vs Socure RiskOS",
        "url": "https://www.anchorterminal.com/compare/didit-vs-socure-riskos"
      },
      {
        "json": "https://www.anchorterminal.com/compare/jumio-vs-shufti.json",
        "title": "Jumio vs Shufti",
        "url": "https://www.anchorterminal.com/compare/jumio-vs-shufti"
      },
      {
        "json": "https://www.anchorterminal.com/compare/jumio-vs-socure-riskos.json",
        "title": "Jumio vs Socure RiskOS",
        "url": "https://www.anchorterminal.com/compare/jumio-vs-socure-riskos"
      },
      {
        "json": "https://www.anchorterminal.com/compare/persona-vs-shufti.json",
        "title": "Persona vs Shufti",
        "url": "https://www.anchorterminal.com/compare/persona-vs-shufti"
      },
      {
        "json": "https://www.anchorterminal.com/compare/persona-vs-socure-riskos.json",
        "title": "Persona vs Socure RiskOS",
        "url": "https://www.anchorterminal.com/compare/persona-vs-socure-riskos"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shufti-vs-sumsub.json",
        "title": "Shufti vs Sumsub",
        "url": "https://www.anchorterminal.com/compare/shufti-vs-sumsub"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shufti-vs-trulioo.json",
        "title": "Shufti vs Trulioo",
        "url": "https://www.anchorterminal.com/compare/shufti-vs-trulioo"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shufti-vs-veriff.json",
        "title": "Shufti vs Veriff",
        "url": "https://www.anchorterminal.com/compare/shufti-vs-veriff"
      },
      {
        "json": "https://www.anchorterminal.com/compare/socure-riskos-vs-sumsub.json",
        "title": "Socure RiskOS vs Sumsub",
        "url": "https://www.anchorterminal.com/compare/socure-riskos-vs-sumsub"
      },
      {
        "json": "https://www.anchorterminal.com/compare/socure-riskos-vs-trulioo.json",
        "title": "Socure RiskOS vs Trulioo",
        "url": "https://www.anchorterminal.com/compare/socure-riskos-vs-trulioo"
      },
      {
        "json": "https://www.anchorterminal.com/compare/socure-riskos-vs-veriff.json",
        "title": "Socure RiskOS vs Veriff",
        "url": "https://www.anchorterminal.com/compare/socure-riskos-vs-veriff"
      },
      {
        "json": "https://www.anchorterminal.com/compare/complyadvantage-vs-shufti.json",
        "title": "ComplyAdvantage vs Shufti",
        "url": "https://www.anchorterminal.com/compare/complyadvantage-vs-shufti"
      },
      {
        "json": "https://www.anchorterminal.com/compare/complyadvantage-vs-socure-riskos.json",
        "title": "ComplyAdvantage vs Socure RiskOS",
        "url": "https://www.anchorterminal.com/compare/complyadvantage-vs-socure-riskos"
      },
      {
        "json": "https://www.anchorterminal.com/compare/middesk-vs-shufti.json",
        "title": "Middesk vs Shufti",
        "url": "https://www.anchorterminal.com/compare/middesk-vs-shufti"
      },
      {
        "json": "https://www.anchorterminal.com/compare/middesk-vs-socure-riskos.json",
        "title": "Middesk vs Socure RiskOS",
        "url": "https://www.anchorterminal.com/compare/middesk-vs-socure-riskos"
      }
    ],
    "scores": [
      {
        "by": 10,
        "edge": "socure-riskos",
        "key": "reliability",
        "name": "Reliability",
        "shufti": 65,
        "socure-riskos": 75,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 26,
        "edge": "socure-riskos",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "shufti": 58,
        "socure-riskos": 84,
        "weight": 13
      },
      {
        "by": 1,
        "edge": "shufti",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "shufti": 47,
        "socure-riskos": 46,
        "weight": 13
      },
      {
        "by": 2,
        "edge": "shufti",
        "key": "security",
        "name": "Security \u0026 auth",
        "shufti": 62,
        "socure-riskos": 60,
        "weight": 14
      },
      {
        "by": 0,
        "edge": "",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "shufti": 35,
        "socure-riskos": 35,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 3,
        "edge": "socure-riskos",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "shufti": 72,
        "socure-riskos": 75,
        "weight": 7
      },
      {
        "by": 3,
        "edge": "shufti",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "shufti": 71,
        "socure-riskos": 68,
        "weight": 7
      }
    ],
    "summary": "Socure RiskOS scores 63.5 (B) on agent readiness against Shufti's 57.8 (C), and leads in 3 of 7 scored categories. Both do kyc identity.",
    "verdicts": {
      "shufti": "One endpoint covers document, face, address, AML and KYB checks, with a free plan of 10 verifications a month, and a hosted MCP server adds OAuth with three scopes. No OpenAPI file, server SDK or idempotency key was found, and the status page history could not be read.",
      "socure-riskos": "A public OpenAPI file, llms.txt, 15 documented error codes and dated release notes cover a ten-operation REST API, and Socure Launch publishes prices from $0.80 an evaluation with a free sandbox. API keys carry no scopes, no idempotency header is defined, no service terms are published, and production stays at zero requests until Socure activates it."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/shufti-vs-socure-riskos",
    "json": "https://www.anchorterminal.com/compare/shufti-vs-socure-riskos.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/shufti-vs-socure-riskos.md",
    "slim": "https://www.anchorterminal.com/compare/shufti-vs-socure-riskos.min.md"
  },
  "markdown": "Socure RiskOS scores 63.5 (B) on agent readiness against Shufti's 57.8 (C), and leads in 3 of 7 scored categories. Both do kyc identity.\n\n- Shufti: grade C, 57.8/100, rank #538 of 842. Markdown https://www.anchorterminal.com/tools/shufti.md · JSON https://www.anchorterminal.com/api/v1/tools/shufti.json\n- Socure RiskOS: grade B, 63.5/100, rank #357 of 842. Markdown https://www.anchorterminal.com/tools/socure-riskos.md · JSON https://www.anchorterminal.com/api/v1/tools/socure-riskos.json\n\n## Which one, for what\n\n### Shufti (C)\n\nGood for: A team that wants document, face, address, AML and KYB checks behind one endpoint, a free plan for low volume, and an MCP server that hands the person a hosted verification link.\n\nAlso in its favour:\n- Free to start without a card\n\nWatch for: No OpenAPI file or other machine-readable contract was found. The reference is prose tables plus Postman collections\n\n### Socure RiskOS (B)\n\nGood for: A company in the United States that wants one decision from combined KYC, document, fraud and watchlist checks through a single evaluation call.\n\nAhead on:\n- Reliability, 75 against 65\n- Schema \u0026 documentation, 84 against 58\n\nWatch for: No service agreement or API terms are published. The only terms pages are website terms of use and end-user terms for document capture\n\n\n## Score by category\n\n| Category | Weight | Shufti | Socure RiskOS | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 65 | 75 | Socure RiskOS +10 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 58 | 84 | Socure RiskOS +26 |\n| Agent ergonomics | 13% (16.2 this run) | 47 | 46 | Shufti +1 |\n| Security \u0026 auth | 14% (17.5 this run) | 62 | 60 | Shufti +2 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 35 | 35 | even |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 72 | 75 | Socure RiskOS +3 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 71 | 68 | Shufti +3 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **57.8 · C** | **63.5 · B** | |\n\n## Facts side by side\n\n| Fact | Shufti | Socure RiskOS |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Shufti Pro Limited | Socure Inc. |\n| Hosted endpoint | `https://api.shuftipro.com` | `https://mcp.riskos.socure.com/sandbox` |\n| Transports | HTTP, Streamable HTTP | HTTP |\n| Auth | OAuth or key | API key |\n| Pricing | Freemium | Pay per use |\n| x402 | no | no |\n| Licence | Proprietary service under Shufti's Terms and Conditions. The licences of the mobile capture SDKs were not checked | Proprietary service. No service agreement is published, and the OpenAPI file states its licence as Proprietary |\n| Tools exposed | 25 | 9 |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| Last release | 2026-10-06 | 2026-10-06 |\n| Terms last updated |  | no document linked |\n| Privacy policy last updated | 2026-09-01 | no date given |\n| Customer content may train models | yes, with an opt-out | yes |\n| Terms restrict automated access |  |  |\n| Terms restrict benchmarking |  |  |\n| Terms or service can change without notice |  |  |\n| Arbitration or class-action waiver |  |  |\n| Popularity | 673 npm/wk | 35k npm/wk |\n\n## Verdicts\n\n**Shufti.** One endpoint covers document, face, address, AML and KYB checks, with a free plan of 10 verifications a month, and a hosted MCP server adds OAuth with three scopes. No OpenAPI file, server SDK or idempotency key was found, and the status page history could not be read.\n\n**Socure RiskOS.** A public OpenAPI file, llms.txt, 15 documented error codes and dated release notes cover a ten-operation REST API, and Socure Launch publishes prices from $0.80 an evaluation with a free sandbox. API keys carry no scopes, no idempotency header is defined, no service terms are published, and production stays at zero requests until Socure activates it.\n\n## Before you call either\n\n### Shufti\n\n1. POST every verification to `https://api.shuftipro.com/` with a unique `reference` of 6 to 250 characters and one object per service. Read results from `/status` with that reference\n2. Register the callback domain in the back office first. An unregistered `callback_url` is rejected\n3. Stay under 60 requests a minute per IP on a production account and 20 on a trial account\n4. Check the `Signature` response header. Accounts created after 15 March 2023 hash the Secret Key with SHA-256 before appending it to the raw response\n5. Through MCP, identity checks return a `verification_url` for the person to open. No tool accepts an image, so use the REST API for offsite proofs\n\n### Socure RiskOS\n\n1. Send `Authorization: Bearer \u003ckey\u003e` to `https://riskos.sandbox.socure.com/api/evaluation` for tests and `https://riskos.socure.com/api/evaluation` for live checks. The two environments use separate keys.\n2. Use dummy data only in the sandbox. It returns predefined results, connects to no live data source and expects the documented test values.\n3. Store the `eval_id` from every `POST /api/evaluation` response. No list or search endpoint exists to find it later.\n4. On 429 wait the seconds given in `X-Retry-After`. Do not blindly resend a failed `POST /api/evaluation`, because no idempotency header is documented and Launch bills each initiated evaluation.\n5. The MCP server at `https://mcp.riskos.socure.com/sandbox` reads docs, workflows and webhooks with its own MCP Server Key. It cannot run evaluations or read results.\n\n## Questions\n\n### Which is better for AI agents, Shufti or Socure RiskOS?\n\nSocure RiskOS scores 63.5 (B) on agent readiness against Shufti's 57.8 (C), and leads in 3 of 7 scored categories.\n\n### Do Shufti and Socure RiskOS need an API key?\n\nShufti takes an API key or an OAuth sign-in. Socure RiskOS needs an API key.\n\n### Can an agent call Shufti and Socure RiskOS without installing anything?\n\nYes. Shufti has a hosted endpoint at https://api.shuftipro.com and Socure RiskOS at https://mcp.riskos.socure.com/sandbox.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/shufti-vs-socure-riskos.json, and with the fewest tokens: https://www.anchorterminal.com/compare/shufti-vs-socure-riskos.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"shufti\", \"b\": \"socure-riskos\"}`. From a terminal: `anchor compare shufti socure-riskos`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/shufti.json and https://www.anchorterminal.com/api/v1/tools/socure-riskos.json\n\n## Other comparisons with Shufti or Socure RiskOS\n\n- [ComplyCube vs Shufti](https://www.anchorterminal.com/compare/complycube-vs-shufti.md)\n- [ComplyCube vs Socure RiskOS](https://www.anchorterminal.com/compare/complycube-vs-socure-riskos.md)\n- [Didit vs Shufti](https://www.anchorterminal.com/compare/didit-vs-shufti.md)\n- [Didit vs Socure RiskOS](https://www.anchorterminal.com/compare/didit-vs-socure-riskos.md)\n- [Jumio vs Shufti](https://www.anchorterminal.com/compare/jumio-vs-shufti.md)\n- [Jumio vs Socure RiskOS](https://www.anchorterminal.com/compare/jumio-vs-socure-riskos.md)\n- [Persona vs Shufti](https://www.anchorterminal.com/compare/persona-vs-shufti.md)\n- [Persona vs Socure RiskOS](https://www.anchorterminal.com/compare/persona-vs-socure-riskos.md)\n- [Shufti vs Sumsub](https://www.anchorterminal.com/compare/shufti-vs-sumsub.md)\n- [Shufti vs Trulioo](https://www.anchorterminal.com/compare/shufti-vs-trulioo.md)\n- [Shufti vs Veriff](https://www.anchorterminal.com/compare/shufti-vs-veriff.md)\n- [Socure RiskOS vs Sumsub](https://www.anchorterminal.com/compare/socure-riskos-vs-sumsub.md)\n- [Socure RiskOS vs Trulioo](https://www.anchorterminal.com/compare/socure-riskos-vs-trulioo.md)\n- [Socure RiskOS vs Veriff](https://www.anchorterminal.com/compare/socure-riskos-vs-veriff.md)\n- [ComplyAdvantage vs Shufti](https://www.anchorterminal.com/compare/complyadvantage-vs-shufti.md)\n- [ComplyAdvantage vs Socure RiskOS](https://www.anchorterminal.com/compare/complyadvantage-vs-socure-riskos.md)\n- [Middesk vs Shufti](https://www.anchorterminal.com/compare/middesk-vs-shufti.md)\n- [Middesk vs Socure RiskOS](https://www.anchorterminal.com/compare/middesk-vs-socure-riskos.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Shufti vs Socure RiskOS",
        "url": ""
      }
    ],
    "description": "Socure RiskOS scores 63.5 (B) on agent readiness against Shufti's 57.8 (C), and leads in 3 of 7 scored categories. Both do kyc identity. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Shufti C 57.8",
      "Socure RiskOS B 63.5",
      "scores"
    ],
    "h1": "Shufti vs Socure RiskOS",
    "image": "https://www.anchorterminal.com/assets/og/compare-shufti-vs-socure-riskos.png",
    "path": "/compare/shufti-vs-socure-riskos",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Shufti vs Socure RiskOS for AI agents, C 57.8 vs B 63.5",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/shufti-vs-socure-riskos"
  },
  "tokens": {
    "markdown": 2250,
    "slim": 630
  },
  "version": 1
}
