Head to head · Kyc identity · October 2026 research run

Shufti vs Sumsub

Sumsub scores 68.5 (B) on agent readiness against Shufti's 57.8 (C), and leads in 6 of 7 scored categories. Shufti leads on payments & pricing. Both do kyc identity.

Which one, for what

Shufti C

Good for A team that wants document, face, address, AML and KYB checks behind one endpoint, a free plan for low volume, and an MCP server that hands the person a hosted verification link.

Ahead on

  • Payments & pricing, 35 against 25

Also in its favour

  • Free to start without a card

Watch for

No OpenAPI file or other machine-readable contract was found. The reference is prose tables plus Postman collections

Sumsub B

Good for An agent that starts verifications, sends links, reads results and AML cases, and works case queues for a regulated business, with one token limited to those permissions.

Ahead on

  • Reliability, 80 against 65
  • Schema & documentation, 78 against 58
  • Agent ergonomics, 60 against 47
  • Security & auth, 80 against 62

Watch for

No idempotency keys and no Retry-After or backoff guidance found in the reviewed documentation

Score by category

CategoryWeight this runShuftiSumsubEdge
Reliability16%206580Sumsub +15
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.25878Sumsub +20
Agent ergonomics13%16.24760Sumsub +13
Security & auth14%17.56280Sumsub +18
Payments & pricing10%12.53525Shufti +10
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87274Sumsub +2
Transparency & trust7%8.87174Sumsub +3
Negative events≤1500
Total57.8 · C68.5 · B

Facts side by side

FactShuftiSumsub
KindHTTP APIHTTP API
VendorShufti Pro LimitedSum and Substance Ltd
Hosted endpointhttps://api.shuftipro.comhttps://api.sumsub.com
TransportsHTTP, Streamable HTTPHTTP
AuthOAuth or keyOAuth or key
PricingFreemiumPay per use
x402nono
LicenceProprietary service under Shufti's Terms and Conditions. The licences of the mobile capture SDKs were not checkedProprietary service under Sumsub's terms and conditions. The agent skills repository and the @sumsub/websdk npm package are MIT
Tools exposed25none
Read-only variant documentednono
llms.txtyesyes
Last release2026-10-062026-10-03
Terms last updated2026-05-21
Privacy policy last updated2026-09-012026-03-19
Customer content may train modelsyes, with an opt-outyes
Terms restrict automated accessnot found in the text
Terms restrict benchmarkingnot found in the text
Terms or service can change without noticeyes
Arbitration or class-action waiveryes
Popularity673 npm/wk172k npm/wk

Verdicts

Shufti

One endpoint covers document, face, address, AML and KYB checks, with a free plan of 10 verifications a month, and a hosted MCP server adds OAuth with three scopes. No OpenAPI file, server SDK or idempotency key was found, and the status page history could not be read.

Sumsub

Per-token permissions, an IP allowlist, HMAC-signed requests and a public OpenAPI spec with Markdown docs suit an agent working on verification cases. No idempotency keys or Retry-After guidance were found, there is no server SDK, and production access needs a browser signup, a bank card and Sumsub's review of the integration.

Before you call either

Shufti

  1. POST every verification to https://api.shuftipro.com/ with a unique reference of 6 to 250 characters and one object per service. Read results from /status with that reference
  2. Register the callback domain in the back office first. An unregistered callback_url is rejected
  3. Stay under 60 requests a minute per IP on a production account and 20 on a trial account
  4. Check the Signature response header. Accounts created after 15 March 2023 hash the Secret Key with SHA-256 before appending it to the raw response
  5. Through MCP, identity checks return a verification_url for the person to open. No tool accepts an image, so use the REST API for offsite proofs

Sumsub

  1. Sign every request. X-App-Access-Sig is the lowercase hex HMAC-SHA256 of timestamp, uppercase method, path with query and raw body, and the timestamp must be within one minute of server time
  2. Use a sandbox token (prefix sbx) for agent work. Sandbox and production tokens are separate, and Sumsub's own skills refuse any other prefix
  3. Stay under 300 GET and 50 POST requests per 5 seconds, and under 500 new applicants per 24 hours in Sandbox
  4. Token permissions can't be edited after creation. Generate a new token with the narrower set and delete the old one
  5. Subscribe to the applicantReviewed webhook for results and verify x-payload-digest against the raw body before trusting it

Questions

Which is better for AI agents, Shufti or Sumsub?

Sumsub scores 68.5 (B) on agent readiness against Shufti's 57.8 (C), and leads in 6 of 7 scored categories. Shufti leads on payments & pricing.

Do Shufti and Sumsub need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call Shufti and Sumsub without installing anything?

Yes. Shufti has a hosted endpoint at https://api.shuftipro.com and Sumsub at https://api.sumsub.com.

Other comparisons with Shufti or Sumsub

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.