# Shufti vs Sumsub > Sumsub scores 68.5 (B) on agent readiness against Shufti's 57.8 (C), and leads in 6 of 7 scored categories. Shufti leads on payments & pricing. Both do kyc identity. Category scores, facts, verdicts and agent notes side by side. - Canonical: https://www.anchorterminal.com/compare/shufti-vs-sumsub - Markdown: https://www.anchorterminal.com/compare/shufti-vs-sumsub.md (~2,200 tokens) - Slim: https://www.anchorterminal.com/compare/shufti-vs-sumsub.min.md (~730 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/compare/shufti-vs-sumsub.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-09 Sumsub scores 68.5 (B) on agent readiness against Shufti's 57.8 (C), and leads in 6 of 7 scored categories. Shufti leads on payments & pricing. Both do kyc identity. - Shufti: grade C, 57.8/100, rank #538 of 842. Markdown https://www.anchorterminal.com/tools/shufti.md · JSON https://www.anchorterminal.com/api/v1/tools/shufti.json - Sumsub: grade B, 68.5/100, rank #200 of 842. Markdown https://www.anchorterminal.com/tools/sumsub.md · JSON https://www.anchorterminal.com/api/v1/tools/sumsub.json ## Which one, for what ### Shufti (C) Good for: A team that wants document, face, address, AML and KYB checks behind one endpoint, a free plan for low volume, and an MCP server that hands the person a hosted verification link. Ahead on: - Payments & pricing, 35 against 25 Also in its favour: - Free to start without a card Watch for: No OpenAPI file or other machine-readable contract was found. The reference is prose tables plus Postman collections ### Sumsub (B) Good for: An agent that starts verifications, sends links, reads results and AML cases, and works case queues for a regulated business, with one token limited to those permissions. Ahead on: - Reliability, 80 against 65 - Schema & documentation, 78 against 58 - Agent ergonomics, 60 against 47 - Security & auth, 80 against 62 Watch for: No idempotency keys and no Retry-After or backoff guidance found in the reviewed documentation ## Score by category | Category | Weight | Shufti | Sumsub | Edge | | --- | --- | --- | --- | --- | | Reliability | 16% (20 this run) | 65 | 80 | Sumsub +15 | | Performance | 10%, pending | pending | pending | not scored in this run | | Schema & documentation | 13% (16.2 this run) | 58 | 78 | Sumsub +20 | | Agent ergonomics | 13% (16.2 this run) | 47 | 60 | Sumsub +13 | | Security & auth | 14% (17.5 this run) | 62 | 80 | Sumsub +18 | | Payments & pricing | 10% (12.5 this run) | 35 | 25 | Shufti +10 | | Task success | 10%, pending | pending | pending | not scored in this run | | Maintenance & community | 7% (8.8 this run) | 72 | 74 | Sumsub +2 | | Transparency & trust | 7% (8.8 this run) | 71 | 74 | Sumsub +3 | | Negative events | ≤15 | 0 | 0 | | | **Total** | | **57.8 · C** | **68.5 · B** | | ## Facts side by side | Fact | Shufti | Sumsub | | --- | --- | --- | | Kind | HTTP API | HTTP API | | Vendor | Shufti Pro Limited | Sum and Substance Ltd | | Hosted endpoint | `https://api.shuftipro.com` | `https://api.sumsub.com` | | Transports | HTTP, Streamable HTTP | HTTP | | Auth | OAuth or key | OAuth or key | | Pricing | Freemium | Pay per use | | x402 | no | no | | Licence | Proprietary service under Shufti's Terms and Conditions. The licences of the mobile capture SDKs were not checked | Proprietary service under Sumsub's terms and conditions. The agent skills repository and the @sumsub/websdk npm package are MIT | | Tools exposed | 25 | none | | Read-only variant documented | no | no | | llms.txt | yes | yes | | Last release | 2026-10-06 | 2026-10-03 | | Terms last updated | | 2026-05-21 | | Privacy policy last updated | 2026-09-01 | 2026-03-19 | | Customer content may train models | yes, with an opt-out | yes | | Terms restrict automated access | | not found in the text | | Terms restrict benchmarking | | not found in the text | | Terms or service can change without notice | | yes | | Arbitration or class-action waiver | | yes | | Popularity | 673 npm/wk | 172k npm/wk | ## Verdicts **Shufti.** One endpoint covers document, face, address, AML and KYB checks, with a free plan of 10 verifications a month, and a hosted MCP server adds OAuth with three scopes. No OpenAPI file, server SDK or idempotency key was found, and the status page history could not be read. **Sumsub.** Per-token permissions, an IP allowlist, HMAC-signed requests and a public OpenAPI spec with Markdown docs suit an agent working on verification cases. No idempotency keys or Retry-After guidance were found, there is no server SDK, and production access needs a browser signup, a bank card and Sumsub's review of the integration. ## Before you call either ### Shufti 1. POST every verification to `https://api.shuftipro.com/` with a unique `reference` of 6 to 250 characters and one object per service. Read results from `/status` with that reference 2. Register the callback domain in the back office first. An unregistered `callback_url` is rejected 3. Stay under 60 requests a minute per IP on a production account and 20 on a trial account 4. Check the `Signature` response header. Accounts created after 15 March 2023 hash the Secret Key with SHA-256 before appending it to the raw response 5. Through MCP, identity checks return a `verification_url` for the person to open. No tool accepts an image, so use the REST API for offsite proofs ### Sumsub 1. Sign every request. X-App-Access-Sig is the lowercase hex HMAC-SHA256 of timestamp, uppercase method, path with query and raw body, and the timestamp must be within one minute of server time 2. Use a sandbox token (prefix sbx) for agent work. Sandbox and production tokens are separate, and Sumsub's own skills refuse any other prefix 3. Stay under 300 GET and 50 POST requests per 5 seconds, and under 500 new applicants per 24 hours in Sandbox 4. Token permissions can't be edited after creation. Generate a new token with the narrower set and delete the old one 5. Subscribe to the applicantReviewed webhook for results and verify x-payload-digest against the raw body before trusting it ## Questions ### Which is better for AI agents, Shufti or Sumsub? Sumsub scores 68.5 (B) on agent readiness against Shufti's 57.8 (C), and leads in 6 of 7 scored categories. Shufti leads on payments & pricing. ### Do Shufti and Sumsub need an API key? Both take an API key or an OAuth sign-in. ### Can an agent call Shufti and Sumsub without installing anything? Yes. Shufti has a hosted endpoint at https://api.shuftipro.com and Sumsub at https://api.sumsub.com. ## For agents - This comparison as JSON: https://www.anchorterminal.com/compare/shufti-vs-sumsub.json, and with the fewest tokens: https://www.anchorterminal.com/compare/shufti-vs-sumsub.min.md - Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {"a": "shufti", "b": "sumsub"}`. From a terminal: `anchor compare shufti sumsub` - Each listing in full: https://www.anchorterminal.com/api/v1/tools/shufti.json and https://www.anchorterminal.com/api/v1/tools/sumsub.json ## Other comparisons with Shufti or Sumsub - [ComplyCube vs Shufti](https://www.anchorterminal.com/compare/complycube-vs-shufti.md) - [ComplyCube vs Sumsub](https://www.anchorterminal.com/compare/complycube-vs-sumsub.md) - [Didit vs Shufti](https://www.anchorterminal.com/compare/didit-vs-shufti.md) - [Didit vs Sumsub](https://www.anchorterminal.com/compare/didit-vs-sumsub.md) - [Jumio vs Shufti](https://www.anchorterminal.com/compare/jumio-vs-shufti.md) - [Jumio vs Sumsub](https://www.anchorterminal.com/compare/jumio-vs-sumsub.md) - [Persona vs Shufti](https://www.anchorterminal.com/compare/persona-vs-shufti.md) - [Persona vs Sumsub](https://www.anchorterminal.com/compare/persona-vs-sumsub.md) - [Shufti vs Socure RiskOS](https://www.anchorterminal.com/compare/shufti-vs-socure-riskos.md) - [Shufti vs Trulioo](https://www.anchorterminal.com/compare/shufti-vs-trulioo.md) - [Shufti vs Veriff](https://www.anchorterminal.com/compare/shufti-vs-veriff.md) - [Socure RiskOS vs Sumsub](https://www.anchorterminal.com/compare/socure-riskos-vs-sumsub.md) - [Sumsub vs Trulioo](https://www.anchorterminal.com/compare/sumsub-vs-trulioo.md) - [Sumsub vs Veriff](https://www.anchorterminal.com/compare/sumsub-vs-veriff.md) - [ComplyAdvantage vs Shufti](https://www.anchorterminal.com/compare/complyadvantage-vs-shufti.md) - [ComplyAdvantage vs Sumsub](https://www.anchorterminal.com/compare/complyadvantage-vs-sumsub.md) - [Middesk vs Shufti](https://www.anchorterminal.com/compare/middesk-vs-shufti.md) - [Middesk vs Sumsub](https://www.anchorterminal.com/compare/middesk-vs-sumsub.md)