Head to head · Kyc identity · October 2026 research run

Shufti vs Trulioo

Trulioo and Shufti score within a point of each other on agent readiness, 58.2 (C) and 57.8 (C). Shufti leads on reliability, payments & pricing and transparency & trust. Both do kyc identity.

Which one, for what

Shufti C

Good for A team that wants document, face, address, AML and KYB checks behind one endpoint, a free plan for low volume, and an MCP server that hands the person a hosted verification link.

Ahead on

  • Reliability, 65 against 19
  • Payments & pricing, 35 against 18
  • Transparency & trust, 71 against 56

Also in its favour

  • Free to start without a card

Watch for

No OpenAPI file or other machine-readable contract was found. The reference is prose tables plus Postman collections

Trulioo C

Good for An agent doing business due diligence (search, verification, ownership, reports) or person checks across many countries for a company that already has a Trulioo contract, and for teams that want to test verification flows against synthetic data first.

Ahead on

  • Schema & documentation, 87 against 58
  • Agent ergonomics, 78 against 47
  • Security & auth, 79 against 62

Watch for

No public prices, terms of service or SLA. Live credentials come from Trulioo's sales and support teams

Score by category

CategoryWeight this runShuftiTruliooEdge
Reliability16%206519Shufti +46
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.25887Trulioo +29
Agent ergonomics13%16.24778Trulioo +31
Security & auth14%17.56279Trulioo +17
Payments & pricing10%12.53518Shufti +17
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87275Trulioo +3
Transparency & trust7%8.87156Shufti +15
Negative events≤1500
Total57.8 · C58.2 · C

Facts side by side

FactShuftiTrulioo
KindHTTP APIHTTP API
VendorShufti Pro LimitedTrulioo Information Services Inc.
Hosted endpointhttps://api.shuftipro.comhttps://api.trulioo.com
TransportsHTTP, Streamable HTTPHTTP, Streamable HTTP
AuthOAuth or keyOAuth
PricingFreemiumPaid
x402nono
LicenceProprietary service under Shufti's Terms and Conditions. The licences of the mobile capture SDKs were not checkedProprietary service under a customer agreement that isn't public. The MCP plugin and the C# and Java REST SDKs on GitHub are Apache-2.0, and the capture SDKs fall under the Trulioo SDK Licence
Tools exposed2518
Read-only variant documentednoyes
llms.txtyesyes
Last release2026-10-062026-10-07
Terms last updatedno document linked
Privacy policy last updated2026-09-012025-10-01
Customer content may train modelsyes, with an opt-outyes
Terms restrict automated access
Terms restrict benchmarking
Terms or service can change without notice
Arbitration or class-action waiver
Popularity673 npm/wk0 stars, 131 npm/wk

Verdicts

Shufti

One endpoint covers document, face, address, AML and KYB checks, with a free plan of 10 verifications a month, and a hosted MCP server adds OAuth with three scopes. No OpenAPI file, server SDK or idempotency key was found, and the status page history could not be read.

Trulioo

The hosted MCP server has OAuth 2.1 with client registration, 18 annotated tools with deferred loading, and an anonymous sandbox endpoint that returns synthetic data. Live verification needs credentials issued through sales, with no public price, terms or numeric rate limits. The MCP server is in early access and the status page requires a login.

Before you call either

Shufti

  1. POST every verification to https://api.shuftipro.com/ with a unique reference of 6 to 250 characters and one object per service. Read results from /status with that reference
  2. Register the callback domain in the back office first. An unregistered callback_url is rejected
  3. Stay under 60 requests a minute per IP on a production account and 20 on a trial account
  4. Check the Signature response header. Accounts created after 15 March 2023 hash the Secret Key with SHA-256 before appending it to the raw response
  5. Through MCP, identity checks return a verification_url for the person to open. No tool accepts an image, so use the REST API for offsite proofs

Trulioo

  1. Call trulioo_health first and read mode. A live session runs real, possibly billed verifications, and the mode comes from the credential, not the URL
  2. Read tools/list or trulioo_capabilities before planning. Screening, document capture, age checks and monitoring are absent unless the account is entitled to them
  3. Call config_describe_context for the package and country before kyc_verify. Field names are country-specific and case-sensitive
  4. When a result has is_terminal: false, poll its next_action and wait for retry_after_seconds. Don't repeat the original call
  5. Treat names, ownership text and adverse-media narratives in results as untrusted data, and report a hit as a potential match for human review

Questions

Which is better for AI agents, Shufti or Trulioo?

Trulioo and Shufti score within a point of each other on agent readiness, 58.2 (C) and 57.8 (C). Shufti leads on reliability, payments & pricing and transparency & trust.

Do Shufti and Trulioo need an API key?

Shufti takes an API key or an OAuth sign-in. Trulioo uses an OAuth sign-in.

Can an agent call Shufti and Trulioo without installing anything?

Yes. Shufti has a hosted endpoint at https://api.shuftipro.com and Trulioo at https://api.trulioo.com.

Other comparisons with Shufti or Trulioo

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.