Head to head · Kyc identity · October 2026 research run
Shufti vs Veriff
Veriff scores 61.1 (C) on agent readiness against Shufti's 57.8 (C), and leads in 4 of 7 scored categories. Both do kyc identity.
Which one, for what
Shufti C
Good for A team that wants document, face, address, AML and KYB checks behind one endpoint, a free plan for low volume, and an MCP server that hands the person a hosted verification link.
Also in its favour
- A hosted endpoint, with nothing to install
- Free to start without a card
Watch for
No OpenAPI file or other machine-readable contract was found. The reference is prose tables plus Postman collections
Veriff C
Good for A team that needs document and selfie verification with public per-verification prices and a trial, and that can run a webhook receiver and HMAC signing.
Ahead on
- Schema & documentation, 82 against 58
- Payments & pricing, 40 against 35
Watch for
No server-side SDK and no MCP server. Official packages cover only browser and mobile capture
Score by category
| Category | Weight this run | Shufti | Veriff | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 65 | 62 | Shufti +3 |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 58 | 82 | Veriff +24 |
| Agent ergonomics | 13%16.2 | 47 | 43 | Shufti +4 |
| Security & auth | 14%17.5 | 62 | 63 | Veriff +1 |
| Payments & pricing | 10%12.5 | 35 | 40 | Veriff +5 |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 72 | 74 | Veriff +2 |
| Transparency & trust | 7%8.8 | 71 | 67 | Shufti +4 |
| Negative events | ≤15 | 0 | 0 | |
| Total | 57.8 · C | 61.1 · C |
Facts side by side
| Fact | Shufti | Veriff |
|---|---|---|
| Kind | HTTP API | HTTP API |
| Vendor | Shufti Pro Limited | Veriff OÜ |
| Hosted endpoint | https://api.shuftipro.com | no (local only) |
| Transports | HTTP, Streamable HTTP | HTTP |
| Auth | OAuth or key | API key |
| Pricing | Freemium | Pay per use |
| x402 | no | no |
| Licence | Proprietary service under Shufti's Terms and Conditions. The licences of the mobile capture SDKs were not checked | Proprietary service. The npm capture SDKs are ISC (@veriff/js-sdk, @veriff/incontext-sdk) and MIT (@veriff/react-native-sdk) |
| Tools exposed | 25 | none |
| Read-only variant documented | no | no |
| llms.txt | yes | yes |
| Last release | 2026-10-06 | 2026-10-02 |
| Terms last updated | couldn't be read | |
| Privacy policy last updated | 2026-09-01 | 2026-04-16 |
| Customer content may train models | yes, with an opt-out | yes |
| Terms restrict automated access | couldn't be read | |
| Terms restrict benchmarking | couldn't be read | |
| Terms or service can change without notice | couldn't be read | |
| Arbitration or class-action waiver | couldn't be read | |
| Popularity | 673 npm/wk | 32 stars, 110k npm/wk |
Verdicts
Shufti
One endpoint covers document, face, address, AML and KYB checks, with a free plan of 10 verifications a month, and a hosted MCP server adds OAuth with three scopes. No OpenAPI file, server SDK or idempotency key was found, and the status page history could not be read.
Veriff
Per-verification prices are public from $0.80, with a 15-day trial of 50 sessions and no card. Each endpoint page is Markdown with an OpenAPI 3.0 fragment. There is no server SDK, MCP server or idempotency key, most calls need an HMAC signature, and the status page shows nine incidents between 20 July and 7 October 2026.
Before you call either
Shufti
- POST every verification to
https://api.shuftipro.com/with a uniquereferenceof 6 to 250 characters and one object per service. Read results from/statuswith that reference - Register the callback domain in the back office first. An unregistered
callback_urlis rejected - Stay under 60 requests a minute per IP on a production account and 20 on a trial account
- Check the
Signatureresponse header. Accounts created after 15 March 2023 hash the Secret Key with SHA-256 before appending it to the raw response - Through MCP, identity checks return a
verification_urlfor the person to open. No tool accepts an image, so use the REST API for offsite proofs
Veriff
- Take the base URL from the integration's API keys page. Send X-AUTH-CLIENT on every call and store verification.id from POST /v1/sessions
- Sign POST and PATCH bodies, and the session ID on GET and DELETE, with HMAC-SHA256 in X-HMAC-SIGNATURE. POST /v1/sessions needs no signature
- Stay under 30 session creations a minute on Self-Serve, 600 on Enterprise. A 429 carries code 1004
- Don't blindly retry POST /v1/sessions. Each call makes a new session, which is billed on a live integration
- Poll GET /v1/sessions/{id}/decision until
verificationis not null, or accept webhooks within 5 seconds and treat duplicates as normal
Questions
Which is better for AI agents, Shufti or Veriff?
Veriff scores 61.1 (C) on agent readiness against Shufti's 57.8 (C), and leads in 4 of 7 scored categories.
Do Shufti and Veriff need an API key?
Shufti takes an API key or an OAuth sign-in. Veriff needs an API key.
Can an agent call Shufti and Veriff without installing anything?
Shufti has a hosted endpoint at https://api.shuftipro.com. No hosted endpoint is listed for Veriff.
Other comparisons with Shufti or Veriff
- ComplyCube vs Shufti
- ComplyCube vs Veriff
- Didit vs Shufti
- Didit vs Veriff
- Jumio vs Shufti
- Jumio vs Veriff
- Middesk vs Veriff
- Persona vs Shufti
- Persona vs Veriff
- Shufti vs Socure RiskOS
- Shufti vs Sumsub
- Shufti vs Trulioo
- Socure RiskOS vs Veriff
- Sumsub vs Veriff
- Trulioo vs Veriff
- ComplyAdvantage vs Shufti
- ComplyAdvantage vs Veriff
- Middesk vs Shufti
Machine-readable
- This page as Markdown
/compare/shufti-vs-veriff.md· slim.min.md· JSON.json(or sendAccept: text/markdown) - Each listing in full
/api/v1/tools/shufti.json·/api/v1/tools/veriff.json - From a terminal
anchor compare shufti veriff(the CLI) - Over MCP
compare_tools {"a": "shufti", "b": "veriff"}at/mcp, no key