{
  "data": {
    "a": {
      "slug": "shufti",
      "name": "Shufti",
      "vendor": "Shufti Pro Limited",
      "vendorUrl": "https://shuftipro.com",
      "kind": "http-api",
      "category": "identity-verification",
      "summary": "Identity and business verification service from Shufti Pro Limited in London. One REST endpoint runs document, face, address, AML screening and KYB checks chosen in the request body, with results by callback. A hosted MCP server exposes 25 tools.",
      "url": "https://www.anchorterminal.com/tools/shufti",
      "markdownUrl": "https://www.anchorterminal.com/tools/shufti.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/shufti.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/shufti.json",
      "repo": "https://github.com/shuftipro/iOS-SDK",
      "license": "Proprietary service under Shufti's Terms and Conditions. The licences of the mobile capture SDKs were not checked",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.shuftipro.com",
      "packages": [
        {
          "registry": "npm",
          "name": "shuftipro-onsite-mobilesdk"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve. Signing up creates a back office account, and the Client ID and Secret Key come from Settings, API Configuration, API Keys. The REST API takes them as HTTP Basic auth, or a Bearer access token from `/get/access/token` that lasts one hour. The key pair has no scopes, and the Secret Key is shown once and replaced by generating a new one. The MCP server uses OAuth 2.1 with PKCE and dynamic client registration. Its login page asks for the same Client ID and Secret Key, and it issues tokens with the scopes `knowledge:read`, `verification:read` and `verification:write`. Callback and redirect domains must be registered in the back office.",
      "pricing": "freemium",
      "pricingNotes": "Free Forever covers up to 10 verifications a month with no card, on the production environment. Essentials starts from $1.50 a verification, pay as you go with no monthly minimum, up to 20,000 verifications. Enterprise is quoted by sales and adds e-IDV, Travel Rule, video KYC and other services. The pricing page says only successful verification attempts are billed and resubmissions are free. Trial accounts accept test ID samples (https://shuftipro.com/pricing/, checked 2026-10-09).",
      "priceSummary": "$1.50 / tx",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the developer docs (llms-full.txt), the pricing page or the terms (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": 25,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 673,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://developers.shuftipro.com/docs/get_started",
      "llmsTxt": "https://developers.shuftipro.com/llms.txt",
      "capabilities": [
        "kyc.identity",
        "kyc.documents",
        "kyc.business",
        "kyc.screening"
      ],
      "tags": [
        "hosted",
        "api-key",
        "oauth",
        "mcp",
        "webhooks",
        "llms-txt",
        "free-tier",
        "no-card",
        "status-page",
        "sla",
        "soc2",
        "iso27001"
      ],
      "lastRelease": "2026-10-06",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 57.8,
        "grade": "C",
        "agentReady": false,
        "rank": 538,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 9,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 47,
          "maintenance": 72,
          "payments": 35,
          "reliability": 65,
          "schema": 58,
          "security": 62,
          "transparency": 71
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": 0,
        "verdict": "One endpoint covers document, face, address, AML and KYB checks, with a free plan of 10 verifications a month, and a hosted MCP server adds OAuth with three scopes. No OpenAPI file, server SDK or idempotency key was found, and the status page history could not be read.",
        "bestFor": "A team that wants document, face, address, AML and KYB checks behind one endpoint, a free plan for low volume, and an MCP server that hands the person a hosted verification link.",
        "strengths": [
          "Free Forever plan of 10 verifications a month with no card, on the production environment, per the pricing page",
          "Hosted MCP server at `https://ai.shuftipro.com/mcp` with 25 tools, OAuth 2.1 with PKCE and three scopes enforced on every call",
          "Docs published as llms.txt, a 2.9 MB llms-full.txt and a Markdown twin of each page, with samples in nine languages",
          "Public terms (version 11.1, 13 May 2026) include an availability schedule targeting 99 per cent monthly uptime",
          "Revision history with 19 dated entries between 24 July and 6 October 2026"
        ],
        "weaknesses": [
          "No OpenAPI file or other machine-readable contract was found. The reference is prose tables plus Postman collections",
          "The REST credential is one Client ID and Secret Key pair with no scopes, sent as Basic auth on every call",
          "No idempotency key, Retry-After header or backoff guidance was found for the documented 429",
          "No server-side SDK. Official packages cover Android, iOS, Flutter, React Native and Cordova capture only",
          "Standard KYB was deprecated on 6 October 2026 and its pages removed the same day, with no notice period stated",
          "The sub-processor list is available to clients on request only, and security.txt returns 404"
        ],
        "agentNotes": [
          "POST every verification to `https://api.shuftipro.com/` with a unique `reference` of 6 to 250 characters and one object per service. Read results from `/status` with that reference",
          "Register the callback domain in the back office first. An unregistered `callback_url` is rejected",
          "Stay under 60 requests a minute per IP on a production account and 20 on a trial account",
          "Check the `Signature` response header. Accounts created after 15 March 2023 hash the Secret Key with SHA-256 before appending it to the raw response",
          "Through MCP, identity checks return a `verification_url` for the person to open. No tool accepts an image, so use the REST API for offsite proofs"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 57.8
          }
        ],
        "editorialScores": {
          "ergonomics": 47,
          "maintenance": 72,
          "payments": 35,
          "reliability": 65,
          "schema": 58,
          "security": 62,
          "transparency": 51
        },
        "provenanceScore": 90
      },
      "connect": {
        "http": "curl --location --request POST 'https://api.shuftipro.com' \\\n--header 'Content-Type: application/json' \\\n--header 'Authorization: Basic \u003cbase64 of CLIENT_ID:SECRET_KEY\u003e' \\\n--data-raw '{\n    \"reference\"    : \"1234567\",\n    \"callback_url\" : \"https://yourdomain.com/profile/notifyCallback\",\n    \"country\"      : \"GB\",\n    \"language\"     : \"EN\",\n    \"verification_mode\" : \"any\",\n    \"face\" : {\n        \"proof\"            : \"\"\n    }\n}'",
        "claudeCode": "claude mcp add --transport http shufti https://ai.shuftipro.com/mcp",
        "config": {
          "mcpServers": {
            "shufti": {
              "args": [
                "mcp-remote",
                "https://ai.shuftipro.com/mcp"
              ],
              "command": "npx"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/kyc.identity",
        "tool": "https://letme.dev/shufti"
      },
      "area": "domain-data",
      "unitPrices": [
        {
          "item": "Verification, Free Forever plan (document and face checks)",
          "unit": "tx",
          "usd": 0,
          "note": "up to 10 verifications a month, no card"
        },
        {
          "item": "Verification, Essentials plan, starting price",
          "unit": "tx",
          "usd": 1.5,
          "note": "rate depends on volume and the services chosen, up to 20,000 verifications"
        }
      ],
      "provenance": {
        "legalEntity": "Shufti Pro Limited",
        "domain": "shuftipro.com",
        "domainRegistered": "2016-06-28",
        "endpointOnVendorDomain": true,
        "terms": "https://shuftipro.com/wp-content/uploads/Version-11.1-w.e.f.-May-13th-2026.pdf",
        "privacy": "https://shuftipro.com/services-privacy-notice/",
        "statusPage": "https://status.shuftipro.com",
        "changelog": "https://developers.shuftipro.com/docs/revision_history",
        "securityTxt": "none",
        "checked": "2026-10-09",
        "notes": [
          "The terms and the MCP privacy notice name Shufti Pro Limited, Office 408 Coppergate House, 10 Whites Row, London E1 7NF.",
          "The governing terms are a PDF, version 11.1, linked from shuftipro.com/terms-and-conditions/, which itself carries only a summary and links to every earlier version. The page labels the file 12 May 2026 and the file name says 13 May.",
          "The privacy link is the Services Privacy Notice, version 1.2, last updated September 2026, which covers verification data. A separate notice covers the website.",
          "shuftipro.com/.well-known/security.txt answered 502 on the first request and 404 on the second.",
          "RDAP for shuftipro.com gives a registration date of 2016-06-28.",
          "The API answers at api.shuftipro.com and the MCP server at ai.shuftipro.com. The lead's shufti.ai is a parked domain for sale and unrelated to the vendor.",
          "status.shuftipro.com is an UptimeRobot page whose data loads from /api/, a path its robots.txt disallows, so the incident history was not read."
        ],
        "score": 90
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/shufti.json",
      "live": {
        "slug": "shufti",
        "probe": {
          "target": "https://api.shuftipro.com",
          "method": "get",
          "lastAt": "2026-10-09T11:46:40.498968542Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 347,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 321,
          "p95ms24h": 367,
          "samples24h": 44,
          "samples30d": 44,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 44,
              "ok": 44
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.shuftipro.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-09T07:58:32.112017753Z"
        },
        "updatedAt": "2026-10-09T11:46:40.498968542Z"
      }
    },
    "answer": "Veriff scores 61.1 (C) on agent readiness against Shufti's 57.8 (C), and leads in 4 of 7 scored categories.",
    "b": {
      "slug": "veriff",
      "name": "Veriff",
      "vendor": "Veriff OÜ",
      "vendorUrl": "https://www.veriff.com",
      "kind": "http-api",
      "category": "identity-verification",
      "summary": "Identity verification service from Veriff in Tallinn. It checks an identity document and a selfie, with liveness, database checks and PEP and sanctions screening. Sessions are created and read through the Public API v1, with results sent by webhook.",
      "url": "https://www.anchorterminal.com/tools/veriff",
      "markdownUrl": "https://www.anchorterminal.com/tools/veriff.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/veriff.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/veriff.json",
      "repo": "https://github.com/Veriff/veriff-js-sdk",
      "license": "Proprietary service. The npm capture SDKs are ISC (@veriff/js-sdk, @veriff/incontext-sdk) and MIT (@veriff/react-native-sdk)",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "@veriff/incontext-sdk"
        },
        {
          "registry": "npm",
          "name": "@veriff/js-sdk"
        },
        {
          "registry": "npm",
          "name": "@veriff/react-native-sdk"
        }
      ],
      "auth": "api-key",
      "authNotes": "Self-serve. Signing up for a Self-Serve plan creates a Customer Portal account with a test integration, and Enterprise accounts start from a sales form. Each integration has an API key, sent as `X-AUTH-CLIENT`, and up to five shared secret keys used to compute an HMAC-SHA256 `X-HMAC-SIGNATURE` (over the body on POST and PATCH, over the session ID on GET and DELETE). POST /v1/sessions needs only the API key. Secrets are shown once and can be rotated or deleted by an admin. There are no scopes. A live integration unlocks once the account holder passes Veriff's own identity verification.",
      "pricing": "usage",
      "pricingNotes": "Self-Serve is priced per verification with a monthly minimum. Essential is $0.80 ($49 a month minimum), Plus $1.39 ($99) and Premium $1.89 ($209). PEP and sanctions screening adds $0.64, ongoing monitoring $0.09 and two-year retention $0.30. A 15-day trial covers up to 50 sessions with no card, after the account holder completes identity verification. Test integrations are free and unbilled. Enterprise, suggested for 5,000 or more verifications a month, is priced by sales (https://www.veriff.com/plans/self-serve, checked 2026-10-08).",
      "priceSummary": "$0.80 / tx",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the developer docs index, the API guides or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 32,
        "npmWeekly": 109625,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://devdocs.veriff.com",
      "llmsTxt": "https://devdocs.veriff.com/llms.txt",
      "openapi": "https://devdocs.veriff.com/apidocs/v1sessions.md",
      "capabilities": [
        "kyc.identity",
        "kyc.documents",
        "kyc.screening"
      ],
      "tags": [
        "hosted",
        "api-key",
        "hmac",
        "webhooks",
        "openapi",
        "llms-txt",
        "free-trial",
        "sandbox",
        "status-page",
        "bug-bounty",
        "soc2",
        "iso27001"
      ],
      "lastRelease": "2026-10-02",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 61.1,
        "grade": "C",
        "agentReady": false,
        "rank": 436,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 6,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 43,
          "maintenance": 74,
          "payments": 40,
          "reliability": 62,
          "schema": 82,
          "security": 63,
          "transparency": 67
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "Per-verification prices are public from $0.80, with a 15-day trial of 50 sessions and no card. Each endpoint page is Markdown with an OpenAPI 3.0 fragment. There is no server SDK, MCP server or idempotency key, most calls need an HMAC signature, and the status page shows nine incidents between 20 July and 7 October 2026.",
        "bestFor": "A team that needs document and selfie verification with public per-verification prices and a trial, and that can run a webhook receiver and HMAC signing.",
        "strengths": [
          "Public prices of $0.80, $1.39 and $1.89 a verification, with a 15-day trial of up to 50 sessions and no card",
          "llms.txt index and Markdown pages, each API endpoint with an OpenAPI 3.0.0 fragment, examples and error schemas",
          "Up to five shared secret keys per integration, shown once, with documented rotation and deletion",
          "Test integrations are created at signup, aren't billed, and let the developer force a decision",
          "ISO/IEC 27001:2022, SOC 2 Type II, Cyber Essentials and a bug bounty on Intigriti paying 50 to 6,000 euros"
        ],
        "weaknesses": [
          "No server-side SDK and no MCP server. Official packages cover only browser and mobile capture",
          "No idempotency key on POST /v1/sessions, and no Retry-After or backoff guidance for the documented 429",
          "Nine status-page incidents between 20 July and 7 October 2026, mostly delayed decisions in the US region",
          "No endpoint lists sessions and no pagination was found. Every read needs a stored session ID",
          "Session deletion by API is off by default and capped at 10 sessions in 24 hours",
          "No security.txt, and the sub-processor list sits on a help centre page that needs JavaScript"
        ],
        "agentNotes": [
          "Take the base URL from the integration's API keys page. Send X-AUTH-CLIENT on every call and store verification.id from POST /v1/sessions",
          "Sign POST and PATCH bodies, and the session ID on GET and DELETE, with HMAC-SHA256 in X-HMAC-SIGNATURE. POST /v1/sessions needs no signature",
          "Stay under 30 session creations a minute on Self-Serve, 600 on Enterprise. A 429 carries code 1004",
          "Don't blindly retry POST /v1/sessions. Each call makes a new session, which is billed on a live integration",
          "Poll GET /v1/sessions/{id}/decision until `verification` is not null, or accept webhooks within 5 seconds and treat duplicates as normal"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 61.1
          }
        ],
        "editorialScores": {
          "ergonomics": 43,
          "maintenance": 74,
          "payments": 40,
          "reliability": 62,
          "schema": 82,
          "security": 63,
          "transparency": 48
        },
        "provenanceScore": 85
      },
      "connect": {
        "http": "curl -X POST \"https://\u003cBaseURL\u003e/v1/sessions\" \\\n  -H 'Content-Type: application/json' \\\n  -H 'X-AUTH-CLIENT: API-KEY' \\\n  -d '{\"verification\": {}}'"
      },
      "letme": {
        "capability": "https://letme.dev/kyc.identity",
        "tool": "https://letme.dev/veriff"
      },
      "area": "domain-data",
      "unitPrices": [
        {
          "item": "Verification, Essential plan (automated decision)",
          "unit": "tx",
          "usd": 0.8,
          "note": "$49 a month minimum"
        },
        {
          "item": "Verification, Plus plan",
          "unit": "tx",
          "usd": 1.39,
          "note": "$99 a month minimum"
        },
        {
          "item": "Verification, Premium plan",
          "unit": "tx",
          "usd": 1.89,
          "note": "$209 a month minimum"
        },
        {
          "item": "PEP and sanctions screening add-on, per verification",
          "unit": "tx",
          "usd": 0.64,
          "note": "charged on top of the monthly minimum"
        },
        {
          "item": "Ongoing monitoring add-on, per verification",
          "unit": "tx",
          "usd": 0.09,
          "note": "charged on top of the monthly minimum"
        }
      ],
      "provenance": {
        "legalEntity": "Veriff OÜ",
        "domain": "veriff.com",
        "domainRegistered": "2006-04-12",
        "endpointOnVendorDomain": true,
        "terms": "https://www.veriff.com/terms-of-service",
        "privacy": "https://www.veriff.com/privacy-notice",
        "statusPage": "https://status.veriff.com",
        "changelog": "https://devdocs.veriff.com/docs/release-notes",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The privacy notice (valid from 30 July 2020, last updated 16 April 2026) names Veriff OÜ and Veriff Brazil Ltda. and gives the Estonian Data Protection Inspectorate as lead supervisory authority.",
          "www.veriff.com/terms-of-service answers 200 with the title Terms of Service but no terms text in the HTML we fetched, so the terms themselves weren't read.",
          "www.veriff.com/.well-known/security.txt and /security.txt return 404. Reports go to a bug bounty programme on Intigriti (https://www.veriff.com/bug-bounty).",
          "The API base URL is per integration and shown in the Customer Portal. Code samples in the docs use https://stationapi.veriff.com.",
          "RDAP for veriff.com gives a registration date of 2006-04-12, which predates the company.",
          "The sub-processor list is linked from the privacy notice to help.veriff.com, which returned only a JavaScript shell to our fetch."
        ],
        "score": 85
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/veriff.json",
      "live": {
        "slug": "veriff",
        "vendorStatus": {
          "page": "https://status.veriff.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-09T11:41:13.411444533Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "Veriff/veriff-js-sdk",
            "version": "v2.0.0",
            "released": "2025-09-09",
            "seenAt": "2026-10-08T16:34:12.058479178Z"
          },
          {
            "registry": "npm",
            "name": "@veriff/incontext-sdk",
            "version": "2.5.0",
            "seenAt": "2026-10-08T16:34:07.822049846Z"
          },
          {
            "registry": "npm",
            "name": "@veriff/js-sdk",
            "version": "2.0.0",
            "seenAt": "2026-10-08T16:34:08.944903091Z"
          },
          {
            "registry": "npm",
            "name": "@veriff/react-native-sdk",
            "version": "13.2.0",
            "seenAt": "2026-10-08T16:34:10.073325113Z"
          }
        ],
        "githubStars": 32,
        "npmWeekly": 109625,
        "securityTxt": {
          "url": "https://veriff.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:34.847122653Z"
        },
        "pages": [
          {
            "url": "https://devdocs.veriff.com/docs/release-notes",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:17:01.404186048Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "26520a9df2cc"
          },
          {
            "url": "https://www.veriff.com/privacy-notice",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:31:21.093035848Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "024c0d3f9713"
          },
          {
            "url": "https://www.veriff.com/terms-of-service",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:31:23.123829782Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "d9e650601ce7"
          }
        ],
        "updatedAt": "2026-10-09T11:41:13.411444533Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Shufti Pro Limited",
        "b": "Veriff OÜ",
        "name": "Vendor"
      },
      {
        "a": "https://api.shuftipro.com",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "API key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Pay per use",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under Shufti's Terms and Conditions. The licences of the mobile capture SDKs were not checked",
        "b": "Proprietary service. The npm capture SDKs are ISC (@veriff/js-sdk, @veriff/incontext-sdk) and MIT (@veriff/react-native-sdk)",
        "name": "Licence"
      },
      {
        "a": "25",
        "b": "none",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-06",
        "b": "2026-10-02",
        "name": "Last release"
      },
      {
        "a": "",
        "b": "couldn't be read",
        "name": "Terms last updated"
      },
      {
        "a": "2026-09-01",
        "b": "2026-04-16",
        "name": "Privacy policy last updated"
      },
      {
        "a": "yes, with an opt-out",
        "b": "yes",
        "name": "Customer content may train models"
      },
      {
        "a": "",
        "b": "couldn't be read",
        "name": "Terms restrict automated access"
      },
      {
        "a": "",
        "b": "couldn't be read",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "",
        "b": "couldn't be read",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "",
        "b": "couldn't be read",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "673 npm/wk",
        "b": "32 stars, 110k npm/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Veriff scores 61.1 (C) on agent readiness against Shufti's 57.8 (C), and leads in 4 of 7 scored categories.",
        "question": "Which is better for AI agents, Shufti or Veriff?"
      },
      {
        "answer": "Shufti takes an API key or an OAuth sign-in. Veriff needs an API key.",
        "question": "Do Shufti and Veriff need an API key?"
      },
      {
        "answer": "Shufti has a hosted endpoint at https://api.shuftipro.com. No hosted endpoint is listed for Veriff.",
        "question": "Can an agent call Shufti and Veriff without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": null,
        "also": [
          "A hosted endpoint, with nothing to install",
          "Free to start without a card"
        ],
        "goodFor": "A team that wants document, face, address, AML and KYB checks behind one endpoint, a free plan for low volume, and an MCP server that hands the person a hosted verification link.",
        "slug": "shufti",
        "watchFor": "No OpenAPI file or other machine-readable contract was found. The reference is prose tables plus Postman collections"
      },
      {
        "aheadOn": [
          "Schema \u0026 documentation, 82 against 58",
          "Payments \u0026 pricing, 40 against 35"
        ],
        "also": null,
        "goodFor": "A team that needs document and selfie verification with public per-verification prices and a trial, and that can run a webhook receiver and HMAC signing.",
        "slug": "veriff",
        "watchFor": "No server-side SDK and no MCP server. Official packages cover only browser and mobile capture"
      }
    ],
    "job": {
      "capability": "kyc.identity",
      "name": "Kyc identity"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/complycube-vs-shufti.json",
        "title": "ComplyCube vs Shufti",
        "url": "https://www.anchorterminal.com/compare/complycube-vs-shufti"
      },
      {
        "json": "https://www.anchorterminal.com/compare/complycube-vs-veriff.json",
        "title": "ComplyCube vs Veriff",
        "url": "https://www.anchorterminal.com/compare/complycube-vs-veriff"
      },
      {
        "json": "https://www.anchorterminal.com/compare/didit-vs-shufti.json",
        "title": "Didit vs Shufti",
        "url": "https://www.anchorterminal.com/compare/didit-vs-shufti"
      },
      {
        "json": "https://www.anchorterminal.com/compare/didit-vs-veriff.json",
        "title": "Didit vs Veriff",
        "url": "https://www.anchorterminal.com/compare/didit-vs-veriff"
      },
      {
        "json": "https://www.anchorterminal.com/compare/jumio-vs-shufti.json",
        "title": "Jumio vs Shufti",
        "url": "https://www.anchorterminal.com/compare/jumio-vs-shufti"
      },
      {
        "json": "https://www.anchorterminal.com/compare/jumio-vs-veriff.json",
        "title": "Jumio vs Veriff",
        "url": "https://www.anchorterminal.com/compare/jumio-vs-veriff"
      },
      {
        "json": "https://www.anchorterminal.com/compare/middesk-vs-veriff.json",
        "title": "Middesk vs Veriff",
        "url": "https://www.anchorterminal.com/compare/middesk-vs-veriff"
      },
      {
        "json": "https://www.anchorterminal.com/compare/persona-vs-shufti.json",
        "title": "Persona vs Shufti",
        "url": "https://www.anchorterminal.com/compare/persona-vs-shufti"
      },
      {
        "json": "https://www.anchorterminal.com/compare/persona-vs-veriff.json",
        "title": "Persona vs Veriff",
        "url": "https://www.anchorterminal.com/compare/persona-vs-veriff"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shufti-vs-socure-riskos.json",
        "title": "Shufti vs Socure RiskOS",
        "url": "https://www.anchorterminal.com/compare/shufti-vs-socure-riskos"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shufti-vs-sumsub.json",
        "title": "Shufti vs Sumsub",
        "url": "https://www.anchorterminal.com/compare/shufti-vs-sumsub"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shufti-vs-trulioo.json",
        "title": "Shufti vs Trulioo",
        "url": "https://www.anchorterminal.com/compare/shufti-vs-trulioo"
      },
      {
        "json": "https://www.anchorterminal.com/compare/socure-riskos-vs-veriff.json",
        "title": "Socure RiskOS vs Veriff",
        "url": "https://www.anchorterminal.com/compare/socure-riskos-vs-veriff"
      },
      {
        "json": "https://www.anchorterminal.com/compare/sumsub-vs-veriff.json",
        "title": "Sumsub vs Veriff",
        "url": "https://www.anchorterminal.com/compare/sumsub-vs-veriff"
      },
      {
        "json": "https://www.anchorterminal.com/compare/trulioo-vs-veriff.json",
        "title": "Trulioo vs Veriff",
        "url": "https://www.anchorterminal.com/compare/trulioo-vs-veriff"
      },
      {
        "json": "https://www.anchorterminal.com/compare/complyadvantage-vs-shufti.json",
        "title": "ComplyAdvantage vs Shufti",
        "url": "https://www.anchorterminal.com/compare/complyadvantage-vs-shufti"
      },
      {
        "json": "https://www.anchorterminal.com/compare/complyadvantage-vs-veriff.json",
        "title": "ComplyAdvantage vs Veriff",
        "url": "https://www.anchorterminal.com/compare/complyadvantage-vs-veriff"
      },
      {
        "json": "https://www.anchorterminal.com/compare/middesk-vs-shufti.json",
        "title": "Middesk vs Shufti",
        "url": "https://www.anchorterminal.com/compare/middesk-vs-shufti"
      }
    ],
    "scores": [
      {
        "by": 3,
        "edge": "shufti",
        "key": "reliability",
        "name": "Reliability",
        "shufti": 65,
        "veriff": 62,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 24,
        "edge": "veriff",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "shufti": 58,
        "veriff": 82,
        "weight": 13
      },
      {
        "by": 4,
        "edge": "shufti",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "shufti": 47,
        "veriff": 43,
        "weight": 13
      },
      {
        "by": 1,
        "edge": "veriff",
        "key": "security",
        "name": "Security \u0026 auth",
        "shufti": 62,
        "veriff": 63,
        "weight": 14
      },
      {
        "by": 5,
        "edge": "veriff",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "shufti": 35,
        "veriff": 40,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 2,
        "edge": "veriff",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "shufti": 72,
        "veriff": 74,
        "weight": 7
      },
      {
        "by": 4,
        "edge": "shufti",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "shufti": 71,
        "veriff": 67,
        "weight": 7
      }
    ],
    "summary": "Veriff scores 61.1 (C) on agent readiness against Shufti's 57.8 (C), and leads in 4 of 7 scored categories. Both do kyc identity.",
    "verdicts": {
      "shufti": "One endpoint covers document, face, address, AML and KYB checks, with a free plan of 10 verifications a month, and a hosted MCP server adds OAuth with three scopes. No OpenAPI file, server SDK or idempotency key was found, and the status page history could not be read.",
      "veriff": "Per-verification prices are public from $0.80, with a 15-day trial of 50 sessions and no card. Each endpoint page is Markdown with an OpenAPI 3.0 fragment. There is no server SDK, MCP server or idempotency key, most calls need an HMAC signature, and the status page shows nine incidents between 20 July and 7 October 2026."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/shufti-vs-veriff",
    "json": "https://www.anchorterminal.com/compare/shufti-vs-veriff.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/shufti-vs-veriff.md",
    "slim": "https://www.anchorterminal.com/compare/shufti-vs-veriff.min.md"
  },
  "markdown": "Veriff scores 61.1 (C) on agent readiness against Shufti's 57.8 (C), and leads in 4 of 7 scored categories. Both do kyc identity.\n\n- Shufti: grade C, 57.8/100, rank #538 of 842. Markdown https://www.anchorterminal.com/tools/shufti.md · JSON https://www.anchorterminal.com/api/v1/tools/shufti.json\n- Veriff: grade C, 61.1/100, rank #436 of 842. Markdown https://www.anchorterminal.com/tools/veriff.md · JSON https://www.anchorterminal.com/api/v1/tools/veriff.json\n\n## Which one, for what\n\n### Shufti (C)\n\nGood for: A team that wants document, face, address, AML and KYB checks behind one endpoint, a free plan for low volume, and an MCP server that hands the person a hosted verification link.\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n- Free to start without a card\n\nWatch for: No OpenAPI file or other machine-readable contract was found. The reference is prose tables plus Postman collections\n\n### Veriff (C)\n\nGood for: A team that needs document and selfie verification with public per-verification prices and a trial, and that can run a webhook receiver and HMAC signing.\n\nAhead on:\n- Schema \u0026 documentation, 82 against 58\n- Payments \u0026 pricing, 40 against 35\n\nWatch for: No server-side SDK and no MCP server. Official packages cover only browser and mobile capture\n\n\n## Score by category\n\n| Category | Weight | Shufti | Veriff | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 65 | 62 | Shufti +3 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 58 | 82 | Veriff +24 |\n| Agent ergonomics | 13% (16.2 this run) | 47 | 43 | Shufti +4 |\n| Security \u0026 auth | 14% (17.5 this run) | 62 | 63 | Veriff +1 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 35 | 40 | Veriff +5 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 72 | 74 | Veriff +2 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 71 | 67 | Shufti +4 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **57.8 · C** | **61.1 · C** | |\n\n## Facts side by side\n\n| Fact | Shufti | Veriff |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Shufti Pro Limited | Veriff OÜ |\n| Hosted endpoint | `https://api.shuftipro.com` | no (local only) |\n| Transports | HTTP, Streamable HTTP | HTTP |\n| Auth | OAuth or key | API key |\n| Pricing | Freemium | Pay per use |\n| x402 | no | no |\n| Licence | Proprietary service under Shufti's Terms and Conditions. The licences of the mobile capture SDKs were not checked | Proprietary service. The npm capture SDKs are ISC (@veriff/js-sdk, @veriff/incontext-sdk) and MIT (@veriff/react-native-sdk) |\n| Tools exposed | 25 | none |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| Last release | 2026-10-06 | 2026-10-02 |\n| Terms last updated |  | couldn't be read |\n| Privacy policy last updated | 2026-09-01 | 2026-04-16 |\n| Customer content may train models | yes, with an opt-out | yes |\n| Terms restrict automated access |  | couldn't be read |\n| Terms restrict benchmarking |  | couldn't be read |\n| Terms or service can change without notice |  | couldn't be read |\n| Arbitration or class-action waiver |  | couldn't be read |\n| Popularity | 673 npm/wk | 32 stars, 110k npm/wk |\n\n## Verdicts\n\n**Shufti.** One endpoint covers document, face, address, AML and KYB checks, with a free plan of 10 verifications a month, and a hosted MCP server adds OAuth with three scopes. No OpenAPI file, server SDK or idempotency key was found, and the status page history could not be read.\n\n**Veriff.** Per-verification prices are public from $0.80, with a 15-day trial of 50 sessions and no card. Each endpoint page is Markdown with an OpenAPI 3.0 fragment. There is no server SDK, MCP server or idempotency key, most calls need an HMAC signature, and the status page shows nine incidents between 20 July and 7 October 2026.\n\n## Before you call either\n\n### Shufti\n\n1. POST every verification to `https://api.shuftipro.com/` with a unique `reference` of 6 to 250 characters and one object per service. Read results from `/status` with that reference\n2. Register the callback domain in the back office first. An unregistered `callback_url` is rejected\n3. Stay under 60 requests a minute per IP on a production account and 20 on a trial account\n4. Check the `Signature` response header. Accounts created after 15 March 2023 hash the Secret Key with SHA-256 before appending it to the raw response\n5. Through MCP, identity checks return a `verification_url` for the person to open. No tool accepts an image, so use the REST API for offsite proofs\n\n### Veriff\n\n1. Take the base URL from the integration's API keys page. Send X-AUTH-CLIENT on every call and store verification.id from POST /v1/sessions\n2. Sign POST and PATCH bodies, and the session ID on GET and DELETE, with HMAC-SHA256 in X-HMAC-SIGNATURE. POST /v1/sessions needs no signature\n3. Stay under 30 session creations a minute on Self-Serve, 600 on Enterprise. A 429 carries code 1004\n4. Don't blindly retry POST /v1/sessions. Each call makes a new session, which is billed on a live integration\n5. Poll GET /v1/sessions/{id}/decision until `verification` is not null, or accept webhooks within 5 seconds and treat duplicates as normal\n\n## Questions\n\n### Which is better for AI agents, Shufti or Veriff?\n\nVeriff scores 61.1 (C) on agent readiness against Shufti's 57.8 (C), and leads in 4 of 7 scored categories.\n\n### Do Shufti and Veriff need an API key?\n\nShufti takes an API key or an OAuth sign-in. Veriff needs an API key.\n\n### Can an agent call Shufti and Veriff without installing anything?\n\nShufti has a hosted endpoint at https://api.shuftipro.com. No hosted endpoint is listed for Veriff.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/shufti-vs-veriff.json, and with the fewest tokens: https://www.anchorterminal.com/compare/shufti-vs-veriff.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"shufti\", \"b\": \"veriff\"}`. From a terminal: `anchor compare shufti veriff`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/shufti.json and https://www.anchorterminal.com/api/v1/tools/veriff.json\n\n## Other comparisons with Shufti or Veriff\n\n- [ComplyCube vs Shufti](https://www.anchorterminal.com/compare/complycube-vs-shufti.md)\n- [ComplyCube vs Veriff](https://www.anchorterminal.com/compare/complycube-vs-veriff.md)\n- [Didit vs Shufti](https://www.anchorterminal.com/compare/didit-vs-shufti.md)\n- [Didit vs Veriff](https://www.anchorterminal.com/compare/didit-vs-veriff.md)\n- [Jumio vs Shufti](https://www.anchorterminal.com/compare/jumio-vs-shufti.md)\n- [Jumio vs Veriff](https://www.anchorterminal.com/compare/jumio-vs-veriff.md)\n- [Middesk vs Veriff](https://www.anchorterminal.com/compare/middesk-vs-veriff.md)\n- [Persona vs Shufti](https://www.anchorterminal.com/compare/persona-vs-shufti.md)\n- [Persona vs Veriff](https://www.anchorterminal.com/compare/persona-vs-veriff.md)\n- [Shufti vs Socure RiskOS](https://www.anchorterminal.com/compare/shufti-vs-socure-riskos.md)\n- [Shufti vs Sumsub](https://www.anchorterminal.com/compare/shufti-vs-sumsub.md)\n- [Shufti vs Trulioo](https://www.anchorterminal.com/compare/shufti-vs-trulioo.md)\n- [Socure RiskOS vs Veriff](https://www.anchorterminal.com/compare/socure-riskos-vs-veriff.md)\n- [Sumsub vs Veriff](https://www.anchorterminal.com/compare/sumsub-vs-veriff.md)\n- [Trulioo vs Veriff](https://www.anchorterminal.com/compare/trulioo-vs-veriff.md)\n- [ComplyAdvantage vs Shufti](https://www.anchorterminal.com/compare/complyadvantage-vs-shufti.md)\n- [ComplyAdvantage vs Veriff](https://www.anchorterminal.com/compare/complyadvantage-vs-veriff.md)\n- [Middesk vs Shufti](https://www.anchorterminal.com/compare/middesk-vs-shufti.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Shufti vs Veriff",
        "url": ""
      }
    ],
    "description": "Veriff scores 61.1 (C) on agent readiness against Shufti's 57.8 (C), and leads in 4 of 7 scored categories. Both do kyc identity. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Shufti C 57.8",
      "Veriff C 61.1",
      "scores"
    ],
    "h1": "Shufti vs Veriff",
    "image": "https://www.anchorterminal.com/assets/og/compare-shufti-vs-veriff.png",
    "path": "/compare/shufti-vs-veriff",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Shufti vs Veriff for AI agents, C 57.8 vs C 61.1 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/shufti-vs-veriff"
  },
  "tokens": {
    "markdown": 2150,
    "slim": 680
  },
  "version": 1
}
