Head to head · Kyc identity · October 2026 research run
Sumsub vs Veriff
Sumsub scores 68.5 (B) on agent readiness against Veriff's 61.1 (C), and leads in 4 of 7 scored categories. Veriff leads on payments & pricing. Both do kyc identity.
Which one, for what
Sumsub B
Good for An agent that starts verifications, sends links, reads results and AML cases, and works case queues for a regulated business, with one token limited to those permissions.
Ahead on
- Reliability, 80 against 62
- Agent ergonomics, 60 against 43
- Security & auth, 80 against 63
- Transparency & trust, 74 against 67
Also in its favour
- A hosted endpoint, with nothing to install
Watch for
No idempotency keys and no Retry-After or backoff guidance found in the reviewed documentation
Veriff C
Good for A team that needs document and selfie verification with public per-verification prices and a trial, and that can run a webhook receiver and HMAC signing.
Ahead on
- Payments & pricing, 40 against 25
Watch for
No server-side SDK and no MCP server. Official packages cover only browser and mobile capture
Score by category
| Category | Weight this run | Sumsub | Veriff | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 80 | 62 | Sumsub +18 |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 78 | 82 | Veriff +4 |
| Agent ergonomics | 13%16.2 | 60 | 43 | Sumsub +17 |
| Security & auth | 14%17.5 | 80 | 63 | Sumsub +17 |
| Payments & pricing | 10%12.5 | 25 | 40 | Veriff +15 |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 74 | 74 | even |
| Transparency & trust | 7%8.8 | 74 | 67 | Sumsub +7 |
| Negative events | ≤15 | 0 | 0 | |
| Total | 68.5 · B | 61.1 · C |
Facts side by side
| Fact | Sumsub | Veriff |
|---|---|---|
| Kind | HTTP API | HTTP API |
| Vendor | Sum and Substance Ltd | Veriff OÜ |
| Hosted endpoint | https://api.sumsub.com | no (local only) |
| Transports | HTTP | HTTP |
| Auth | OAuth or key | API key |
| Pricing | Pay per use | Pay per use |
| x402 | no | no |
| Licence | Proprietary service under Sumsub's terms and conditions. The agent skills repository and the @sumsub/websdk npm package are MIT | Proprietary service. The npm capture SDKs are ISC (@veriff/js-sdk, @veriff/incontext-sdk) and MIT (@veriff/react-native-sdk) |
| Read-only variant documented | no | no |
| llms.txt | yes | yes |
| Last release | 2026-10-03 | 2026-10-02 |
| Terms last updated | 2026-05-21 | couldn't be read |
| Privacy policy last updated | 2026-03-19 | 2026-04-16 |
| Customer content may train models | yes | yes |
| Terms restrict automated access | not found in the text | couldn't be read |
| Terms restrict benchmarking | not found in the text | couldn't be read |
| Terms or service can change without notice | yes | couldn't be read |
| Arbitration or class-action waiver | yes | couldn't be read |
| Popularity | 172k npm/wk | 32 stars, 110k npm/wk |
Verdicts
Sumsub
Per-token permissions, an IP allowlist, HMAC-signed requests and a public OpenAPI spec with Markdown docs suit an agent working on verification cases. No idempotency keys or Retry-After guidance were found, there is no server SDK, and production access needs a browser signup, a bank card and Sumsub's review of the integration.
Veriff
Per-verification prices are public from $0.80, with a 15-day trial of 50 sessions and no card. Each endpoint page is Markdown with an OpenAPI 3.0 fragment. There is no server SDK, MCP server or idempotency key, most calls need an HMAC signature, and the status page shows nine incidents between 20 July and 7 October 2026.
Before you call either
Sumsub
- Sign every request. X-App-Access-Sig is the lowercase hex HMAC-SHA256 of timestamp, uppercase method, path with query and raw body, and the timestamp must be within one minute of server time
- Use a sandbox token (prefix sbx) for agent work. Sandbox and production tokens are separate, and Sumsub's own skills refuse any other prefix
- Stay under 300 GET and 50 POST requests per 5 seconds, and under 500 new applicants per 24 hours in Sandbox
- Token permissions can't be edited after creation. Generate a new token with the narrower set and delete the old one
- Subscribe to the applicantReviewed webhook for results and verify x-payload-digest against the raw body before trusting it
Veriff
- Take the base URL from the integration's API keys page. Send X-AUTH-CLIENT on every call and store verification.id from POST /v1/sessions
- Sign POST and PATCH bodies, and the session ID on GET and DELETE, with HMAC-SHA256 in X-HMAC-SIGNATURE. POST /v1/sessions needs no signature
- Stay under 30 session creations a minute on Self-Serve, 600 on Enterprise. A 429 carries code 1004
- Don't blindly retry POST /v1/sessions. Each call makes a new session, which is billed on a live integration
- Poll GET /v1/sessions/{id}/decision until
verificationis not null, or accept webhooks within 5 seconds and treat duplicates as normal
Questions
Which is better for AI agents, Sumsub or Veriff?
Sumsub scores 68.5 (B) on agent readiness against Veriff's 61.1 (C), and leads in 4 of 7 scored categories. Veriff leads on payments & pricing.
Do Sumsub and Veriff need an API key?
Sumsub takes an API key or an OAuth sign-in. Veriff needs an API key.
Can an agent call Sumsub and Veriff without installing anything?
Sumsub has a hosted endpoint at https://api.sumsub.com. No hosted endpoint is listed for Veriff.
Other comparisons with Sumsub or Veriff
Machine-readable
- This page as Markdown
/compare/sumsub-vs-veriff.md· slim.min.md· JSON.json(or sendAccept: text/markdown) - Each listing in full
/api/v1/tools/sumsub.json·/api/v1/tools/veriff.json - From a terminal
anchor compare sumsub veriff(the CLI) - Over MCP
compare_tools {"a": "sumsub", "b": "veriff"}at/mcp, no key