# ComplyAdvantage (slim) > ComplyAdvantage screens people and companies against sanctions lists, watchlists, politically exposed person registers and adverse media, with ongoing monitoring and case management. Agents reach its Mesh platform through a REST API with a public OpenAPI spec. - Full: https://www.anchorterminal.com/tools/complyadvantage.md (~6,850 tokens) · this version ~1,780 tokens · JSON https://www.anchorterminal.com/tools/complyadvantage.json · canonical https://www.anchorterminal.com/tools/complyadvantage - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **D · 52.6/100 · rank #564 of 722 · #9 in Identity & business verification · not agent-ready · confidence medium** Assessment: The Mesh API has a public OpenAPI 3.0.3 spec with 165 described operations, per-credential permissions and audit log endpoints, which suits an agent screening customers and working alerts. No status page, changelog, SDK, service agreement or subprocessor list was found in public, and access starts with a paid plan bought by a person. ## Facts - Kind: HTTP API · vendor: IVXS UK Limited (trading as ComplyAdvantage) · category: Identity & business verification · legal entity: IVXS UK Limited (trading as ComplyAdvantage) · provenance 59/100 - Endpoint: `https://api.mesh.complyadvantage.com` (HTTP) - Auth: OAuth · pricing: Paid · x402: no · licence: Proprietary service. No service agreement is published, and the terms page on complyadvantage.com covers the website only - Probe metrics: not measured yet (probes haven't run) - API: Mesh REST API, OpenAPI 3.0.3 titled Mesh API v2.0, 165 operations on 124 paths (84 GET, 47 POST, 14 PATCH, 10 PUT, 10 DELETE) under `/v2` and `/v3`. Server in the spec is https://api.mesh.complyadvantage.com - Regions: The webhooks guide names six regional hosts, api.eu, api.eu3, api.us, api.us2, api.ca and api.au under mesh.complyadvantage.com. Support confirms which one an account is on - Screening: `POST /v2/workflows/sync/create-and-screen` creates a customer, scores risk, screens against sanctions, watchlists, politically exposed persons and adverse media, and raises alerts and cases. An asynchronous version and a rescreen workflow also exist - Credentials: Access key and secret per integration with chosen permissions and optional expiry, exchanged for a 24-hour bearer token at `POST /v3/token`. Not editable. Deactivation is permanent and invalidates issued tokens - Rate limits: 1,000 requests a minute in production and 300 in Sandbox by default, set per account. 429 returns `API rate limit exceeded` - Lists: `page_number` and `page_size` (default 50 on customers), attribute, range and substring filters, and `sort` with a minus sign for descending. The customers list returns at most 10,000 records, with exports for more - Idempotency: `X-ComplyAdvantage-Idempotency-Key` header on the rescreen workflow. Create-and-screen and update-and-rescore are described as idempotent on resending the same request - Audit: `GET /v2/audit/...` for the account, cases, customers, roles, transactions and users - Older API: docs.complyadvantage.com documents the earlier search API at api.complyadvantage.com (EU), api.us and api.ap, limited to 600 calls a minute on a standard contract and 300 in Sandbox, with exponential backoff guidance for 429 - Status: No public status page found. Outages are reported to support by email - Certifications: ComplyAdvantage's own article of 21 January 2025 lists ISO 27001 and SOC 2 for Mesh. No trust centre or public report was found - Data handling: The privacy notice of 12 June 2026 says ComplyAdvantage is controller of its screening database and processor or sub-processor when screening a client's customer data. No public data processing agreement or subprocessor list was found - Prices: Essentials Starter Plan, up to 100 monitored entities $119 per month (plan); Essentials Starter Plan, up to 1,000 monitored entities $323 per month (plan); Essentials Starter Plan, up to 2,000 monitored entities $383 per month (plan); Agentic Starter Plan, up to 100 monitored entities $179 per month (plan) - Scores: Reliability 42, Performance pending, Schema & documentation 82, Agent ergonomics 67, Security & auth 68, Payments & pricing 10, Task success pending, Maintenance & community 28, Transparency & trust 50 · total over the 7 assessed categories - Why: Reliability, Graded on the Mesh REST API, hosted lines. · Schema & documentation, Public OpenAPI 3.0.3 spec with 165 operations on 124 paths (25). · Agent ergonomics, List responses are partial records sized with `page_size`. · Security & auth, OAuth2 client credentials with per-credential permissions, optional expiry, 24-hour tokens and deactivation that invalidates issued tokens. · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, No changelog or release notes were found, so dates come from docs page timestamps. · Transparency & trust, Closed service. - Sources: 20, open questions: 8, both in the full twin - Capabilities: kyc.screening, kyc.cases - JSON: https://www.anchorterminal.com/api/v1/tools/complyadvantage.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/complyadvantage.svg` or a link to https://www.anchorterminal.com/tools/complyadvantage from a page on complyadvantage.com or one of its subdomains, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Exchange the access key and secret at `POST /v3/token` for a bearer token. It lasts 24 hours and can't be refreshed, so request a new one before expiry 2. Ask for a credential with only the permissions the task needs. Permissions can't be edited later, and each reference page names the ones a call requires 3. Create a screening configuration first and keep its `configuration_identifier`. Creating and screening a customer needs it 4. Give each customer a unique external identifier. A concurrent request for the same identifier returns 409 with a pointer to the first workflow 5. Read `Ratelimit-Remaining` and `Ratelimit-Reset` on every response. A 429 body is only `API rate limit exceeded` ## Connect ```bash curl -X POST https://api.mesh.complyadvantage.com/v3/token \ -H 'Content-Type: application/json' \ -d '{"access_key": "", "secret": ""}' ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/complyadvantage ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Didit | BB | 75 | kyc.screening, kyc.cases | https://www.anchorterminal.com/tools/didit.min.md | | Persona | B | 69.5 | kyc.screening, kyc.cases | https://www.anchorterminal.com/tools/persona.min.md | | Sumsub | B | 68.5 | kyc.screening, kyc.cases | https://www.anchorterminal.com/tools/sumsub.min.md | | Middesk | C | 59 | kyc.screening, kyc.cases | https://www.anchorterminal.com/tools/middesk.min.md | | Grep AI | B | 64.4 | kyc.screening | https://www.anchorterminal.com/tools/grep-ai.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)