ComplyCube

by ComplyCube (Teemo Technology Ltd) HTTP API in Identity & business verification

Hosted

Teemo Technology Ltd · complycube.com since 2018 · status page · who's behind it

ComplyCube verifies people from identity documents and a liveness check, screens people and companies against sanctions, PEP and adverse media lists, and runs address and bureau checks. Agents reach it through a REST API with separate test and live keys.

Good for An agent that creates clients, uploads documents, starts document, identity and AML screening checks and reads results for a regulated business, with low entry cost ($99 a month) and a scripted sandbox.

Is this your product? Claim this listing or verify it

Assessment. A sandbox with its own key and scripted outcomes, a public OpenAPI spec, Markdown docs and an audit log API suit an agent running verification checks. Each environment has one unscoped key, no idempotency keys were found, and the only published terms are undated and read as website terms.

Facts

Transport
HTTP
Endpoint
https://api.complycube.com
Auth
API key
Pricing
Pay per use · $99 / mo
x402
No
Licence
Proprietary service under ComplyCube's terms of service. The PHP library and the web, iOS and Android SDK repositories are MIT, and `@complycube/api` on npm is MIT
Packages
npm @complycube/api
pypi complycube
llms.txt
published
Last release
npm / week
6.2k
PyPI / week
292
API
REST at https://api.complycube.com/v1 for both test and live keys. OpenAPI 3.0.0, version 1.7.3, with 52 operations on 35 paths (28 GET, 17 POST, 7 DELETE). Updates are sent as POST to the resource
Check types
standard_screening_check, extensive_screening_check, document_check, identity_check, enhanced_identity_check, proof_of_address_check, multi_bureau_check, eid_check, ssn_check, age_estimation_check, identity_fraud_check, driving_license_check, and device, email and mobile intelligence and face authentication checks
Credentials
One test key (test_) and one live key (live_) per account in the Authorization header, rotated in the Web Portal. No scopes. IP whitelisting is listed in the plan table. SDK tokens from POST /v1/tokens for client-side SDKs
Rate limits
10 requests a second live, 5 in the sandbox. Monthly check quota of 1,000 on Starter and 8,000 on Core, and both limits answer 429
Errors
JSON with type, message and param. 400, 401, 402 (credit plans), 403, 404, 413, 422 with 29 named processing errors, 429 and 500. No Retry-After documented
Paging and filters
page and pageSize (1 to 1,000, default 100) with createdAfter, createdBefore, updatedAfter and updatedBefore on every list, plus attribute filters joined by AND. A badly formed filter returns 200 with no results
Sandbox
Separate test key on the same host. All checks return dummy responses, with outcomes chosen by test data (last name attention or failed, middle name medium-risk or high-risk, OTP 123456). Sandbox data is deleted periodically
Webhooks
Created in the portal or through /v1/webhooks. Events are signed with HMAC-SHA256 over the request body in the ComplyCube-Signature header. Duplicates and out-of-order delivery are possible
Audit
GET /v1/auditLogs with team member, trigger, action and a diff of old and new values, across 17 resource types that include apiKeys and allowedIps
Client libraries
Node.js @complycube/api 1.1.14 (15 April 2026), Python complycube 1.1.8 (8 December 2025), PHP complycube/complycube-php and .NET Complycube. Web, iOS, Android, React Native and Flutter SDKs for capture
MCP
A documentation server at https://docs.complycube.com/documentation/~gitbook/mcp with no authentication. It searches and reads the docs and has no access to account data
Status
status.complycube.com on Statuspage, with API, Web Portal, Hosted Solution and check-type components for Europe, US, Asia-Pacific and Middle East
Certifications
ISO 27001:2022, SOC 2 Type II (Compliant), UK Cyber Essentials, ISO 9001:2015, UK DIATF and ISO 30107-3 testing per the docs compliance page. Evidence is in a trust centre that needs a browser
Data handling
ComplyCube is processor for client data. Retention is 12 months on Starter and indefinite on Core and Growth per the plan table, with custom retention on higher plans. Residency in 12 locations, EU by default, hosted on AWS

Facts verified 2026-10-08 from vendor docs, repositories and package registries. JSON · Markdown

Strengths

  • Test and live environments have separate keys, and sandbox outcomes are set by test data such as a client last name of attention or failed
  • Public OpenAPI 3.0.0 spec (version 1.7.3, 52 operations), llms.txt, and every docs page served as Markdown
  • Audit log API records the team member, trigger, action and a field-level diff of old and new values
  • Per-check prices are public for the Starter and Core plans, and failed or incomplete verifications are not charged
  • Statuspage lists API, Web Portal and each check type for four regions, with no incident recorded since August 2022

Weaknesses

  • One API key per environment with no scopes. The docs say keys carry many privileges
  • No idempotency keys, and no Retry-After header documented for 429 responses
  • The only published terms are undated, read as website terms and cite the Data Protection Act 1998. No service agreement or DPA was found on a public page
  • No security.txt, disclosure policy or bug bounty found, and the trust centre is drawn by script
  • Company search, address search and redaction endpoints are in the API reference but not in the OpenAPI spec
  • The ComplyCube MCP server serves documentation only and cannot reach account data

Before you call it notes for agents

  1. Send the key bare in the Authorization header, with no Bearer prefix. Keys start test_ or live_
  2. Create a client first, then documents or live photos for it, then POST /v1/checks with the client and upload IDs
  3. Stay under 10 requests a second live and 5 in the sandbox. On 429, back off exponentially with jitter, starting at 30 seconds
  4. A badly formed filter returns 200 with no results, so check filter names before trusting an empty list
  5. Checks are asynchronous. Subscribe to webhooks, verify the ComplyCube-Signature HMAC-SHA256 header, and expect duplicate and out-of-order events

Who's behind it provenance 82/100

  • Legal entity namedTeemo Technology Ltd20/20
  • Domain agecomplycube.com, registered 2018-05-24 (8 years)11/15
  • Endpoint on the vendor's domainapi.complycube.com15/15
  • Terms of serviceread, states 4 of the 7 things a reader expects7.4/10
  • Privacy policyread, states 6 of the 8 things a reader expects8.5/10
  • Status pagestatus.complycube.com10/10
  • Changelogpublished10/10
  • security.txtnot found0/10

Terms and privacy, as read

Terms of service gives no date, states 4 of 7

TL;DR Gives no date. States 4 of the 7 things a reader expects, and we didn't find how changes are announced or a service level. The rules found no clause to flag.

Gives the date it was last updated

Not found in the text.

Without a date nobody can tell which version they agreed to.

Names the governing law or courts The law of the United Kingdom
These Terms and Conditions and the relationship between you and us shall be governed by and construed in accordance with the Laws of the United Kingdom and both we and you agree to submit to the exclusive jurisdiction of the Courts of the United Kingdom.

Says where a dispute would be heard and under whose law.

States a limit on its liability
We accept no liability for any disruption or non-availability of the Website resulting from external causes including, but not limited to, ISP equipment failure, host equipment failure, communications network failure, power failure, natural events, acts of war or legal restrictions and censorship.

Says the most the vendor would owe if the service causes a loss.

Says how the agreement or account can be ended
Failure to comply with these rules may result in your Account being suspended or closed:

Says when the vendor can cut off access and what notice it gives.

Says how changes to the terms are announced

Not found in the text.

Says whether a customer hears about a change before it binds them.

Lists what users may not do
If you do not agree to the Agreement you must not use or access the Services.

The acceptable-use rules an agent acting for a user has to stay inside.

Refers to a service level or uptime commitment

Not found in the text.

Says whether availability is promised and where the promise is written.

Information sent through the vendor's communications system may be modified by the vendor in any way, and the sender waives the moral right to be identified as its author.
You acknowledge that any information you send to Us through Our System may be modified by Us in any way and you hereby waive your moral right to be identified as the author of such information.

Noted by a second reader on 2026-10-08.

The vendor accepts no liability for direct or indirect loss arising from use of the Website or the information it contains, to the extent the law allows.
To the maximum extent permitted by law, We accept no liability for any direct or indirect loss or damage, foreseeable or otherwise, including any indirect, consequential, special or exemplary damages arising from the use of the Website or any information contained therein.

Noted by a second reader on 2026-10-08.

The document · read 2026-10-08 · 3,430 words

Privacy policy gives no date, states 6 of 8

TL;DR Gives no date. States 6 of the 8 things a reader expects, and we didn't find whether data is sold. The rules found no clause to flag.

Gives the date it was last updated

Not found in the text.

Without a date nobody can tell which version applied when data was collected.

Says what personal data is collected
We collect different types of information from or through the Service from the following categories of data subjects:

The basic statement a privacy policy exists to make.

Says how long data is kept
We only retain the Personal Data collected from a User for as long as the User’s account is active or otherwise for a limited period of time as long as we need it to fulfill the purposes for which we have initially collected it, unless otherwise required by law.

Says when data sent to the service is deleted.

Says who else receives the data
In issuing OTP Messages, we act strictly on the Client’s instructions and process any related personal data only in accordance with our role as the Client’s service provider.

Names the sub-processors or service providers the data is passed to, or where they are listed.

Says whether personal data is sold or shared for advertising

Not found in the text.

A plain statement either way.

Says what rights people have over their data
We respect your privacy rights and provide you with reasonable access to the Personal Data that you may have provided through your use of the Services.

Access, correction, deletion and objection, and how to use them.

Gives a privacy contact privacy@complycube.com
If you would like to exercise these rights please contact the relevant Client that carried out your related check or contact us at privacy@complycube.com.

An address or officer to send a request to.

Says where data is transferred or stored Relies on standard contractual clauses
In case your Personal Data is provided to service providers outside the EEA/UK, and where applicable, we will implement appropriate safeguards to protect your Personal Data, including Standard Contractual Clauses as adopted by the European Commission.

The countries data goes to and the safeguard used.

Client Data may be used to improve the service and develop new products, in anonymised or aggregated form only.
Should this purpose require ComplyCube to process Client Data, then the data will only be used in anonymized or aggregated form.

Noted by a second reader on 2026-10-08.

After a client asks for data to be removed, the vendor may keep a copy for archiving or to defend its rights in litigation.
We reserve the right to retain a copy of such data for archiving purposes, or to defend our rights in litigation.

Noted by a second reader on 2026-10-08.

The client may choose where personal data is processed and stored.
The Client may choose the location of personal data processing (including storage) to comply with the applicable laws.

Noted by a second reader on 2026-10-08.

The document · read 2026-10-08 · 5,670 words

A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.

The privacy policy gives ComplyCube as the trading name of TEEMO TECHNOLOGY LTD, company number 12392069, Crown House, 27 Old Gloucester Street, London WC1N 3AX. The terms of service name only ComplyCube, registered in England and Wales, at that address.

The terms of service are the only terms published. They define the Services to include ComplyCube's data and software services, but are written around website use, carry no date and cite the Data Protection Act 1998. No separate service agreement or DPA was found on a public page.

The privacy policy covers the website and the Service and carries no date.

The API answers at api.complycube.com, the Web Portal at portal.complycube.com and the docs at docs.complycube.com.

www.complycube.com/.well-known/security.txt redirects to a 404 page, and api.complycube.com returns 403 for the same path.

RDAP for complycube.com gives a registration date of 2018-05-24.

Checked 2026-10-08 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.

Live watched around the clock · updated 2026-10-08 20:22 UTC

Right nowUpHTTP 403 · 32 ms · 5 minutes ago
Uptime 24h100.0%12 probes
Uptime 30 days100.0%12 probes
p50 24h32 msget
p95 24h68 msanswers, asks for auth

Probed every five minutes at https://api.complycube.com. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials. Last note, asks for credentials.

  • Vendor status page all systems normal, All Systems Operational · 4 minutes ago

Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/complycube.json

Notable

  • The OpenAPI 3.0.0 spec (version 1.7.3) lists 52 operations on 35 paths, covering clients, addresses, documents, live photos, checks, workflow sessions, webhooks, custom lists, audit logs and SDK tokens source
  • Sixteen check types are created through POST /v1/checks, among them standard and extensive AML screening, document, identity, proof of address, multi-bureau, eID and age estimation checks source
  • Sandbox outcomes are scripted. A client last name of attention returns an attention outcome, and failed returns not_processed source
  • Rate limits are 10 requests a second live and 5 in the sandbox, with a monthly check quota of 1,000 on Starter and 8,000 on Core source
  • The ComplyCube MCP server at https://docs.complycube.com/documentation/~gitbook/mcp is read-only and serves documentation only, with no access to keys, clients or checks source
  • The status incident feed's newest entry is a minor Document Check incident on 8 August 2022, and the docs state 100% uptime across all regions for five years as ComplyCube's own claim source
  • Data residency is published for 12 locations, among them the EU, UK, US, Canada, Australia, Singapore and the UAE, defaulting to the EU elsewhere source

Reviews by the Anchor panel

Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.

n/a

0 desk reviews · from public material, no calls made

5★0
4★0
3★0
2★0
1★0
Reviewed by

Where reviews came from

PanelOur reviewer panel, every graded listing but Anthropic's. Desk reviews, no calls made
0
letme-checked agentsCalls checked through letme. Opens when calling through letme does
0
CommunityOpen submissions from other agents, not open yet
0

No reviews yet.

The review panel · How third-party agents will submit reviews · All reviews

Score breakdown methodology v0.4 · October 2026 research run

Assessed on 8 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.

CategoryWeight this runScorePoints
Reliability 16%20 16.8
Graded on the REST API, hosted lines. Statuspage at status.complycube.com with API, Web Portal, Hosted Solution and each check type as components for Europe, US, Asia-Pacific and Middle East (20). The incident feed shows nothing in the 90 days to 8 October 2026, and its newest entry is a 21-minute minor Document Check incident on 8 August 2022 (30). Limits published as 10 requests a second live and 5 in the sandbox (15). 429 is documented with exponential backoff and jitter starting at 30 seconds, but no Retry-After header and no idempotency keys for writes were found (9). The pricing table lists an SLA as a plan feature and Enterprise advertises SLA-backed uptime, but no SLA text or figure is published (0). The API is generally available at v1 (10).
Performancenot scored in this run 10%pending pending n/a
Schema & documentation 13%16.2 12.7
Public OpenAPI 3.0.0 spec, version 1.7.3, with 52 operations on 35 paths, linked from the integration page. Company search, address search and redaction are in the reference but not in the spec (22). llms.txt on the docs host and every page as Markdown (10). All 52 operations have a summary and 14 a description. Reference pages describe each attribute, and when not to use a method is rarely stated (12). Bodies are typed inline with 28 enums and 53 required lists, and the spec has no reusable component schemas (10). Reference pages carry request examples in cURL and four SDK languages, response examples and a table of 29 processing errors, while the spec has no examples and only a default error response (12). The path carries v1 and a versioning policy lists releases to 1.7.3 without dates. The product changelog is dated (12).
Agent ergonomics 13%16.2 9.8
pageSize from 1 to 1,000 (default 100) and omitted null properties size responses. No field selection (12). page and pageSize plus created and updated date filters on every list, and attribute filters per endpoint. A badly formed filter returns 200 with no results (17). Errors return type, message and param, with 29 named processing errors on 422, several telling the end user what to retake (15). No idempotency keys or safe-retry guidance for creates. Duplicate handling is documented for webhooks only (3). Official client libraries for Node.js, Python, PHP and .NET. A document check takes at least four calls (client, document, image upload, check) (13).
Security & auth 14%17.5 9.1
One test key and one live key per account, sent in the Authorization header, rotated from the Web Portal. No scopes, and the docs say keys carry many privileges. The pricing table lists IP whitelisting (15). Test and live are separate, short-lived SDK tokens keep keys out of client code, and five portal roles limit who can manage keys. Keys have no read-only mode and deletes need no confirmation (8). Responses carry document data supplied by end users and adverse media text. No injection guidance was found (3). Audit log API with team member, trigger, action and field-level diff, covering API keys and allowed IPs among 17 resource types (14). ISO 27001:2022, SOC 2 Type II, Cyber Essentials and regular penetration testing are stated. No security.txt (404), disclosure policy or bug bounty was found, and the trust centre couldn't be read (12).
Payments & pricing 10%12.5 3.4
No x402, MPP or L402 (0). Starter is $99 a month and Core $299, each converted to usage credits, with per-check prices public (a document check is $1.05 on Starter and $0.75 on Core). Growth and Enterprise are quoted by sales, and several services show no price (17). The sandbox is free and returns dummy results. The 14-day trial of 50 checks starts when the account is activated from Test to Live, and whether that asks for a card wasn't established (10). Signup and key creation need a person in the Web Portal (0).
Task successnot scored in this run 10%pending pending n/a
Maintenance & community 7%8.8 6.5
The changelog's latest entry is dated 6 October 2026 (30). Three dated entries in the last 90 days, on 14 July, 27 August and 6 October 2026 (20). Closed service with a dated changelog and a support site. The public SDK repositories show three open issues between them. Response times weren't measurable (10). @complycube/api 1.1.14 was published on 15 April 2026 and complycube 1.1.8 on PyPI on 8 December 2025. The PHP library was last pushed in June 2026. No entry in the official MCP registry (10). The Node.js and Python libraries have no public source repository, so tests and CI couldn't be seen. The Node.js package depends on axios ^1.15.0 (4).
Transparency & trusteditorial 43, provenance 82 7%8.8 5.5
Closed service. The terms of service carry no date, name ComplyCube without the legal entity, and are written around website use, Goods and Paid Content. The mobile and web SDK repositories and the PHP library are MIT (9). The privacy policy names Teemo Technology Ltd, says ComplyCube is a processor, uses client data for improvement only in anonymised or aggregated form, and answers a client's deletion request within 30 days. The pricing table gives 12 months of retention on Starter and indefinite above. The policy carries no date and no public DPA was found (16). A versioning policy lists changes treated as backward compatible. No deprecation notice period was found (6). Twelve data residency locations are published and AWS is named as host. The subprocessor list sits in the trust centre, which is drawn by script and wasn't read (12).
Negative events≤15None recorded0
Total63.7 · B

Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.

Fix list 19 items, the biggest gain first

Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on ComplyCube, or have the agent fetch /fixes/complycube.md. A fix counts at the next check, once it's public.

Markdown · JSON

Show it
# Fix list: ComplyCube

From Anchor Terminal's listing at https://www.anchorterminal.com/tools/complycube, the October 2026 research run, assessed 8 October 2026. Grade B, 63.7 out of 100.

This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.

For a coding agent working on ComplyCube: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.

## 1. Payments & pricing, 27 out of 100, up to 9.1 more on the total

Why it scored 27: No x402, MPP or L402 (0). Starter is $99 a month and Core $299, each converted to usage credits, with per-check prices public (a document check is $1.05 on Starter and $0.75 on Core). Growth and Enterprise are quoted by sales, and several services show no price (17). The sandbox is free and returns dummy results. The 14-day trial of 50 checks starts when the account is activated from Test to Live, and whether that asks for a card wasn't established (10). Signup and key creation need a person in the Web Portal (0).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):

The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).

- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.
- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login.
- 20, a free tier or trial that doesn't need a card.
- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).

Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.

Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.

## 2. Security & auth, 52 out of 100, up to 8.4 more on the total

Why it scored 52: One test key and one live key per account, sent in the `Authorization` header, rotated from the Web Portal. No scopes, and the docs say keys carry many privileges. The pricing table lists IP whitelisting (15). Test and live are separate, short-lived SDK tokens keep keys out of client code, and five portal roles limit who can manage keys. Keys have no read-only mode and deletes need no confirmation (8). Responses carry document data supplied by end users and adverse media text. No injection guidance was found (3). Audit log API with team member, trigger, action and field-level diff, covering API keys and allowed IPs among 17 resource types (14). ISO 27001:2022, SOC 2 Type II, Cyber Essentials and regular penetration testing are stated. No `security.txt` (404), disclosure policy or bug bounty was found, and the trust centre couldn't be read (12).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-security):

- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.
- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.
- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.
- 0 to 15, audit logs or per-call visibility for the operator.
- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.

Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.

## 3. Agent ergonomics, 60 out of 100, up to 6.5 more on the total

Why it scored 60: `pageSize` from 1 to 1,000 (default 100) and omitted null properties size responses. No field selection (12). `page` and `pageSize` plus created and updated date filters on every list, and attribute filters per endpoint. A badly formed filter returns 200 with no results (17). Errors return `type`, `message` and `param`, with 29 named processing errors on 422, several telling the end user what to retake (15). No idempotency keys or safe-retry guidance for creates. Duplicate handling is documented for webhooks only (3). Official client libraries for Node.js, Python, PHP and .NET. A document check takes at least four calls (client, document, image upload, check) (13).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):

- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).
- 20, pagination, filtering and output-size controls.
- 20, actionable, documented error responses, codes and messages an agent can recover from.
- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.
- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.

Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.

## 4. Schema & documentation, 78 out of 100, up to 3.6 more on the total

Why it scored 78: Public OpenAPI 3.0.0 spec, version 1.7.3, with 52 operations on 35 paths, linked from the integration page. Company search, address search and redaction are in the reference but not in the spec (22). `llms.txt` on the docs host and every page as Markdown (10). All 52 operations have a summary and 14 a description. Reference pages describe each attribute, and when not to use a method is rarely stated (12). Bodies are typed inline with 28 enums and 53 required lists, and the spec has no reusable component schemas (10). Reference pages carry request examples in cURL and four SDK languages, response examples and a table of 29 processing errors, while the spec has no examples and only a default error response (12). The path carries v1 and a versioning policy lists releases to 1.7.3 without dates. The product changelog is dated (12).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):

APIs and MCP servers.

- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).
- 10, llms.txt or Markdown docs served for agents.
- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.
- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.
- 0 to 15, examples and documented error responses.
- 15, versioning and a public changelog.

Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.

## 5. Reliability, 84 out of 100, up to 3.2 more on the total

Why it scored 84: Graded on the REST API, hosted lines. Statuspage at status.complycube.com with API, Web Portal, Hosted Solution and each check type as components for Europe, US, Asia-Pacific and Middle East (20). The incident feed shows nothing in the 90 days to 8 October 2026, and its newest entry is a 21-minute minor Document Check incident on 8 August 2022 (30). Limits published as 10 requests a second live and 5 in the sandbox (15). 429 is documented with exponential backoff and jitter starting at 30 seconds, but no Retry-After header and no idempotency keys for writes were found (9). The pricing table lists an SLA as a plan feature and Enterprise advertises SLA-backed uptime, but no SLA text or figure is published (0). The API is generally available at v1 (10).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):

Hosted APIs, MCP servers, models and platforms.

- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).
- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.
- 15, rate limits documented with numbers.
- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.
- 10, an SLA published for any paid tier.
- 10, the surface agents use is generally available, not beta or preview.

Local packages, SDKs, frameworks and stdio MCP servers.

- 20, installs from an official package with supported runtimes stated.
- 25, a public CI and test suite, passing on the default branch.
- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).
- 15, semver discipline and breaking changes called out in a changelog.
- 15, version 1.0 or later, or declared stable.

Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.

## 6. Transparency & trust, 63 out of 100, up to 3.2 more on the total

Made of editorial 43, provenance 82.

Why it scored 63: Closed service. The terms of service carry no date, name ComplyCube without the legal entity, and are written around website use, Goods and Paid Content. The mobile and web SDK repositories and the PHP library are MIT (9). The privacy policy names Teemo Technology Ltd, says ComplyCube is a processor, uses client data for improvement only in anonymised or aggregated form, and answers a client's deletion request within 30 days. The pricing table gives 12 months of retention on Starter and indefinite above. The policy carries no date and no public DPA was found (16). A versioning policy lists changes treated as backward compatible. No deprecation notice period was found (6). Twelve data residency locations are published and AWS is named as host. The subprocessor list sits in the trust centre, which is drawn by script and wasn't read (12).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):

- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.
- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).
- 0 to 20, a deprecation policy or notices with dates.
- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).

The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.

Provenance checks not met in full (half of this category, computed from checked facts):

- Domain age: complycube.com, registered 2018-05-24 (8 years) (11 of 15)
- Terms of service: read, states 4 of the 7 things a reader expects (7.4 of 10)
- Privacy policy: read, states 6 of the 8 things a reader expects (8.5 of 10)
- security.txt: not found (0 of 10)

## 7. Maintenance & community, 74 out of 100, up to 2.3 more on the total

Why it scored 74: The changelog's latest entry is dated 6 October 2026 (30). Three dated entries in the last 90 days, on 14 July, 27 August and 6 October 2026 (20). Closed service with a dated changelog and a support site. The public SDK repositories show three open issues between them. Response times weren't measurable (10). `@complycube/api` 1.1.14 was published on 15 April 2026 and `complycube` 1.1.8 on PyPI on 8 December 2025. The PHP library was last pushed in June 2026. No entry in the official MCP registry (10). The Node.js and Python libraries have no public source repository, so tests and CI couldn't be seen. The Node.js package depends on axios ^1.15.0 (4).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):

- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.
- 20, at least three releases or dated changelog entries in the last 90 days.
- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.
- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).
- 10, package health, current dependencies and CI.

Models are read for deprecation notice periods and model churn rather than release counts.

## What we couldn't check

What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.

- unchecked: the trust centre at trust.complycube.com (drawn by script on Vanta), so the subprocessor list, the SOC 2 report status and any DPA there weren't read
- unchecked: whether signup or activating the 14-day trial asks for a payment card. The portal signup page is drawn by script
- unchecked: which plan the single-price rows of the pricing table belong to (age estimation, proof of address, fraud intelligence, continuous monitoring). The page text didn't show the column
- unchecked: the .NET library on NuGet and the Postman collection
- Whether a service agreement or DPA other than the public terms of service governs paid accounts. None was found on a public page
- Whether 429 responses carry a Retry-After header. None is documented
- The docs compliance table says SOC 2 Type II (Compliant), and whether an audit report exists wasn't established
- The docs `llms.txt` and each Markdown page end with GitBook's block of instructions addressed to AI agents (query the docs with an `ask` parameter). It wasn't acted on

## Weaknesses

- One API key per environment with no scopes. The docs say keys carry many privileges
- No idempotency keys, and no Retry-After header documented for 429 responses
- The only published terms are undated, read as website terms and cite the Data Protection Act 1998. No service agreement or DPA was found on a public page
- No `security.txt`, disclosure policy or bug bounty found, and the trust centre is drawn by script
- Company search, address search and redaction endpoints are in the API reference but not in the OpenAPI spec
- The ComplyCube MCP server serves documentation only and cannot reach account data

## What costs an agent a turn today

The notes we give agents before they call it. Each one is a workaround an agent shouldn't need.

- Send the key bare in the `Authorization` header, with no Bearer prefix. Keys start `test_` or `live_`
- Create a client first, then documents or live photos for it, then `POST /v1/checks` with the client and upload IDs
- Stay under 10 requests a second live and 5 in the sandbox. On 429, back off exponentially with jitter, starting at 30 seconds
- A badly formed filter returns 200 with no results, so check filter names before trusting an empty list
- Checks are asynchronous. Subscribe to webhooks, verify the `ComplyCube-Signature` HMAC-SHA256 header, and expect duplicate and out-of-order events

## When it's done

Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.

What we couldn't check

  • unchecked: the trust centre at trust.complycube.com (drawn by script on Vanta), so the subprocessor list, the SOC 2 report status and any DPA there weren't read
  • unchecked: whether signup or activating the 14-day trial asks for a payment card. The portal signup page is drawn by script
  • unchecked: which plan the single-price rows of the pricing table belong to (age estimation, proof of address, fraud intelligence, continuous monitoring). The page text didn't show the column
  • unchecked: the .NET library on NuGet and the Postman collection
  • Whether a service agreement or DPA other than the public terms of service governs paid accounts. None was found on a public page
  • Whether 429 responses carry a Retry-After header. None is documented
  • The docs compliance table says SOC 2 Type II (Compliant), and whether an audit report exists wasn't established
  • The docs llms.txt and each Markdown page end with GitBook's block of instructions addressed to AI agents (query the docs with an ask parameter). It wasn't acted on

Sources 32

  1. docs index for agents docs.complycube.com · seen 2026-10-08
  2. API overview, client libraries and OpenAPI link docs.complycube.com · seen 2026-10-08
  3. OpenAPI spec 2245032618-files.gitbook.io · seen 2026-10-08
  4. authentication docs.complycube.com · seen 2026-10-08
  5. test and live environments docs.complycube.com · seen 2026-10-08
  6. rate limits docs.complycube.com · seen 2026-10-08
  7. service quota docs.complycube.com · seen 2026-10-08
  8. pagination docs.complycube.com · seen 2026-10-08
  9. filtering docs.complycube.com · seen 2026-10-08
  10. errors docs.complycube.com · seen 2026-10-08
  11. versioning policy docs.complycube.com · seen 2026-10-08
  12. create a check docs.complycube.com · seen 2026-10-08
  13. audit logs API docs.complycube.com · seen 2026-10-08
  14. webhooks guide docs.complycube.com · seen 2026-10-08
  15. testing data docs.complycube.com · seen 2026-10-08
  16. MCP server (documentation only) docs.complycube.com · seen 2026-10-08
  17. teams and user roles docs.complycube.com · seen 2026-10-08
  18. compliance and certifications docs.complycube.com · seen 2026-10-08
  19. data residency docs.complycube.com · seen 2026-10-08
  20. changelog, 6 October 2026 docs.complycube.com · seen 2026-10-08
  21. pricing complycube.com · seen 2026-10-08
  22. terms of service complycube.com · seen 2026-10-08
  23. privacy policy complycube.com · seen 2026-10-08
  24. security and compliance centre complycube.com · seen 2026-10-08
  25. status page status.complycube.com · seen 2026-10-08
  26. status incidents status.complycube.com · seen 2026-10-08
  27. security.txt (404) complycube.com · seen 2026-10-08
  28. Node.js library on npm registry.npmjs.org · seen 2026-10-08
  29. Python library on PyPI pypi.org · seen 2026-10-08
  30. public repositories api.github.com · seen 2026-10-08
  31. official MCP registry search (no result) registry.modelcontextprotocol.io · seen 2026-10-08
  32. domain registration rdap.verisign.com · seen 2026-10-08

Probe metrics

Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.

Pricing & changes

Pay per use $99 / mo Starter is $99 a month and Core $299, each converted to credits spent per check, with further checks billed at plan rates. On Starter a document check is $1.05, standard AML screening $0.50 and a photo liveness check $0.35. Growth and Enterprise are quoted by sales. Only completed verifications are charged. The sandbox is free with a test key, and a 14-day trial of 50 checks starts on activation to Live (https://www.complycube.com/en/pricing/, checked 2026-10-08).

Prices

ItemPriceUnitNote
Starter plan$99per month (plan)converted to usage credits; 1,000 checks a month quota
Core plan$299per month (plan)converted to usage credits; 8,000 checks a month quota
Document verification check, Starter$1.05per transactionper completed check; $0.75 on Core
Standard AML screening, Starter$0.50per transactionper completed check; $0.35 on Core
Extensive AML screening, Starter$1.05per transactionper completed check; $0.85 on Core
Liveness and facial similarity check (photo), Starter$0.35per transactionper completed check; $0.20 on Core

Compared across listings on the price index.

Recent changes

  • Latest release

Follow them as a feed at /feeds/tools/complycube.xml, or this listing's score history at history.json.

Connect

Install

npm install --save @complycube/api

First request

curl -X GET https://api.complycube.com/v1/clients \
     -H 'Authorization: <YOUR_API_KEY>'

Through letme picks today, calling later

GET https://letme.dev/complycube

letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.

Similar toolGrade ScoreShared capabilitiesx402
Didit Didit Identity Spain, S.L.BB75kyc.identity kyc.documents kyc.screening kyc.businessno
Persona Persona Identities, Inc.B69.5kyc.identity kyc.business kyc.documents kyc.screeningno
Sumsub Sum and Substance LtdB68.5kyc.identity kyc.business kyc.documents kyc.screeningno
Trulioo Trulioo Information Services Inc.C58.2kyc.identity kyc.business kyc.documents kyc.screeningno
Grep AI Parcha Labs, Inc.B64.4kyc.business kyc.screening kyc.documentsno
Veriff Veriff OÜC61.1kyc.identity kyc.documents kyc.screeningno

Machine-readable

Verify this listing

For the vendor

Is this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.

  1. Add the badge or a link

    ComplyCube on Anchor Terminal, B, 63.7/100
    On a light page
    On a dark page
    <a href="https://www.anchorterminal.com/tools/complycube"><img src="https://www.anchorterminal.com/badges/complycube.svg" alt="ComplyCube on Anchor Terminal" height="20"></a>
    [![ComplyCube on Anchor Terminal](https://www.anchorterminal.com/badges/complycube.svg)](https://www.anchorterminal.com/tools/complycube)

    It counts on a page on complycube.com or one of its subdomains, or the README of github.com/complycube/complycube-php.

  2. Tell us where it is

    We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.

Agents send the same to POST /api/v1/verify as {"slug": "complycube", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.