{
  "data": {
    "similar": [
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/persona.json",
        "name": "Persona",
        "score": 69.5,
        "shared": [
          "kyc.identity",
          "kyc.business",
          "kyc.documents",
          "kyc.screening",
          "kyc.cases"
        ],
        "slug": "persona"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/sumsub.json",
        "name": "Sumsub",
        "score": 68.5,
        "shared": [
          "kyc.identity",
          "kyc.business",
          "kyc.documents",
          "kyc.screening",
          "kyc.cases"
        ],
        "slug": "sumsub"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/complycube.json",
        "name": "ComplyCube",
        "score": 63.7,
        "shared": [
          "kyc.identity",
          "kyc.documents",
          "kyc.screening",
          "kyc.business"
        ],
        "slug": "complycube"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/middesk.json",
        "name": "Middesk",
        "score": 59,
        "shared": [
          "kyc.business",
          "kyc.screening",
          "kyc.cases",
          "kyc.identity"
        ],
        "slug": "middesk"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/trulioo.json",
        "name": "Trulioo",
        "score": 58.2,
        "shared": [
          "kyc.identity",
          "kyc.business",
          "kyc.documents",
          "kyc.screening"
        ],
        "slug": "trulioo"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/grep-ai.json",
        "name": "Grep AI",
        "score": 64.4,
        "shared": [
          "kyc.business",
          "kyc.screening",
          "kyc.documents"
        ],
        "slug": "grep-ai"
      }
    ],
    "tool": {
      "slug": "didit",
      "name": "Didit",
      "vendor": "Didit Identity Spain, S.L.",
      "vendorUrl": "https://didit.me",
      "kind": "http-api",
      "category": "identity-verification",
      "summary": "Didit is a hosted identity verification service for document, liveness, face match, sanctions screening and business registry checks. Developers reach it through a REST API with an OpenAPI spec, a hosted MCP server and client SDKs.",
      "url": "https://www.anchorterminal.com/tools/didit",
      "markdownUrl": "https://www.anchorterminal.com/tools/didit.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/didit.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/didit.json",
      "repo": "https://github.com/didit-protocol/mcp",
      "license": "Proprietary service under Didit's Business Terms and Conditions. The MCP server in didit-protocol/mcp is MIT",
      "transports": [
        "http",
        "streamable-http",
        "stdio"
      ],
      "remoteUrl": "https://verification.didit.me",
      "packages": [
        {
          "registry": "npm",
          "name": "@didit-protocol/mcp-server"
        },
        {
          "registry": "npm",
          "name": "@didit-protocol/sdk-web"
        },
        {
          "registry": "npm",
          "name": "@didit-protocol/sdk-react-native"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve. The REST API takes an application API key in the `x-api-key` header. A key comes from the Business Console or from the registration API on `apx.didit.me`, which emails a 6-character code and returns the key with no browser step. Each application has a primary key with full access and any number of named keys with read or write access per resource, workflow and status limits, an IP allowlist and an expiry date. Named keys are created, rotated and revoked only in the console. The hosted MCP server uses OAuth 2.1 with PKCE and dynamic client registration, with the scopes `didit:management` and `didit:verification`, and accepts no API key.",
      "pricing": "usage",
      "pricingNotes": "Pay per completed check from prepaid USD credits, with no contract or minimum and no card needed to sign up. In a workflow, ID verification is $0.15, passive liveness $0.10, face match $0.05, device and IP analysis $0.03 and AML screening $0.20. Until 1 November 2026 each organisation gets 500 free checks a month for each of the first four. From 1 November that becomes $10 of credit a month, with optional Growth ($99 a month) and Scale ($299 a month) plans. Sandbox applications are not billed (https://docs.didit.me/getting-started/pricing, checked 2026-10-08).",
      "priceSummary": "$0.15 / tx",
      "where": "both",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the OpenAPI spec, the docs index or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 156,
      "popularity": {
        "githubStars": 0,
        "npmWeekly": 27338,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.didit.me",
      "llmsTxt": "https://docs.didit.me/llms.txt",
      "openapi": "https://docs.didit.me/openapi-25.json",
      "registryName": "me.didit/mcp",
      "capabilities": [
        "kyc.identity",
        "kyc.documents",
        "kyc.screening",
        "kyc.business",
        "kyc.cases"
      ],
      "tags": [
        "hosted",
        "api-key",
        "oauth",
        "mcp",
        "webhooks",
        "openapi",
        "llms-txt",
        "free-tier",
        "no-card",
        "sandbox",
        "status-page",
        "sla",
        "soc2",
        "iso27001"
      ],
      "lastRelease": "2026-10-08",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 75,
        "grade": "BB",
        "agentReady": true,
        "rank": 54,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 1,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 69,
          "maintenance": 82,
          "payments": 60,
          "reliability": 80,
          "schema": 88,
          "security": 76,
          "transparency": 63
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 80,
            "points": 16,
            "reason": "Graded on the REST API v3 with the hosted lines. Status page on incident.io at status.didit.me with Core APIs, Business Console and Hosted Verification Web App components (20). Three incidents in the last 90 days, all marked major by Didit and all partial outages of the core APIs traced to the primary database. 22 July 2026 lasted 21 minutes, 15 August about 65 minutes and 4 September about 40 minutes. The page reports 99.93 per cent uptime for Core APIs from July to October. We scored 10, between the lines for one major outage and several, because each was partial and about an hour or less (10). Limits are published per scope, 600 GET and 300 write requests a minute per key (15). A 429 carries `Retry-After` and `X-RateLimit-*` headers, backoff guidance is written out, and `Idempotency-Key` is documented on 31 operations (15). A public SLA commits to 99.9 per cent monthly uptime with service credits, excluding free-tier use (10). GA (10)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 88,
            "points": 14.3,
            "reason": "A public OpenAPI 3.0.0 spec with 206 paths and 256 operations, and a second spec for the account routes (25). llms.txt and a Markdown copy of each docs page (10). 215 of the 256 operations have descriptions longer than 80 characters, covering billing, idempotency and which key access is needed. Few say when not to use an endpoint (17). 586 enum declarations, required lists and limits. Error bodies are loosely typed, and session creation returns either an array of strings or a plain string per field (12). 184 operations carry examples and status codes from 400 to 503 are described (13). A `/v3` path and a monthly changelog. Entries are grouped by month, with no day given, and the session routes still list v1 and v2 paths (12). The 88 total takes 1 off for the spec's 3.2 MB size, which no agent can load whole."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 69,
            "points": 11.21,
            "reason": "Graded on the REST API. No field selection, and the decision payload returns every feature result as an array. Scoped keys can null out media links (12). `GET /v3/sessions/` takes `limit` and `offset`, returns `next` and `previous` links and filters on status, workflow, dates, country and `vendor_data` (18). Errors return `detail` or a field-keyed object, with two shapes on some routes and a bare array on password rules, each documented (14). `Idempotency-Key` on AML screening, transactions and wallet calls, and session creation returns the existing unfinished session for the same `vendor_data`. The MCP server marks read and destructive tools and asks for `confirm: true` on deletes (18). `workflow_id` is the only required field for a session. No server-side SDK was found in any language, only capture SDKs (7)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 76,
            "points": 13.3,
            "reason": "Named API keys take read or write access per resource, workflow and status limits, an IP allowlist, an expiry date, rotation with a 24-hour overlap and instant revoke. Keys travel in a header only. The primary key has full access, and the key returned by registration is that key (28). Read-only key presets, keys limited to approved sessions, `confirm: true` on MCP deletes and OAuth scopes that split management from verification. The MCP server's role check defaults to a mode that lists every tool and leaves refusal to the backend (16). Responses carry text read from documents, AML and adverse media hits. No guidance on injected content was found in the docs or the MCP repository (3). Audit logs record each API call with key name, path, status and IP, kept for 365 days (15). SOC 2 Type 2 issued 30 July 2026, ISO/IEC 27001:2022, yearly external penetration tests and a reporting address. No security.txt, no bounty terms and no public advisories found (14)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 60,
            "points": 7.5,
            "reason": "No x402, MPP or L402 (0). Per-check prices are public without a login, such as $0.15 for ID verification and $0.20 for AML screening (20). 500 free checks a month per core feature with no card, changing to $10 of monthly credit on 1 November 2026 (20). An agent can register and receive an API key through `POST /auth/v2/programmatic/register/` and `verify-email` with no browser. It needs a real inbox for the emailed code, and we scored the line in full (20)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 82,
            "points": 7.18,
            "reason": "The MCP server was released as v5.1.34 on 8 October 2026 and the September 2026 changelog covers the API (30). Monthly changelogs for July, August and September and three MCP tags in the period (20). Closed service with a public changelog and support by email, chat and WhatsApp. No public forum was found, and the MCP repository has no stars or open issues to judge replies by (10). The MCP server is in the official registry as `me.didit/mcp`, though the entry is at 5.0.1, and the capture SDKs are current (15). The MCP repository has a CI workflow that builds and tests, and publishes to npm from release tags. Whether CI passes wasn't checked (7)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 63,
            "points": 5.51,
            "note": "editorial 53, provenance 73",
            "reason": "Closed service with public, dated and versioned terms, and an MIT licence on the MCP server (17). A privacy policy, a data processing addendum inside the Business Terms and retention settings from 30 days to 10 years, unlimited by default. The terms allow model training on verification data by default with a console opt-out. The addendum says the sub-processor list is published at `/terms/sub-processors`, while that address shows the legal index, which says the list is sent after a signed NDA (20). `X-Signature-Simple` is marked deprecated with no end date, the terms promise 30 days' notice of changes to terms and prices, and the pricing change of 1 November was announced on 2 October. No API deprecation policy was found (8). Data is processed in the EU on AWS by default with an Australian data plane. The sub-processors aren't named in public (8)."
          }
        ],
        "assessment": {
          "date": "2026-10-08",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "Graded on the REST API. No field selection, and the decision payload returns every feature result as an array. Scoped keys can null out media links (12). `GET /v3/sessions/` takes `limit` and `offset`, returns `next` and `previous` links and filters on status, workflow, dates, country and `vendor_data` (18). Errors return `detail` or a field-keyed object, with two shapes on some routes and a bare array on password rules, each documented (14). `Idempotency-Key` on AML screening, transactions and wallet calls, and session creation returns the existing unfinished session for the same `vendor_data`. The MCP server marks read and destructive tools and asks for `confirm: true` on deletes (18). `workflow_id` is the only required field for a session. No server-side SDK was found in any language, only capture SDKs (7).",
            "maintenance": "The MCP server was released as v5.1.34 on 8 October 2026 and the September 2026 changelog covers the API (30). Monthly changelogs for July, August and September and three MCP tags in the period (20). Closed service with a public changelog and support by email, chat and WhatsApp. No public forum was found, and the MCP repository has no stars or open issues to judge replies by (10). The MCP server is in the official registry as `me.didit/mcp`, though the entry is at 5.0.1, and the capture SDKs are current (15). The MCP repository has a CI workflow that builds and tests, and publishes to npm from release tags. Whether CI passes wasn't checked (7).",
            "payments": "No x402, MPP or L402 (0). Per-check prices are public without a login, such as $0.15 for ID verification and $0.20 for AML screening (20). 500 free checks a month per core feature with no card, changing to $10 of monthly credit on 1 November 2026 (20). An agent can register and receive an API key through `POST /auth/v2/programmatic/register/` and `verify-email` with no browser. It needs a real inbox for the emailed code, and we scored the line in full (20).",
            "reliability": "Graded on the REST API v3 with the hosted lines. Status page on incident.io at status.didit.me with Core APIs, Business Console and Hosted Verification Web App components (20). Three incidents in the last 90 days, all marked major by Didit and all partial outages of the core APIs traced to the primary database. 22 July 2026 lasted 21 minutes, 15 August about 65 minutes and 4 September about 40 minutes. The page reports 99.93 per cent uptime for Core APIs from July to October. We scored 10, between the lines for one major outage and several, because each was partial and about an hour or less (10). Limits are published per scope, 600 GET and 300 write requests a minute per key (15). A 429 carries `Retry-After` and `X-RateLimit-*` headers, backoff guidance is written out, and `Idempotency-Key` is documented on 31 operations (15). A public SLA commits to 99.9 per cent monthly uptime with service credits, excluding free-tier use (10). GA (10).",
            "schema": "A public OpenAPI 3.0.0 spec with 206 paths and 256 operations, and a second spec for the account routes (25). llms.txt and a Markdown copy of each docs page (10). 215 of the 256 operations have descriptions longer than 80 characters, covering billing, idempotency and which key access is needed. Few say when not to use an endpoint (17). 586 enum declarations, required lists and limits. Error bodies are loosely typed, and session creation returns either an array of strings or a plain string per field (12). 184 operations carry examples and status codes from 400 to 503 are described (13). A `/v3` path and a monthly changelog. Entries are grouped by month, with no day given, and the session routes still list v1 and v2 paths (12). The 88 total takes 1 off for the spec's 3.2 MB size, which no agent can load whole.",
            "security": "Named API keys take read or write access per resource, workflow and status limits, an IP allowlist, an expiry date, rotation with a 24-hour overlap and instant revoke. Keys travel in a header only. The primary key has full access, and the key returned by registration is that key (28). Read-only key presets, keys limited to approved sessions, `confirm: true` on MCP deletes and OAuth scopes that split management from verification. The MCP server's role check defaults to a mode that lists every tool and leaves refusal to the backend (16). Responses carry text read from documents, AML and adverse media hits. No guidance on injected content was found in the docs or the MCP repository (3). Audit logs record each API call with key name, path, status and IP, kept for 365 days (15). SOC 2 Type 2 issued 30 July 2026, ISO/IEC 27001:2022, yearly external penetration tests and a reporting address. No security.txt, no bounty terms and no public advisories found (14).",
            "transparency": "Closed service with public, dated and versioned terms, and an MIT licence on the MCP server (17). A privacy policy, a data processing addendum inside the Business Terms and retention settings from 30 days to 10 years, unlimited by default. The terms allow model training on verification data by default with a console opt-out. The addendum says the sub-processor list is published at `/terms/sub-processors`, while that address shows the legal index, which says the list is sent after a signed NDA (20). `X-Signature-Simple` is marked deprecated with no end date, the terms promise 30 days' notice of changes to terms and prices, and the pricing change of 1 November was announced on 2 October. No API deprecation policy was found (8). Data is processed in the EU on AWS by default with an Australian data plane. The sub-processors aren't named in public (8)."
          },
          "sources": [
            {
              "what": "docs index for agents",
              "url": "https://docs.didit.me/llms.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "OpenAPI spec",
              "url": "https://docs.didit.me/openapi-25.json",
              "seen": "2026-10-08"
            },
            {
              "what": "API authentication",
              "url": "https://docs.didit.me/getting-started/api-authentication",
              "seen": "2026-10-08"
            },
            {
              "what": "scoped API keys",
              "url": "https://docs.didit.me/console/api-keys",
              "seen": "2026-10-08"
            },
            {
              "what": "programmatic registration",
              "url": "https://docs.didit.me/integration/programmatic-registration",
              "seen": "2026-10-08"
            },
            {
              "what": "rate limiting",
              "url": "https://docs.didit.me/integration/rate-limiting",
              "seen": "2026-10-08"
            },
            {
              "what": "pricing",
              "url": "https://docs.didit.me/getting-started/pricing",
              "seen": "2026-10-08"
            },
            {
              "what": "pricing change from 1 November 2026",
              "url": "https://didit.me/blog/new-pricing-november-2026/",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP server overview",
              "url": "https://docs.didit.me/integration/ai-agent-integration",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP authentication",
              "url": "https://docs.didit.me/integration/mcp/authentication",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP tools reference",
              "url": "https://docs.didit.me/integration/mcp/tools",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP server repository (clone)",
              "url": "https://github.com/didit-protocol/mcp",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP registry entry",
              "url": "https://registry.modelcontextprotocol.io/v0/servers?search=didit",
              "seen": "2026-10-08"
            },
            {
              "what": "status page",
              "url": "https://status.didit.me",
              "seen": "2026-10-08"
            },
            {
              "what": "incident feed",
              "url": "https://status.didit.me/api/v2/incidents.json",
              "seen": "2026-10-08"
            },
            {
              "what": "changelog, September 2026",
              "url": "https://docs.didit.me/changelog/september-2026",
              "seen": "2026-10-08"
            },
            {
              "what": "changelog, August 2026",
              "url": "https://docs.didit.me/changelog/august-2026",
              "seen": "2026-10-08"
            },
            {
              "what": "security and compliance",
              "url": "https://docs.didit.me/getting-started/security-compliance",
              "seen": "2026-10-08"
            },
            {
              "what": "audit logs",
              "url": "https://docs.didit.me/console/audit-logs",
              "seen": "2026-10-08"
            },
            {
              "what": "data retention",
              "url": "https://docs.didit.me/console/data-retention",
              "seen": "2026-10-08"
            },
            {
              "what": "Business Terms and Conditions with SLA and DPA annexes",
              "url": "https://didit.me/terms/business/",
              "seen": "2026-10-08"
            },
            {
              "what": "Service Level Agreement",
              "url": "https://didit.me/terms/service-level-agreement/",
              "seen": "2026-10-08"
            },
            {
              "what": "Privacy Policy",
              "url": "https://didit.me/terms/privacy-policy/",
              "seen": "2026-10-08"
            },
            {
              "what": "Information Security Policy",
              "url": "https://didit.me/terms/information-security/",
              "seen": "2026-10-08"
            },
            {
              "what": "legal index",
              "url": "https://didit.me/terms/",
              "seen": "2026-10-08"
            },
            {
              "what": "SDK list",
              "url": "https://docs.didit.me/integration/sdks",
              "seen": "2026-10-08"
            }
          ],
          "openQuestions": [
            "unchecked: the registration date of didit.me (whois returned nothing and rdap.org has no service for .me)",
            "unchecked: whether CI passes on the default branch of didit-protocol/mcp, and the pages of the Business Console, which need a login",
            "Whether the August 2026 change to session deletion responses (204 to 200 with a body) was announced before it shipped. The changelog labels it breaking and we found no earlier notice, so no deduction was taken.",
            "The SLA names `api.didit.me` as the covered API while the documented base URL is `verification.didit.me`. Whether the SLA covers that host wasn't established.",
            "The sub-processor list. The addendum says it is published at `/terms/sub-processors`, the legal index says it is sent after a signed NDA, and the privacy policy says on request.",
            "Whether the limit of 600 session creations a minute applies to free accounts in practice. The docs say a defined 10 a minute free-tier limit is not applied.",
            "The lead was right on the interface and the 500 free checks, which end on 1 November 2026. The SDKs are capture clients, with no server-side library."
          ]
        },
        "negative": 0,
        "verdict": "A self-serve verification API with public per-check prices, key registration by API, scoped keys and a 365-day audit log. The status page shows three incidents marked major between 22 July and 4 September 2026, each a partial outage of the core APIs, and the sub-processor list isn't public.",
        "bestFor": "A team that wants document, liveness, screening and business registry checks from one API with public prices and no sales step, and an agent that has to set itself up.",
        "strengths": [
          "An account and API key can be created by API at `apx.didit.me/auth/v2/programmatic/register/`, with an emailed code and no browser step",
          "Public OpenAPI 3.0.0 spec with 256 operations, plus llms.txt and a Markdown copy of every docs page",
          "Named API keys take read or write access per resource, workflow limits, an IP allowlist and an expiry date, and rotation keeps the old secret for 24 hours",
          "429 responses carry `Retry-After`, limits are published per scope, and 31 operations document an `Idempotency-Key` header or a reuse rule",
          "Per-check prices are public, charged only when a check finishes, with 500 free checks a month per core feature until 1 November 2026"
        ],
        "weaknesses": [
          "Three incidents marked major on status.didit.me from 22 July to 4 September 2026, each a partial outage of the core APIs traced to the primary database",
          "No server-side SDK in any language. The published SDKs are capture clients for web, iOS, Android, React Native and Flutter",
          "The data processing addendum says the sub-processor list is published at `/terms/sub-processors`, but that address shows the legal index, which says the list is sent after a signed NDA",
          "Verification data is used for model training by default until an organisation owner turns it off in the console",
          "The hosted MCP server lists 156 tools to a signed-in user, 23 of them destructive, and role checks run in a mode that logs without hiding tools by default"
        ],
        "agentNotes": [
          "Register with `POST https://apx.didit.me/auth/v2/programmatic/register/`, then `verify-email` with the emailed 6-character code. Use a real inbox, because reserved test domains return 500.",
          "Send the key as `x-api-key` to `https://verification.didit.me/v3/`. The JWT from registration works only on `apx.didit.me`.",
          "Create a workflow before `POST /v3/session/`. `workflow_id` is the only required field, and an unfinished session with the same `vendor_data` is returned again.",
          "Read results from webhooks and use `GET /v3/session/{sessionId}/decision/` for back-fill. Every per-feature result is a plural array.",
          "The MCP server at `https://mcp.didit.me/mcp` takes OAuth sign-in only, never an API key. Approve `didit:verification` alone when the task doesn't change workflows or keys."
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 75
          }
        ],
        "editorialScores": {
          "ergonomics": 69,
          "maintenance": 82,
          "payments": 60,
          "reliability": 80,
          "schema": 88,
          "security": 76,
          "transparency": 53
        },
        "provenanceScore": 73
      },
      "connect": {
        "http": "curl -X POST https://verification.didit.me/v3/session/ \\\n  -H \"x-api-key: $DIDIT_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"workflow_id\":\"\u003cWORKFLOW_ID\u003e\",\"vendor_data\":\"user-42\",\"callback\":\"https://myapp.com/return\"}'",
        "claudeCode": "claude mcp add --transport http didit https://mcp.didit.me/mcp",
        "config": {
          "mcpServers": {
            "didit": {
              "url": "https://mcp.didit.me/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/kyc.identity",
        "tool": "https://letme.dev/didit"
      },
      "notable": [
        "Programmatic registration creates an organisation, an application and an API key through two calls to `apx.didit.me/auth/v2/programmatic/`, limited to 5 registrations per IP per hour (https://docs.didit.me/integration/programmatic-registration)",
        "The OpenAPI spec is version 3.0.0, titled Didit Verification API 3.0.0, with 206 paths and 256 operations at 3.2 MB (https://docs.didit.me/openapi-25.json)",
        "Rate limits are 600 GET and 300 write requests a minute per key, with 600 a minute for session creation, and a 429 carries `Retry-After` and `X-RateLimit-*` headers (https://docs.didit.me/integration/rate-limiting)",
        "The hosted MCP server defines 158 tools and shows 156 to a signed-in user (73 read, 60 write, 23 destructive), built from didit-protocol/mcp (https://docs.didit.me/integration/mcp/tools)",
        "The status page lists three incidents marked major on 22 July, 15 August and 4 September 2026, each a partial outage of the core APIs (https://status.didit.me)",
        "Pricing changes on 1 November 2026, when 500 free checks a month per core feature become $10 of credit a month (https://didit.me/blog/new-pricing-november-2026/)",
        "The Business Terms allow model training on verification data by default, with an opt-out in the console under organisation settings (https://didit.me/terms/business/)",
        "Docs pages and llms.txt carry prompts addressed to AI coding agents, including an integration prompt to paste into an agent. We read them as data and took no deduction (https://docs.didit.me/getting-started/api-authentication)",
        "The npm figure is last week's downloads of `@didit-protocol/sdk-web`. `@didit-protocol/mcp-server` had 45 in the same week (https://api.npmjs.org/downloads/point/last-week/@didit-protocol/sdk-web)"
      ],
      "area": "domain-data",
      "details": [
        {
          "label": "Surface graded",
          "value": "REST API v3 at https://verification.didit.me, authenticated with `x-api-key`. The hosted MCP server at https://mcp.didit.me/mcp is described alongside it"
        },
        {
          "label": "Endpoints",
          "value": "Sessions (`POST /v3/session/`, `GET /v3/sessions/`, `GET /v3/session/{sessionId}/decision/`, update status, update data, delete, PDF), standalone checks (`/v3/id-verification/`, `/v3/passive-liveness/`, `/v3/face-match/`, `/v3/aml/`, `/v3/poa/`, `/v3/kyb/search/`), and management routes for workflows, lists, users, businesses, transactions, webhooks and billing"
        },
        {
          "label": "MCP server",
          "value": "Streamable HTTP at https://mcp.didit.me/mcp, version 5.1.1 per its `/healthz` on 8 October 2026. OAuth 2.1 with PKCE and dynamic client registration against business.didit.me. 156 tools for a signed-in user. Source in didit-protocol/mcp (MIT), also on npm as `@didit-protocol/mcp-server` for stdio"
        },
        {
          "label": "Credentials",
          "value": "Primary key with full access per application, plus named keys scoped per resource, with workflow limits, IP allowlist and expiry. Rotation returns a new secret once and keeps the old one for 24 hours"
        },
        {
          "label": "Rate limits",
          "value": "600 GET and 300 write requests a minute per key. Session creation 600 a minute, PDF generation 50 a minute, data updates 10 a minute. Registration 5 per IP per hour"
        },
        {
          "label": "Retries",
          "value": "`Retry-After` on 429. `Idempotency-Key` header on AML screening, transactions and digital ID wallet calls. Session creation returns the existing unfinished session for the same `vendor_data`"
        },
        {
          "label": "Webhooks",
          "value": "HMAC-SHA256 signatures in `X-Signature-V2`. `X-Signature-Simple` was marked deprecated in September 2026"
        },
        {
          "label": "SDKs",
          "value": "Web (`@didit-protocol/sdk-web`), iOS, Android, React Native and Flutter capture SDKs. No server-side client library found"
        },
        {
          "label": "Data",
          "value": "Processed in the EU on AWS by default, with an Australian data plane and in-country processing for enterprise accounts. Retention is unlimited by default and configurable from 30 days to 10 years"
        },
        {
          "label": "SLA",
          "value": "99.9 per cent monthly uptime with service credits of 10, 25 or 50 per cent of the month's spend. Free-tier use is excluded (https://didit.me/terms/service-level-agreement/)"
        },
        {
          "label": "Certifications",
          "value": "SOC 2 Type 2 issued 30 July 2026, ISO/IEC 27001:2022 certificate ES144068 from Bureau Veritas, iBeta Level 1 for liveness, per Didit's Information Security Policy"
        }
      ],
      "unitPrices": [
        {
          "item": "ID verification in a workflow (document capture)",
          "unit": "tx",
          "usd": 0.15,
          "note": "500 free a month until 1 November 2026"
        },
        {
          "item": "Passive liveness in a workflow",
          "unit": "tx",
          "usd": 0.1,
          "note": "500 free a month until 1 November 2026"
        },
        {
          "item": "Face match 1:1 in a workflow",
          "unit": "tx",
          "usd": 0.05,
          "note": "500 free a month until 1 November 2026"
        },
        {
          "item": "Device and IP analysis in a workflow",
          "unit": "tx",
          "usd": 0.03,
          "note": "500 free a month until 1 November 2026"
        },
        {
          "item": "AML screening",
          "unit": "tx",
          "usd": 0.2,
          "note": "no free allowance"
        },
        {
          "item": "Proof of address",
          "unit": "tx",
          "usd": 0.2,
          "note": "no free allowance"
        },
        {
          "item": "KYB registry, per selected company (Lite profile)",
          "unit": "tx",
          "usd": 2,
          "note": "search is charged separately at up to $0.50"
        }
      ],
      "provenance": {
        "legalEntity": "Didit Identity Spain, S.L.",
        "domain": "didit.me",
        "domainRegistered": "",
        "endpointOnVendorDomain": true,
        "terms": "https://didit.me/terms/business/",
        "privacy": "https://didit.me/terms/privacy-policy/",
        "statusPage": "https://status.didit.me",
        "changelog": "https://docs.didit.me/changelog/september-2026",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The Business Terms and Conditions (updated 23 September 2026) name two contracting entities. Didit Identity Spain, S.L., CIF B22929327, Barcelona, contracts with clients in the EU, EEA, UK and Switzerland, and Didit Identity, Inc., Dover, Delaware, with clients elsewhere.",
          "The Business Terms are the self-serve contract and include the SLA as Annex 1 and the Data Processing Addendum as Annex 2. A separate Master Services Agreement covers enterprise order forms.",
          "The Privacy Policy was updated on 7 October 2026 and names the Spanish Data Protection Agency as lead supervisory authority. A Verification Privacy Notice supplements it for end users.",
          "didit.me/.well-known/security.txt and docs.didit.me/.well-known/security.txt return 404. The Information Security Policy sends reports to security@didit.me.",
          "The API answers at verification.didit.me, account routes at apx.didit.me and the MCP server at mcp.didit.me, all on the vendor's domain.",
          "The registration date of didit.me wasn't established. whois returned nothing and rdap.org has no RDAP service for .me."
        ],
        "score": 73,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Didit Identity Spain, S.L.",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "didit.me, no registry record we could read",
            "points": 0,
            "max": 15,
            "state": "no"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "verification.didit.me",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Terms of service",
            "value": "read, states 7 of the 7 things a reader expects, and has 1 clause that costs points",
            "points": 8,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 8 of the 8 things a reader expects",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Status page",
            "value": "status.didit.me",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://didit.me/terms/business/",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2026-09-23",
            "words": 9292,
            "points": 8,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Updated: September 23, 2026",
                "says": "Last updated 2026-09-23"
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": true,
                "quote": "This Agreement is governed by the laws of Spain (without reference to its conflict-of-laws principles), and the Parties irrevocably submit to the exclusive jurisdiction of the courts of the city of Barcelona, Spain for any dispute arising out of or in connection with this Agreement.",
                "says": "The law of Spain, with disputes in the courts of the City of Barcelona, Spain"
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": true,
                "quote": "DIDIT'S TOTAL AND CUMULATIVE LIABILITY UNDER THIS AGREEMENT FOR ANY CAUSE AND UNDER ANY THEORY OF LIABILITY SHALL BE LIMITED TO THE AMOUNT OF CREDITS OR SERVICE FEES ACTUALLY PAID BY THE CLIENT TO DIDIT IN THE TWELVE (12) MONTHS PRECEDING THE EVENT GIVING RISE TO THE CLAIM.",
                "says": "Capped at the fees paid in the 12 months before the claim"
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "5.1 Agreement Term: This Agreement shall commence on the Effective Date and shall continue in full force and effect until terminated by either Party in accordance with Section 15 hereof."
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": true,
                "quote": "Didit will notify the Client of such modifications at least thirty (30) days in advance by publishing the revised Terms on its Website or Business Console, or by sending direct notification to the Client.",
                "says": "Gives thirty days of notice before a change"
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": true,
                "quote": "If you do not have such authority, or if you do not agree with these Terms, you must not use or access the Services."
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": true,
                "quote": "…material breach or insolvency under Section 15.2, (ii) for chronic SLA failure (Monthly Uptime below 99.0% in two of three consecutive calendar months, or below 95.0% in any single calendar month, per Annex 1), or (iii) following a Force Majeure event affecting Didit that continues for more than thirty (30) consecutiv…",
                "says": "Names 99.0% availability"
              }
            ],
            "toKnow": [
              {
                "key": "training.optout",
                "label": "Says it may use customer content to train or improve models, and gives an opt-out",
                "found": true,
                "quote": "An organization owner or administrator may opt the organization out at any time, directly in the Business Console, by turning off Allow Didit to use my organization's verification data to improve models under Organization Settings → Account → Privacy and data use."
              },
              {
                "key": "terms.benchmark",
                "label": "Restricts benchmarking or competitive use",
                "found": true,
                "quote": "Build or attempt to build a competing identity verification service using the Services or any information obtained therefrom.",
                "costsPoints": true
              },
              {
                "key": "terms.cutoff",
                "label": "Says access can be ended without notice or for any reason",
                "found": true,
                "quote": "By Didit: Didit may terminate this Agreement and the Client's access to the Services for convenience, without cause, upon thirty (30) days' prior written notice."
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "The client grants Didit a sublicensable and transferable licence to process client data for providing the services and for improving them.",
                "quote": "The Client grants Didit a worldwide, non-exclusive, royalty-free, sublicensable, and transferable license to process Client Data solely for the purpose of providing the Services to the Client and improving the Services"
              },
              {
                "date": "2026-10-08",
                "text": "Clients may not use verification results or client data obtained through the services to train or improve their own AI or machine learning models without Didit's prior written consent.",
                "quote": "Use the Verification results or any Client Data obtained through the Services to train, develop, or improve machine learning (ML) or artificial intelligence (AI) models, or any other similar algorithm or technology, without Didit's prior written consent."
              },
              {
                "date": "2026-10-08",
                "text": "Purchased credits are non-refundable unless the agreement or an order form states otherwise.",
                "quote": "All payments are final, and purchased Credits are non-refundable, unless expressly stated otherwise in this Agreement or an Order Form."
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://didit.me/terms/privacy-policy/",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2026-10-07",
            "words": 7234,
            "points": 10,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Updated: October 7, 2026",
                "says": "Last updated 2026-10-07"
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": true,
                "quote": "13.3 How we collect personal information, and anonymity (APPs 2 to 4)"
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": true,
                "quote": "Customers configure general verification-data retention per application in the Business Console between 30 days and 10 years.",
                "says": "Names a period of 30 days"
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "In those cases, it is the controller or business, and Didit acts as its processor or service provider."
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": true,
                "quote": "Didit does not sell or share (as those terms are defined under the CCPA/CPRA) personal information, including biometric information.",
                "says": "Says it does not sell personal data"
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": true,
                "quote": "right to know what personal information is collected, used, disclosed, and sold/shared;"
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "Australian privacy contact: Privacy Officer, Didit ID (Australia) Pty Ltd, privacy@didit.me",
                "says": "privacy@didit.me"
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": true,
                "quote": "the European Commission's 2021 Standard Contractual Clauses (SCCs) and any equivalent UK or Swiss addenda;",
                "says": "Relies on standard contractual clauses"
              }
            ],
            "toKnow": [
              {
                "key": "training.optout",
                "label": "Says it may use customer content to train or improve models, and gives an opt-out",
                "found": true,
                "quote": "Model training is allowed by default. An organization owner or administrator can opt the organization out at any time, directly in the Business Console and without contacting Didit"
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Verification data is kept indefinitely by default unless the customer sets a shorter period.",
                "quote": "Verification data, the default retention is indefinite (\"unlimited\"), unless the customer configures a shorter period."
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/didit.json",
      "live": {
        "slug": "didit",
        "probe": {
          "target": "https://verification.didit.me",
          "method": "get",
          "lastAt": "2026-10-08T21:12:08.968530696Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 54,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 61,
          "p95ms24h": 88,
          "samples24h": 21,
          "samples30d": 21,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 21,
              "ok": 21
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.didit.me",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T21:05:59.379981915Z"
        },
        "updatedAt": "2026-10-08T21:12:08.968530696Z"
      }
    },
    "verify": {
      "accepts": "a page on didit.me or one of its subdomains, or the README of github.com/didit-protocol/mcp",
      "badgeUrl": "https://www.anchorterminal.com/badges/didit.svg",
      "body": {
        "slug": "didit",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/didit",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/didit\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/didit.svg\" alt=\"Didit on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Didit on Anchor Terminal](https://www.anchorterminal.com/badges/didit.svg)](https://www.anchorterminal.com/tools/didit)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/didit\"\u003eDidit on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/didit",
    "json": "https://www.anchorterminal.com/tools/didit.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/didit.md",
    "slim": "https://www.anchorterminal.com/tools/didit.min.md"
  },
  "markdown": "## Overview\n\n**Grade BB · 75/100 · rank #54 of 722 · #1 in Identity \u0026 business verification · agent-ready · confidence medium**\n\n\n## Assessment\n\nA self-serve verification API with public per-check prices, key registration by API, scoped keys and a 365-day audit log. The status page shows three incidents marked major between 22 July and 4 September 2026, each a partial outage of the core APIs, and the sub-processor list isn't public.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Didit Identity Spain, S.L. (https://didit.me) |\n| Kind | HTTP API |\n| Category | Identity \u0026 business verification (https://www.anchorterminal.com/categories/identity-verification) |\n| Transport | HTTP, Streamable HTTP, stdio |\n| Endpoint | `https://verification.didit.me` |\n| Auth | OAuth or key · Self-serve. The REST API takes an application API key in the `x-api-key` header. A key comes from the Business Console or from the registration API on `apx.didit.me`, which emails a 6-character code and returns the key with no browser step. Each application has a primary key with full access and any number of named keys with read or write access per resource, workflow and status limits, an IP allowlist and an expiry date. Named keys are created, rotated and revoked only in the console. The hosted MCP server uses OAuth 2.1 with PKCE and dynamic client registration, with the scopes `didit:management` and `didit:verification`, and accepts no API key. |\n| Pricing | Pay per use ($0.15 / tx) · Pay per completed check from prepaid USD credits, with no contract or minimum and no card needed to sign up. In a workflow, ID verification is $0.15, passive liveness $0.10, face match $0.05, device and IP analysis $0.03 and AML screening $0.20. Until 1 November 2026 each organisation gets 500 free checks a month for each of the first four. From 1 November that becomes $10 of credit a month, with optional Growth ($99 a month) and Scale ($299 a month) plans. Sandbox applications are not billed (https://docs.didit.me/getting-started/pricing, checked 2026-10-08). |\n| x402 | No · No x402, MPP or L402 in the OpenAPI spec, the docs index or the pricing page (checked 2026-10-08). |\n| Licence | Proprietary service under Didit's Business Terms and Conditions. The MCP server in didit-protocol/mcp is MIT |\n| Tools exposed | 156 |\n| Packages | npm: `@didit-protocol/mcp-server`; npm: `@didit-protocol/sdk-web`; npm: `@didit-protocol/sdk-react-native` |\n| MCP registry name | `me.didit/mcp` |\n| Source | https://github.com/didit-protocol/mcp |\n| Docs | https://docs.didit.me |\n| llms.txt | https://docs.didit.me/llms.txt |\n| Last release | 2026-10-08 |\n| GitHub stars | 0 (as of 2026-10-08) |\n| npm downloads / week | 27,338 |\n| Surface graded | REST API v3 at https://verification.didit.me, authenticated with `x-api-key`. The hosted MCP server at https://mcp.didit.me/mcp is described alongside it |\n| Endpoints | Sessions (`POST /v3/session/`, `GET /v3/sessions/`, `GET /v3/session/{sessionId}/decision/`, update status, update data, delete, PDF), standalone checks (`/v3/id-verification/`, `/v3/passive-liveness/`, `/v3/face-match/`, `/v3/aml/`, `/v3/poa/`, `/v3/kyb/search/`), and management routes for workflows, lists, users, businesses, transactions, webhooks and billing |\n| MCP server | Streamable HTTP at https://mcp.didit.me/mcp, version 5.1.1 per its `/healthz` on 8 October 2026. OAuth 2.1 with PKCE and dynamic client registration against business.didit.me. 156 tools for a signed-in user. Source in didit-protocol/mcp (MIT), also on npm as `@didit-protocol/mcp-server` for stdio |\n| Credentials | Primary key with full access per application, plus named keys scoped per resource, with workflow limits, IP allowlist and expiry. Rotation returns a new secret once and keeps the old one for 24 hours |\n| Rate limits | 600 GET and 300 write requests a minute per key. Session creation 600 a minute, PDF generation 50 a minute, data updates 10 a minute. Registration 5 per IP per hour |\n| Retries | `Retry-After` on 429. `Idempotency-Key` header on AML screening, transactions and digital ID wallet calls. Session creation returns the existing unfinished session for the same `vendor_data` |\n| Webhooks | HMAC-SHA256 signatures in `X-Signature-V2`. `X-Signature-Simple` was marked deprecated in September 2026 |\n| SDKs | Web (`@didit-protocol/sdk-web`), iOS, Android, React Native and Flutter capture SDKs. No server-side client library found |\n| Data | Processed in the EU on AWS by default, with an Australian data plane and in-country processing for enterprise accounts. Retention is unlimited by default and configurable from 30 days to 10 years |\n| SLA | 99.9 per cent monthly uptime with service credits of 10, 25 or 50 per cent of the month's spend. Free-tier use is excluded (https://didit.me/terms/service-level-agreement/) |\n| Certifications | SOC 2 Type 2 issued 30 July 2026, ISO/IEC 27001:2022 certificate ES144068 from Bureau Veritas, iBeta Level 1 for liveness, per Didit's Information Security Policy |\n| Capabilities | kyc.identity, kyc.documents, kyc.screening, kyc.business, kyc.cases |\n| Tags | hosted, api-key, oauth, mcp, webhooks, openapi, llms-txt, free-tier, no-card, sandbox, status-page, sla, soc2, iso27001 |\n| JSON | https://www.anchorterminal.com/api/v1/tools/didit.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 80 | 16.0 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 88 | 14.3 |\n| Agent ergonomics | 13% | 16.2 | 69 | 11.2 |\n| Security \u0026 auth | 14% | 17.5 | 76 | 13.3 |\n| Payments \u0026 pricing | 10% | 12.5 | 60 | 7.5 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 82 | 7.2 |\n| Transparency \u0026 trust (editorial 53, provenance 73) | 7% | 8.8 | 63 | 5.5 |\n| Negative events | up to −15 | up to −15 | none recorded | 0 |\n| **Total** | | | | **75 → BB** |\n\n### Why each score\n\n- Reliability 80: Graded on the REST API v3 with the hosted lines. Status page on incident.io at status.didit.me with Core APIs, Business Console and Hosted Verification Web App components (20). Three incidents in the last 90 days, all marked major by Didit and all partial outages of the core APIs traced to the primary database. 22 July 2026 lasted 21 minutes, 15 August about 65 minutes and 4 September about 40 minutes. The page reports 99.93 per cent uptime for Core APIs from July to October. We scored 10, between the lines for one major outage and several, because each was partial and about an hour or less (10). Limits are published per scope, 600 GET and 300 write requests a minute per key (15). A 429 carries `Retry-After` and `X-RateLimit-*` headers, backoff guidance is written out, and `Idempotency-Key` is documented on 31 operations (15). A public SLA commits to 99.9 per cent monthly uptime with service credits, excluding free-tier use (10). GA (10).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 88: A public OpenAPI 3.0.0 spec with 206 paths and 256 operations, and a second spec for the account routes (25). llms.txt and a Markdown copy of each docs page (10). 215 of the 256 operations have descriptions longer than 80 characters, covering billing, idempotency and which key access is needed. Few say when not to use an endpoint (17). 586 enum declarations, required lists and limits. Error bodies are loosely typed, and session creation returns either an array of strings or a plain string per field (12). 184 operations carry examples and status codes from 400 to 503 are described (13). A `/v3` path and a monthly changelog. Entries are grouped by month, with no day given, and the session routes still list v1 and v2 paths (12). The 88 total takes 1 off for the spec's 3.2 MB size, which no agent can load whole.\n- Agent ergonomics 69: Graded on the REST API. No field selection, and the decision payload returns every feature result as an array. Scoped keys can null out media links (12). `GET /v3/sessions/` takes `limit` and `offset`, returns `next` and `previous` links and filters on status, workflow, dates, country and `vendor_data` (18). Errors return `detail` or a field-keyed object, with two shapes on some routes and a bare array on password rules, each documented (14). `Idempotency-Key` on AML screening, transactions and wallet calls, and session creation returns the existing unfinished session for the same `vendor_data`. The MCP server marks read and destructive tools and asks for `confirm: true` on deletes (18). `workflow_id` is the only required field for a session. No server-side SDK was found in any language, only capture SDKs (7).\n- Security \u0026 auth 76: Named API keys take read or write access per resource, workflow and status limits, an IP allowlist, an expiry date, rotation with a 24-hour overlap and instant revoke. Keys travel in a header only. The primary key has full access, and the key returned by registration is that key (28). Read-only key presets, keys limited to approved sessions, `confirm: true` on MCP deletes and OAuth scopes that split management from verification. The MCP server's role check defaults to a mode that lists every tool and leaves refusal to the backend (16). Responses carry text read from documents, AML and adverse media hits. No guidance on injected content was found in the docs or the MCP repository (3). Audit logs record each API call with key name, path, status and IP, kept for 365 days (15). SOC 2 Type 2 issued 30 July 2026, ISO/IEC 27001:2022, yearly external penetration tests and a reporting address. No security.txt, no bounty terms and no public advisories found (14).\n- Payments \u0026 pricing 60: No x402, MPP or L402 (0). Per-check prices are public without a login, such as $0.15 for ID verification and $0.20 for AML screening (20). 500 free checks a month per core feature with no card, changing to $10 of monthly credit on 1 November 2026 (20). An agent can register and receive an API key through `POST /auth/v2/programmatic/register/` and `verify-email` with no browser. It needs a real inbox for the emailed code, and we scored the line in full (20).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 82: The MCP server was released as v5.1.34 on 8 October 2026 and the September 2026 changelog covers the API (30). Monthly changelogs for July, August and September and three MCP tags in the period (20). Closed service with a public changelog and support by email, chat and WhatsApp. No public forum was found, and the MCP repository has no stars or open issues to judge replies by (10). The MCP server is in the official registry as `me.didit/mcp`, though the entry is at 5.0.1, and the capture SDKs are current (15). The MCP repository has a CI workflow that builds and tests, and publishes to npm from release tags. Whether CI passes wasn't checked (7).\n- Transparency \u0026 trust 63: Closed service with public, dated and versioned terms, and an MIT licence on the MCP server (17). A privacy policy, a data processing addendum inside the Business Terms and retention settings from 30 days to 10 years, unlimited by default. The terms allow model training on verification data by default with a console opt-out. The addendum says the sub-processor list is published at `/terms/sub-processors`, while that address shows the legal index, which says the list is sent after a signed NDA (20). `X-Signature-Simple` is marked deprecated with no end date, the terms promise 30 days' notice of changes to terms and prices, and the pricing change of 1 November was announced on 2 October. No API deprecation policy was found (8). Data is processed in the EU on AWS by default with an Australian data plane. The sub-processors aren't named in public (8).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (17 items): https://www.anchorterminal.com/fixes/didit.md (JSON https://www.anchorterminal.com/fixes/didit.json)\n\n### What we couldn't check\n\n- unchecked: the registration date of didit.me (whois returned nothing and rdap.org has no service for .me)\n- unchecked: whether CI passes on the default branch of didit-protocol/mcp, and the pages of the Business Console, which need a login\n- Whether the August 2026 change to session deletion responses (204 to 200 with a body) was announced before it shipped. The changelog labels it breaking and we found no earlier notice, so no deduction was taken.\n- The SLA names `api.didit.me` as the covered API while the documented base URL is `verification.didit.me`. Whether the SLA covers that host wasn't established.\n- The sub-processor list. The addendum says it is published at `/terms/sub-processors`, the legal index says it is sent after a signed NDA, and the privacy policy says on request.\n- Whether the limit of 600 session creations a minute applies to free accounts in practice. The docs say a defined 10 a minute free-tier limit is not applied.\n- The lead was right on the interface and the 500 free checks, which end on 1 November 2026. The SDKs are capture clients, with no server-side library.\n\n### Sources\n\n- docs index for agents: \u003chttps://docs.didit.me/llms.txt\u003e (seen 2026-10-08)\n- OpenAPI spec: \u003chttps://docs.didit.me/openapi-25.json\u003e (seen 2026-10-08)\n- API authentication: \u003chttps://docs.didit.me/getting-started/api-authentication\u003e (seen 2026-10-08)\n- scoped API keys: \u003chttps://docs.didit.me/console/api-keys\u003e (seen 2026-10-08)\n- programmatic registration: \u003chttps://docs.didit.me/integration/programmatic-registration\u003e (seen 2026-10-08)\n- rate limiting: \u003chttps://docs.didit.me/integration/rate-limiting\u003e (seen 2026-10-08)\n- pricing: \u003chttps://docs.didit.me/getting-started/pricing\u003e (seen 2026-10-08)\n- pricing change from 1 November 2026: \u003chttps://didit.me/blog/new-pricing-november-2026/\u003e (seen 2026-10-08)\n- MCP server overview: \u003chttps://docs.didit.me/integration/ai-agent-integration\u003e (seen 2026-10-08)\n- MCP authentication: \u003chttps://docs.didit.me/integration/mcp/authentication\u003e (seen 2026-10-08)\n- MCP tools reference: \u003chttps://docs.didit.me/integration/mcp/tools\u003e (seen 2026-10-08)\n- MCP server repository (clone): \u003chttps://github.com/didit-protocol/mcp\u003e (seen 2026-10-08)\n- MCP registry entry: \u003chttps://registry.modelcontextprotocol.io/v0/servers?search=didit\u003e (seen 2026-10-08)\n- status page: \u003chttps://status.didit.me\u003e (seen 2026-10-08)\n- incident feed: \u003chttps://status.didit.me/api/v2/incidents.json\u003e (seen 2026-10-08)\n- changelog, September 2026: \u003chttps://docs.didit.me/changelog/september-2026\u003e (seen 2026-10-08)\n- changelog, August 2026: \u003chttps://docs.didit.me/changelog/august-2026\u003e (seen 2026-10-08)\n- security and compliance: \u003chttps://docs.didit.me/getting-started/security-compliance\u003e (seen 2026-10-08)\n- audit logs: \u003chttps://docs.didit.me/console/audit-logs\u003e (seen 2026-10-08)\n- data retention: \u003chttps://docs.didit.me/console/data-retention\u003e (seen 2026-10-08)\n- Business Terms and Conditions with SLA and DPA annexes: \u003chttps://didit.me/terms/business/\u003e (seen 2026-10-08)\n- Service Level Agreement: \u003chttps://didit.me/terms/service-level-agreement/\u003e (seen 2026-10-08)\n- Privacy Policy: \u003chttps://didit.me/terms/privacy-policy/\u003e (seen 2026-10-08)\n- Information Security Policy: \u003chttps://didit.me/terms/information-security/\u003e (seen 2026-10-08)\n- legal index: \u003chttps://didit.me/terms/\u003e (seen 2026-10-08)\n- SDK list: \u003chttps://docs.didit.me/integration/sdks\u003e (seen 2026-10-08)\n\n## Who's behind it (provenance 73/100, checked 2026-10-08)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Didit Identity Spain, S.L. | 20/20 |\n| Domain age | didit.me, no registry record we could read | 0/15 |\n| Endpoint on the vendor's domain | verification.didit.me | 15/15 |\n| Terms of service | read, states 7 of the 7 things a reader expects, and has 1 clause that costs points | 8/10 |\n| Privacy policy | read, states 8 of the 8 things a reader expects | 10/10 |\n| Status page | status.didit.me | 10/10 |\n| Changelog | published | 10/10 |\n| security.txt | not found | 0/10 |\n\nThe Business Terms and Conditions (updated 23 September 2026) name two contracting entities. Didit Identity Spain, S.L., CIF B22929327, Barcelona, contracts with clients in the EU, EEA, UK and Switzerland, and Didit Identity, Inc., Dover, Delaware, with clients elsewhere.\n\nThe Business Terms are the self-serve contract and include the SLA as Annex 1 and the Data Processing Addendum as Annex 2. A separate Master Services Agreement covers enterprise order forms.\n\nThe Privacy Policy was updated on 7 October 2026 and names the Spanish Data Protection Agency as lead supervisory authority. A Verification Privacy Notice supplements it for end users.\n\ndidit.me/.well-known/security.txt and docs.didit.me/.well-known/security.txt return 404. The Information Security Policy sends reports to security@didit.me.\n\nThe API answers at verification.didit.me, account routes at apx.didit.me and the MCP server at mcp.didit.me, all on the vendor's domain.\n\nThe registration date of didit.me wasn't established. whois returned nothing and rdap.org has no RDAP service for .me.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://didit.me/terms/business/), read 2026-10-08, dated 2026-09-23, states 7 of the 7 things a reader expects.\n\n- To know. Says it may use customer content to train or improve models, and gives an opt-out. \"An organization owner or administrator may opt the organization out at any time, directly in the Business Console, by turning off Allow Didit to use my organization's verification data to improve models under Organization Settings → Account → Privacy and data use.\"\n- To know. Restricts benchmarking or competitive use (costs points). \"Build or attempt to build a competing identity verification service using the Services or any information obtained therefrom.\"\n- To know. Says access can be ended without notice or for any reason. \"By Didit: Didit may terminate this Agreement and the Client's access to the Services for convenience, without cause, upon thirty (30) days' prior written notice.\"\n- Gives the date it was last updated. Last updated 2026-09-23.\n- Names the governing law or courts. The law of Spain, with disputes in the courts of the City of Barcelona, Spain.\n- States a limit on its liability. Capped at the fees paid in the 12 months before the claim.\n- Says how changes to the terms are announced. Gives thirty days of notice before a change.\n- Refers to a service level or uptime commitment. Names 99.0% availability.\n- Also in the text (2026-10-08). The client grants Didit a sublicensable and transferable licence to process client data for providing the services and for improving them. \"The Client grants Didit a worldwide, non-exclusive, royalty-free, sublicensable, and transferable license to process Client Data solely for the purpose of providing the Services to the Client and improving the Services\"\n- Also in the text (2026-10-08). Clients may not use verification results or client data obtained through the services to train or improve their own AI or machine learning models without Didit's prior written consent. \"Use the Verification results or any Client Data obtained through the Services to train, develop, or improve machine learning (ML) or artificial intelligence (AI) models, or any other similar algorithm or technology, without Didit's prior written consent.\"\n- Also in the text (2026-10-08). Purchased credits are non-refundable unless the agreement or an order form states otherwise. \"All payments are final, and purchased Credits are non-refundable, unless expressly stated otherwise in this Agreement or an Order Form.\"\n\n**Privacy policy** (https://didit.me/terms/privacy-policy/), read 2026-10-08, dated 2026-10-07, states 8 of the 8 things a reader expects.\n\n- To know. Says it may use customer content to train or improve models, and gives an opt-out. \"Model training is allowed by default. An organization owner or administrator can opt the organization out at any time, directly in the Business Console and without contacting Didit\"\n- Gives the date it was last updated. Last updated 2026-10-07.\n- Says how long data is kept. Names a period of 30 days.\n- Says whether personal data is sold or shared for advertising. Says it does not sell personal data.\n- Gives a privacy contact. privacy@didit.me.\n- Says where data is transferred or stored. Relies on standard contractual clauses.\n- Also in the text (2026-10-08). Verification data is kept indefinitely by default unless the customer sets a shorter period. \"Verification data, the default retention is indefinite (\"unlimited\"), unless the customer configures a shorter period.\"\n\n## Live (updated 2026-10-08 21:12 UTC)\n\n- Right now: up, HTTP 404, 54 ms, checked 2026-10-08 21:12 UTC (get on `https://verification.didit.me`)\n- Uptime 24h 100.0% (21 probes) · 30 days 100.0% (21 probes) · p50 61 ms · p95 88 ms\n- Vendor status page: none, All Systems Operational\n- Always current: https://www.anchorterminal.com/api/v1/live/didit.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Prices\n\n| Item | Price | Unit | Note |\n| --- | --- | --- | --- |\n| ID verification in a workflow (document capture) | $0.15 | per transaction | 500 free a month until 1 November 2026 |\n| Passive liveness in a workflow | $0.10 | per transaction | 500 free a month until 1 November 2026 |\n| Face match 1:1 in a workflow | $0.05 | per transaction | 500 free a month until 1 November 2026 |\n| Device and IP analysis in a workflow | $0.03 | per transaction | 500 free a month until 1 November 2026 |\n| AML screening | $0.20 | per transaction | no free allowance |\n| Proof of address | $0.20 | per transaction | no free allowance |\n| KYB registry, per selected company (Lite profile) | $2 | per transaction | search is charged separately at up to $0.50 |\n\nAcross all listings: https://www.anchorterminal.com/prices/index.md\n\n## Strengths\n\n- An account and API key can be created by API at `apx.didit.me/auth/v2/programmatic/register/`, with an emailed code and no browser step\n- Public OpenAPI 3.0.0 spec with 256 operations, plus llms.txt and a Markdown copy of every docs page\n- Named API keys take read or write access per resource, workflow limits, an IP allowlist and an expiry date, and rotation keeps the old secret for 24 hours\n- 429 responses carry `Retry-After`, limits are published per scope, and 31 operations document an `Idempotency-Key` header or a reuse rule\n- Per-check prices are public, charged only when a check finishes, with 500 free checks a month per core feature until 1 November 2026\n\n## Weaknesses\n\n- Three incidents marked major on status.didit.me from 22 July to 4 September 2026, each a partial outage of the core APIs traced to the primary database\n- No server-side SDK in any language. The published SDKs are capture clients for web, iOS, Android, React Native and Flutter\n- The data processing addendum says the sub-processor list is published at `/terms/sub-processors`, but that address shows the legal index, which says the list is sent after a signed NDA\n- Verification data is used for model training by default until an organisation owner turns it off in the console\n- The hosted MCP server lists 156 tools to a signed-in user, 23 of them destructive, and role checks run in a mode that logs without hiding tools by default\n\n## Before you call it (notes for agents)\n\n1. Register with `POST https://apx.didit.me/auth/v2/programmatic/register/`, then `verify-email` with the emailed 6-character code. Use a real inbox, because reserved test domains return 500.\n2. Send the key as `x-api-key` to `https://verification.didit.me/v3/`. The JWT from registration works only on `apx.didit.me`.\n3. Create a workflow before `POST /v3/session/`. `workflow_id` is the only required field, and an unfinished session with the same `vendor_data` is returned again.\n4. Read results from webhooks and use `GET /v3/session/{sessionId}/decision/` for back-fill. Every per-feature result is a plural array.\n5. The MCP server at `https://mcp.didit.me/mcp` takes OAuth sign-in only, never an API key. Approve `didit:verification` alone when the task doesn't change workflows or keys.\n\n## Connect\n\nFirst request:\n\n```bash\ncurl -X POST https://verification.didit.me/v3/session/ \\\n  -H \"x-api-key: $DIDIT_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"workflow_id\":\"\u003cWORKFLOW_ID\u003e\",\"vendor_data\":\"user-42\",\"callback\":\"https://myapp.com/return\"}'\n```\n\nClaude Code:\n\n```bash\nclaude mcp add --transport http didit https://mcp.didit.me/mcp\n```\n\nMCP client configuration:\n\n```json\n{\n  \"mcpServers\": {\n    \"didit\": {\n      \"url\": \"https://mcp.didit.me/mcp\"\n    }\n  }\n}\n```\n\nThrough letme (picks today, calling later): https://letme.dev/didit (letme picks it for kyc.business, the top-graded tool for the job, letme picks it for kyc.cases, the top-graded tool for the job, letme picks it for kyc.documents, the top-graded tool for the job, letme picks it for kyc.identity, the top-graded tool for the job, letme picks it for kyc.screening, the top-graded tool for the job). letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| Persona | B | 69.5 | 157 | kyc.identity, kyc.business, kyc.documents, kyc.screening, kyc.cases | no | https://www.anchorterminal.com/tools/persona.md |\n| Sumsub | B | 68.5 | 177 | kyc.identity, kyc.business, kyc.documents, kyc.screening, kyc.cases | no | https://www.anchorterminal.com/tools/sumsub.md |\n| ComplyCube | B | 63.7 | 299 | kyc.identity, kyc.documents, kyc.screening, kyc.business | no | https://www.anchorterminal.com/tools/complycube.md |\n| Middesk | C | 59 | 440 | kyc.business, kyc.screening, kyc.cases, kyc.identity | no | https://www.anchorterminal.com/tools/middesk.md |\n| Trulioo | C | 58.2 | 457 | kyc.identity, kyc.business, kyc.documents, kyc.screening | no | https://www.anchorterminal.com/tools/trulioo.md |\n| Grep AI | B | 64.4 | 275 | kyc.business, kyc.screening, kyc.documents | no | https://www.anchorterminal.com/tools/grep-ai.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- Programmatic registration creates an organisation, an application and an API key through two calls to `apx.didit.me/auth/v2/programmatic/`, limited to 5 registrations per IP per hour (source: \u003chttps://docs.didit.me/integration/programmatic-registration\u003e)\n- The OpenAPI spec is version 3.0.0, titled Didit Verification API 3.0.0, with 206 paths and 256 operations at 3.2 MB (source: \u003chttps://docs.didit.me/openapi-25.json\u003e)\n- Rate limits are 600 GET and 300 write requests a minute per key, with 600 a minute for session creation, and a 429 carries `Retry-After` and `X-RateLimit-*` headers (source: \u003chttps://docs.didit.me/integration/rate-limiting\u003e)\n- The hosted MCP server defines 158 tools and shows 156 to a signed-in user (73 read, 60 write, 23 destructive), built from didit-protocol/mcp (source: \u003chttps://docs.didit.me/integration/mcp/tools\u003e)\n- The status page lists three incidents marked major on 22 July, 15 August and 4 September 2026, each a partial outage of the core APIs (source: \u003chttps://status.didit.me\u003e)\n- Pricing changes on 1 November 2026, when 500 free checks a month per core feature become $10 of credit a month (source: \u003chttps://didit.me/blog/new-pricing-november-2026/\u003e)\n- The Business Terms allow model training on verification data by default, with an opt-out in the console under organisation settings (source: \u003chttps://didit.me/terms/business/\u003e)\n- Docs pages and llms.txt carry prompts addressed to AI coding agents, including an integration prompt to paste into an agent. We read them as data and took no deduction (source: \u003chttps://docs.didit.me/getting-started/api-authentication\u003e)\n- The npm figure is last week's downloads of `@didit-protocol/sdk-web`. `@didit-protocol/mcp-server` had 45 in the same week (source: \u003chttps://api.npmjs.org/downloads/point/last-week/@didit-protocol/sdk-web\u003e)\n\n## Compare\n\n- [ComplyCube vs Didit](https://www.anchorterminal.com/compare/complycube-vs-didit.md): B 63.7 vs BB 75\n- [Didit vs Jumio](https://www.anchorterminal.com/compare/didit-vs-jumio.md): BB 75 vs C 55\n- [Didit vs Middesk](https://www.anchorterminal.com/compare/didit-vs-middesk.md): BB 75 vs C 59\n- [Didit vs Persona](https://www.anchorterminal.com/compare/didit-vs-persona.md): BB 75 vs B 69.5\n- [Didit vs Sumsub](https://www.anchorterminal.com/compare/didit-vs-sumsub.md): BB 75 vs B 68.5\n- [Didit vs Trulioo](https://www.anchorterminal.com/compare/didit-vs-trulioo.md): BB 75 vs C 58.2\n- [Didit vs Veriff](https://www.anchorterminal.com/compare/didit-vs-veriff.md): BB 75 vs C 61.1\n- [ComplyAdvantage vs Didit](https://www.anchorterminal.com/compare/complyadvantage-vs-didit.md): D 52.6 vs BB 75\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on didit.me or one of its subdomains, or the README of github.com/didit-protocol/mcp. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"didit\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/didit\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/didit.svg\" alt=\"Didit on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Didit on Anchor Terminal](https://www.anchorterminal.com/badges/didit.svg)](https://www.anchorterminal.com/tools/didit)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/didit\"\u003eDidit on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Didit is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/didit-dark.png\n- Light: https://www.anchorterminal.com/assets/share/didit-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Identity \u0026 business verification",
        "url": "https://www.anchorterminal.com/categories/identity-verification"
      },
      {
        "name": "Didit",
        "url": ""
      }
    ],
    "description": "Didit is a hosted identity verification service for document, liveness, face match, sanctions screening and business registry checks. Developers reach it through a REST API with an OpenAPI spec, a hosted MCP server and client SDKs.",
    "facts": [
      "rank #54 of 722",
      "OAuth or key auth",
      "0 desk reviews"
    ],
    "h1": "Didit",
    "image": "https://www.anchorterminal.com/assets/og/tools-didit.png",
    "path": "/tools/didit",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Didit review for AI agents, grade BB (75/100) | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/tools/didit"
  },
  "tokens": {
    "markdown": 8200,
    "slim": 1930
  },
  "version": 1
}
