# Didit (slim) > Didit is a hosted identity verification service for document, liveness, face match, sanctions screening and business registry checks. Developers reach it through a REST API with an OpenAPI spec, a hosted MCP server and client SDKs. - Full: https://www.anchorterminal.com/tools/didit.md (~8,200 tokens) · this version ~1,930 tokens · JSON https://www.anchorterminal.com/tools/didit.json · canonical https://www.anchorterminal.com/tools/didit - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **BB · 75/100 · rank #54 of 722 · #1 in Identity & business verification · agent-ready · confidence medium** Assessment: A self-serve verification API with public per-check prices, key registration by API, scoped keys and a 365-day audit log. The status page shows three incidents marked major between 22 July and 4 September 2026, each a partial outage of the core APIs, and the sub-processor list isn't public. ## Facts - Kind: HTTP API · vendor: Didit Identity Spain, S.L. · category: Identity & business verification · legal entity: Didit Identity Spain, S.L. · provenance 73/100 - Endpoint: `https://verification.didit.me` (HTTP, Streamable HTTP, stdio) - Auth: OAuth or key · pricing: Pay per use · x402: no · licence: Proprietary service under Didit's Business Terms and Conditions. The MCP server in didit-protocol/mcp is MIT - Probe metrics: not measured yet (probes haven't run) - Surface graded: REST API v3 at https://verification.didit.me, authenticated with `x-api-key`. The hosted MCP server at https://mcp.didit.me/mcp is described alongside it - Endpoints: Sessions (`POST /v3/session/`, `GET /v3/sessions/`, `GET /v3/session/{sessionId}/decision/`, update status, update data, delete, PDF), standalone checks (`/v3/id-verification/`, `/v3/passive-liveness/`, `/v3/face-match/`, `/v3/aml/`, `/v3/poa/`, `/v3/kyb/search/`), and management routes for workflows, lists, users, businesses, transactions, webhooks and billing - MCP server: Streamable HTTP at https://mcp.didit.me/mcp, version 5.1.1 per its `/healthz` on 8 October 2026. OAuth 2.1 with PKCE and dynamic client registration against business.didit.me. 156 tools for a signed-in user. Source in didit-protocol/mcp (MIT), also on npm as `@didit-protocol/mcp-server` for stdio - Credentials: Primary key with full access per application, plus named keys scoped per resource, with workflow limits, IP allowlist and expiry. Rotation returns a new secret once and keeps the old one for 24 hours - Rate limits: 600 GET and 300 write requests a minute per key. Session creation 600 a minute, PDF generation 50 a minute, data updates 10 a minute. Registration 5 per IP per hour - Retries: `Retry-After` on 429. `Idempotency-Key` header on AML screening, transactions and digital ID wallet calls. Session creation returns the existing unfinished session for the same `vendor_data` - Webhooks: HMAC-SHA256 signatures in `X-Signature-V2`. `X-Signature-Simple` was marked deprecated in September 2026 - SDKs: Web (`@didit-protocol/sdk-web`), iOS, Android, React Native and Flutter capture SDKs. No server-side client library found - Data: Processed in the EU on AWS by default, with an Australian data plane and in-country processing for enterprise accounts. Retention is unlimited by default and configurable from 30 days to 10 years - SLA: 99.9 per cent monthly uptime with service credits of 10, 25 or 50 per cent of the month's spend. Free-tier use is excluded (https://didit.me/terms/service-level-agreement/) - Certifications: SOC 2 Type 2 issued 30 July 2026, ISO/IEC 27001:2022 certificate ES144068 from Bureau Veritas, iBeta Level 1 for liveness, per Didit's Information Security Policy - Prices: ID verification in a workflow (document capture) $0.15 per transaction; Passive liveness in a workflow $0.10 per transaction; Face match 1:1 in a workflow $0.05 per transaction; Device and IP analysis in a workflow $0.03 per transaction; AML screening $0.20 per transaction; Proof of address $0.20 per transaction; KYB registry, per selected company (Lite profile) $2 per transaction - Scores: Reliability 80, Performance pending, Schema & documentation 88, Agent ergonomics 69, Security & auth 76, Payments & pricing 60, Task success pending, Maintenance & community 82, Transparency & trust 63 · total over the 7 assessed categories - Why: Reliability, Graded on the REST API v3 with the hosted lines. · Schema & documentation, A public OpenAPI 3.0.0 spec with 206 paths and 256 operations, and a second spec for the account routes (25). · Agent ergonomics, Graded on the REST API. · Security & auth, Named API keys take read or write access per resource, workflow and status limits, an IP allowlist, an expiry date, rotation with a 24-hour… · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, The MCP server was released as v5.1.34 on 8 October 2026 and the September 2026 changelog covers the API (30). · Transparency & trust, Closed service with public, dated and versioned terms, and an MIT licence on the MCP server (17). - Sources: 26, open questions: 7, both in the full twin - Capabilities: kyc.identity, kyc.documents, kyc.screening, kyc.business, kyc.cases - JSON: https://www.anchorterminal.com/api/v1/tools/didit.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/didit.svg` or a link to https://www.anchorterminal.com/tools/didit from a page on didit.me or one of its subdomains, or the README of github.com/didit-protocol/mcp, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Register with `POST https://apx.didit.me/auth/v2/programmatic/register/`, then `verify-email` with the emailed 6-character code. Use a real inbox, because reserved test domains return 500. 2. Send the key as `x-api-key` to `https://verification.didit.me/v3/`. The JWT from registration works only on `apx.didit.me`. 3. Create a workflow before `POST /v3/session/`. `workflow_id` is the only required field, and an unfinished session with the same `vendor_data` is returned again. 4. Read results from webhooks and use `GET /v3/session/{sessionId}/decision/` for back-fill. Every per-feature result is a plural array. 5. The MCP server at `https://mcp.didit.me/mcp` takes OAuth sign-in only, never an API key. Approve `didit:verification` alone when the task doesn't change workflows or keys. ## Connect ```bash curl -X POST https://verification.didit.me/v3/session/ \ -H "x-api-key: $DIDIT_API_KEY" \ -H "Content-Type: application/json" \ -d '{"workflow_id":"","vendor_data":"user-42","callback":"https://myapp.com/return"}' ``` ```bash claude mcp add --transport http didit https://mcp.didit.me/mcp ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/didit ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Persona | B | 69.5 | kyc.identity, kyc.business, kyc.documents, kyc.screening, kyc.cases | https://www.anchorterminal.com/tools/persona.min.md | | Sumsub | B | 68.5 | kyc.identity, kyc.business, kyc.documents, kyc.screening, kyc.cases | https://www.anchorterminal.com/tools/sumsub.min.md | | ComplyCube | B | 63.7 | kyc.identity, kyc.documents, kyc.screening, kyc.business | https://www.anchorterminal.com/tools/complycube.min.md | | Middesk | C | 59 | kyc.business, kyc.screening, kyc.cases, kyc.identity | https://www.anchorterminal.com/tools/middesk.min.md | | Trulioo | C | 58.2 | kyc.identity, kyc.business, kyc.documents, kyc.screening | https://www.anchorterminal.com/tools/trulioo.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)