{
  "data": {
    "similar": [
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/persona.json",
        "name": "Persona",
        "score": 69.5,
        "shared": [
          "kyc.identity",
          "kyc.business",
          "kyc.screening",
          "kyc.cases"
        ],
        "slug": "persona"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/sumsub.json",
        "name": "Sumsub",
        "score": 68.5,
        "shared": [
          "kyc.identity",
          "kyc.business",
          "kyc.screening",
          "kyc.cases"
        ],
        "slug": "sumsub"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/trulioo.json",
        "name": "Trulioo",
        "score": 58.2,
        "shared": [
          "kyc.identity",
          "kyc.business",
          "kyc.screening"
        ],
        "slug": "trulioo"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/grep-ai.json",
        "name": "Grep AI",
        "score": 64.4,
        "shared": [
          "kyc.business",
          "kyc.screening"
        ],
        "slug": "grep-ai"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/veriff.json",
        "name": "Veriff",
        "score": 61.1,
        "shared": [
          "kyc.identity",
          "kyc.screening"
        ],
        "slug": "veriff"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/jumio.json",
        "name": "Jumio",
        "score": 55,
        "shared": [
          "kyc.identity",
          "kyc.screening"
        ],
        "slug": "jumio"
      }
    ],
    "tool": {
      "slug": "middesk",
      "name": "Middesk",
      "vendor": "Middesk, Inc.",
      "vendorUrl": "https://www.middesk.com",
      "kind": "http-api",
      "category": "identity-verification",
      "summary": "Business verification API from Middesk in San Francisco. It checks US and international businesses against registry, tax ID, sanctions and watchlist records, monitors them for changes, and files liens and state tax registrations, over REST and a hosted MCP server.",
      "url": "https://www.anchorterminal.com/tools/middesk",
      "markdownUrl": "https://www.anchorterminal.com/tools/middesk.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/middesk.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/middesk.json",
      "repo": "https://github.com/middesk/plugins",
      "license": "Proprietary service under Middesk's Business Verification Terms and Conditions. The Claude Code and Codex plugins on GitHub are MIT",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://api.middesk.com/v1",
      "packages": [],
      "auth": "mixed",
      "authNotes": "Access is granted by Middesk's sales team, and keys are then created in the dashboard under Settings, Developer, Credentials. An API key goes as the Basic auth username or as a Bearer token. `mk_test` keys work only against https://api-sandbox.middesk.com/v1 and `mk_live` keys only against https://api.middesk.com/v1. OAuth 2.0 authorisation code is available for acting in another Middesk user's account, with up to 5 clients an account, `read_only` or `read_write` scope, no consent screen, access tokens that don't expire and a revoke endpoint. The hosted MCP server takes OAuth 2.1 with PKCE and dynamic client registration, or a live API key as a Bearer token. The account's IP allowlist applies to OAuth requests.",
      "pricing": "paid",
      "pricingNotes": "No public prices. Fees are set in an order form under the Business Verification Terms and Conditions, the site has no pricing page (middesk.com/pricing returns 404) and its buttons ask for a demo. A sandbox with mock data comes with every account. Middesk's plugin README says trial accounts exist and issue test keys only, and we didn't find how one is opened without sales. Creating a business places billable orders (checked 2026-10-08).",
      "priceSummary": "Paid",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs index, the OpenAPI spec or the site (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 11,
      "popularity": {
        "githubStars": 2,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.middesk.com",
      "llmsTxt": "https://docs.middesk.com/llms.txt",
      "openapi": "https://docs.middesk.com/openapi.json",
      "capabilities": [
        "kyc.business",
        "kyc.screening",
        "kyc.cases",
        "kyc.identity"
      ],
      "tags": [
        "hosted",
        "enterprise",
        "sales-led",
        "api-key",
        "oauth",
        "mcp",
        "openapi",
        "llms-txt",
        "webhooks",
        "sandbox",
        "graphql",
        "status-page",
        "soc2"
      ],
      "lastRelease": "2026-10-05",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 59,
        "grade": "C",
        "agentReady": false,
        "rank": 389,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 4,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 56,
          "maintenance": 64,
          "payments": 10,
          "reliability": 73,
          "schema": 82,
          "security": 56,
          "transparency": 61
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 73,
            "points": 14.6,
            "reason": "Graded on the REST API with the hosted-service lines. Statuspage at status.middesk.com with six components and incident history (20). From 10 July to 8 October 2026 it lists 13 incidents. Most are state registry sources (California, Texas, Nevada, Tennessee) running slow or offline. Two are marked major, about three hours of delayed outbound email on 28 July that blocked Middesk Agent sign-in, and ten minutes of intermittent sandbox availability on 1 September. Neither took the production API down for an hour, so we read the record as minor incidents only (20). 20 requests a second per customer is published (15). 429 is documented, with a `Retry-After` header only for sandbox business creation, and safe retries are documented for sub-account creation and lien continuations but no general idempotency key was found (8). No SLA in the public terms (0). REST v1 is generally available (10)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 82,
            "points": 13.33,
            "reason": "Public OpenAPI 3.1 spec with 62 paths and 87 operations (25). llms.txt, and every docs page is served as Markdown by adding .md (10). 41 of 87 operations carry a description, and the guides explain orders, lifecycle and review tasks, with little on when not to call an endpoint (12). 148 enums and required fields in the spec, though `GET /v1/businesses` declares no query parameters and several 422 bodies are typed as any (11). Example responses and a status code table are on the docs pages. The spec itself holds no examples, and errors are a message with an optional parameter name (9). Versioned as v1 with a dated changelog (15)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 56,
            "points": 9.1,
            "reason": "List endpoints return a simplified business item, and a few reads take `include`, but the full Business object is large (the Markdown reference page for create business is 1.4 MB) and field selection through GraphQL is early access. The MCP server has eleven tools per the vendor's README (14). `page` and `per_page` with `has_more` and `total_count`, and filters on signals, mail and sub-accounts. The spec shows no filters on the business list (15). Errors are a JSON array of messages with an optional `parameter`, with no machine-readable codes (12). No idempotency key header. `external_id` is an idempotency key for sub-accounts only, lien continuations return the one in flight, and MCP annotations couldn't be read (8). Only `name` and `addresses` are required to create a business, but no official SDK was found in any language (7)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 56,
            "points": 9.8,
            "reason": "Revocable API keys split by environment, sub-account keys managed through the API, and OAuth 2.0 with `read_only` and `read_write` scopes and a revoke endpoint. OAuth access tokens don't expire, there's no consent screen, and an API key carries full account access (24). A `read_only` token is limited to GET, the sandbox is a separate host and key, and an IP allowlist applies. The MCP server advertises only `read_write`, and no approval step for billable writes was found in the API (12). Responses carry text from websites, adverse media and an LLM-written analyst summary, and no guidance on prompt injection was found (3). Actions record who changed a business and what changed, and a timeline endpoint lists events. No log of API calls for the operator was found (7). SOC 2 Type II audited annually and a Vanta trust centre. No security.txt, disclosure policy or bug bounty found (10)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 10,
            "points": 1.25,
            "reason": "No x402, MPP or L402 (0). No public price. Fees are set in an order form and middesk.com/pricing returns 404 (0). A sandbox with mock data comes with an account, and the vendor's plugin README says trial accounts issue test keys. We couldn't establish how a trial is opened or whether it needs a card, so half credit (10). Access starts with a demo request and a dashboard sign-in (0)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 64,
            "points": 5.6,
            "reason": "Latest changelog entry 5 October 2026 (30). Nine dated entries between 20 July and 5 October (20). Closed service with a weekly changelog, a help centre and support in standard hours under the terms. No public issue tracker or community channel was found (9). No official SDK, and the MCP server isn't in the official registry. The middesk/plugins repository has four commits since 16 September 2026 (3). No published packages, and the plugins repository has no CI (2)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 61,
            "points": 5.34,
            "note": "editorial 43, provenance 78",
            "reason": "Closed service with public terms last updated 21 August 2026, and MIT plugins (15). The terms bar training generative AI models on customer data and limit ML training to de-identified data. The privacy policy of 2 November 2025 keeps data as long as necessary with no periods, and no public DPA was found (14). The API change policy promises advance notice and an opt-out for breaking changes without a notice period, the terms give 60 days' notice before data is withdrawn, and the changelog labels breaking changes (10). Socure is named for identity checks. No subprocessor list or data location was found outside the trust centre, which we couldn't read (4)."
          }
        ],
        "assessment": {
          "date": "2026-10-08",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "List endpoints return a simplified business item, and a few reads take `include`, but the full Business object is large (the Markdown reference page for create business is 1.4 MB) and field selection through GraphQL is early access. The MCP server has eleven tools per the vendor's README (14). `page` and `per_page` with `has_more` and `total_count`, and filters on signals, mail and sub-accounts. The spec shows no filters on the business list (15). Errors are a JSON array of messages with an optional `parameter`, with no machine-readable codes (12). No idempotency key header. `external_id` is an idempotency key for sub-accounts only, lien continuations return the one in flight, and MCP annotations couldn't be read (8). Only `name` and `addresses` are required to create a business, but no official SDK was found in any language (7).",
            "maintenance": "Latest changelog entry 5 October 2026 (30). Nine dated entries between 20 July and 5 October (20). Closed service with a weekly changelog, a help centre and support in standard hours under the terms. No public issue tracker or community channel was found (9). No official SDK, and the MCP server isn't in the official registry. The middesk/plugins repository has four commits since 16 September 2026 (3). No published packages, and the plugins repository has no CI (2).",
            "payments": "No x402, MPP or L402 (0). No public price. Fees are set in an order form and middesk.com/pricing returns 404 (0). A sandbox with mock data comes with an account, and the vendor's plugin README says trial accounts issue test keys. We couldn't establish how a trial is opened or whether it needs a card, so half credit (10). Access starts with a demo request and a dashboard sign-in (0).",
            "reliability": "Graded on the REST API with the hosted-service lines. Statuspage at status.middesk.com with six components and incident history (20). From 10 July to 8 October 2026 it lists 13 incidents. Most are state registry sources (California, Texas, Nevada, Tennessee) running slow or offline. Two are marked major, about three hours of delayed outbound email on 28 July that blocked Middesk Agent sign-in, and ten minutes of intermittent sandbox availability on 1 September. Neither took the production API down for an hour, so we read the record as minor incidents only (20). 20 requests a second per customer is published (15). 429 is documented, with a `Retry-After` header only for sandbox business creation, and safe retries are documented for sub-account creation and lien continuations but no general idempotency key was found (8). No SLA in the public terms (0). REST v1 is generally available (10).",
            "schema": "Public OpenAPI 3.1 spec with 62 paths and 87 operations (25). llms.txt, and every docs page is served as Markdown by adding .md (10). 41 of 87 operations carry a description, and the guides explain orders, lifecycle and review tasks, with little on when not to call an endpoint (12). 148 enums and required fields in the spec, though `GET /v1/businesses` declares no query parameters and several 422 bodies are typed as any (11). Example responses and a status code table are on the docs pages. The spec itself holds no examples, and errors are a message with an optional parameter name (9). Versioned as v1 with a dated changelog (15).",
            "security": "Revocable API keys split by environment, sub-account keys managed through the API, and OAuth 2.0 with `read_only` and `read_write` scopes and a revoke endpoint. OAuth access tokens don't expire, there's no consent screen, and an API key carries full account access (24). A `read_only` token is limited to GET, the sandbox is a separate host and key, and an IP allowlist applies. The MCP server advertises only `read_write`, and no approval step for billable writes was found in the API (12). Responses carry text from websites, adverse media and an LLM-written analyst summary, and no guidance on prompt injection was found (3). Actions record who changed a business and what changed, and a timeline endpoint lists events. No log of API calls for the operator was found (7). SOC 2 Type II audited annually and a Vanta trust centre. No security.txt, disclosure policy or bug bounty found (10).",
            "transparency": "Closed service with public terms last updated 21 August 2026, and MIT plugins (15). The terms bar training generative AI models on customer data and limit ML training to de-identified data. The privacy policy of 2 November 2025 keeps data as long as necessary with no periods, and no public DPA was found (14). The API change policy promises advance notice and an opt-out for breaking changes without a notice period, the terms give 60 days' notice before data is withdrawn, and the changelog labels breaking changes (10). Socure is named for identity checks. No subprocessor list or data location was found outside the trust centre, which we couldn't read (4)."
          },
          "sources": [
            {
              "what": "docs index for agents (llms.txt)",
              "url": "https://docs.middesk.com/llms.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "OpenAPI 3.1 spec",
              "url": "https://docs.middesk.com/openapi.json",
              "seen": "2026-10-08"
            },
            {
              "what": "API keys and environments",
              "url": "https://docs.middesk.com/build/api-keys",
              "seen": "2026-10-08"
            },
            {
              "what": "OAuth 2.0 scopes, token lifetime and revocation",
              "url": "https://docs.middesk.com/authentication/oauth",
              "seen": "2026-10-08"
            },
            {
              "what": "status codes, error format and the 20 requests a second limit",
              "url": "https://docs.middesk.com/build/status-codes-errors",
              "seen": "2026-10-08"
            },
            {
              "what": "API change and versioning policy",
              "url": "https://docs.middesk.com/build/api-changes",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP server endpoints and auth",
              "url": "https://docs.middesk.com/build/mcp-server",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP OAuth metadata",
              "url": "https://mcp.middesk.com/.well-known/oauth-authorization-server",
              "seen": "2026-10-08"
            },
            {
              "what": "vendor plugin repository, MCP tool list and billing notes",
              "url": "https://github.com/middesk/plugins",
              "seen": "2026-10-08"
            },
            {
              "what": "changelog index",
              "url": "https://docs.middesk.com/guides/get-started/changelog",
              "seen": "2026-10-08"
            },
            {
              "what": "changelog entry of 17 August 2026 (breaking lien change, sandbox 429)",
              "url": "https://docs.middesk.com/guides/get-started/changelog/2026/8/17",
              "seen": "2026-10-08"
            },
            {
              "what": "webhook events, retries and signing",
              "url": "https://docs.middesk.com/build/webhooks",
              "seen": "2026-10-08"
            },
            {
              "what": "sandbox and trigger values",
              "url": "https://docs.middesk.com/environments",
              "seen": "2026-10-08"
            },
            {
              "what": "status incidents (Statuspage JSON)",
              "url": "https://status.middesk.com/api/v2/incidents.json",
              "seen": "2026-10-08"
            },
            {
              "what": "security certifications",
              "url": "https://docs.middesk.com/security/certifications-principles",
              "seen": "2026-10-08"
            },
            {
              "what": "Business Verification Terms and Conditions, 21 August 2026",
              "url": "https://www.middesk.com/policies/bv-msa",
              "seen": "2026-10-08"
            },
            {
              "what": "privacy policy, 2 November 2025",
              "url": "https://www.middesk.com/policies/privacy-policy",
              "seen": "2026-10-08"
            },
            {
              "what": "security.txt (404)",
              "url": "https://www.middesk.com/.well-known/security.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "official MCP registry search (no result)",
              "url": "https://registry.modelcontextprotocol.io/v0.1/servers?search=middesk",
              "seen": "2026-10-08"
            },
            {
              "what": "domain registration (RDAP)",
              "url": "https://rdap.verisign.com/com/v1/domain/middesk.com",
              "seen": "2026-10-08"
            }
          ],
          "openQuestions": [
            "unchecked: the MCP server's tool definitions, input schemas and annotations. tools/list needs a token, so the count of eleven comes from the vendor's plugin README",
            "unchecked: the trust centre at trust.middesk.com, which only renders with JavaScript. The SOC 2 report, any subprocessor list and any DPA may sit there",
            "unchecked: how a trial account is opened. The plugin README says trial accounts exist and issue test keys only. The site shows only a demo request, and app.middesk.com/signup is a JavaScript shell",
            "Whether an SLA exists in order forms. None is in the public terms",
            "Whether customers had notice before the 17 August 2026 lien `packet_number` change. The policy says affected customers are told in advance, and we could see only the changelog entry",
            "Whether production 429 responses carry `Retry-After`. The changelog documents it for sandbox business creation only",
            "Whether `unique_external_id` makes `POST /v1/businesses` safe to retry. The spec types it as a string with no description",
            "Per-check prices, which are set in an order form"
          ]
        },
        "negative": 0,
        "verdict": "A public OpenAPI 3.1 contract for 87 operations, llms.txt, Markdown docs and a dated weekly changelog make the REST API readable to an agent, and OAuth has a read-only scope. Access is sales-led. No price, self-serve signup or official SDK was found, and the hosted MCP server rejects sandbox keys.",
        "bestFor": "An agent onboarding or re-checking US businesses for a bank, lender or marketplace that already holds a Middesk contract, with registry, TIN, sanctions and lien data in one object.",
        "strengths": [
          "Public OpenAPI 3.1 spec with 87 operations and 373 schemas, plus llms.txt and a Markdown copy of every docs page",
          "Dated changelog with nine entries between 20 July and 5 October 2026, breaking changes labelled as such",
          "OAuth 2.0 with `read_only` and `read_write` scopes and a revoke endpoint. The MCP server adds PKCE and dynamic client registration",
          "Sandbox at api-sandbox.middesk.com with documented trigger values for names, addresses, TINs, people and watchlist hits",
          "The public terms of 21 August 2026 bar training generative AI models on customer data in any form"
        ],
        "weaknesses": [
          "No public price. Fees are set in an order form, and every docs page ends with a prompt to contact sales",
          "No official SDK found on npm, PyPI or RubyGems, and none in the vendor's GitHub organisation",
          "The hosted MCP server runs against production only, so a sandbox key fails on every call",
          "Creating a business places billable orders, and an empty `orders` array doesn't prevent that",
          "OAuth access tokens don't expire, and no security.txt, disclosure policy or bug bounty was found"
        ],
        "agentNotes": [
          "Match the key to the host. `mk_test` keys work only at https://api-sandbox.middesk.com/v1 and `mk_live` keys only at https://api.middesk.com/v1",
          "Name the `orders` on `POST /v1/businesses`. Omitting them places a verification order plus every package the account runs automatically, all billed",
          "Send `address_line1` and `address_line2`. The API ignores `address_line_1` without an error",
          "A 201 means the business was created, not verified. Wait for the `business.updated` webhook or poll until `status` leaves `pending`",
          "Stay under 20 requests a second per account, and in sandbox wait the seconds in `Retry-After` after a 429 on business creation"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 59
          }
        ],
        "editorialScores": {
          "ergonomics": 56,
          "maintenance": 64,
          "payments": 10,
          "reliability": 73,
          "schema": 82,
          "security": 56,
          "transparency": 43
        },
        "provenanceScore": 78
      },
      "connect": {
        "http": "curl -X POST https://api-sandbox.middesk.com/v1/businesses \\\n  -u $MIDDESK_SANDBOX_API_KEY: \\\n  -H \"Accept: application/json\" \\\n  -d name=Corporation \\\n  -d addresses\\[0\\]\\[address_line1\\]=223+Grand+St. \\\n  -d addresses\\[0\\]\\[city\\]=new+york \\\n  -d addresses\\[0\\]\\[state\\]=NY \\\n  -d addresses\\[0\\]\\[postal_code\\]=10013",
        "claudeCode": "claude mcp add --transport http middesk https://mcp.middesk.com/mcp \\\n  --header \"Authorization: Bearer mk_live_...\"",
        "config": {
          "mcpServers": {
            "middesk": {
              "headers": {
                "Authorization": "Bearer mk_live_your_api_key"
              },
              "url": "https://mcp.middesk.com/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/kyc.business",
        "tool": "https://letme.dev/middesk"
      },
      "notable": [
        "The REST API has a public OpenAPI 3.1 spec with 62 paths and 87 operations covering businesses, orders, signals, monitoring, liens, webhooks, agent runs and sub-accounts (https://docs.middesk.com/openapi.json)",
        "A hosted MCP server answers at https://mcp.middesk.com/mcp (Streamable HTTP) and https://mcp.middesk.com/sse, with OAuth 2.1 or a live API key (https://docs.middesk.com/build/mcp-server)",
        "The vendor's plugin README lists eleven MCP tools, among them create_business, retrieve_business, list_businesses, create_order, list_enabled_packages and create_signal, and says the server runs against production only (https://github.com/middesk/plugins)",
        "OFAC sanctions screening runs automatically on every business created, with adverse media, politically exposed persons and watchlist monitoring as further products (https://docs.middesk.com/verify-business/sanctions)",
        "Identity checks on a business's people run through Socure, which Middesk provisions after a contract is signed (https://docs.middesk.com/verify-business/kyc)",
        "The changelog entry of 31 August 2026 says earlier examples and the request schema showed `address_line_1`, a key the API ignores, so street lines were dropped without an error (https://docs.middesk.com/guides/get-started/changelog/2026/8/31)",
        "The public terms say Middesk may not use customer data in any form to train or fine-tune generative AI models, and may train its ML models only on de-identified data (https://www.middesk.com/policies/bv-msa)"
      ],
      "area": "domain-data",
      "details": [
        {
          "label": "Graded surface",
          "value": "The public REST API at https://api.middesk.com/v1 (sandbox at https://api-sandbox.middesk.com/v1). The hosted MCP server is noted alongside it"
        },
        {
          "label": "API",
          "value": "OpenAPI 3.1, 62 paths, 87 operations (51 GET, 24 POST, 5 DELETE, 4 PATCH, 3 PUT), 373 schemas. Version v1, with no dated versions"
        },
        {
          "label": "MCP server",
          "value": "Hosted at https://mcp.middesk.com/mcp and /sse. Eleven tools per the vendor's plugin README, two of them behind an account entitlement. Production only, so test keys are rejected. Not in the official MCP registry"
        },
        {
          "label": "Checks",
          "value": "Secretary of State registrations, TIN match, name and address, owners and officers, OFAC and watchlists, adverse media, politically exposed persons, web presence, industry classification, liens, litigation, bankruptcies, and international registrations"
        },
        {
          "label": "Credentials",
          "value": "API keys per environment (`mk_test`, `mk_live`), OAuth 2.0 with `read_only` or `read_write` scope and non-expiring tokens, OAuth 2.1 with PKCE and dynamic client registration on the MCP server, sub-account keys through the API"
        },
        {
          "label": "Rate limits",
          "value": "20 requests a second per customer. Sandbox business creation has a per-minute limit that answers 429 with `Retry-After`"
        },
        {
          "label": "Errors",
          "value": "JSON `errors` array with a `message` and an optional `parameter`. Documented statuses are 200, 201, 202, 400, 401, 404, 422, 429 and 500"
        },
        {
          "label": "Pagination",
          "value": "`page` and `per_page`, with `has_more` and `total_count` in list responses"
        },
        {
          "label": "Webhooks",
          "value": "HMAC SHA-256 signature in `X-Middesk-Signature-256`, or mutual TLS or OAuth tokens. Up to 10 retries over about 3 days. Separate endpoints for sandbox and production"
        },
        {
          "label": "Sandbox",
          "value": "Mock results driven by trigger values in the submitted name, address, TIN and people, plus an enhanced sandbox with configurable scenarios in the dashboard"
        },
        {
          "label": "GraphQL",
          "value": "https://api.middesk.com/graphql, optional, a subset of the REST API. The vendor's release post describes it as early access for a limited set of customers"
        },
        {
          "label": "SDKs",
          "value": "None found. `middesk` returns 404 on npm, PyPI and RubyGems. middesk/plugins holds a Claude Code plugin and a ChatGPT and Codex plugin, both marked in development"
        },
        {
          "label": "Certifications",
          "value": "SOC 2 Type II, audited annually, and alignment with the NIST Cybersecurity Framework per the docs. The report sits in a trust centre at trust.middesk.com"
        },
        {
          "label": "Status",
          "value": "status.middesk.com on Statuspage, six components (Business Verification, APIs, TIN Match, Signal, Dashboard, Entity Management)"
        },
        {
          "label": "AI training",
          "value": "The public terms bar training generative AI models on customer data in any form, and allow ML training only on de-identified data"
        }
      ],
      "provenance": {
        "legalEntity": "Middesk, Inc.",
        "domain": "middesk.com",
        "domainRegistered": "2018-11-20",
        "endpointOnVendorDomain": true,
        "terms": "https://www.middesk.com/policies/bv-msa",
        "privacy": "https://www.middesk.com/policies/privacy-policy",
        "statusPage": "https://status.middesk.com",
        "changelog": "https://docs.middesk.com/guides/get-started/changelog",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The Business Verification Terms and Conditions (last updated 21 August 2026) define Middesk as Middesk, Inc. The website terms (last updated 9 November 2023) give the address 85 2nd St., Suite 710, San Francisco, CA 94105.",
          "The API answers at api.middesk.com and api-sandbox.middesk.com, and the MCP server at mcp.middesk.com, all middesk.com subdomains.",
          "security.txt returns 404 on www.middesk.com, docs.middesk.com and api.middesk.com.",
          "The privacy policy was last updated on 2 November 2025 and gives no retention periods.",
          "trust.middesk.com is a Vanta trust centre that only renders with JavaScript, so we couldn't read its contents.",
          "RDAP for middesk.com gives a registration date of 2018-11-20."
        ],
        "score": 78,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Middesk, Inc.",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "middesk.com, registered 2018-11-20 (7 years)",
            "points": 11,
            "max": 15,
            "state": "part"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "api.middesk.com",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Terms of service",
            "value": "read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points",
            "points": 5.1,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 4 of the 8 things a reader expects",
            "points": 7,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Status page",
            "value": "status.middesk.com",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://www.middesk.com/policies/bv-msa",
            "state": "read",
            "readAt": "2026-10-08",
            "words": 8068,
            "points": 5.1,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": false
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": true,
                "quote": "The Agreement is governed by and construed in accordance with the laws of the state of California, without giving effect to its conflict of laws provisions.",
                "says": "The law of the State of California"
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": true,
                "quote": "…THE AGREEMENT, REGARDLESS OF THE LEGAL OR EQUITABLE THEORY, IS LIMITED TO DIRECT DAMAGES, WHICH WILL NOT EXCEED THE AMOUNT PAID BY CUSTOMER TO MIDDESK UNDER THE AGREEMENT FOR THE PARTICULAR SERVICES THAT ARE THE SUBJECT OF THE CLAIM DURING THE TWELVE-MONTH PERIOD PRECEDING THE DATE ON WHICH THE CLAIM WAS MADE.",
                "says": "Capped at the fees paid in the 12 months before the claim"
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "…affected Services or materially increases Customer’s total cost for the affected Services, Customer may terminate the affected Services upon thirty (30) days’ written notice delivered within sixty (60) days after Middesk’s notice, and Middesk shall refund any pre-paid, unused Fees for the terminated Services on a pro-…"
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": true,
                "quote": "Middesk may, upon sixty (60) days' prior written notice to Customer: (i) withdraw or restrict access to Middesk Data and modify the terms of the Agreement or the Services where reasonably necessary to comply with applicable law or third-party supplier requirements or to address privacy, confidentiality, or security;",
                "says": "Gives sixty days of notice before a change"
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": true,
                "quote": "Customer shall not, directly or indirectly: (i) reverse engineer, decompile, disassemble, or otherwise attempt to discover the source code, object code, or underlying structure, ideas, know-how, or algorithms relevant to the Services or any software, documentation, or data related to the Platform;"
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": true,
                "quote": "No specific response time, resolution time, or service availability commitment applies under this Agreement unless expressly set forth in an SLA Schedule attached to an applicable Order Form."
              }
            ],
            "toKnow": [
              {
                "key": "training",
                "label": "Says it may use customer content to train or improve models, and no opt-out was found",
                "found": true,
                "quote": "For the avoidance of doubt, Middesk may extract, aggregate, and use anonymized or de-identified features and signals derived from Customer Data to train and improve its ML models, provided that such derived features cannot reasonably be used to re-identify Customer or any individual whose data is reflected in the Cust…",
                "costsPoints": true
              },
              {
                "key": "terms.benchmark",
                "label": "Restricts benchmarking or competitive use",
                "found": true,
                "quote": "use, transform, modify, or adapt the Services, Platform, or Middesk Data for any other purpose, including the development or functioning of any product or service that is competitive, in part or in whole, with any product or service of Middesk that is then generally available",
                "costsPoints": true
              },
              {
                "key": "terms.arbitration",
                "label": "Requires arbitration or waives class actions",
                "found": true,
                "quote": "Any dispute not resolved by the Parties by mutual consultation will be determined by arbitration in San Francisco, California before a single arbitrator."
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "On terminations other than for Middesk's uncured breach, the customer owes the minimum fees for the rest of the current term.",
                "quote": "Customer shall pay (1) all Fees for Services through the effective date of termination, and (2) the minimum Fees due for the remainder of the then-current Term, discounted to present value at the prime rate published in The Wall Street Journal in effect as of the effective date of termination."
              },
              {
                "date": "2026-10-08",
                "text": "The agreement renews automatically unless either party gives written notice of non-renewal at least 60 days before the current term ends.",
                "quote": "this Agreement is for the Initial Term, and will be automatically renewed for additional periods specified on the Order Form, unless either Party delivers written notice of non-renewal at least sixty (60) days prior to the end of the then-current term."
              },
              {
                "date": "2026-10-08",
                "text": "Middesk may audit the customer's and its affiliates' compliance once a year on 30 days' written notice.",
                "quote": "Customer agrees that Middesk will have the right, no more than once annually and upon at least thirty (30) days’ prior written notice, to audit Customer’s and any of its Affiliates’ compliance with the terms of the Agreement"
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://www.middesk.com/policies/privacy-policy",
            "state": "read",
            "readAt": "2026-10-08",
            "words": 1977,
            "points": 7,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": false
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": true,
                "quote": "We collect your PII when you or your employer provide it to us when utilizing the services, when participating in activities on the Sites, or otherwise contacting us."
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": true,
                "quote": "We will only keep your PII for as long as it is necessary for the purposes set out in this Privacy Policy, unless a longer retention period is required or permitted by law (such as tax, accounting or other legal requirements).",
                "says": "For as long as needed, with no period named"
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "The collection, sharing and use of personally identifiable information (PII) by our service providers, third-party partners, and customers are governed by their respective privacy policies."
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": false
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": false
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "If you have any questions or concerns about our privacy policy, or our practices with regards to your personal information, please contact us at [email protected].",
                "says": "Gives an email address, hidden from our reader by the page"
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": false
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "The policy lists passwords and similar security information for third party websites among the personal information Middesk collects.",
                "quote": "We collect passwords, password hints, and similar security information used for authentication and account access to third party websites."
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/middesk.json",
      "live": {
        "slug": "middesk",
        "probe": {
          "target": "https://api.middesk.com/v1",
          "method": "get",
          "lastAt": "2026-10-08T18:20:34.934226551Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 190,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 212,
          "p95ms24h": 316,
          "samples24h": 33,
          "samples30d": 33,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 33,
              "ok": 33
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.middesk.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T18:22:07.547803744Z"
        },
        "githubStars": 2,
        "securityTxt": {
          "url": "https://middesk.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:39.426096193Z"
        },
        "pages": [
          {
            "url": "https://docs.middesk.com/guides/get-started/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:19:07.781323249Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "eebdc6aa87ba"
          }
        ],
        "updatedAt": "2026-10-08T18:22:07.547803744Z"
      }
    },
    "verify": {
      "accepts": "a page on middesk.com or one of its subdomains, or the README of github.com/middesk/plugins",
      "badgeUrl": "https://www.anchorterminal.com/badges/middesk.svg",
      "body": {
        "slug": "middesk",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/middesk",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/middesk\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/middesk.svg\" alt=\"Middesk on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Middesk on Anchor Terminal](https://www.anchorterminal.com/badges/middesk.svg)](https://www.anchorterminal.com/tools/middesk)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/middesk\"\u003eMiddesk on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/middesk",
    "json": "https://www.anchorterminal.com/tools/middesk.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/middesk.md",
    "slim": "https://www.anchorterminal.com/tools/middesk.min.md"
  },
  "markdown": "## Overview\n\n**Grade C · 59/100 · rank #389 of 629 · #4 in Identity \u0026 business verification · not agent-ready · confidence medium**\n\n\n## Assessment\n\nA public OpenAPI 3.1 contract for 87 operations, llms.txt, Markdown docs and a dated weekly changelog make the REST API readable to an agent, and OAuth has a read-only scope. Access is sales-led. No price, self-serve signup or official SDK was found, and the hosted MCP server rejects sandbox keys.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Middesk, Inc. (https://www.middesk.com) |\n| Kind | HTTP API |\n| Category | Identity \u0026 business verification (https://www.anchorterminal.com/categories/identity-verification) |\n| Transport | HTTP |\n| Endpoint | `https://api.middesk.com/v1` |\n| Auth | OAuth or key · Access is granted by Middesk's sales team, and keys are then created in the dashboard under Settings, Developer, Credentials. An API key goes as the Basic auth username or as a Bearer token. `mk_test` keys work only against https://api-sandbox.middesk.com/v1 and `mk_live` keys only against https://api.middesk.com/v1. OAuth 2.0 authorisation code is available for acting in another Middesk user's account, with up to 5 clients an account, `read_only` or `read_write` scope, no consent screen, access tokens that don't expire and a revoke endpoint. The hosted MCP server takes OAuth 2.1 with PKCE and dynamic client registration, or a live API key as a Bearer token. The account's IP allowlist applies to OAuth requests. |\n| Pricing | Paid (Paid) · No public prices. Fees are set in an order form under the Business Verification Terms and Conditions, the site has no pricing page (middesk.com/pricing returns 404) and its buttons ask for a demo. A sandbox with mock data comes with every account. Middesk's plugin README says trial accounts exist and issue test keys only, and we didn't find how one is opened without sales. Creating a business places billable orders (checked 2026-10-08). |\n| x402 | No · No x402, MPP or L402 in the docs index, the OpenAPI spec or the site (checked 2026-10-08). |\n| Licence | Proprietary service under Middesk's Business Verification Terms and Conditions. The Claude Code and Codex plugins on GitHub are MIT |\n| Tools exposed | 11 |\n| Source | https://github.com/middesk/plugins |\n| Docs | https://docs.middesk.com |\n| llms.txt | https://docs.middesk.com/llms.txt |\n| Last release | 2026-10-05 |\n| GitHub stars | 2 (as of 2026-10-08) |\n| Graded surface | The public REST API at https://api.middesk.com/v1 (sandbox at https://api-sandbox.middesk.com/v1). The hosted MCP server is noted alongside it |\n| API | OpenAPI 3.1, 62 paths, 87 operations (51 GET, 24 POST, 5 DELETE, 4 PATCH, 3 PUT), 373 schemas. Version v1, with no dated versions |\n| MCP server | Hosted at https://mcp.middesk.com/mcp and /sse. Eleven tools per the vendor's plugin README, two of them behind an account entitlement. Production only, so test keys are rejected. Not in the official MCP registry |\n| Checks | Secretary of State registrations, TIN match, name and address, owners and officers, OFAC and watchlists, adverse media, politically exposed persons, web presence, industry classification, liens, litigation, bankruptcies, and international registrations |\n| Credentials | API keys per environment (`mk_test`, `mk_live`), OAuth 2.0 with `read_only` or `read_write` scope and non-expiring tokens, OAuth 2.1 with PKCE and dynamic client registration on the MCP server, sub-account keys through the API |\n| Rate limits | 20 requests a second per customer. Sandbox business creation has a per-minute limit that answers 429 with `Retry-After` |\n| Errors | JSON `errors` array with a `message` and an optional `parameter`. Documented statuses are 200, 201, 202, 400, 401, 404, 422, 429 and 500 |\n| Pagination | `page` and `per_page`, with `has_more` and `total_count` in list responses |\n| Webhooks | HMAC SHA-256 signature in `X-Middesk-Signature-256`, or mutual TLS or OAuth tokens. Up to 10 retries over about 3 days. Separate endpoints for sandbox and production |\n| Sandbox | Mock results driven by trigger values in the submitted name, address, TIN and people, plus an enhanced sandbox with configurable scenarios in the dashboard |\n| GraphQL | https://api.middesk.com/graphql, optional, a subset of the REST API. The vendor's release post describes it as early access for a limited set of customers |\n| SDKs | None found. `middesk` returns 404 on npm, PyPI and RubyGems. middesk/plugins holds a Claude Code plugin and a ChatGPT and Codex plugin, both marked in development |\n| Certifications | SOC 2 Type II, audited annually, and alignment with the NIST Cybersecurity Framework per the docs. The report sits in a trust centre at trust.middesk.com |\n| Status | status.middesk.com on Statuspage, six components (Business Verification, APIs, TIN Match, Signal, Dashboard, Entity Management) |\n| AI training | The public terms bar training generative AI models on customer data in any form, and allow ML training only on de-identified data |\n| Capabilities | kyc.business, kyc.screening, kyc.cases, kyc.identity |\n| Tags | hosted, enterprise, sales-led, api-key, oauth, mcp, openapi, llms-txt, webhooks, sandbox, graphql, status-page, soc2 |\n| JSON | https://www.anchorterminal.com/api/v1/tools/middesk.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 73 | 14.6 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 82 | 13.3 |\n| Agent ergonomics | 13% | 16.2 | 56 | 9.1 |\n| Security \u0026 auth | 14% | 17.5 | 56 | 9.8 |\n| Payments \u0026 pricing | 10% | 12.5 | 10 | 1.2 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 64 | 5.6 |\n| Transparency \u0026 trust (editorial 43, provenance 78) | 7% | 8.8 | 61 | 5.3 |\n| Negative events | up to −15 | up to −15 | none recorded | 0 |\n| **Total** | | | | **59 → C** |\n\n### Why each score\n\n- Reliability 73: Graded on the REST API with the hosted-service lines. Statuspage at status.middesk.com with six components and incident history (20). From 10 July to 8 October 2026 it lists 13 incidents. Most are state registry sources (California, Texas, Nevada, Tennessee) running slow or offline. Two are marked major, about three hours of delayed outbound email on 28 July that blocked Middesk Agent sign-in, and ten minutes of intermittent sandbox availability on 1 September. Neither took the production API down for an hour, so we read the record as minor incidents only (20). 20 requests a second per customer is published (15). 429 is documented, with a `Retry-After` header only for sandbox business creation, and safe retries are documented for sub-account creation and lien continuations but no general idempotency key was found (8). No SLA in the public terms (0). REST v1 is generally available (10).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 82: Public OpenAPI 3.1 spec with 62 paths and 87 operations (25). llms.txt, and every docs page is served as Markdown by adding .md (10). 41 of 87 operations carry a description, and the guides explain orders, lifecycle and review tasks, with little on when not to call an endpoint (12). 148 enums and required fields in the spec, though `GET /v1/businesses` declares no query parameters and several 422 bodies are typed as any (11). Example responses and a status code table are on the docs pages. The spec itself holds no examples, and errors are a message with an optional parameter name (9). Versioned as v1 with a dated changelog (15).\n- Agent ergonomics 56: List endpoints return a simplified business item, and a few reads take `include`, but the full Business object is large (the Markdown reference page for create business is 1.4 MB) and field selection through GraphQL is early access. The MCP server has eleven tools per the vendor's README (14). `page` and `per_page` with `has_more` and `total_count`, and filters on signals, mail and sub-accounts. The spec shows no filters on the business list (15). Errors are a JSON array of messages with an optional `parameter`, with no machine-readable codes (12). No idempotency key header. `external_id` is an idempotency key for sub-accounts only, lien continuations return the one in flight, and MCP annotations couldn't be read (8). Only `name` and `addresses` are required to create a business, but no official SDK was found in any language (7).\n- Security \u0026 auth 56: Revocable API keys split by environment, sub-account keys managed through the API, and OAuth 2.0 with `read_only` and `read_write` scopes and a revoke endpoint. OAuth access tokens don't expire, there's no consent screen, and an API key carries full account access (24). A `read_only` token is limited to GET, the sandbox is a separate host and key, and an IP allowlist applies. The MCP server advertises only `read_write`, and no approval step for billable writes was found in the API (12). Responses carry text from websites, adverse media and an LLM-written analyst summary, and no guidance on prompt injection was found (3). Actions record who changed a business and what changed, and a timeline endpoint lists events. No log of API calls for the operator was found (7). SOC 2 Type II audited annually and a Vanta trust centre. No security.txt, disclosure policy or bug bounty found (10).\n- Payments \u0026 pricing 10: No x402, MPP or L402 (0). No public price. Fees are set in an order form and middesk.com/pricing returns 404 (0). A sandbox with mock data comes with an account, and the vendor's plugin README says trial accounts issue test keys. We couldn't establish how a trial is opened or whether it needs a card, so half credit (10). Access starts with a demo request and a dashboard sign-in (0).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 64: Latest changelog entry 5 October 2026 (30). Nine dated entries between 20 July and 5 October (20). Closed service with a weekly changelog, a help centre and support in standard hours under the terms. No public issue tracker or community channel was found (9). No official SDK, and the MCP server isn't in the official registry. The middesk/plugins repository has four commits since 16 September 2026 (3). No published packages, and the plugins repository has no CI (2).\n- Transparency \u0026 trust 61: Closed service with public terms last updated 21 August 2026, and MIT plugins (15). The terms bar training generative AI models on customer data and limit ML training to de-identified data. The privacy policy of 2 November 2025 keeps data as long as necessary with no periods, and no public DPA was found (14). The API change policy promises advance notice and an opt-out for breaking changes without a notice period, the terms give 60 days' notice before data is withdrawn, and the changelog labels breaking changes (10). Socure is named for identity checks. No subprocessor list or data location was found outside the trust centre, which we couldn't read (4).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (19 items): https://www.anchorterminal.com/fixes/middesk.md (JSON https://www.anchorterminal.com/fixes/middesk.json)\n\n### What we couldn't check\n\n- unchecked: the MCP server's tool definitions, input schemas and annotations. tools/list needs a token, so the count of eleven comes from the vendor's plugin README\n- unchecked: the trust centre at trust.middesk.com, which only renders with JavaScript. The SOC 2 report, any subprocessor list and any DPA may sit there\n- unchecked: how a trial account is opened. The plugin README says trial accounts exist and issue test keys only. The site shows only a demo request, and app.middesk.com/signup is a JavaScript shell\n- Whether an SLA exists in order forms. None is in the public terms\n- Whether customers had notice before the 17 August 2026 lien `packet_number` change. The policy says affected customers are told in advance, and we could see only the changelog entry\n- Whether production 429 responses carry `Retry-After`. The changelog documents it for sandbox business creation only\n- Whether `unique_external_id` makes `POST /v1/businesses` safe to retry. The spec types it as a string with no description\n- Per-check prices, which are set in an order form\n\n### Sources\n\n- docs index for agents (llms.txt): \u003chttps://docs.middesk.com/llms.txt\u003e (seen 2026-10-08)\n- OpenAPI 3.1 spec: \u003chttps://docs.middesk.com/openapi.json\u003e (seen 2026-10-08)\n- API keys and environments: \u003chttps://docs.middesk.com/build/api-keys\u003e (seen 2026-10-08)\n- OAuth 2.0 scopes, token lifetime and revocation: \u003chttps://docs.middesk.com/authentication/oauth\u003e (seen 2026-10-08)\n- status codes, error format and the 20 requests a second limit: \u003chttps://docs.middesk.com/build/status-codes-errors\u003e (seen 2026-10-08)\n- API change and versioning policy: \u003chttps://docs.middesk.com/build/api-changes\u003e (seen 2026-10-08)\n- MCP server endpoints and auth: \u003chttps://docs.middesk.com/build/mcp-server\u003e (seen 2026-10-08)\n- MCP OAuth metadata: \u003chttps://mcp.middesk.com/.well-known/oauth-authorization-server\u003e (seen 2026-10-08)\n- vendor plugin repository, MCP tool list and billing notes: \u003chttps://github.com/middesk/plugins\u003e (seen 2026-10-08)\n- changelog index: \u003chttps://docs.middesk.com/guides/get-started/changelog\u003e (seen 2026-10-08)\n- changelog entry of 17 August 2026 (breaking lien change, sandbox 429): \u003chttps://docs.middesk.com/guides/get-started/changelog/2026/8/17\u003e (seen 2026-10-08)\n- webhook events, retries and signing: \u003chttps://docs.middesk.com/build/webhooks\u003e (seen 2026-10-08)\n- sandbox and trigger values: \u003chttps://docs.middesk.com/environments\u003e (seen 2026-10-08)\n- status incidents (Statuspage JSON): \u003chttps://status.middesk.com/api/v2/incidents.json\u003e (seen 2026-10-08)\n- security certifications: \u003chttps://docs.middesk.com/security/certifications-principles\u003e (seen 2026-10-08)\n- Business Verification Terms and Conditions, 21 August 2026: \u003chttps://www.middesk.com/policies/bv-msa\u003e (seen 2026-10-08)\n- privacy policy, 2 November 2025: \u003chttps://www.middesk.com/policies/privacy-policy\u003e (seen 2026-10-08)\n- security.txt (404): \u003chttps://www.middesk.com/.well-known/security.txt\u003e (seen 2026-10-08)\n- official MCP registry search (no result): \u003chttps://registry.modelcontextprotocol.io/v0.1/servers?search=middesk\u003e (seen 2026-10-08)\n- domain registration (RDAP): \u003chttps://rdap.verisign.com/com/v1/domain/middesk.com\u003e (seen 2026-10-08)\n\n## Who's behind it (provenance 78/100, checked 2026-10-08)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Middesk, Inc. | 20/20 |\n| Domain age | middesk.com, registered 2018-11-20 (7 years) | 11/15 |\n| Endpoint on the vendor's domain | api.middesk.com | 15/15 |\n| Terms of service | read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points | 5.1/10 |\n| Privacy policy | read, states 4 of the 8 things a reader expects | 7/10 |\n| Status page | status.middesk.com | 10/10 |\n| Changelog | published | 10/10 |\n| security.txt | not found | 0/10 |\n\nThe Business Verification Terms and Conditions (last updated 21 August 2026) define Middesk as Middesk, Inc. The website terms (last updated 9 November 2023) give the address 85 2nd St., Suite 710, San Francisco, CA 94105.\n\nThe API answers at api.middesk.com and api-sandbox.middesk.com, and the MCP server at mcp.middesk.com, all middesk.com subdomains.\n\nsecurity.txt returns 404 on www.middesk.com, docs.middesk.com and api.middesk.com.\n\nThe privacy policy was last updated on 2 November 2025 and gives no retention periods.\n\ntrust.middesk.com is a Vanta trust centre that only renders with JavaScript, so we couldn't read its contents.\n\nRDAP for middesk.com gives a registration date of 2018-11-20.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://www.middesk.com/policies/bv-msa), read 2026-10-08, gives no date, states 6 of the 7 things a reader expects.\n\n- To know. Says it may use customer content to train or improve models, and no opt-out was found (costs points). \"For the avoidance of doubt, Middesk may extract, aggregate, and use anonymized or de-identified features and signals derived from Customer Data to train and improve its ML models, provided that such derived features cannot reasonably be used to re-identify Customer or any individual whose data is reflected in the Cust…\"\n- To know. Restricts benchmarking or competitive use (costs points). \"use, transform, modify, or adapt the Services, Platform, or Middesk Data for any other purpose, including the development or functioning of any product or service that is competitive, in part or in whole, with any product or service of Middesk that is then generally available\"\n- To know. Requires arbitration or waives class actions. \"Any dispute not resolved by the Parties by mutual consultation will be determined by arbitration in San Francisco, California before a single arbitrator.\"\n- Not found in the text. Gives the date it was last updated.\n- Names the governing law or courts. The law of the State of California.\n- States a limit on its liability. Capped at the fees paid in the 12 months before the claim.\n- Says how changes to the terms are announced. Gives sixty days of notice before a change.\n- Also in the text (2026-10-08). On terminations other than for Middesk's uncured breach, the customer owes the minimum fees for the rest of the current term. \"Customer shall pay (1) all Fees for Services through the effective date of termination, and (2) the minimum Fees due for the remainder of the then-current Term, discounted to present value at the prime rate published in The Wall Street Journal in effect as of the effective date of termination.\"\n- Also in the text (2026-10-08). The agreement renews automatically unless either party gives written notice of non-renewal at least 60 days before the current term ends. \"this Agreement is for the Initial Term, and will be automatically renewed for additional periods specified on the Order Form, unless either Party delivers written notice of non-renewal at least sixty (60) days prior to the end of the then-current term.\"\n- Also in the text (2026-10-08). Middesk may audit the customer's and its affiliates' compliance once a year on 30 days' written notice. \"Customer agrees that Middesk will have the right, no more than once annually and upon at least thirty (30) days’ prior written notice, to audit Customer’s and any of its Affiliates’ compliance with the terms of the Agreement\"\n\n**Privacy policy** (https://www.middesk.com/policies/privacy-policy), read 2026-10-08, gives no date, states 4 of the 8 things a reader expects.\n\n- Not found in the text. Gives the date it was last updated.\n- Says how long data is kept. For as long as needed, with no period named.\n- Not found in the text. Says whether personal data is sold or shared for advertising.\n- Not found in the text. Says what rights people have over their data.\n- Gives a privacy contact. Gives an email address, hidden from our reader by the page.\n- Not found in the text. Says where data is transferred or stored.\n- Also in the text (2026-10-08). The policy lists passwords and similar security information for third party websites among the personal information Middesk collects. \"We collect passwords, password hints, and similar security information used for authentication and account access to third party websites.\"\n\n## Live (updated 2026-10-08 18:22 UTC)\n\n- Right now: up, HTTP 404, 190 ms, checked 2026-10-08 18:20 UTC (get on `https://api.middesk.com/v1`)\n- Uptime 24h 100.0% (33 probes) · 30 days 100.0% (33 probes) · p50 212 ms · p95 316 ms\n- Vendor status page: none, All Systems Operational\n- security.txt: none\n- Watching changelog \u003chttps://docs.middesk.com/guides/get-started/changelog\u003e\n- Always current: https://www.anchorterminal.com/api/v1/live/middesk.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Strengths\n\n- Public OpenAPI 3.1 spec with 87 operations and 373 schemas, plus llms.txt and a Markdown copy of every docs page\n- Dated changelog with nine entries between 20 July and 5 October 2026, breaking changes labelled as such\n- OAuth 2.0 with `read_only` and `read_write` scopes and a revoke endpoint. The MCP server adds PKCE and dynamic client registration\n- Sandbox at api-sandbox.middesk.com with documented trigger values for names, addresses, TINs, people and watchlist hits\n- The public terms of 21 August 2026 bar training generative AI models on customer data in any form\n\n## Weaknesses\n\n- No public price. Fees are set in an order form, and every docs page ends with a prompt to contact sales\n- No official SDK found on npm, PyPI or RubyGems, and none in the vendor's GitHub organisation\n- The hosted MCP server runs against production only, so a sandbox key fails on every call\n- Creating a business places billable orders, and an empty `orders` array doesn't prevent that\n- OAuth access tokens don't expire, and no security.txt, disclosure policy or bug bounty was found\n\n## Before you call it (notes for agents)\n\n1. Match the key to the host. `mk_test` keys work only at https://api-sandbox.middesk.com/v1 and `mk_live` keys only at https://api.middesk.com/v1\n2. Name the `orders` on `POST /v1/businesses`. Omitting them places a verification order plus every package the account runs automatically, all billed\n3. Send `address_line1` and `address_line2`. The API ignores `address_line_1` without an error\n4. A 201 means the business was created, not verified. Wait for the `business.updated` webhook or poll until `status` leaves `pending`\n5. Stay under 20 requests a second per account, and in sandbox wait the seconds in `Retry-After` after a 429 on business creation\n\n## Connect\n\nFirst request:\n\n```bash\ncurl -X POST https://api-sandbox.middesk.com/v1/businesses \\\n  -u $MIDDESK_SANDBOX_API_KEY: \\\n  -H \"Accept: application/json\" \\\n  -d name=Corporation \\\n  -d addresses\\[0\\]\\[address_line1\\]=223+Grand+St. \\\n  -d addresses\\[0\\]\\[city\\]=new+york \\\n  -d addresses\\[0\\]\\[state\\]=NY \\\n  -d addresses\\[0\\]\\[postal_code\\]=10013\n```\n\nClaude Code:\n\n```bash\nclaude mcp add --transport http middesk https://mcp.middesk.com/mcp \\\n  --header \"Authorization: Bearer mk_live_...\"\n```\n\nMCP client configuration:\n\n```json\n{\n  \"mcpServers\": {\n    \"middesk\": {\n      \"headers\": {\n        \"Authorization\": \"Bearer mk_live_your_api_key\"\n      },\n      \"url\": \"https://mcp.middesk.com/mcp\"\n    }\n  }\n}\n```\n\nThrough letme (picks today, calling later): https://letme.dev/middesk. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| Persona | B | 69.5 | 148 | kyc.identity, kyc.business, kyc.screening, kyc.cases | no | https://www.anchorterminal.com/tools/persona.md |\n| Sumsub | B | 68.5 | 167 | kyc.identity, kyc.business, kyc.screening, kyc.cases | no | https://www.anchorterminal.com/tools/sumsub.md |\n| Trulioo | C | 58.2 | 406 | kyc.identity, kyc.business, kyc.screening | no | https://www.anchorterminal.com/tools/trulioo.md |\n| Grep AI | B | 64.4 | 252 | kyc.business, kyc.screening | no | https://www.anchorterminal.com/tools/grep-ai.md |\n| Veriff | C | 61.1 | 334 | kyc.identity, kyc.screening | no | https://www.anchorterminal.com/tools/veriff.md |\n| Jumio | C | 55 | 461 | kyc.identity, kyc.screening | no | https://www.anchorterminal.com/tools/jumio.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- The REST API has a public OpenAPI 3.1 spec with 62 paths and 87 operations covering businesses, orders, signals, monitoring, liens, webhooks, agent runs and sub-accounts (source: \u003chttps://docs.middesk.com/openapi.json\u003e)\n- A hosted MCP server answers at https://mcp.middesk.com/mcp (Streamable HTTP) and https://mcp.middesk.com/sse, with OAuth 2.1 or a live API key (source: \u003chttps://docs.middesk.com/build/mcp-server\u003e)\n- The vendor's plugin README lists eleven MCP tools, among them create_business, retrieve_business, list_businesses, create_order, list_enabled_packages and create_signal, and says the server runs against production only (source: \u003chttps://github.com/middesk/plugins\u003e)\n- OFAC sanctions screening runs automatically on every business created, with adverse media, politically exposed persons and watchlist monitoring as further products (source: \u003chttps://docs.middesk.com/verify-business/sanctions\u003e)\n- Identity checks on a business's people run through Socure, which Middesk provisions after a contract is signed (source: \u003chttps://docs.middesk.com/verify-business/kyc\u003e)\n- The changelog entry of 31 August 2026 says earlier examples and the request schema showed `address_line_1`, a key the API ignores, so street lines were dropped without an error (source: \u003chttps://docs.middesk.com/guides/get-started/changelog/2026/8/31\u003e)\n- The public terms say Middesk may not use customer data in any form to train or fine-tune generative AI models, and may train its ML models only on de-identified data (source: \u003chttps://www.middesk.com/policies/bv-msa\u003e)\n\n## Compare\n\n- [Jumio vs Middesk](https://www.anchorterminal.com/compare/jumio-vs-middesk.md): C 55 vs C 59\n- [Middesk vs Veriff](https://www.anchorterminal.com/compare/middesk-vs-veriff.md): C 59 vs C 61.1\n- [Middesk vs Persona](https://www.anchorterminal.com/compare/middesk-vs-persona.md): C 59 vs B 69.5\n- [Middesk vs Sumsub](https://www.anchorterminal.com/compare/middesk-vs-sumsub.md): C 59 vs B 68.5\n- [Middesk vs Trulioo](https://www.anchorterminal.com/compare/middesk-vs-trulioo.md): C 59 vs C 58.2\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on middesk.com or one of its subdomains, or the README of github.com/middesk/plugins. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"middesk\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/middesk\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/middesk.svg\" alt=\"Middesk on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Middesk on Anchor Terminal](https://www.anchorterminal.com/badges/middesk.svg)](https://www.anchorterminal.com/tools/middesk)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/middesk\"\u003eMiddesk on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Middesk is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/middesk-dark.png\n- Light: https://www.anchorterminal.com/assets/share/middesk-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Identity \u0026 business verification",
        "url": "https://www.anchorterminal.com/categories/identity-verification"
      },
      {
        "name": "Middesk",
        "url": ""
      }
    ],
    "description": "Business verification API from Middesk in San Francisco. It checks US and international businesses against registry, tax ID, sanctions and watchlist records, monitors them for changes, and files liens and state tax registrations, over REST and a hosted MCP server.",
    "facts": [
      "rank #389 of 629",
      "OAuth or key auth",
      "0 desk reviews"
    ],
    "h1": "Middesk",
    "image": "https://www.anchorterminal.com/assets/og/tools-middesk.png",
    "path": "/tools/middesk",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Middesk review for AI agents, grade C (59/100) | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/tools/middesk"
  },
  "tokens": {
    "markdown": 7400,
    "slim": 1880
  },
  "version": 1
}
