# Middesk (slim) > Business verification API from Middesk in San Francisco. It checks US and international businesses against registry, tax ID, sanctions and watchlist records, monitors them for changes, and files liens and state tax registrations, over REST and a hosted MCP server. - Full: https://www.anchorterminal.com/tools/middesk.md (~7,450 tokens) · this version ~1,880 tokens · JSON https://www.anchorterminal.com/tools/middesk.json · canonical https://www.anchorterminal.com/tools/middesk - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **C · 59/100 · rank #389 of 629 · #4 in Identity & business verification · not agent-ready · confidence medium** Assessment: A public OpenAPI 3.1 contract for 87 operations, llms.txt, Markdown docs and a dated weekly changelog make the REST API readable to an agent, and OAuth has a read-only scope. Access is sales-led. No price, self-serve signup or official SDK was found, and the hosted MCP server rejects sandbox keys. ## Facts - Kind: HTTP API · vendor: Middesk, Inc. · category: Identity & business verification · legal entity: Middesk, Inc. · provenance 78/100 - Endpoint: `https://api.middesk.com/v1` (HTTP) - Auth: OAuth or key · pricing: Paid · x402: no · licence: Proprietary service under Middesk's Business Verification Terms and Conditions. The Claude Code and Codex plugins on GitHub are MIT - Probe metrics: not measured yet (probes haven't run) - Graded surface: The public REST API at https://api.middesk.com/v1 (sandbox at https://api-sandbox.middesk.com/v1). The hosted MCP server is noted alongside it - API: OpenAPI 3.1, 62 paths, 87 operations (51 GET, 24 POST, 5 DELETE, 4 PATCH, 3 PUT), 373 schemas. Version v1, with no dated versions - MCP server: Hosted at https://mcp.middesk.com/mcp and /sse. Eleven tools per the vendor's plugin README, two of them behind an account entitlement. Production only, so test keys are rejected. Not in the official MCP registry - Checks: Secretary of State registrations, TIN match, name and address, owners and officers, OFAC and watchlists, adverse media, politically exposed persons, web presence, industry classification, liens, litigation, bankruptcies, and international registrations - Credentials: API keys per environment (`mk_test`, `mk_live`), OAuth 2.0 with `read_only` or `read_write` scope and non-expiring tokens, OAuth 2.1 with PKCE and dynamic client registration on the MCP server, sub-account keys through the API - Rate limits: 20 requests a second per customer. Sandbox business creation has a per-minute limit that answers 429 with `Retry-After` - Errors: JSON `errors` array with a `message` and an optional `parameter`. Documented statuses are 200, 201, 202, 400, 401, 404, 422, 429 and 500 - Pagination: `page` and `per_page`, with `has_more` and `total_count` in list responses - Webhooks: HMAC SHA-256 signature in `X-Middesk-Signature-256`, or mutual TLS or OAuth tokens. Up to 10 retries over about 3 days. Separate endpoints for sandbox and production - Sandbox: Mock results driven by trigger values in the submitted name, address, TIN and people, plus an enhanced sandbox with configurable scenarios in the dashboard - GraphQL: https://api.middesk.com/graphql, optional, a subset of the REST API. The vendor's release post describes it as early access for a limited set of customers - SDKs: None found. `middesk` returns 404 on npm, PyPI and RubyGems. middesk/plugins holds a Claude Code plugin and a ChatGPT and Codex plugin, both marked in development - Certifications: SOC 2 Type II, audited annually, and alignment with the NIST Cybersecurity Framework per the docs. The report sits in a trust centre at trust.middesk.com - Status: status.middesk.com on Statuspage, six components (Business Verification, APIs, TIN Match, Signal, Dashboard, Entity Management) - AI training: The public terms bar training generative AI models on customer data in any form, and allow ML training only on de-identified data - Scores: Reliability 73, Performance pending, Schema & documentation 82, Agent ergonomics 56, Security & auth 56, Payments & pricing 10, Task success pending, Maintenance & community 64, Transparency & trust 61 · total over the 7 assessed categories - Why: Reliability, Graded on the REST API with the hosted-service lines. · Schema & documentation, Public OpenAPI 3.1 spec with 62 paths and 87 operations (25). · Agent ergonomics, List endpoints return a simplified business item, and a few reads take `include`, but the full Business object is large (the Markdown refere… · Security & auth, Revocable API keys split by environment, sub-account keys managed through the API, and OAuth 2.0 with `read_only` and `read_write` scopes an… · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, Latest changelog entry 5 October 2026 (30). · Transparency & trust, Closed service with public terms last updated 21 August 2026, and MIT plugins (15). - Sources: 20, open questions: 8, both in the full twin - Capabilities: kyc.business, kyc.screening, kyc.cases, kyc.identity - JSON: https://www.anchorterminal.com/api/v1/tools/middesk.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/middesk.svg` or a link to https://www.anchorterminal.com/tools/middesk from a page on middesk.com or one of its subdomains, or the README of github.com/middesk/plugins, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Match the key to the host. `mk_test` keys work only at https://api-sandbox.middesk.com/v1 and `mk_live` keys only at https://api.middesk.com/v1 2. Name the `orders` on `POST /v1/businesses`. Omitting them places a verification order plus every package the account runs automatically, all billed 3. Send `address_line1` and `address_line2`. The API ignores `address_line_1` without an error 4. A 201 means the business was created, not verified. Wait for the `business.updated` webhook or poll until `status` leaves `pending` 5. Stay under 20 requests a second per account, and in sandbox wait the seconds in `Retry-After` after a 429 on business creation ## Connect ```bash curl -X POST https://api-sandbox.middesk.com/v1/businesses \ -u $MIDDESK_SANDBOX_API_KEY: \ -H "Accept: application/json" \ -d name=Corporation \ -d addresses\[0\]\[address_line1\]=223+Grand+St. \ -d addresses\[0\]\[city\]=new+york \ -d addresses\[0\]\[state\]=NY \ -d addresses\[0\]\[postal_code\]=10013 ``` ```bash claude mcp add --transport http middesk https://mcp.middesk.com/mcp \ --header "Authorization: Bearer mk_live_..." ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/middesk ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Persona | B | 69.5 | kyc.identity, kyc.business, kyc.screening, kyc.cases | https://www.anchorterminal.com/tools/persona.min.md | | Sumsub | B | 68.5 | kyc.identity, kyc.business, kyc.screening, kyc.cases | https://www.anchorterminal.com/tools/sumsub.min.md | | Trulioo | C | 58.2 | kyc.identity, kyc.business, kyc.screening | https://www.anchorterminal.com/tools/trulioo.min.md | | Grep AI | B | 64.4 | kyc.business, kyc.screening | https://www.anchorterminal.com/tools/grep-ai.min.md | | Veriff | C | 61.1 | kyc.identity, kyc.screening | https://www.anchorterminal.com/tools/veriff.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)