# Shufti (slim) > Identity and business verification service from Shufti Pro Limited in London. One REST endpoint runs document, face, address, AML screening and KYB checks chosen in the request body, with results by callback. A hosted MCP server exposes 25 tools. - Full: https://www.anchorterminal.com/tools/shufti.md (~7,750 tokens) · this version ~1,930 tokens · JSON https://www.anchorterminal.com/tools/shufti.json · canonical https://www.anchorterminal.com/tools/shufti - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-09 **C · 57.8/100 · rank #538 of 842 · #9 in Identity & business verification · not agent-ready · confidence medium** Assessment: One endpoint covers document, face, address, AML and KYB checks, with a free plan of 10 verifications a month, and a hosted MCP server adds OAuth with three scopes. No OpenAPI file, server SDK or idempotency key was found, and the status page history could not be read. ## Facts - Kind: HTTP API · vendor: Shufti Pro Limited · category: Identity & business verification · legal entity: Shufti Pro Limited · provenance 90/100 - Endpoint: `https://api.shuftipro.com` (HTTP, Streamable HTTP) - Auth: OAuth or key · pricing: Freemium · x402: no · licence: Proprietary service under Shufti's Terms and Conditions. The licences of the mobile capture SDKs were not checked - Probe metrics: not measured yet (probes haven't run) - Surface graded: REST API at `https://api.shuftipro.com/`, a single endpoint where each service is an object in the JSON body. The hosted MCP server is read as a second surface - Endpoints: POST `/` (verification), `/status`, `/delete`, `/account/info/`, `/get/access/token`, a callback resend endpoint and a proof access URL valid for 15 minutes - Services: Document, second document, face, address, consent, phone and email one-time codes, AML screening for people and businesses, Enhanced KYB, e-IDV Pro database checks, age verification, video KYC, e-signature, crypto wallet screening, Travel Rule and transaction screening - MCP server: `https://ai.shuftipro.com/mcp`, Streamable HTTP, OAuth 2.1 with PKCE and dynamic client registration. 25 tools, 7 knowledge and 18 verification. Scopes `knowledge:read`, `verification:read` and `verification:write` - Credentials: Client ID and Secret Key as HTTP Basic auth, or a Bearer access token from `/get/access/token` valid for one hour. The Secret Key is shown once and regenerated in the back office - Rate limits: 60 requests a minute per IP address on a production account, 20 a minute on a trial account. Shufti says the limits can change and can be raised on request - Callbacks: Sent to a registered `callback_url` with a `Signature` header. Failed deliveries retry automatically, and a callback can be resent by API or from the back office once an hour - Webhook IPs: Two in Europe and four in the United States, listed in the docs - Errors: JSON with an `event` such as `request.invalid` and an `error` object naming the service, the key and a message. HTTP codes 400, 401, 402, 403, 404, 409, 429, 500, 504 and 524 are listed, and decline reasons carry codes such as SPDR370 - Testing: Trial accounts accept published test ID samples for face, document and address checks. The samples do not work on a production account - SDKs: Capture SDKs only. Android 3.0.8 (31 August 2026), iOS 1.3.55, Flutter 1.0.33, React Native 1.1.1 and Cordova. No server-side client library - Retention: Seven years after the services end where the client gives no instruction, per the terms. Records can be deleted by API with a reference and a comment - Certifications: SOC 2 Type II, ISO 27001:2022, PCI DSS, Cyber Essentials Plus and iBeta PAD Level 3 per shuftipro.com/certifications. The Vanta trust centre at trust.shuftipro.com was not read - Status: status.shuftipro.com, hosted by UptimeRobot, with 90-day uptime and an update history drawn by script - Prices: Verification, Free Forever plan (document and face checks) free per transaction; Verification, Essentials plan, starting price $1.50 per transaction - Scores: Reliability 65, Performance pending, Schema & documentation 58, Agent ergonomics 47, Security & auth 62, Payments & pricing 35, Task success pending, Maintenance & community 72, Transparency & trust 71 · total over the 7 assessed categories - Why: Reliability, Graded on the REST API with the hosted lines. · Schema & documentation, No OpenAPI file or other machine-readable contract was found. · Agent ergonomics, REST responses can't be trimmed by field, and AML and e-IDV responses are long. · Security & auth, The REST API uses one Client ID and Secret Key pair as Basic auth, with no scopes. · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, The revision history's newest entry is dated 6 October 2026 (30). · Transparency & trust, Closed service with public terms, version 11.1 with effect from 13 May 2026, and every earlier version linked (15). - Sources: 25, open questions: 11, both in the full twin - Capabilities: kyc.identity, kyc.documents, kyc.business, kyc.screening - JSON: https://www.anchorterminal.com/api/v1/tools/shufti.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/shufti.svg` or a link to https://www.anchorterminal.com/tools/shufti from a page on shuftipro.com or one of its subdomains, or the README of github.com/shuftipro/iOS-SDK, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. POST every verification to `https://api.shuftipro.com/` with a unique `reference` of 6 to 250 characters and one object per service. Read results from `/status` with that reference 2. Register the callback domain in the back office first. An unregistered `callback_url` is rejected 3. Stay under 60 requests a minute per IP on a production account and 20 on a trial account 4. Check the `Signature` response header. Accounts created after 15 March 2023 hash the Secret Key with SHA-256 before appending it to the raw response 5. Through MCP, identity checks return a `verification_url` for the person to open. No tool accepts an image, so use the REST API for offsite proofs ## Connect ```bash curl --location --request POST 'https://api.shuftipro.com' \ --header 'Content-Type: application/json' \ --header 'Authorization: Basic ' \ --data-raw '{ "reference" : "1234567", "callback_url" : "https://yourdomain.com/profile/notifyCallback", "country" : "GB", "language" : "EN", "verification_mode" : "any", "face" : { "proof" : "" } }' ``` ```bash claude mcp add --transport http shufti https://ai.shuftipro.com/mcp ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/shufti ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Didit | BB | 75 | kyc.identity, kyc.documents, kyc.screening, kyc.business | https://www.anchorterminal.com/tools/didit.min.md | | Persona | B | 69.5 | kyc.identity, kyc.business, kyc.documents, kyc.screening | https://www.anchorterminal.com/tools/persona.min.md | | Sumsub | B | 68.5 | kyc.identity, kyc.business, kyc.documents, kyc.screening | https://www.anchorterminal.com/tools/sumsub.min.md | | ComplyCube | B | 63.7 | kyc.identity, kyc.documents, kyc.screening, kyc.business | https://www.anchorterminal.com/tools/complycube.min.md | | Socure RiskOS | B | 63.5 | kyc.identity, kyc.documents, kyc.screening, kyc.business | https://www.anchorterminal.com/tools/socure-riskos.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)