# Socure RiskOS (slim) > Socure RiskOS is an identity verification and risk decisioning platform from Socure Inc. Its Evaluation API runs configured workflows for KYC, document and selfie checks, fraud scoring and watchlist screening, and returns a decision with reason codes. - Full: https://www.anchorterminal.com/tools/socure-riskos.md (~8,500 tokens) · this version ~2,230 tokens · JSON https://www.anchorterminal.com/tools/socure-riskos.json · canonical https://www.anchorterminal.com/tools/socure-riskos - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-09 **B · 63.5/100 · rank #357 of 842 · #5 in Identity & business verification · not agent-ready · confidence medium** Assessment: A public OpenAPI file, llms.txt, 15 documented error codes and dated release notes cover a ten-operation REST API, and Socure Launch publishes prices from $0.80 an evaluation with a free sandbox. API keys carry no scopes, no idempotency header is defined, no service terms are published, and production stays at zero requests until Socure activates it. ## Facts - Kind: HTTP API · vendor: Socure Inc. · category: Identity & business verification · legal entity: Socure Inc. · provenance 82/100 - Endpoint: `https://mcp.riskos.socure.com/sandbox` (HTTP) - Auth: API key · pricing: Pay per use · x402: no · licence: Proprietary service. No service agreement is published, and the OpenAPI file states its licence as Proprietary - Probe metrics: not measured yet (probes haven't run) - API: REST with JSON at https://riskos.socure.com (production) and https://riskos.sandbox.socure.com (sandbox). OpenAPI 3.0.3, version 2025-01-01.orion, ten operations (4 POST, 3 GET, 2 PUT, 1 PATCH). An optional `X-API-Version` header pins the version - Checks: Workflows combine Socure Verify (KYC), Predictive DocV (government ID and selfie), Sigma identity, synthetic and first-party fraud scores, email, phone and address risk, device intelligence, global watchlist screening with daily monitoring, eCBSV, deceased check, bank account verification and business onboarding - Integration paths: Direct API, synchronous or asynchronous with webhooks, or a Socure-hosted flow that returns results by webhook. Decisions are `ACCEPT`, `REVIEW` or `REJECT` by default - MCP server: Hosted over HTTP at https://mcp.riskos.socure.com/sandbox and /prod with an MCP Server Key as bearer token. Nine tools (`ask_docs`, `add_webhook`, `update_webhook`, `list_webhooks`, `list_events`, `list_testcases`, `list_usecases`, `list_workflows`, `integration_checklist`), two prompts and one OpenAPI resource. It runs no evaluations - Credentials: Bearer API keys per environment, regenerated in the dashboard with the old key working until deleted. Each key reaches all workflows. Separate MCP, SDK and Okta keys. Optional IP allowlist, mutual TLS and JWE payload encryption - Rate limits: Sandbox 10 requests a second and 1,000 a day per endpoint and method. Socure Launch 1 evaluation a second and 500 a day. Production 0 until activated, then set per account. Headers `X-RateLimit-Limit-Day`, `X-RateLimit-Limit-Window` and `X-Retry-After` on 429 - Errors: JSON with `error`, `code`, optional `message`, `details` and `invalid_args`. 15 documented codes from `INVALID_REQUEST` to `BAD_GATEWAY`. Some legacy endpoints omit `code` - Webhooks: Events such as `evaluation_completed` and `decision_update`, authenticated by Basic, bearer token or OAuth 2.0 client credentials. Up to 10 attempts with backoff capped at 60 seconds. Receivers dedupe on `event_id` - SDKs: Client-side only. Digital Intelligence and Predictive DocV SDKs for web, iOS, Android and React Native. `@socure-inc/device-risk-sdk` 2.11.0 on npm (1 September 2026). No server-side SDK found - Audit: Dashboard audit logs for account and workflow changes, and compliance reports exported as CSV. No API request log was found in the docs - Certifications: SOC 2 Type 2, ISO/IEC 27001:2022, 27017:2015, 27018:2025 and 27701:2025, FedRAMP Moderate and TX-RAMP Level 2 per trust.socure.com and the security page - Status: status.socure.com on Statuspage, with RiskOS and each product as components and incident history back to December 2025 - Sub-processors: Amazon Web Services (US East), Google Cloud for RiskOS (United States) and Snowflake (United States) per trust.socure.com. The privacy notice also names service providers in the Philippines and staff access from India, the United Kingdom and Europe - Prices: Socure Launch, Document Verification (DocV) $0.80 per transaction; Socure Launch, DocV + Watchlist $0.90 per transaction; Socure Launch, KYC + Fraud + Watchlist with DocV step-up $1 per transaction; Socure Launch, Prefill, KYC + Fraud + Watchlist with DocV step-up $1.30 per transaction - Scores: Reliability 75, Performance pending, Schema & documentation 84, Agent ergonomics 46, Security & auth 60, Payments & pricing 35, Task success pending, Maintenance & community 75, Transparency & trust 68 · total over the 7 assessed categories - Why: Reliability, Read with the hosted lines and scored on the Evaluation API. · Schema & documentation, An OpenAPI 3.0.3 file for ten operations and a 3.1 file for the webhook payload are public on GitHub and embedded in each reference page (25… · Agent ergonomics, Scored on the REST API. · Security & auth, Bearer API keys are separate for sandbox and production and can be regenerated with an overlap period, and the MCP server takes its own key. · Payments & pricing, Read with the hosted rubric. · Maintenance & community, The latest release note is dated 6 October 2026 (30). · Transparency & trust, The service is closed, and no service agreement or API terms are published. - Sources: 26, open questions: 9, both in the full twin - Capabilities: kyc.identity, kyc.documents, kyc.screening, kyc.business, kyc.cases - JSON: https://www.anchorterminal.com/api/v1/tools/socure-riskos.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/socure-riskos.svg` or a link to https://www.anchorterminal.com/tools/socure-riskos from a page on socure.com or one of its subdomains, or the README of github.com/socure-inc/.github, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Send `Authorization: Bearer ` to `https://riskos.sandbox.socure.com/api/evaluation` for tests and `https://riskos.socure.com/api/evaluation` for live checks. The two environments use separate keys. 2. Use dummy data only in the sandbox. It returns predefined results, connects to no live data source and expects the documented test values. 3. Store the `eval_id` from every `POST /api/evaluation` response. No list or search endpoint exists to find it later. 4. On 429 wait the seconds given in `X-Retry-After`. Do not blindly resend a failed `POST /api/evaluation`, because no idempotency header is documented and Launch bills each initiated evaluation. 5. The MCP server at `https://mcp.riskos.socure.com/sandbox` reads docs, workflows and webhooks with its own MCP Server Key. It cannot run evaluations or read results. ## Connect ```bash curl --request POST \ --url "https://riskos.sandbox.socure.com/api/evaluation" \ --header "Authorization: Bearer YOUR_API_KEY" \ --header "Content-Type: application/json" \ --header "Accept: application/json" \ --data '{"id":"customer-onb-12345","timestamp":"2024-12-01T08:15:30.456Z","workflow":"consumer_onboarding","data":{"individual":{"given_name":"Jane","family_name":"Doe","email":"jane.doe@example.com","phone_number":"+1-555-123-4567","address":{"line_1":"123 Main St","locality":"San Francisco","major_admin_division":"CA","postal_code":"94105","country":"US"}}}}' ``` ```bash claude mcp add --transport http socure-dev-assist https://mcp.riskos.socure.com/sandbox --header "Authorization: Bearer $RISKOS_MCP_KEY" ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/socure-riskos ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Didit | BB | 75 | kyc.identity, kyc.documents, kyc.screening, kyc.business, kyc.cases | https://www.anchorterminal.com/tools/didit.min.md | | Persona | B | 69.5 | kyc.identity, kyc.business, kyc.documents, kyc.screening, kyc.cases | https://www.anchorterminal.com/tools/persona.min.md | | Sumsub | B | 68.5 | kyc.identity, kyc.business, kyc.documents, kyc.screening, kyc.cases | https://www.anchorterminal.com/tools/sumsub.min.md | | ComplyCube | B | 63.7 | kyc.identity, kyc.documents, kyc.screening, kyc.business | https://www.anchorterminal.com/tools/complycube.min.md | | Middesk | C | 59 | kyc.business, kyc.screening, kyc.cases, kyc.identity | https://www.anchorterminal.com/tools/middesk.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)