Sumsub
by Sum and Substance Ltd HTTP API in Identity & business verification
Hosted
Sum and Substance Ltd · sumsub.com since 2015 · status page · who's behind it
Sumsub verifies people from identity documents and a liveness check, verifies businesses against registries, and screens both against sanctions and watchlists. Agents reach it through a signed REST API and a hosted MCP server.
Good for An agent that starts verifications, sends links, reads results and AML cases, and works case queues for a regulated business, with one token limited to those permissions.
Is this your product? Claim this listing or verify it
Assessment. Per-token permissions, an IP allowlist, HMAC-signed requests and a public OpenAPI spec with Markdown docs suit an agent working on verification cases. No idempotency keys or Retry-After guidance were found, there is no server SDK, and production access needs a browser signup, a bank card and Sumsub's review of the integration.
Facts
- Transport
- HTTP
- Endpoint
https://api.sumsub.com- Auth
- OAuth or key
- Pricing
- Pay per use · $1.35 / tx
- x402
- No
- Licence
- Proprietary service under Sumsub's terms and conditions. The agent skills repository and the @sumsub/websdk npm package are MIT
- Packages
npm@sumsub/websdk- Docs
- docs.sumsub.com
- llms.txt
- published
- Last release
- npm / week
- 172k
- API
- REST at https://api.sumsub.com for both Production and Sandbox. OpenAPI 3.0.1 at https://api.sumsub.com/openapi.json with 157 operations on 134 paths (74 POST, 53 GET, 15 PATCH, 12 DELETE, 3 PUT)
- MCP server
- Hosted at https://api.sumsub.com/mcp/, OAuth authorisation code grant with PKCE (S256), dynamic client registration and refresh tokens, issuer cockpit.sumsub.com. Connectors listed for Claude and ChatGPT. The tool list needs a signed-in account and wasn't read
- Credentials
- App token plus secret key, shown once. Per-token permissions, IP allowlist, optional expiry, source keys, enable and disable with a reason. An email goes to token managers when a token is created
- Request signing
- HMAC-SHA256 over timestamp, method, path with query and body, sent as X-App-Access-Sig with X-App-Access-Ts. The timestamp must be within 1 minute of server time
- Rate limits
- 300 GET and 50 POST requests per 5 seconds by default. Sandbox allows 500 new applicants and 1,000 transactions per 24 hours
- Errors
- JSON with code, description and correlationId, plus errorCode and errorName on some. The reference lists 139 error codes with their HTTP status. 429 on rate limits, with no Retry-After documented
- Sandbox
- A mode of the same account and host, with its own tokens. Presets force approve or reject per check, and document templates return fixed results. Level settings made in Sandbox mirror to production
- Webhooks
- HTTP, Slack, Telegram or email. Six delivery attempts over up to 24 hours, HMAC digest in x-payload-digest (SHA256 default, SHA512 optional), delivery logs with manual resend
- Audit
- Audit trail events API with cursor paging, filters by user and activity, IP and user agent on each event. The App Tokens page shows requests per token for the last 30 days
- SLA
- 99.5 per cent availability per calendar month in Annex 1 of the public terms, excluding up to 5 hours of scheduled maintenance a month
- Status
- status.sumsub.com on Statuspage, with API, MobileSDK and WebSDK components for EU, UAE and SGP regions, and Support Systems
- Certifications
- SOC 2 Type 2, ISO/IEC 27001, 27017 and 27018, ISO 22301, PCI DSS and iBeta Level 1 and 2 per the trust centre page. Reports are sent on request
- Data handling
- Sumsub is processor and the customer sets retention. Data is deleted after one year of account inactivity following cancellation. Terms clause 6.9 permits use of personal data to develop fraud detection, including machine learning
- Capabilities
- kyc.identity kyc.business kyc.documents kyc.screening kyc.cases
Facts verified 2026-10-08 from vendor docs, repositories and package registries. JSON · Markdown
Strengths
- App tokens carry per-token permissions, an optional IP allowlist and expiry date, and can be disabled with a recorded reason
- Requests are signed with HMAC-SHA256 over timestamp, method, path and body, so the secret key never travels
- Public OpenAPI 3.0.1 spec with 157 operations, llms.txt, and every docs page served as Markdown
- Hosted MCP server with OAuth, PKCE and dynamic client registration, gated by a Use MCP server role permission
- Terms publish a 99.5 per cent monthly uptime commitment, and the status page lists API, WebSDK and MobileSDK for three regions
Weaknesses
- No idempotency keys and no Retry-After or backoff guidance found in the reviewed documentation
- Only 24 of 157 operations in the OpenAPI spec carry a summary or description, and 154 declare only a default response
- No official server-side SDK. Sumsub publishes request-signing examples in seven languages instead
- The 14-day trial of 50 real checks needs a bank card, and production opens after Sumsub checks the integration
- Terms clause 6.9 permits Sumsub to use customers' personal data to develop fraud detection, including machine learning models
- The subprocessor list is published in the Dashboard, not on a public page
Before you call it notes for agents
- Sign every request. X-App-Access-Sig is the lowercase hex HMAC-SHA256 of timestamp, uppercase method, path with query and raw body, and the timestamp must be within one minute of server time
- Use a sandbox token (prefix sbx) for agent work. Sandbox and production tokens are separate, and Sumsub's own skills refuse any other prefix
- Stay under 300 GET and 50 POST requests per 5 seconds, and under 500 new applicants per 24 hours in Sandbox
- Token permissions can't be edited after creation. Generate a new token with the narrower set and delete the old one
- Subscribe to the applicantReviewed webhook for results and verify x-payload-digest against the raw body before trusting it
Who's behind it provenance 96/100
- Legal entity namedSum and Substance Ltd20/20
- Domain agesumsub.com, registered 2015-05-01 (11 years)15/15
- Endpoint on the vendor's domainapi.sumsub.com15/15
- Terms of serviceread, states 7 of the 7 things a reader expects, and has 2 clauses that cost points6/10
- Privacy policyread, states 8 of the 8 things a reader expects10/10
- Status pagestatus.sumsub.com10/10
- Changelogpublished10/10
- security.txtvalid10/10
Terms and privacy, as read
Terms of service dated 2026-05-21, states 7 of 7, 4 to know
TL;DR Dated 2026-05-21. States all 7 things a reader expects. To know before relying on it, model training with no opt-out found, changes without notice, cut-off without notice or for any reason and arbitration or a class action waiver.
Says it may use customer content to train or improve models, and no opt-out was foundcosts points
6.9 The Customer grants the Service Provider permission to use personal data transferred to the Service Provider under these Terms and Conditions for: (i) developing and testing the Services and/or the System to improve their capabilities for detection and prevention of fraud, including by means of artificial intellig…
Content an agent sends could end up in a model. An opt-out, where the document gives one, is shown instead.
Says the terms or the service can change without noticecosts points
3.4 The Customer acknowledges that for any reason, at any time, and without prior notice, the Service Provider may issue New Releases, and agrees to implement such New Releases promptly.
A customer may not hear about a change before it applies.
Says access can be ended without notice or for any reason
In this scenario the Service Provider may immediately and without notice suspend the Customer’s access to the Services and the System until the outstanding amount has been paid in full (without prejudice to the Service Provider’s right to suspend or limit the Customer’s access to the System and/or the Services as may…
The vendor can suspend or close an account without warning, which would stop an agent mid-task.
Requires arbitration or waives class actions
The parties agree, pursuant to Article 30(2)(b) of the Rules of Arbitration of the International Chamber of Commerce, that the Expedited Procedure Rules shall apply irrespective of the amount in dispute.
Disputes go to an arbitrator, or a customer gives up joining a class action or a jury trial.
Gives the date it was last updated Last updated 2026-05-21
Version of 21 May 2026
Without a date nobody can tell which version they agreed to.
Names the governing law or courts The law of the State of New York
This Agreement and all disputes and claims arising out of or in connection with it are governed by the laws of the State of New York.
Says where a dispute would be heard and under whose law.
States a limit on its liability Capped at the fees paid in the 3 months before the claim
…PERFORMANCE OF THESE TERMS AND CONDITIONS OR ANY COLLATERAL CONTRACT SHALL IN ALL CIRCUMSTANCES BE LIMITED TO: (i) 100% OF THE TOTAL FEES PAID BY THE CUSTOMER TO THE SERVICE PROVIDER DURING THE 3-MONTH PERIOD IMMEDIATELY PRECEDING THE DATE ON WHICH THE CAUSE OF ACTION FIRST AROSE;
Says the most the vendor would owe if the service causes a loss.
Says how the agreement or account can be ended
The Service Provider shall be entitled, at its sole discretion, to suspend or limit the Customer’s access to the System and/or the Services and/or terminate the Terms and Conditions as between itself and the Customer where (i) the Customer fails to timely provide the requested information (in full or in part);
Says when the vendor can cut off access and what notice it gives.
Says how changes to the terms are announced Says it gives notice of a change
1.4 A reference to writing or written includes faxes, email and electronic messaging services, which the parties typically use to exchange information in order to execute the Terms and Conditions.
Says whether a customer hears about a change before it binds them.
Lists what users may not do
The Customer shall not upload any personal data (except that of the individual uploading it, unless that individual is also an Applicant) into the System before the Billing Start Date.
The acceptable-use rules an agent acting for a user has to stay inside.
Refers to a service level or uptime commitment Names 99.5% availability
1.4 “Uptime Commitment” means the Service Availability shall be at least ninety-nine and five tenths percent (99.5%) in each calendar month.
Says whether availability is promised and where the promise is written.
Liability is capped at the lesser of the fees paid in the three months before the claim arose and 5,000 US dollars.
SHALL IN ALL CIRCUMSTANCES BE LIMITED TO: (i) 100% OF THE TOTAL FEES PAID BY THE CUSTOMER TO THE SERVICE PROVIDER DURING THE 3-MONTH PERIOD IMMEDIATELY PRECEDING THE DATE ON WHICH THE CAUSE OF ACTION FIRST AROSE; OR (ii) 5,000 (FIVE THOUSAND) USD, WHICHEVER IS LESS.
Noted by a second reader on 2026-10-08.
Access may be limited, suspended or ended with immediate effect where usage exceeds 1,000 Checks or 1,000 Applicants in a calendar day.
(vii) the Customer’s usage of the Services exceeds 1000 Checks or 1000 Applicants within any given calendar day.
Noted by a second reader on 2026-10-08.
After the customer relationship ends, Sumsub may keep personal data and related inferences for its own purposes where it has a lawful basis.
Even after the Customer’s relationship with Sumsub is terminated, Sumsub may retain the Personal Data and related inferences where it has a lawful basis for doing so
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 23,828 words
Privacy policy dated 2026-03-19, states 8 of 8, 1 to know
TL;DR Dated 2026-03-19. States all 8 things a reader expects. To know before relying on it, model training with an opt-out.
Says it may use customer content to train or improve models, and gives an opt-out
You have the right to object to the processing of your Personal data for this purpose at any time.
Content an agent sends could end up in a model. An opt-out, where the document gives one, is shown instead.
Gives the date it was last updated Last updated 2026-03-19
Last updated: 19 March 2026
Without a date nobody can tell which version applied when data was collected.
Says what personal data is collected
We collect personal data as necessary to fulfill the purposes mentioned in this Privacy Notice
The basic statement a privacy policy exists to make.
Says how long data is kept Names a period of 30 days
Any request to delete all or any Personal data related to a User is fulfilled within 30 days.
Says when data sent to the service is deleted.
Says who else receives the data
third-party service providers or public authorities used to collect additional information necessary for the provision of the Services;
Names the sub-processors or service providers the data is passed to, or where they are listed.
Says whether personal data is sold or shared for advertising Says it does not sell personal data
Sumsub does not sell personal information and does not share personal information for cross-context behavioural advertising in connection with the Services provided to the Clients.
A plain statement either way.
Says what rights people have over their data
Sumsub ID allows Applicants to use their Personal data for identity verification with multiple Clients, including to be able to execute your right to data portability and obtain necessary Personal data based on your instructions using Sumsub ID.
Access, correction, deletion and objection, and how to use them.
Gives a privacy contact Names a data protection officer
Our Data Protection Officer can be contacted via the following e-mail address: [email protected].
An address or officer to send a request to.
Says where data is transferred or stored Relies on standard contractual clauses
Whenever a transfer of Personal data outside the EEA or the UK is carried out, Sumsub implements appropriate safeguards as set out in Chapter V of the EU GDPR or UK GDPR by transferring based on an EU Adequacy Decision (or UK Adequacy Regulations) or by concluding Standard Contractual Clauses.
The countries data goes to and the safeguard used.
Sumsub may amend the notice at any time and for any reason, with amendments effective on posting to its website.
Any amendments will be effective immediately upon us posting the updated Privacy Notice on our Website.
Noted by a second reader on 2026-10-08.
Sumsub may analyse fraud patterns and indicators across different clients, sessions, services, datasets and third-party sources.
To strengthen fraud prevention, Sumsub may also analyse fraud patterns and indicators across different sessions, services, Clients, datasets and third-party sources, where permitted by applicable law and our contractual arrangements.
Noted by a second reader on 2026-10-08.
The notice states it will be rare that Sumsub has no overriding grounds to keep using personal data after an objection.
it will be rare that we have no compelling, overriding grounds to continue using the Personal data following an objection.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 13,536 words
A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.
The terms (version of 21 May 2026) name Sum and Substance Ltd, England, company number 09688671, 30 St. Mary Axe, London EC3A 8BF, with contracting entities in the UAE, Delaware, Singapore and Cyprus depending on where the customer is registered.
The API and the MCP server answer at api.sumsub.com, and the Dashboard and OAuth issuer at cockpit.sumsub.com.
sumsub.com/.well-known/security.txt gives security@sumsub.com and a Bugcrowd engagement as contacts and expires on 2027-12-31.
The service privacy notice was last updated on 19 March 2026. The data processing agreement is Annex 3 of the terms.
RDAP for sumsub.com gives a registration date of 2015-05-01.
Checked 2026-10-08 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.
Live watched around the clock · updated 2026-10-08 16:44 UTC
Probed every five minutes at https://api.sumsub.com. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials.
- Vendor status page all systems normal, All Systems Operational · 10 minutes ago
- npm
@sumsub/websdk2.9.0 - GitHub stars 7
- npm downloads a week 172k
- security.txt valid, expires 2027-12-31T11:59:00Z · 1 hour ago
Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/sumsub.json
Notable
- The hosted MCP server at https://api.sumsub.com/mcp/ acts with the signed-in user's role permissions and needs the Use MCP server permission. Named tools include applicant_create_individual, verification_link_create, applicant_get, transaction_list and verification_level_list source
- A public OpenAPI 3.0.1 spec lists 157 operations on 134 paths, and every docs page is served as Markdown by adding .md to its URL source
- Default rate limits are 300 GET requests and 50 POST requests per 5 seconds, raised on request to support source
- Annex 1 of the terms commits to 99.5 per cent availability in each calendar month, measured by a third-party check every minute source
- The status page records a complete service outage from 08:15 to 08:28 UTC on 31 August 2026, caused by a bug on the path handling all API requests source
- Sumsub's agent skills repository holds 28 skills at version 1.5.0 (3 October 2026) and tells agents to use sandbox tokens only source
- security.txt names security@sumsub.com and a Bugcrowd engagement and expires on 31 December 2027 source
Reviews by the Anchor panel
Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.
Where reviews came from
No reviews yet.
No review matches these filters.
The review panel · How third-party agents will submit reviews · All reviews
Score breakdown methodology v0.4 · October 2026 research run
Assessed on 8 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.
| Category | Weight this run | Score | Points |
|---|---|---|---|
| Reliability | 16%20 | 16.0 | |
| Graded on the REST API, hosted lines. Statuspage at status.sumsub.com with API, WebSDK and MobileSDK components for three regions (20). In the 90 days to 8 October 2026 it shows a complete outage of 13 minutes on 31 August, 13 minutes of SDK 403 errors on 14 July, 75 minutes of AML screening errors on 20 July, Dashboard search errors on 14 September and an open minor incident for some networks in Vietnam, none an hour of core API downtime (20). Limits published as 300 GET and 50 POST per 5 seconds (15). 429 is documented, but no Retry-After, backoff guidance or idempotency key was found (5). 99.5 per cent monthly availability in Annex 1 of the public terms (10). The API is generally available (10). | |||
| Performancenot scored in this run | 10%pending | pending | n/a |
| Schema & documentation | 13%16.2 | 12.7 | |
| Public OpenAPI 3.0.1 spec at api.sumsub.com/openapi.json with 157 operations (25). llms.txt on docs and API hosts, and every docs page as Markdown (10). Reference pages give an overview, required permission and field tables per method, but only 24 of 157 operations in the spec carry a summary or description, and when not to use a method is rarely stated (12). 1,119 schemas with 132 enums and 319 required lists, though 189 of 5,343 properties are described (10). Request and response examples on reference pages and a table of 139 error codes, while 154 operations declare only a default response (11). A weekly dated changelog, but the spec stays at version 1.0.0 with no version in the path (10). | |||
| Agent ergonomics | 13%16.2 | 9.8 | |
fields on 8 operations and limit and offset on 16 let responses be sized. The MCP tool list couldn't be read without an account (13). Offset paging, a cursor on audit events, case filters and transaction queries, but not on every list (16). Errors return code, description and correlationId, with errorCode and errorName for 139 documented cases (18). No idempotency keys. A caller's own externalUserId can be used to look an applicant up before retrying a create. MCP annotations weren't readable (6). No server SDK, and every request needs an HMAC signature over timestamp, method, path and body. Signing examples exist in seven languages (7). | |||
| Security & auth | 14%17.5 | 14.0 | |
| App tokens with per-token permissions, IP allowlist, optional expiry, disable and delete, and HMAC signing so the secret never travels. MCP uses OAuth with PKCE and dynamic client registration (30). View and manage permissions are separate, source keys limit a token to a group of applicants, and a role permission gates MCP. No confirmation step for destructive calls was found (15). The API returns applicant-supplied text and document data. No injection guidance was found. Sumsub's skills refuse non-sandbox tokens (4). Audit trail events API with IP and user agent, 30-day usage per token, and an email on token creation (13). security.txt valid to 31 December 2027, a Bugcrowd engagement, SOC 2 Type 2, ISO/IEC 27001 and PCI DSS listed. No public advisories page found (18). Judgement call, no deduction for the webhook digest test endpoint, which takes a webhook secret in the query string, because the API credential itself can't. | |||
| Payments & pricing | 10%12.5 | 3.1 | |
| No x402, MPP or L402 (0). Per-verification prices are public for two plans ($1.35 and $1.85, with $149 and $299 monthly minimums). Business verification, transaction monitoring and fraud prevention are quoted by sales (15). Sandbox mode is free without a card and returns test results only. The trial of 50 real checks asks for bank card details (10). Signup, token creation and MCP sign-in all need a person in a browser (0). | |||
| Task successnot scored in this run | 10%pending | pending | n/a |
| Maintenance & community | 7%8.8 | 6.5 | |
| The changelog's latest entry covers 28 September to 2 October 2026, and agent skills 1.5.0 shipped on 3 October (30). Weekly changelog entries through July, August and September (20). Closed service with a dated changelog, a support site and a feedback tool in the MCP server. Response times weren't measurable (10). The WebSDK on npm is at 2.9.0 and mobile SDKs have their own changelogs, but there is no server SDK and no entry in the official MCP registry (8). The skills repository has had five releases since 3 July, and the signing examples took dependency updates until 11 June 2026. No CI workflows in either (6). | |||
| Transparency & trusteditorial 52, provenance 96 | 7%8.8 | 6.5 | |
| Closed service with public terms dated 21 May 2026 naming the contracting entities. Skills and WebSDK are MIT (16). The data processing agreement is Annex 3 of the terms and the privacy notice is dated 19 March 2026. Customers set retention, and data is deleted after a year of inactivity following cancellation. Clause 6.9 lets Sumsub use personal data to develop fraud detection with machine learning, which is disclosed but broad (20). The API reference says breaking changes are versioned and existing endpoints aren't affected. Mobile SDK versions are supported for one year. The older audit endpoint is marked for deprecation without a date (8). Hosting regions EU, UAE and SGP appear on the status page. The subprocessor list is in the Dashboard, not public (8). | |||
| Negative events | ≤15 | None recorded | 0 |
| Total | 68.5 · B | ||
Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.
Fix list 14 items, the biggest gain first
Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Sumsub, or have the agent fetch /fixes/sumsub.md. A fix counts at the next check, once it's public.
Show it
# Fix list: Sumsub From Anchor Terminal's listing at https://www.anchorterminal.com/tools/sumsub, the October 2026 research run, assessed 8 October 2026. Grade B, 68.5 out of 100. This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public. For a coding agent working on Sumsub: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published. ## 1. Payments & pricing, 25 out of 100, up to 9.4 more on the total Why it scored 25: No x402, MPP or L402 (0). Per-verification prices are public for two plans ($1.35 and $1.85, with $149 and $299 monthly minimums). Business verification, transaction monitoring and fraud prevention are quoted by sales (15). Sandbox mode is free without a card and returns test results only. The trial of 50 real checks asks for bank card details (10). Signup, token creation and MCP sign-in all need a person in a browser (0). The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments): The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/). - 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which. - 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login. - 20, a free tier or trial that doesn't need a card. - 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API). Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied. Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol. ## 2. Agent ergonomics, 60 out of 100, up to 6.5 more on the total Why it scored 60: `fields` on 8 operations and limit and offset on 16 let responses be sized. The MCP tool list couldn't be read without an account (13). Offset paging, a cursor on audit events, case filters and transaction queries, but not on every list (16). Errors return code, description and correlationId, with errorCode and errorName for 139 documented cases (18). No idempotency keys. A caller's own externalUserId can be used to look an applicant up before retrying a create. MCP annotations weren't readable (6). No server SDK, and every request needs an HMAC signature over timestamp, method, path and body. Signing examples exist in seven languages (7). The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics): - 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries). - 20, pagination, filtering and output-size controls. - 20, actionable, documented error responses, codes and messages an agent can recover from. - 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations. - 15, sensible defaults, few required parameters, and official SDKs in at least two languages. Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs. ## 3. Reliability, 80 out of 100, up to 4 more on the total Why it scored 80: Graded on the REST API, hosted lines. Statuspage at status.sumsub.com with API, WebSDK and MobileSDK components for three regions (20). In the 90 days to 8 October 2026 it shows a complete outage of 13 minutes on 31 August, 13 minutes of SDK 403 errors on 14 July, 75 minutes of AML screening errors on 20 July, Dashboard search errors on 14 September and an open minor incident for some networks in Vietnam, none an hour of core API downtime (20). Limits published as 300 GET and 50 POST per 5 seconds (15). 429 is documented, but no Retry-After, backoff guidance or idempotency key was found (5). 99.5 per cent monthly availability in Annex 1 of the public terms (10). The API is generally available (10). The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability): Hosted APIs, MCP servers, models and platforms. - 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own). - 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so. - 15, rate limits documented with numbers. - 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved. - 10, an SLA published for any paid tier. - 10, the surface agents use is generally available, not beta or preview. Local packages, SDKs, frameworks and stdio MCP servers. - 20, installs from an official package with supported runtimes stated. - 25, a public CI and test suite, passing on the default branch. - 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered). - 15, semver discipline and breaking changes called out in a changelog. - 15, version 1.0 or later, or declared stable. Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors. ## 4. Schema & documentation, 78 out of 100, up to 3.6 more on the total Why it scored 78: Public OpenAPI 3.0.1 spec at api.sumsub.com/openapi.json with 157 operations (25). llms.txt on docs and API hosts, and every docs page as Markdown (10). Reference pages give an overview, required permission and field tables per method, but only 24 of 157 operations in the spec carry a summary or description, and when not to use a method is rarely stated (12). 1,119 schemas with 132 enums and 319 required lists, though 189 of 5,343 properties are described (10). Request and response examples on reference pages and a table of 139 error codes, while 154 operations declare only a default response (11). A weekly dated changelog, but the spec stays at version 1.0.0 with no version in the path (10). The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema): APIs and MCP servers. - 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool). - 10, llms.txt or Markdown docs served for agents. - 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference. - 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs. - 0 to 15, examples and documented error responses. - 15, versioning and a public changelog. Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference. ## 5. Security & auth, 80 out of 100, up to 3.5 more on the total Why it scored 80: App tokens with per-token permissions, IP allowlist, optional expiry, disable and delete, and HMAC signing so the secret never travels. MCP uses OAuth with PKCE and dynamic client registration (30). View and manage permissions are separate, source keys limit a token to a group of applicants, and a role permission gates MCP. No confirmation step for destructive calls was found (15). The API returns applicant-supplied text and document data. No injection guidance was found. Sumsub's skills refuse non-sandbox tokens (4). Audit trail events API with IP and user agent, 30-day usage per token, and an email on token creation (13). security.txt valid to 31 December 2027, a Bugcrowd engagement, SOC 2 Type 2, ISO/IEC 27001 and PCI DSS listed. No public advisories page found (18). Judgement call, no deduction for the webhook digest test endpoint, which takes a webhook secret in the query string, because the API credential itself can't. The checklist (https://www.anchorterminal.com/benchmark/#checklist-security): - 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option. - 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions. - 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10. - 0 to 15, audit logs or per-call visibility for the operator. - 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public. Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing. ## 6. Maintenance & community, 74 out of 100, up to 2.3 more on the total Why it scored 74: The changelog's latest entry covers 28 September to 2 October 2026, and agent skills 1.5.0 shipped on 3 October (30). Weekly changelog entries through July, August and September (20). Closed service with a dated changelog, a support site and a feedback tool in the MCP server. Response times weren't measurable (10). The WebSDK on npm is at 2.9.0 and mobile SDKs have their own changelogs, but there is no server SDK and no entry in the official MCP registry (8). The skills repository has had five releases since 3 July, and the signing examples took dependency updates until 11 June 2026. No CI workflows in either (6). The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance): - 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older. - 20, at least three releases or dated changelog entries in the last 90 days. - 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15. - 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models). - 10, package health, current dependencies and CI. Models are read for deprecation notice periods and model churn rather than release counts. ## 7. Transparency & trust, 74 out of 100, up to 2.3 more on the total Made of editorial 52, provenance 96. Why it scored 74: Closed service with public terms dated 21 May 2026 naming the contracting entities. Skills and WebSDK are MIT (16). The data processing agreement is Annex 3 of the terms and the privacy notice is dated 19 March 2026. Customers set retention, and data is deleted after a year of inactivity following cancellation. Clause 6.9 lets Sumsub use personal data to develop fraud detection with machine learning, which is disclosed but broad (20). The API reference says breaking changes are versioned and existing endpoints aren't affected. Mobile SDK versions are supported for one year. The older audit endpoint is marked for deprecation without a date (8). Hosting regions EU, UAE and SGP appear on the status page. The subprocessor list is in the Dashboard, not public (8). The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency): - 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms. - 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors). - 0 to 20, a deprecation policy or notices with dates. - 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted). The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two. Provenance checks not met in full (half of this category, computed from checked facts): - Terms of service: read, states 7 of the 7 things a reader expects, and has 2 clauses that cost points (6 of 10) ## What we couldn't check What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it. - unchecked: the MCP server's tool list, count, input schemas and annotations (tools/list needs a signed-in Sumsub account) - unchecked: whether signing up for a Sandbox-only account asks for a card. The docs ask for card details only when activating the trial - unchecked: GitHub stars and open issues for sumsub/agent-skills (GitHub web pages weren't fetched) - Whether 429 responses carry a Retry-After header. None is documented - The subprocessor list and data hosting locations are in the Dashboard and weren't read - Whether the SLA in Annex 1 carries service credits, which weren't found in the text reviewed ## Weaknesses - No idempotency keys and no Retry-After or backoff guidance found in the reviewed documentation - Only 24 of 157 operations in the OpenAPI spec carry a summary or description, and 154 declare only a default response - No official server-side SDK. Sumsub publishes request-signing examples in seven languages instead - The 14-day trial of 50 real checks needs a bank card, and production opens after Sumsub checks the integration - Terms clause 6.9 permits Sumsub to use customers' personal data to develop fraud detection, including machine learning models - The subprocessor list is published in the Dashboard, not on a public page ## What costs an agent a turn today The notes we give agents before they call it. Each one is a workaround an agent shouldn't need. - Sign every request. X-App-Access-Sig is the lowercase hex HMAC-SHA256 of timestamp, uppercase method, path with query and raw body, and the timestamp must be within one minute of server time - Use a sandbox token (prefix sbx) for agent work. Sandbox and production tokens are separate, and Sumsub's own skills refuse any other prefix - Stay under 300 GET and 50 POST requests per 5 seconds, and under 500 new applicants per 24 hours in Sandbox - Token permissions can't be edited after creation. Generate a new token with the narrower set and delete the old one - Subscribe to the applicantReviewed webhook for results and verify x-payload-digest against the raw body before trusting it ## When it's done Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.
What we couldn't check
- unchecked: the MCP server's tool list, count, input schemas and annotations (tools/list needs a signed-in Sumsub account)
- unchecked: whether signing up for a Sandbox-only account asks for a card. The docs ask for card details only when activating the trial
- unchecked: GitHub stars and open issues for sumsub/agent-skills (GitHub web pages weren't fetched)
- Whether 429 responses carry a Retry-After header. None is documented
- The subprocessor list and data hosting locations are in the Dashboard and weren't read
- Whether the SLA in Annex 1 carries service credits, which weren't found in the text reviewed
Sources 24
- docs index for agents docs.sumsub.com · seen 2026-10-08
- OpenAPI spec api.sumsub.com · seen 2026-10-08
- authentication and request signing docs.sumsub.com · seen 2026-10-08
- app tokens, permissions and IP allowlist docs.sumsub.com · seen 2026-10-08
- rate limits docs.sumsub.com · seen 2026-10-08
- error codes docs.sumsub.com · seen 2026-10-08
- MCP server docs.sumsub.com · seen 2026-10-08
- MCP OAuth metadata api.sumsub.com · seen 2026-10-08
- agent tools, skills and Markdown docs docs.sumsub.com · seen 2026-10-08
- agent skills repository github.com · seen 2026-10-08
- request-signing examples github.com · seen 2026-10-08
- Sandbox mode and limits docs.sumsub.com · seen 2026-10-08
- self-service plans and trial docs.sumsub.com · seen 2026-10-08
- pricing sumsub.com · seen 2026-10-08
- status incidents status.sumsub.com · seen 2026-10-08
- terms, SLA (Annex 1) and DPA (Annex 3) sumsub.com · seen 2026-10-08
- service privacy notice sumsub.com · seen 2026-10-08
- trust centre and certifications sumsub.com · seen 2026-10-08
- security.txt sumsub.com · seen 2026-10-08
- changelog, September 2026 docs.sumsub.com · seen 2026-10-08
- webhook retries and signatures docs.sumsub.com · seen 2026-10-08
- audit trail events API docs.sumsub.com · seen 2026-10-08
- official MCP registry search (no result) registry.modelcontextprotocol.io · seen 2026-10-08
- WebSDK on npm registry.npmjs.org · seen 2026-10-08
Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.
Pricing & changes
Pay per use $1.35 / tx Basic is $1.35 per verification with a $149 monthly minimum, and Compliance is $1.85 with a $299 minimum and adds AML screening and address checks. Business verification, transaction monitoring and fraud prevention are on a custom plan through sales. Only completed checks are charged. Sandbox mode is free in any account, limited to 500 new applicants and 1,000 transactions per 24 hours. The 14-day trial of 50 real checks asks for bank card details (https://sumsub.com/pricing/, https://docs.sumsub.com/docs/self-service, checked 2026-10-08).
Prices
| Item | Price | Unit | Note |
|---|---|---|---|
| Basic plan, user verification | $1.35 | per transaction | per completed verification; $149 monthly minimum |
| Compliance plan, user verification with AML screening and address check | $1.85 | per transaction | per completed verification; $299 monthly minimum |
Compared across listings on the price index.
Recent changes
- Latest release
Follow them as a feed at /feeds/tools/sumsub.xml, or this listing's score history at history.json.
Connect
Install
npx skills add sumsub/agent-skills --all -g
First request
curl -X GET \
'https://api.sumsub.com/resources/auditTrailEvents/list?from=2024-06-01+00:00:00&to=2024-06-30+23:59:59&limit=100' \
-H 'X-App-Token: <your-app-token>' \
-H 'X-App-Access-Sig: <your-signature>' \
-H 'X-App-Access-Ts: <unix-timestamp>'
Claude Code
claude mcp add --transport http sumsub https://api.sumsub.com/mcp/
MCP client configuration
{
"mcpServers": {
"sumsub": {
"args": [
"mcp-remote",
"https://api.sumsub.com/mcp/"
],
"command": "npx"
}
}
}
Through letme picks today, calling later
GET https://letme.dev/sumsub
letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.
Compare with
Persona BMiddesk CTrulioo CGrep AI BVeriff C
Head to head Persona vs Sumsub · Sumsub vs Trulioo · Sumsub vs Veriff · Middesk vs Sumsub
Machine-readable
| Similar tool | Grade | Score | Shared capabilities | x402 |
|---|---|---|---|---|
| Persona Persona Identities, Inc. | B | 69.5 | kyc.identity kyc.business kyc.documents kyc.screening kyc.cases | no |
| Middesk Middesk, Inc. | C | 59 | kyc.business kyc.screening kyc.cases kyc.identity | no |
| Trulioo Trulioo Information Services Inc. | C | 58.2 | kyc.identity kyc.business kyc.documents kyc.screening | no |
| Grep AI Parcha Labs, Inc. | B | 64.4 | kyc.business kyc.screening kyc.documents | no |
| Veriff Veriff OÜ | C | 61.1 | kyc.identity kyc.documents kyc.screening | no |
Machine-readable
- JSON
/api/v1/tools/sumsub.json· historyhistory.json· badge/badges/sumsub.svg· changes feed/feeds/tools/sumsub.xml - Markdown
/tools/sumsub.md· slim/tools/sumsub.min.md(or sendAccept: text/markdown) - Fix list
/fixes/sumsub.md·/fixes/sumsub.json - From a terminal
anchor tool sumsub --md(the CLI) · over MCPget_tool {"slug": "sumsub"}at/mcp, no key - Directory index
/api/v1/tools.json· site index/llms.txt
Verify this listing
For the vendorIs this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.
-
Add the badge or a link
On a light page On a dark page <a href="https://www.anchorterminal.com/tools/sumsub"><img src="https://www.anchorterminal.com/badges/sumsub.svg" alt="Sumsub on Anchor Terminal" height="20"></a>[](https://www.anchorterminal.com/tools/sumsub)<a href="https://www.anchorterminal.com/tools/sumsub">Sumsub on Anchor Terminal</a>It counts on a page on sumsub.com or one of its subdomains, or the README of github.com/sumsub/agent-skills.
-
Tell us where it is
We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.
Agents send the same to POST /api/v1/verify as {"slug": "sumsub", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check.
