# Sumsub > Sumsub verifies people from identity documents and a liveness check, verifies businesses against registries, and screens both against sanctions and watchlists. Agents reach it through a signed REST API and a hosted MCP server. - Canonical: https://www.anchorterminal.com/tools/sumsub - Markdown: https://www.anchorterminal.com/tools/sumsub.md (~7,700 tokens) - Slim: https://www.anchorterminal.com/tools/sumsub.min.md (~1,930 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/sumsub.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-08 ## Overview **Grade B · 68.5/100 · rank #167 of 629 · #2 in Identity & business verification · not agent-ready · confidence medium** ## Assessment Per-token permissions, an IP allowlist, HMAC-signed requests and a public OpenAPI spec with Markdown docs suit an agent working on verification cases. No idempotency keys or Retry-After guidance were found, there is no server SDK, and production access needs a browser signup, a bank card and Sumsub's review of the integration. ## Facts | Field | Value | | --- | --- | | Vendor | Sum and Substance Ltd (https://sumsub.com) | | Kind | HTTP API | | Category | Identity & business verification (https://www.anchorterminal.com/categories/identity-verification) | | Transport | HTTP | | Endpoint | `https://api.sumsub.com` | | Auth | OAuth or key · The REST API takes an app token generated in the Dashboard by a signed-in team member. Each request carries `X-App-Token`, `X-App-Access-Ts` and `X-App-Access-Sig`, an HMAC-SHA256 signature made with the token's secret key over the timestamp, method, path and body. A token has its own permissions, an optional IP allowlist, an optional expiry date and optional source keys that limit it to a group of applicants, and it can be disabled or deleted but not edited. Sandbox and production tokens are separate. The MCP server at https://api.sumsub.com/mcp/ uses OAuth with PKCE and dynamic client registration, signs the user in with Sumsub, and needs the Use MCP server role permission. Production mode opens after Sumsub verifies the integration (https://docs.sumsub.com/reference/about-sumsub-api). | | Pricing | Pay per use ($1.35 / tx) · Basic is $1.35 per verification with a $149 monthly minimum, and Compliance is $1.85 with a $299 minimum and adds AML screening and address checks. Business verification, transaction monitoring and fraud prevention are on a custom plan through sales. Only completed checks are charged. Sandbox mode is free in any account, limited to 500 new applicants and 1,000 transactions per 24 hours. The 14-day trial of 50 real checks asks for bank card details (https://sumsub.com/pricing/, https://docs.sumsub.com/docs/self-service, checked 2026-10-08). | | x402 | No · No x402, MPP or L402 in the API reference, the OpenAPI spec or the pricing page (checked 2026-10-08). | | Licence | Proprietary service under Sumsub's terms and conditions. The agent skills repository and the @sumsub/websdk npm package are MIT | | Packages | npm: `@sumsub/websdk` | | Source | https://github.com/sumsub/agent-skills | | Docs | https://docs.sumsub.com | | llms.txt | https://docs.sumsub.com/llms.txt | | Last release | 2026-10-03 | | npm downloads / week | 172,226 | | API | REST at https://api.sumsub.com for both Production and Sandbox. OpenAPI 3.0.1 at https://api.sumsub.com/openapi.json with 157 operations on 134 paths (74 POST, 53 GET, 15 PATCH, 12 DELETE, 3 PUT) | | MCP server | Hosted at https://api.sumsub.com/mcp/, OAuth authorisation code grant with PKCE (S256), dynamic client registration and refresh tokens, issuer cockpit.sumsub.com. Connectors listed for Claude and ChatGPT. The tool list needs a signed-in account and wasn't read | | Credentials | App token plus secret key, shown once. Per-token permissions, IP allowlist, optional expiry, source keys, enable and disable with a reason. An email goes to token managers when a token is created | | Request signing | HMAC-SHA256 over timestamp, method, path with query and body, sent as X-App-Access-Sig with X-App-Access-Ts. The timestamp must be within 1 minute of server time | | Rate limits | 300 GET and 50 POST requests per 5 seconds by default. Sandbox allows 500 new applicants and 1,000 transactions per 24 hours | | Errors | JSON with code, description and correlationId, plus errorCode and errorName on some. The reference lists 139 error codes with their HTTP status. 429 on rate limits, with no Retry-After documented | | Sandbox | A mode of the same account and host, with its own tokens. Presets force approve or reject per check, and document templates return fixed results. Level settings made in Sandbox mirror to production | | Webhooks | HTTP, Slack, Telegram or email. Six delivery attempts over up to 24 hours, HMAC digest in x-payload-digest (SHA256 default, SHA512 optional), delivery logs with manual resend | | Audit | Audit trail events API with cursor paging, filters by user and activity, IP and user agent on each event. The App Tokens page shows requests per token for the last 30 days | | SLA | 99.5 per cent availability per calendar month in Annex 1 of the public terms, excluding up to 5 hours of scheduled maintenance a month | | Status | status.sumsub.com on Statuspage, with API, MobileSDK and WebSDK components for EU, UAE and SGP regions, and Support Systems | | Certifications | SOC 2 Type 2, ISO/IEC 27001, 27017 and 27018, ISO 22301, PCI DSS and iBeta Level 1 and 2 per the trust centre page. Reports are sent on request | | Data handling | Sumsub is processor and the customer sets retention. Data is deleted after one year of account inactivity following cancellation. Terms clause 6.9 permits use of personal data to develop fraud detection, including machine learning | | Capabilities | kyc.identity, kyc.business, kyc.documents, kyc.screening, kyc.cases | | Tags | hosted, usage-based, sandbox, api-key, oauth, mcp, openapi, llms-txt, webhooks, status-page, sla, bug-bounty, soc2, iso27001 | | JSON | https://www.anchorterminal.com/api/v1/tools/sumsub.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 80 | 16.0 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 78 | 12.7 | | Agent ergonomics | 13% | 16.2 | 60 | 9.8 | | Security & auth | 14% | 17.5 | 80 | 14.0 | | Payments & pricing | 10% | 12.5 | 25 | 3.1 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 74 | 6.5 | | Transparency & trust (editorial 52, provenance 96) | 7% | 8.8 | 74 | 6.5 | | Negative events | up to −15 | up to −15 | none recorded | 0 | | **Total** | | | | **68.5 → B** | ### Why each score - Reliability 80: Graded on the REST API, hosted lines. Statuspage at status.sumsub.com with API, WebSDK and MobileSDK components for three regions (20). In the 90 days to 8 October 2026 it shows a complete outage of 13 minutes on 31 August, 13 minutes of SDK 403 errors on 14 July, 75 minutes of AML screening errors on 20 July, Dashboard search errors on 14 September and an open minor incident for some networks in Vietnam, none an hour of core API downtime (20). Limits published as 300 GET and 50 POST per 5 seconds (15). 429 is documented, but no Retry-After, backoff guidance or idempotency key was found (5). 99.5 per cent monthly availability in Annex 1 of the public terms (10). The API is generally available (10). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 78: Public OpenAPI 3.0.1 spec at api.sumsub.com/openapi.json with 157 operations (25). llms.txt on docs and API hosts, and every docs page as Markdown (10). Reference pages give an overview, required permission and field tables per method, but only 24 of 157 operations in the spec carry a summary or description, and when not to use a method is rarely stated (12). 1,119 schemas with 132 enums and 319 required lists, though 189 of 5,343 properties are described (10). Request and response examples on reference pages and a table of 139 error codes, while 154 operations declare only a default response (11). A weekly dated changelog, but the spec stays at version 1.0.0 with no version in the path (10). - Agent ergonomics 60: `fields` on 8 operations and limit and offset on 16 let responses be sized. The MCP tool list couldn't be read without an account (13). Offset paging, a cursor on audit events, case filters and transaction queries, but not on every list (16). Errors return code, description and correlationId, with errorCode and errorName for 139 documented cases (18). No idempotency keys. A caller's own externalUserId can be used to look an applicant up before retrying a create. MCP annotations weren't readable (6). No server SDK, and every request needs an HMAC signature over timestamp, method, path and body. Signing examples exist in seven languages (7). - Security & auth 80: App tokens with per-token permissions, IP allowlist, optional expiry, disable and delete, and HMAC signing so the secret never travels. MCP uses OAuth with PKCE and dynamic client registration (30). View and manage permissions are separate, source keys limit a token to a group of applicants, and a role permission gates MCP. No confirmation step for destructive calls was found (15). The API returns applicant-supplied text and document data. No injection guidance was found. Sumsub's skills refuse non-sandbox tokens (4). Audit trail events API with IP and user agent, 30-day usage per token, and an email on token creation (13). security.txt valid to 31 December 2027, a Bugcrowd engagement, SOC 2 Type 2, ISO/IEC 27001 and PCI DSS listed. No public advisories page found (18). Judgement call, no deduction for the webhook digest test endpoint, which takes a webhook secret in the query string, because the API credential itself can't. - Payments & pricing 25: No x402, MPP or L402 (0). Per-verification prices are public for two plans ($1.35 and $1.85, with $149 and $299 monthly minimums). Business verification, transaction monitoring and fraud prevention are quoted by sales (15). Sandbox mode is free without a card and returns test results only. The trial of 50 real checks asks for bank card details (10). Signup, token creation and MCP sign-in all need a person in a browser (0). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 74: The changelog's latest entry covers 28 September to 2 October 2026, and agent skills 1.5.0 shipped on 3 October (30). Weekly changelog entries through July, August and September (20). Closed service with a dated changelog, a support site and a feedback tool in the MCP server. Response times weren't measurable (10). The WebSDK on npm is at 2.9.0 and mobile SDKs have their own changelogs, but there is no server SDK and no entry in the official MCP registry (8). The skills repository has had five releases since 3 July, and the signing examples took dependency updates until 11 June 2026. No CI workflows in either (6). - Transparency & trust 74: Closed service with public terms dated 21 May 2026 naming the contracting entities. Skills and WebSDK are MIT (16). The data processing agreement is Annex 3 of the terms and the privacy notice is dated 19 March 2026. Customers set retention, and data is deleted after a year of inactivity following cancellation. Clause 6.9 lets Sumsub use personal data to develop fraud detection with machine learning, which is disclosed but broad (20). The API reference says breaking changes are versioned and existing endpoints aren't affected. Mobile SDK versions are supported for one year. The older audit endpoint is marked for deprecation without a date (8). Hosting regions EU, UAE and SGP appear on the status page. The subprocessor list is in the Dashboard, not public (8). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (14 items): https://www.anchorterminal.com/fixes/sumsub.md (JSON https://www.anchorterminal.com/fixes/sumsub.json) ### What we couldn't check - unchecked: the MCP server's tool list, count, input schemas and annotations (tools/list needs a signed-in Sumsub account) - unchecked: whether signing up for a Sandbox-only account asks for a card. The docs ask for card details only when activating the trial - unchecked: GitHub stars and open issues for sumsub/agent-skills (GitHub web pages weren't fetched) - Whether 429 responses carry a Retry-After header. None is documented - The subprocessor list and data hosting locations are in the Dashboard and weren't read - Whether the SLA in Annex 1 carries service credits, which weren't found in the text reviewed ### Sources - docs index for agents: (seen 2026-10-08) - OpenAPI spec: (seen 2026-10-08) - authentication and request signing: (seen 2026-10-08) - app tokens, permissions and IP allowlist: (seen 2026-10-08) - rate limits: (seen 2026-10-08) - error codes: (seen 2026-10-08) - MCP server: (seen 2026-10-08) - MCP OAuth metadata: (seen 2026-10-08) - agent tools, skills and Markdown docs: (seen 2026-10-08) - agent skills repository: (seen 2026-10-08) - request-signing examples: (seen 2026-10-08) - Sandbox mode and limits: (seen 2026-10-08) - self-service plans and trial: (seen 2026-10-08) - pricing: (seen 2026-10-08) - status incidents: (seen 2026-10-08) - terms, SLA (Annex 1) and DPA (Annex 3): (seen 2026-10-08) - service privacy notice: (seen 2026-10-08) - trust centre and certifications: (seen 2026-10-08) - security.txt: (seen 2026-10-08) - changelog, September 2026: (seen 2026-10-08) - webhook retries and signatures: (seen 2026-10-08) - audit trail events API: (seen 2026-10-08) - official MCP registry search (no result): (seen 2026-10-08) - WebSDK on npm: (seen 2026-10-08) ## Who's behind it (provenance 96/100, checked 2026-10-08) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | Sum and Substance Ltd | 20/20 | | Domain age | sumsub.com, registered 2015-05-01 (11 years) | 15/15 | | Endpoint on the vendor's domain | api.sumsub.com | 15/15 | | Terms of service | read, states 7 of the 7 things a reader expects, and has 2 clauses that cost points | 6/10 | | Privacy policy | read, states 8 of the 8 things a reader expects | 10/10 | | Status page | status.sumsub.com | 10/10 | | Changelog | published | 10/10 | | security.txt | valid | 10/10 | The terms (version of 21 May 2026) name Sum and Substance Ltd, England, company number 09688671, 30 St. Mary Axe, London EC3A 8BF, with contracting entities in the UAE, Delaware, Singapore and Cyprus depending on where the customer is registered. The API and the MCP server answer at api.sumsub.com, and the Dashboard and OAuth issuer at cockpit.sumsub.com. sumsub.com/.well-known/security.txt gives security@sumsub.com and a Bugcrowd engagement as contacts and expires on 2027-12-31. The service privacy notice was last updated on 19 March 2026. The data processing agreement is Annex 3 of the terms. RDAP for sumsub.com gives a registration date of 2015-05-01. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service** (https://sumsub.com/terms-and-conditions/), read 2026-10-08, dated 2026-05-21, states 7 of the 7 things a reader expects. - To know. Says it may use customer content to train or improve models, and no opt-out was found (costs points). "6.9 The Customer grants the Service Provider permission to use personal data transferred to the Service Provider under these Terms and Conditions for: (i) developing and testing the Services and/or the System to improve their capabilities for detection and prevention of fraud, including by means of artificial intellig…" - To know. Says the terms or the service can change without notice (costs points). "3.4 The Customer acknowledges that for any reason, at any time, and without prior notice, the Service Provider may issue New Releases, and agrees to implement such New Releases promptly." - To know. Says access can be ended without notice or for any reason. "In this scenario the Service Provider may immediately and without notice suspend the Customer’s access to the Services and the System until the outstanding amount has been paid in full (without prejudice to the Service Provider’s right to suspend or limit the Customer’s access to the System and/or the Services as may…" - To know. Requires arbitration or waives class actions. "The parties agree, pursuant to Article 30(2)(b) of the Rules of Arbitration of the International Chamber of Commerce, that the Expedited Procedure Rules shall apply irrespective of the amount in dispute." - Gives the date it was last updated. Last updated 2026-05-21. - Names the governing law or courts. The law of the State of New York. - States a limit on its liability. Capped at the fees paid in the 3 months before the claim. - Says how changes to the terms are announced. Says it gives notice of a change. - Refers to a service level or uptime commitment. Names 99.5% availability. - Also in the text (2026-10-08). Liability is capped at the lesser of the fees paid in the three months before the claim arose and 5,000 US dollars. "SHALL IN ALL CIRCUMSTANCES BE LIMITED TO: (i) 100% OF THE TOTAL FEES PAID BY THE CUSTOMER TO THE SERVICE PROVIDER DURING THE 3-MONTH PERIOD IMMEDIATELY PRECEDING THE DATE ON WHICH THE CAUSE OF ACTION FIRST AROSE; OR (ii) 5,000 (FIVE THOUSAND) USD, WHICHEVER IS LESS." - Also in the text (2026-10-08). Access may be limited, suspended or ended with immediate effect where usage exceeds 1,000 Checks or 1,000 Applicants in a calendar day. "(vii) the Customer’s usage of the Services exceeds 1000 Checks or 1000 Applicants within any given calendar day." - Also in the text (2026-10-08). After the customer relationship ends, Sumsub may keep personal data and related inferences for its own purposes where it has a lawful basis. "Even after the Customer’s relationship with Sumsub is terminated, Sumsub may retain the Personal Data and related inferences where it has a lawful basis for doing so" **Privacy policy** (https://sumsub.com/privacy-notice-service/), read 2026-10-08, dated 2026-03-19, states 8 of the 8 things a reader expects. - To know. Says it may use customer content to train or improve models, and gives an opt-out. "You have the right to object to the processing of your Personal data for this purpose at any time." - Gives the date it was last updated. Last updated 2026-03-19. - Says how long data is kept. Names a period of 30 days. - Says whether personal data is sold or shared for advertising. Says it does not sell personal data. - Gives a privacy contact. Names a data protection officer. - Says where data is transferred or stored. Relies on standard contractual clauses. - Also in the text (2026-10-08). Sumsub may amend the notice at any time and for any reason, with amendments effective on posting to its website. "Any amendments will be effective immediately upon us posting the updated Privacy Notice on our Website." - Also in the text (2026-10-08). Sumsub may analyse fraud patterns and indicators across different clients, sessions, services, datasets and third-party sources. "To strengthen fraud prevention, Sumsub may also analyse fraud patterns and indicators across different sessions, services, Clients, datasets and third-party sources, where permitted by applicable law and our contractual arrangements." - Also in the text (2026-10-08). The notice states it will be rare that Sumsub has no overriding grounds to keep using personal data after an objection. "it will be rare that we have no compelling, overriding grounds to continue using the Personal data following an objection." ## Live (updated 2026-10-08 17:36 UTC) - Right now: up, HTTP 200, 225 ms, checked 2026-10-08 17:36 UTC (get on `https://api.sumsub.com`) - Uptime 24h 100.0% (25 probes) · 30 days 100.0% (25 probes) · p50 221 ms · p95 274 ms - Vendor status page: none, All Systems Operational - npm `@sumsub/websdk` 2.9.0 - security.txt: valid, expires 2027-12-31T11:59:00Z - Always current: https://www.anchorterminal.com/api/v1/live/sumsub.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Prices | Item | Price | Unit | Note | | --- | --- | --- | --- | | Basic plan, user verification | $1.35 | per transaction | per completed verification; $149 monthly minimum | | Compliance plan, user verification with AML screening and address check | $1.85 | per transaction | per completed verification; $299 monthly minimum | Across all listings: https://www.anchorterminal.com/prices/index.md ## Strengths - App tokens carry per-token permissions, an optional IP allowlist and expiry date, and can be disabled with a recorded reason - Requests are signed with HMAC-SHA256 over timestamp, method, path and body, so the secret key never travels - Public OpenAPI 3.0.1 spec with 157 operations, llms.txt, and every docs page served as Markdown - Hosted MCP server with OAuth, PKCE and dynamic client registration, gated by a Use MCP server role permission - Terms publish a 99.5 per cent monthly uptime commitment, and the status page lists API, WebSDK and MobileSDK for three regions ## Weaknesses - No idempotency keys and no Retry-After or backoff guidance found in the reviewed documentation - Only 24 of 157 operations in the OpenAPI spec carry a summary or description, and 154 declare only a default response - No official server-side SDK. Sumsub publishes request-signing examples in seven languages instead - The 14-day trial of 50 real checks needs a bank card, and production opens after Sumsub checks the integration - Terms clause 6.9 permits Sumsub to use customers' personal data to develop fraud detection, including machine learning models - The subprocessor list is published in the Dashboard, not on a public page ## Before you call it (notes for agents) 1. Sign every request. X-App-Access-Sig is the lowercase hex HMAC-SHA256 of timestamp, uppercase method, path with query and raw body, and the timestamp must be within one minute of server time 2. Use a sandbox token (prefix sbx) for agent work. Sandbox and production tokens are separate, and Sumsub's own skills refuse any other prefix 3. Stay under 300 GET and 50 POST requests per 5 seconds, and under 500 new applicants per 24 hours in Sandbox 4. Token permissions can't be edited after creation. Generate a new token with the narrower set and delete the old one 5. Subscribe to the applicantReviewed webhook for results and verify x-payload-digest against the raw body before trusting it ## Connect Install: ```bash npx skills add sumsub/agent-skills --all -g ``` First request: ```bash curl -X GET \ 'https://api.sumsub.com/resources/auditTrailEvents/list?from=2024-06-01+00:00:00&to=2024-06-30+23:59:59&limit=100' \ -H 'X-App-Token: ' \ -H 'X-App-Access-Sig: ' \ -H 'X-App-Access-Ts: ' ``` Claude Code: ```bash claude mcp add --transport http sumsub https://api.sumsub.com/mcp/ ``` MCP client configuration: ```json { "mcpServers": { "sumsub": { "args": [ "mcp-remote", "https://api.sumsub.com/mcp/" ], "command": "npx" } } } ``` Through letme (picks today, calling later): https://letme.dev/sumsub. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | Persona | B | 69.5 | 148 | kyc.identity, kyc.business, kyc.documents, kyc.screening, kyc.cases | no | https://www.anchorterminal.com/tools/persona.md | | Middesk | C | 59 | 389 | kyc.business, kyc.screening, kyc.cases, kyc.identity | no | https://www.anchorterminal.com/tools/middesk.md | | Trulioo | C | 58.2 | 406 | kyc.identity, kyc.business, kyc.documents, kyc.screening | no | https://www.anchorterminal.com/tools/trulioo.md | | Grep AI | B | 64.4 | 252 | kyc.business, kyc.screening, kyc.documents | no | https://www.anchorterminal.com/tools/grep-ai.md | | Veriff | C | 61.1 | 334 | kyc.identity, kyc.documents, kyc.screening | no | https://www.anchorterminal.com/tools/veriff.md | | Jumio | C | 55 | 461 | kyc.identity, kyc.documents, kyc.screening | no | https://www.anchorterminal.com/tools/jumio.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - The hosted MCP server at https://api.sumsub.com/mcp/ acts with the signed-in user's role permissions and needs the Use MCP server permission. Named tools include applicant_create_individual, verification_link_create, applicant_get, transaction_list and verification_level_list (source: ) - A public OpenAPI 3.0.1 spec lists 157 operations on 134 paths, and every docs page is served as Markdown by adding .md to its URL (source: ) - Default rate limits are 300 GET requests and 50 POST requests per 5 seconds, raised on request to support (source: ) - Annex 1 of the terms commits to 99.5 per cent availability in each calendar month, measured by a third-party check every minute (source: ) - The status page records a complete service outage from 08:15 to 08:28 UTC on 31 August 2026, caused by a bug on the path handling all API requests (source: ) - Sumsub's agent skills repository holds 28 skills at version 1.5.0 (3 October 2026) and tells agents to use sandbox tokens only (source: ) - security.txt names security@sumsub.com and a Bugcrowd engagement and expires on 31 December 2027 (source: ) ## Compare - [Jumio vs Sumsub](https://www.anchorterminal.com/compare/jumio-vs-sumsub.md): C 55 vs B 68.5 - [Persona vs Sumsub](https://www.anchorterminal.com/compare/persona-vs-sumsub.md): B 69.5 vs B 68.5 - [Sumsub vs Trulioo](https://www.anchorterminal.com/compare/sumsub-vs-trulioo.md): B 68.5 vs C 58.2 - [Sumsub vs Veriff](https://www.anchorterminal.com/compare/sumsub-vs-veriff.md): B 68.5 vs C 61.1 - [Middesk vs Sumsub](https://www.anchorterminal.com/compare/middesk-vs-sumsub.md): C 59 vs B 68.5 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on sumsub.com or one of its subdomains, or the README of github.com/sumsub/agent-skills. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "sumsub", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html Sumsub on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![Sumsub on Anchor Terminal](https://www.anchorterminal.com/badges/sumsub.svg)](https://www.anchorterminal.com/tools/sumsub) ``` Plain link: ```html Sumsub on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Sumsub is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/sumsub-dark.png - Light: https://www.anchorterminal.com/assets/share/sumsub-light.png