# Sumsub (slim) > Sumsub verifies people from identity documents and a liveness check, verifies businesses against registries, and screens both against sanctions and watchlists. Agents reach it through a signed REST API and a hosted MCP server. - Full: https://www.anchorterminal.com/tools/sumsub.md (~7,800 tokens) · this version ~1,930 tokens · JSON https://www.anchorterminal.com/tools/sumsub.json · canonical https://www.anchorterminal.com/tools/sumsub - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **B · 68.5/100 · rank #167 of 629 · #2 in Identity & business verification · not agent-ready · confidence medium** Assessment: Per-token permissions, an IP allowlist, HMAC-signed requests and a public OpenAPI spec with Markdown docs suit an agent working on verification cases. No idempotency keys or Retry-After guidance were found, there is no server SDK, and production access needs a browser signup, a bank card and Sumsub's review of the integration. ## Facts - Kind: HTTP API · vendor: Sum and Substance Ltd · category: Identity & business verification · legal entity: Sum and Substance Ltd · provenance 96/100 - Endpoint: `https://api.sumsub.com` (HTTP) - Auth: OAuth or key · pricing: Pay per use · x402: no · licence: Proprietary service under Sumsub's terms and conditions. The agent skills repository and the @sumsub/websdk npm package are MIT - Probe metrics: not measured yet (probes haven't run) - API: REST at https://api.sumsub.com for both Production and Sandbox. OpenAPI 3.0.1 at https://api.sumsub.com/openapi.json with 157 operations on 134 paths (74 POST, 53 GET, 15 PATCH, 12 DELETE, 3 PUT) - MCP server: Hosted at https://api.sumsub.com/mcp/, OAuth authorisation code grant with PKCE (S256), dynamic client registration and refresh tokens, issuer cockpit.sumsub.com. Connectors listed for Claude and ChatGPT. The tool list needs a signed-in account and wasn't read - Credentials: App token plus secret key, shown once. Per-token permissions, IP allowlist, optional expiry, source keys, enable and disable with a reason. An email goes to token managers when a token is created - Request signing: HMAC-SHA256 over timestamp, method, path with query and body, sent as X-App-Access-Sig with X-App-Access-Ts. The timestamp must be within 1 minute of server time - Rate limits: 300 GET and 50 POST requests per 5 seconds by default. Sandbox allows 500 new applicants and 1,000 transactions per 24 hours - Errors: JSON with code, description and correlationId, plus errorCode and errorName on some. The reference lists 139 error codes with their HTTP status. 429 on rate limits, with no Retry-After documented - Sandbox: A mode of the same account and host, with its own tokens. Presets force approve or reject per check, and document templates return fixed results. Level settings made in Sandbox mirror to production - Webhooks: HTTP, Slack, Telegram or email. Six delivery attempts over up to 24 hours, HMAC digest in x-payload-digest (SHA256 default, SHA512 optional), delivery logs with manual resend - Audit: Audit trail events API with cursor paging, filters by user and activity, IP and user agent on each event. The App Tokens page shows requests per token for the last 30 days - SLA: 99.5 per cent availability per calendar month in Annex 1 of the public terms, excluding up to 5 hours of scheduled maintenance a month - Status: status.sumsub.com on Statuspage, with API, MobileSDK and WebSDK components for EU, UAE and SGP regions, and Support Systems - Certifications: SOC 2 Type 2, ISO/IEC 27001, 27017 and 27018, ISO 22301, PCI DSS and iBeta Level 1 and 2 per the trust centre page. Reports are sent on request - Data handling: Sumsub is processor and the customer sets retention. Data is deleted after one year of account inactivity following cancellation. Terms clause 6.9 permits use of personal data to develop fraud detection, including machine learning - Prices: Basic plan, user verification $1.35 per transaction; Compliance plan, user verification with AML screening and address check $1.85 per transaction - Scores: Reliability 80, Performance pending, Schema & documentation 78, Agent ergonomics 60, Security & auth 80, Payments & pricing 25, Task success pending, Maintenance & community 74, Transparency & trust 74 · total over the 7 assessed categories - Why: Reliability, Graded on the REST API, hosted lines. · Schema & documentation, Public OpenAPI 3.0.1 spec at api.sumsub.com/openapi.json with 157 operations (25). · Agent ergonomics, `fields` on 8 operations and limit and offset on 16 let responses be sized. · Security & auth, App tokens with per-token permissions, IP allowlist, optional expiry, disable and delete, and HMAC signing so the secret never travels. · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, The changelog's latest entry covers 28 September to 2 October 2026, and agent skills 1.5.0 shipped on 3 October (30). · Transparency & trust, Closed service with public terms dated 21 May 2026 naming the contracting entities. - Sources: 24, open questions: 6, both in the full twin - Capabilities: kyc.identity, kyc.business, kyc.documents, kyc.screening, kyc.cases - JSON: https://www.anchorterminal.com/api/v1/tools/sumsub.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/sumsub.svg` or a link to https://www.anchorterminal.com/tools/sumsub from a page on sumsub.com or one of its subdomains, or the README of github.com/sumsub/agent-skills, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Sign every request. X-App-Access-Sig is the lowercase hex HMAC-SHA256 of timestamp, uppercase method, path with query and raw body, and the timestamp must be within one minute of server time 2. Use a sandbox token (prefix sbx) for agent work. Sandbox and production tokens are separate, and Sumsub's own skills refuse any other prefix 3. Stay under 300 GET and 50 POST requests per 5 seconds, and under 500 new applicants per 24 hours in Sandbox 4. Token permissions can't be edited after creation. Generate a new token with the narrower set and delete the old one 5. Subscribe to the applicantReviewed webhook for results and verify x-payload-digest against the raw body before trusting it ## Connect ```bash npx skills add sumsub/agent-skills --all -g ``` ```bash curl -X GET \ 'https://api.sumsub.com/resources/auditTrailEvents/list?from=2024-06-01+00:00:00&to=2024-06-30+23:59:59&limit=100' \ -H 'X-App-Token: ' \ -H 'X-App-Access-Sig: ' \ -H 'X-App-Access-Ts: ' ``` ```bash claude mcp add --transport http sumsub https://api.sumsub.com/mcp/ ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/sumsub ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Persona | B | 69.5 | kyc.identity, kyc.business, kyc.documents, kyc.screening, kyc.cases | https://www.anchorterminal.com/tools/persona.min.md | | Middesk | C | 59 | kyc.business, kyc.screening, kyc.cases, kyc.identity | https://www.anchorterminal.com/tools/middesk.min.md | | Trulioo | C | 58.2 | kyc.identity, kyc.business, kyc.documents, kyc.screening | https://www.anchorterminal.com/tools/trulioo.min.md | | Grep AI | B | 64.4 | kyc.business, kyc.screening, kyc.documents | https://www.anchorterminal.com/tools/grep-ai.min.md | | Veriff | C | 61.1 | kyc.identity, kyc.documents, kyc.screening | https://www.anchorterminal.com/tools/veriff.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)