# Veriff (slim) > Identity verification service from Veriff in Tallinn. It checks an identity document and a selfie, with liveness, database checks and PEP and sanctions screening. Sessions are created and read through the Public API v1, with results sent by webhook. - Full: https://www.anchorterminal.com/tools/veriff.md (~7,150 tokens) · this version ~1,830 tokens · JSON https://www.anchorterminal.com/tools/veriff.json · canonical https://www.anchorterminal.com/tools/veriff - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **C · 61.1/100 · rank #334 of 629 · #3 in Identity & business verification · not agent-ready · confidence medium** Assessment: Per-verification prices are public from $0.80, with a 15-day trial of 50 sessions and no card. Each endpoint page is Markdown with an OpenAPI 3.0 fragment. There is no server SDK, MCP server or idempotency key, most calls need an HMAC signature, and the status page shows nine incidents between 20 July and 7 October 2026. ## Facts - Kind: HTTP API · vendor: Veriff OÜ · category: Identity & business verification · legal entity: Veriff OÜ · provenance 85/100 - Local only (HTTP): npm `@veriff/incontext-sdk`, npm `@veriff/js-sdk`, npm `@veriff/react-native-sdk` - Auth: API key · pricing: Pay per use · x402: no · licence: Proprietary service. The npm capture SDKs are ISC (@veriff/js-sdk, @veriff/incontext-sdk) and MIT (@veriff/react-native-sdk) - Probe metrics: not measured yet (probes haven't run) - Surface graded: Public API v1 (REST over HTTPS). No official MCP server found. The base URL is per integration, shown on the API keys page of the Customer Portal - Endpoints: POST /v1/sessions, PATCH and DELETE /v1/sessions/{id}, POST media and collected-data, GET decision, person, watchlist-screening, attempts and media, POST /v1/validate-registry, Mexican INE and CURP registry reads, POST /v1/faces/import, and a Feedback API for fraud reports - Credentials: API key in X-AUTH-CLIENT plus HMAC-SHA256 in X-HMAC-SIGNATURE with a shared secret key. Up to five secrets per integration, shown once, one of them the master key that signs webhooks - Rate limits: Session creation 30 a minute on Self-Serve and 600 a minute on Enterprise. Session deletion 5 an hour and 10 in 24 hours. No figures found for other endpoints - Sandbox: Test integrations are created at signup and aren't billed. Veriff makes no decision on them, so the developer forces the status from the Customer Portal - Sessions: A session expires 7 days after creation. An end user gets 9 resubmissions and the tenth attempt is declined automatically - Webhooks: Decision, event and watchlist-screening webhooks, signed with X-HMAC-SIGNATURE, delivered at least once and out of order, 200 expected within 5,000 ms, resent for up to a week - Errors: JSON with status fail, a numeric code and a message. Published tables cover codes 1001 to 2104 and authorisation codes 1801 to 1819. A 429 carries code 1004 - SDKs: Capture SDKs only. iOS 10.5.1, Android 9.3.0, React Native 13.2.0, Flutter 7.2.0, Cordova 4.0.0, and @veriff/js-sdk 2.0.0 and @veriff/incontext-sdk 2.5.0 for the web. No server-side client library, and a Postman collection at postman.veriff.com - Retention: 3 months on Essential, 6 months on Plus and Premium, 2 years as a paid add-on per the pricing page. A session deleted by API is removed within 12 hours - Access controls: IP allowlist for the Public API on Enterprise plans, up to 500 entries. An Activity Log in the Customer Portal since 4 May 2026 - Certifications: ISO/IEC 27001:2022 extended to 27017 and 27018, SOC 2 Type II, Cyber Essentials, UK DIATF, iBeta ISO/IEC 30107-3 Levels 1 and 2 per veriff.com/security-and-compliance and the Trust Centre - Status: status.veriff.com on Statuspage, with API, End User Flow, Verification Decisions, Webhooks, Veriff Station, Reporting and KYB components across regions - Prices: Verification, Essential plan (automated decision) $0.80 per transaction; Verification, Plus plan $1.39 per transaction; Verification, Premium plan $1.89 per transaction; PEP and sanctions screening add-on, per verification $0.64 per transaction; Ongoing monitoring add-on, per verification $0.09 per transaction - Scores: Reliability 62, Performance pending, Schema & documentation 82, Agent ergonomics 43, Security & auth 63, Payments & pricing 40, Task success pending, Maintenance & community 74, Transparency & trust 67 · total over the 7 assessed categories - Why: Reliability, Graded on the Public API v1 with the hosted lines. · Schema & documentation, Each endpoint page is served as Markdown with an OpenAPI 3.0.0 fragment (Veriff Public API 1.0.0) and component schemas. · Agent ergonomics, No field selection. · Security & auth, An API key plus HMAC-SHA256 signatures with a shared secret that never travels. · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, Release notes dated 2 October 2026 (Flutter SDK 7.2.0), and the API guides page was updated on 3 September 2026 (30). · Transparency & trust, Closed service. - Sources: 21, open questions: 8, both in the full twin - Capabilities: kyc.identity, kyc.documents, kyc.screening - JSON: https://www.anchorterminal.com/api/v1/tools/veriff.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/veriff.svg` or a link to https://www.anchorterminal.com/tools/veriff from a page on veriff.com or one of its subdomains, or the README of github.com/Veriff/veriff-js-sdk, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Take the base URL from the integration's API keys page. Send X-AUTH-CLIENT on every call and store verification.id from POST /v1/sessions 2. Sign POST and PATCH bodies, and the session ID on GET and DELETE, with HMAC-SHA256 in X-HMAC-SIGNATURE. POST /v1/sessions needs no signature 3. Stay under 30 session creations a minute on Self-Serve, 600 on Enterprise. A 429 carries code 1004 4. Don't blindly retry POST /v1/sessions. Each call makes a new session, which is billed on a live integration 5. Poll GET /v1/sessions/{id}/decision until `verification` is not null, or accept webhooks within 5 seconds and treat duplicates as normal ## Connect ```bash curl -X POST "https:///v1/sessions" \ -H 'Content-Type: application/json' \ -H 'X-AUTH-CLIENT: API-KEY' \ -d '{"verification": {}}' ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/veriff ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Persona | B | 69.5 | kyc.identity, kyc.documents, kyc.screening | https://www.anchorterminal.com/tools/persona.min.md | | Sumsub | B | 68.5 | kyc.identity, kyc.documents, kyc.screening | https://www.anchorterminal.com/tools/sumsub.min.md | | Trulioo | C | 58.2 | kyc.identity, kyc.documents, kyc.screening | https://www.anchorterminal.com/tools/trulioo.min.md | | Jumio | C | 55 | kyc.identity, kyc.documents, kyc.screening | https://www.anchorterminal.com/tools/jumio.min.md | | Grep AI | B | 64.4 | kyc.screening, kyc.documents | https://www.anchorterminal.com/tools/grep-ai.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)