Entrust Identity Verification (Onfido) vs Plaid Identity Verification
enterprise-custom
·usage-based · enterprise-custom
Entrust Identity Verification (Onfido) wins · 17–10 (16 drawn)
Agenticness — how well agents can access and operate the productAgenticness
How well agents can access and operate the product
Agent access
ai-native userPoint an agent at llms.txt or agent-oriented docs
weight 2 · round to Entrust Identity Verification (Onfido)An llms.txt file exists at documentation.identity.entrust.com/llms.txt and is directly probed returning HTTP 200 with structured content describing the API/SDK platform, confirming an agent can be pointed at it. Missing for 10: no evidence of broader agent-oriented doc formats (e.g., markdown-only mirrors, sitemap of llms-full.txt) or third-party confirmation that agents successfully consume it.
- [probe] “PROBE llms.txt: HTTP 200 at https://documentation.identity.entrust.com/llms.txt # Entrust Identity Verification Documentation > Entrust Ide…”
- [claimed-docs] “create an applicant → create a workflow run (returns an SDK token) → collect captures via SDK → retrieve results via webhook or polling”
Plaid does have a confirmed llms.txt at plaid.com/llms.txt and a documented MCP server, showing some agent-oriented infrastructure, but the llms.txt content is generic (not IDV-specific) and the docs-as-markdown probe for the Identity Verification pages returned a 404, meaning agent-friendly docs are not reliably available for this product area. missing for 10: a working IDV-specific llms.txt or markdown docs endpoint, evidence the MCP server exposes IDV-specific docs/tools, and independent confirmation of agent consumption.
- [probe] “PROBE llms.txt: HTTP 200 at https://plaid.com/llms.txt # Plaid > Plaid helps all companies build fintech solutions by making it easy, safe …”
- [probe] “PROBE docs-md: HTTP 404 at https://plaid.com/docs/identity-verification/.md”
- [probe] “official MCP server documented at https://plaid.com/docs/resources/mcp/”
ai-native userRun the product headlessly / in CI for automation
weight 2 · round to Entrust Identity Verification (Onfido)The product exposes a full REST API (create applicant, create workflow run, webhooks, OAuth client-credentials tokens) that could be scripted headlessly in CI, and webhook/polling patterns support automation without UI interaction. However, the primary workflow-building tool is explicitly no-code/drag-and-drop, and there is no evidence of a CLI, SDK for CI pipelines, or documented headless/automation-testing use case. missing for 10: explicit CI/headless automation examples, CLI tooling, documented non-interactive test/staging workflows, and confirmation that Workflow Studio config can be version-controlled or scripted rather than GUI-only.
- [claimed-docs] “Obtaining SDK tokens – SDK tokens are essential for authenticating and initializing the Entrust IDV SDKs”
- [claimed-docs] “create an applicant → create a workflow run (returns an SDK token) → collect captures via SDK → retrieve results via webhook or polling”
- [claimed-docs] “Configuring webhooks – asynchronously monitor the status of identity verification workflows by configuring webhook events to notify you of c…”
- [claimed-docs] “Entrust recommends generating short-lived OAuth access tokens for API authentication using client credentials grant.”
- [claimed-docs] “It's a no-code, drag and drop interface that allows you to build, maintain and update workflows seamlessly without the need for developer in…”
Plaid Identity Verificationnone0/10Evidence shows Plaid IDV as an API/webhook-driven product with a no-code Dashboard editor and Sandbox testing inputs, but there is no documentation of a CLI, SDK automation, or CI-friendly headless workflow that an AI-native user could run in an automated pipeline. Missing for 10: explicit CI/headless usage docs, CLI or automation SDK evidence, example of scripted/unattended runs.
- [claimed-docs] “No-code editor to create and change verification flows”
- [claimed-docs] “In Sandbox mode, Identity Verification accepts the fixed set of inputs below in order to result in successful Data Source and Documentary Ve…”
- [probe] “PROBE openapi: all candidate paths 404 (https://plaid.com/openapi.json, https://plaid.com/swagger.json, https://plaid.com/api/openapi.json, …”
ai-native userConnect an agent via an official MCP server
weight 3 · round to Plaid Identity VerificationEntrust Identity Verification (Onfido)none0/10The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)
Plaid is a platform/service (not itself an agent), so the axis applies, and evidence confirms an official MCP server exists at plaid.com/docs/resources/mcp/. However, the pack only shows the existence of the page, not details on what tools/capabilities are exposed via MCP or independent corroboration of its use. Missing for 10: documentation of specific MCP tool/resource definitions, usage examples, and independent/hands-on confirmation of successful agent connection.
- [probe] “official MCP server documented at https://plaid.com/docs/resources/mcp/”
ai-native userUse an official CLI
weight 2 · round drawnEntrust Identity Verification (Onfido)none0/10The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)
ai-native userDrive the product through a documented public API
weight 3 · round to Entrust Identity Verification (Onfido)Entrust provides a well-documented public API/SDK flow (applicant creation, workflow run, SDK token, webhook or polling for results) plus OAuth client-credentials authentication and webhook signature verification, all confirmed by a live llms.txt probe describing it as 'a comprehensive API and SDK platform'. missing for 10: independent/community corroboration of real-world API integration, and a direct link to a full API reference/OpenAPI spec beyond the docs snippets.
- [claimed-docs] “Obtaining SDK tokens – SDK tokens are essential for authenticating and initializing the Entrust IDV SDKs”
- [claimed-docs] “create an applicant → create a workflow run (returns an SDK token) → collect captures via SDK → retrieve results via webhook or polling”
- [claimed-docs] “Configuring webhooks – asynchronously monitor the status of identity verification workflows by configuring webhook events to notify you of c…”
- [claimed-docs] “You can get the expected signature of the webhook by computing the HMAC of the event request body using the SHA256 algorithm, using the webh…”
- [claimed-docs] “Entrust recommends generating short-lived OAuth access tokens for API authentication using client credentials grant.”
- [probe] “PROBE llms.txt: HTTP 200 at https://documentation.identity.entrust.com/llms.txt # Entrust Identity Verification Documentation > Entrust Ide…”
Plaid IDV is documented as a REST API with webhooks, events, and workflow configuration, indicating a documented public API surface (plaid-idv-docs-1,2,3,5), and Plaid also publishes an official MCP server (plaid-idv-probe-4) supporting agentic access. However, an OpenAPI spec could not be located at standard paths and the docs-md probe 404'd, suggesting incomplete machine-readable API discoverability. missing for 10: publicly discoverable OpenAPI/schema spec, confirmation that MCP server covers IDV endpoints specifically, independent developer corroboration of API-driven automation.
- [claimed-docs] “Using Identity Verification, you can verify identification documents, phone numbers, name, date of birth, ID numbers, addresses, and more.”
- [claimed-docs] “You can combine multiple verification checks within a single Identity Verification template via the Workflow Management editor, and even run…”
- [claimed-docs] “For Identity Verification, there are three events: STEP_UPDATED, STATUS_UPDATED, RETRIED”
- [claimed-docs] “onEvent will fire at certain points throughout the IDV flow with updates on the user's progress at each point.”
- [probe] “PROBE openapi: all candidate paths 404 (https://plaid.com/openapi.json, https://plaid.com/swagger.json, https://plaid.com/api/openapi.json, …”
- [probe] “official MCP server documented at https://plaid.com/docs/resources/mcp/”
ai-native userIssue scoped/least-privilege API credentials for an agent
weight 2 · round to Entrust Identity Verification (Onfido)The docs show OAuth client-credentials grant for short-lived tokens and separate SDK tokens for capture flows, which provides some credential separation, but there is no explicit mention of scoped/least-privilege roles, permission granularity, or agent-specific credential issuance. missing for 10: explicit least-privilege/scoped role definitions, documentation of granting narrower API scopes per use-case or agent, and any AI-agent-specific credential workflow.
- [claimed-docs] “Entrust recommends generating short-lived OAuth access tokens for API authentication using client credentials grant.”
- [claimed-docs] “Obtaining SDK tokens – SDK tokens are essential for authenticating and initializing the Entrust IDV SDKs”
ai-native userBuild against official SDKs
weight 2 · round drawnEvidence confirms official SDKs exist (mobile/web SDKs, SDK tokens, migration guide from Smart Capture SDKs to new IDV SDKs) with documented API/webhook/auth flows, showing developers can build against them. However, there's no evidence of language-specific SDK repos, open-source code samples, versioning/release notes, or independent developer corroboration of build experience. Missing for 10: public SDK repository/language coverage details, code samples, independent developer testimonials, changelog/versioning transparency.
- [claimed-docs] “Obtaining SDK tokens – SDK tokens are essential for authenticating and initializing the Entrust IDV SDKs”
- [claimed-docs] “create an applicant → create a workflow run (returns an SDK token) → collect captures via SDK → retrieve results via webhook or polling”
- [claimed-docs] “Entrust recommends generating short-lived OAuth access tokens for API authentication using client credentials grant.”
- [claimed-docs] “NFC is **only available for integration via the Entrust Identity Verification mobile SDKs**.”
- [claimed-docs] “migration guide to support migrations from the latest Smart Capture SDKs to the new Entrust IDV SDKs and highlight all new features”
Plaid provides official docs, webhooks, and an llms.txt for AI-native discovery, plus a documented official MCP server, but there's no direct evidence of official language-specific SDKs for Identity Verification itself (probes for OpenAPI spec and docs.md all 404). missing for 10: explicit official SDK references/links, independent developer corroboration of SDK usage.
- [claimed-docs] “Using Identity Verification, you can verify identification documents, phone numbers, name, date of birth, ID numbers, addresses, and more.”
- [probe] “PROBE llms.txt: HTTP 200 at https://plaid.com/llms.txt # Plaid > Plaid helps all companies build fintech solutions by making it easy, safe …”
- [probe] “official MCP server documented at https://plaid.com/docs/resources/mcp/”
- [probe] “PROBE docs-md: HTTP 404 at https://plaid.com/docs/identity-verification/.md”
- [probe] “PROBE openapi: all candidate paths 404 (https://plaid.com/openapi.json, https://plaid.com/swagger.json, https://plaid.com/api/openapi.json, …”
ai-native userSubscribe to events via webhooks
weight 2 · round drawnDocs clearly document configurable webhook events to notify on workflow status changes, including signature verification via HMAC-SHA256, showing a supported webhook subscription mechanism. missing for 10: no documentation of event type granularity/catalog, no independent/hands-on corroboration, and no explicit mention of self-serve webhook management UI or retry/delivery guarantees.
- [claimed-docs] “Configuring webhooks – asynchronously monitor the status of identity verification workflows by configuring webhook events to notify you of c…”
- [claimed-docs] “You can get the expected signature of the webhook by computing the HMAC of the event request body using the SHA256 algorithm, using the webh…”
- [claimed-docs] “create an applicant → create a workflow run (returns an SDK token) → collect captures via SDK → retrieve results via webhook or polling”
Plaid IDV documents a clear webhook subscription mechanism with defined events (STEP_UPDATED, STATUS_UPDATED, RETRIED) that fire on verification progress, allowing programmatic/agentic subscription to state changes. Missing for 10: no explicit documentation of webhook payload schema, retry/delivery guarantees, or independent/hands-on confirmation that agentic systems actually consume these webhooks in production.
- [claimed-docs] “For Identity Verification, there are three events: STEP_UPDATED, STATUS_UPDATED, RETRIED”
- [claimed-docs] “onEvent will fire at certain points throughout the IDV flow with updates on the user's progress at each point.”
Agentic features
ai-native userSet up automations that run autonomously in the background
weight 2 · round drawnWorkflow Studio provides no-code, drag-and-drop automation of verification workflows, and webhooks/polling allow asynchronous, background monitoring of workflow status rather than requiring active user polling — evidence of some autonomous background operation. However, this is workflow automation for identity checks, not an AI-native agentic automation framework (no mention of AI agent orchestration, scheduling, or LLM-driven decisioning). Missing for 10: evidence of AI-agent-specific automation setup, autonomous decision-making beyond fixed verification steps, and integration with agent frameworks.
- [claimed-docs] “It's a no-code, drag and drop interface that allows you to build, maintain and update workflows seamlessly without the need for developer in…”
- [claimed-docs] “Configuring webhooks – asynchronously monitor the status of identity verification workflows by configuring webhook events to notify you of c…”
- [claimed-docs] “create an applicant → create a workflow run (returns an SDK token) → collect captures via SDK → retrieve results via webhook or polling”
Plaid IDV supports background automation via webhooks (STEP_UPDATED, STATUS_UPDATED, RETRIED) and a no-code Workflow Management editor that can run conditional verification checks without manual intervention, which enables some autonomous background processing. However, there is no evidence of AI-agent-specific automation setup, natural-language automation configuration, or scheduling/triggering by an AI agent itself. Missing for 10: explicit AI-agent-driven automation setup, natural-language workflow configuration, evidence of autonomous agent-triggered verification chains beyond webhook/workflow primitives.
- [claimed-docs] “You can combine multiple verification checks within a single Identity Verification template via the Workflow Management editor, and even run…”
- [claimed-docs] “For Identity Verification, there are three events: STEP_UPDATED, STATUS_UPDATED, RETRIED”
- [claimed-docs] “No-code editor to create and change verification flows”
- [claimed-docs] “onEvent will fire at certain points throughout the IDV flow with updates on the user's progress at each point.”
ai-native userOperate the product with natural-language commands
weight 2 · round to Plaid Identity VerificationEntrust Identity Verification (Onfido)none0/10The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)
Plaid documents a no-code visual workflow editor for configuring Identity Verification, not natural-language command operation, but a probe confirms Plaid has an official MCP server (plaid.com/docs/resources/mcp/) which could allow AI agents to invoke Plaid APIs including IDV via natural language. There is no direct evidence that this MCP server specifically exposes Identity Verification actions or that end-users can operate IDV flows via NL commands. missing for 10: IDV-specific MCP tool documentation, examples of natural-language driven verification commands, independent confirmation of agentic usage.
- [probe] “official MCP server documented at https://plaid.com/docs/resources/mcp/”
- [claimed-docs] “No-code editor to create and change verification flows”
Api quality
ai-native userExplore an interactive API reference with runnable examples
weight 2 · round drawnEntrust Identity Verification (Onfido)none0/10The evidence pack shows conventional API/SDK documentation (auth, webhooks, workflow setup) but no mention of an interactive API reference, API explorer, or runnable code examples anywhere in the docs.
Plaid Identity Verificationnone0/10No evidence of an interactive API reference with runnable examples; OpenAPI spec probes returned 404s and docs are plain markdown pages, not interactive/runnable explorer.
ai-native userDownload a machine-readable API spec (OpenAPI or equivalent)
weight 2 · round drawnEntrust Identity Verification (Onfido)none0/10The evidence pack shows extensive API/webhook documentation but no mention of a downloadable OpenAPI/Swagger spec or other machine-readable API definition file. As an API-driven platform, this axis is applicable, but no evidence supports it.
Plaid Identity Verificationnone0/10Probes explicitly show no OpenAPI/swagger spec found at any candidate path and no machine-readable .md/doc spec at the IDV docs endpoint; documentation is prose-based rather than a downloadable API spec.
ai-native userTest against a sandbox environment without touching production data
weight 1 · round to Plaid Identity VerificationEntrust Identity Verification (Onfido)none0/10The evidence pack covers SDK tokens, webhooks, OAuth, and workflow tools but contains no mention of a sandbox/test environment separate from production for API or SDK testing. This is a fair axis for an API/SDK platform, but no evidence supports it.
Plaid IDV documents a dedicated Sandbox mode with fixed test inputs to simulate successful/failed verification checks without touching production data, which directly supports safe testing. missing for 10: no independent/hands-on developer confirmation of sandbox fidelity, and no explicit mention of automated/agentic test workflows against the sandbox.
- [claimed-docs] “In Sandbox mode, Identity Verification accepts the fixed set of inputs below in order to result in successful Data Source and Documentary Ve…”
ai-native userRely on versioned APIs with a documented deprecation policy
weight 2 · round to Entrust Identity Verification (Onfido)The docs reference an 'api/latest' version and a migration guide for moving from Smart Capture SDKs to new IDV SDKs, implying some versioning and change management, but there is no explicit documented deprecation policy, version support timeline, or sunset schedule for APIs. missing for 10: explicit versioned API scheme (e.g., v1/v2 endpoints), a published deprecation/sunset policy, and timelines for backward compatibility.
- [claimed-docs] “Obtaining SDK tokens – SDK tokens are essential for authenticating and initializing the Entrust IDV SDKs”
- [claimed-docs] “migration guide to support migrations from the latest Smart Capture SDKs to the new Entrust IDV SDKs and highlight all new features”
Plaid Identity Verificationnone0/10No evidence of API versioning scheme or documented deprecation policy for Plaid Identity Verification's APIs; docs cover verification features, webhooks, sandbox testing, but nothing on version lifecycle or deprecation commitments. The openapi.json probe also 404s, suggesting no discoverable machine-readable API spec that would typically accompany versioning docs.
- [probe] “PROBE openapi: all candidate paths 404 (https://plaid.com/openapi.json, https://plaid.com/swagger.json, https://plaid.com/api/openapi.json, …”
- [claimed-docs] “For Identity Verification, there are three events: STEP_UPDATED, STATUS_UPDATED, RETRIED”
- [claimed-docs] “In Sandbox mode, Identity Verification accepts the fixed set of inputs below in order to result in successful Data Source and Documentary Ve…”
Automation depth — how much of the product can run unattendedAutomation depth
How much of the product can run unattended
ai-native userPerform bulk operations across many items at once
weight 2 · round drawnEntrust Identity Verification (Onfido)none0/10The evidence describes single-applicant workflows (create applicant → workflow run → SDK token → webhook) and no batch/bulk API endpoints, CSV bulk upload, or multi-item processing tools are documented. Bulk operations are a plausible axis for an identity verification API but no supporting evidence exists.
- [claimed-docs] “create an applicant → create a workflow run (returns an SDK token) → collect captures via SDK → retrieve results via webhook or polling”
- [claimed-docs] “Configuring webhooks – asynchronously monitor the status of identity verification workflows by configuring webhook events to notify you of c…”
Plaid Identity Verificationnone0/10No evidence of batch/bulk API operations, bulk session creation, or programmatic multi-item processing for Identity Verification; documentation covers single-session workflows, webhooks, and dashboard-based overrides only, with no mention of bulk endpoints or automation-scale operations across many items.
- [claimed-docs] “You can combine multiple verification checks within a single Identity Verification template via the Workflow Management editor, and even run…”
- [claimed-docs] “For Identity Verification, there are three events: STEP_UPDATED, STATUS_UPDATED, RETRIED”
- [claimed-docs] “you can override a failure via the Dashboard by clicking the Override Result button on the verification detail page in the Dashboard.”
ai-native userDefine rules that trigger actions automatically on events
weight 3 · round to Entrust Identity Verification (Onfido)Workflow Studio provides a no-code, drag-and-drop rule builder for defining identity verification workflows, and webhooks let users trigger downstream actions automatically on workflow status change events, satisfying the event-driven automation story within the IDV domain. Missing for 10: detailed documentation of conditional/branching rule logic within Workflow Studio and independent/hands-on corroboration of the rule engine's flexibility.
- [claimed-docs] “It's a no-code, drag and drop interface that allows you to build, maintain and update workflows seamlessly without the need for developer in…”
- [claimed-docs] “Configuring webhooks – asynchronously monitor the status of identity verification workflows by configuring webhook events to notify you of c…”
- [claimed-docs] “create an applicant → create a workflow run (returns an SDK token) → collect captures via SDK → retrieve results via webhook or polling”
Plaid IDV supports webhooks that fire on defined events (STEP_UPDATED, STATUS_UPDATED, RETRIED) and a Workflow Management editor that lets you run certain verification checks conditionally (e.g., only if another check fails or based on country), which together give a rule/event-driven automation capability. However, this is scoped to verification-flow logic and webhook notifications rather than a general-purpose 'define rules that trigger arbitrary actions' engine. missing for 10: evidence of a broader rule/action engine beyond conditional verification checks, and evidence of user-defined custom actions (not just webhook notifications) triggered by events.
- [claimed-docs] “You can combine multiple verification checks within a single Identity Verification template via the Workflow Management editor, and even run…”
- [claimed-docs] “For Identity Verification, there are three events: STEP_UPDATED, STATUS_UPDATED, RETRIED”
- [claimed-docs] “onEvent will fire at certain points throughout the IDV flow with updates on the user's progress at each point.”
- [claimed-docs] “No-code editor to create and change verification flows”
Biometric liveness — stories about biometric liveness in this arenaBiometric liveness
Stories about biometric liveness in this arena
Deepfake defense
risk analystThe vendor documents specific defenses against AI-generated faces, deepfakes, and camera-injection attacks — named detection capabilities, not just a marketing mention of fraud
weight 2 · round drawnEntrust Identity Verification (Onfido)none0/10Evidence documents general liveness via head-motion challenges (Motion feature) and repeat-face fraud alerts, but nothing names specific defenses against AI-generated faces, deepfakes, or camera-injection attacks as the story requires. Missing for 10: named deepfake detection capability, AI-generated/synthetic face detection, and camera/virtual-camera injection attack prevention documentation.
- [claimed-docs] “Motion also assesses liveness by asking users to complete either a simple head turn pattern in both directions or four randomized head movem…”
- [claimed-docs] “The alerts you to faces which have already been through your identity verification flow, highlighting potential repeat identity fraud attemp…”
Plaid Identity Verificationnone0/10The evidence pack covers document verification, workflow management, webhooks, sandbox testing, risk scoring, and dashboard overrides, but contains no mention of liveness detection, anti-spoofing, deepfake detection, AI-generated face detection, or camera-injection defenses by name. Community items are off-topic (data trust/competition) and irrelevant to biometric liveness. Missing for 10: named liveness/anti-spoofing detection capabilities, deepfake or synthetic-face detection mentions, camera-injection attack defenses.
Duplicate detection
risk analystThe platform detects repeat and duplicate identities across verifications — the same face or document resurfacing under different names is flagged automatically
weight 2 · round to Entrust Identity Verification (Onfido)Docs explicitly describe a facial deduplication feature that flags faces already seen in prior verification flows, directly addressing repeat-identity detection under different names. However, evidence lacks detail on document-level duplicate detection, how matches are surfaced/scored to a risk analyst, or independent/hands-on validation of accuracy. Missing for 10: document dedup evidence, analyst-facing reporting/UI detail, independent corroboration of detection accuracy.
- [claimed-docs] “The alerts you to faces which have already been through your identity verification flow, highlighting potential repeat identity fraud attemp…”
Plaid Identity Verificationnone0/10The evidence covers document/identity verification checks, risk scoring, webhooks, and dashboard overrides, but nothing describes cross-session duplicate or repeat-identity detection (e.g., matching the same face/document under different names). Missing for 10: any documentation of duplicate-identity or repeat-fraud detection across sessions, biometric/face matching against prior submissions, or deduplication reporting.
- [claimed-docs] “Using Identity Verification, you can verify identification documents, phone numbers, name, date of birth, ID numbers, addresses, and more.”
- [claimed-docs] “Identity Verification will also display a set of granular risk assessments (email risk, phone risk, etc.) in the Dashboard for each session,…”
- [claimed-docs] “The conversion rate is defined as the percentage of sessions begun that were completed, regardless of whether the user passed or failed veri…”
Liveness
risk analystSelfie checks match the live user to the document portrait with liveness detection — documented defenses against printed photos, screens, and replayed video
weight 3 · round to Entrust Identity Verification (Onfido)Docs confirm a facial similarity/liveness check using motion challenges (head turns, randomized movements) to match selfie to document portrait, but there is no explicit documentation describing specific defenses against printed photos, screen replays, or video replay attacks. Missing for 10: explicit anti-spoofing detail (printed photo, screen, deepfake/video replay countermeasures), independent testing/accuracy corroboration.
- [claimed-docs] “Motion also assesses liveness by asking users to complete either a simple head turn pattern in both directions or four randomized head movem…”
Plaid Identity Verificationnone0/10The evidence pack covers document verification, workflows, webhooks, sandbox testing, risk scoring, and dashboard overrides, but never mentions selfie/facial matching or liveness detection defenses against photos, screens, or replayed video. No documentation cites a selfie check or anti-spoofing mechanism at all.
Data checks — stories about data checks in this arenaData checks
Stories about data checks in this arena
Db checks
developerVerify identity against authoritative databases without documents — SSN, national registries, or credit-header data — for lower-friction flows where a doc scan is overkill
weight 2 · round to Plaid Identity VerificationEntrust Identity Verification (Onfido)none0/10The evidence pack covers document verification, biometric/facial checks, watchlist/PEP/sanctions screening, webhooks, and SDK auth flows, but contains no mention of document-free identity verification against SSN, national ID registries, or credit-header databases. Since this is a plausible capability for an IDV platform, absence of evidence means 'none' rather than 'na'.
Docs show IDV can check ID numbers, phone, address, name/DOB and combine checks conditionally (skipping some verifications like documents based on risk/country), implying some document-free paths exist, but no evidence explicitly names SSN, national registry, or credit-header-only verification flows as a distinct low-friction option. missing for 10: explicit mention of SSN-only or credit-header verification, explicit 'no-doc' database-only workflow example, independent confirmation of doc-free flows in production.
- [claimed-docs] “Using Identity Verification, you can verify identification documents, phone numbers, name, date of birth, ID numbers, addresses, and more.”
- [claimed-docs] “You can combine multiple verification checks within a single Identity Verification template via the Workflow Management editor, and even run…”
- [claimed-docs] “Authenticate IDs Verify that global ID documents are authentic and valid.”
Kyb
ops leadVerify businesses, not just people — registry lookups, UBO identification, and documented KYB flows that chain into KYC on the owners
weight 2 · round drawnEntrust Identity Verification (Onfido)none0/10All evidence focuses on individual identity verification (document capture, facial similarity, watchlist/PEP checks on applicants, workflow studio for KYC flows) — there is no mention of business/registry lookups, UBO (ultimate beneficial owner) identification, or documented KYB (know-your-business) workflows chaining into KYC on owners.
Plaid Identity Verificationnone0/10All evidence describes Plaid Identity Verification as a personal KYC flow (documents, phone, DOB, ID numbers, risk scoring) with no mention of business registry lookups, UBO identification, or a documented KYB workflow chaining into KYC on owners.
- [claimed-docs] “Using Identity Verification, you can verify identification documents, phone numbers, name, date of birth, ID numbers, addresses, and more.”
- [claimed-docs] “You can combine multiple verification checks within a single Identity Verification template via the Workflow Management editor, and even run…”
- [claimed-docs] “Identity Verification will also display a set of granular risk assessments (email risk, phone risk, etc.) in the Dashboard for each session,…”
- [claimed-docs] “Monitor also integrates directly with Identity Verification for an end-to-end verification and KYC solution.”
Risk signals
developerEnrich verifications with phone, email, and device risk signals — carrier checks, address history, device fingerprint — as additional documented check types
weight 2 · round to Plaid Identity VerificationEntrust Identity Verification (Onfido)none0/10The evidence pack documents document reports, facial similarity/liveness, watchlist/PEP/sanctions checks, and duplicate-face detection, but contains no mention of phone, email, carrier, address history, or device fingerprint risk signals as check types. missing for 10: phone risk check docs, email risk check docs, carrier/device fingerprint check docs, address history check docs.
- [claimed-docs] “In your Dashboard, you can configure which documents you want to accept in your verification workflow, filtering according to issuing countr…”
- [claimed-docs] “Watchlist reports verify an applicant's records against a range of global watchlists, including: Sanctions... Politically Exposed Persons (P…”
- [claimed-docs] “The alerts you to faces which have already been through your identity verification flow, highlighting potential repeat identity fraud attemp…”
- [claimed-docs] “Motion also assesses liveness by asking users to complete either a simple head turn pattern in both directions or four randomized head movem…”
Docs confirm phone and email risk scoring plus granular risk assessments shown per session, and address/name/ID verification is documented as a check type, but there is no explicit documentation of carrier checks, address history checks, or device fingerprinting as distinct check types. missing for 10: explicit carrier check documentation, address history verification, device fingerprint/risk signal documentation.
- [claimed-docs] “Using Identity Verification, you can verify identification documents, phone numbers, name, date of birth, ID numbers, addresses, and more.”
- [claimed-docs] “Identity Verification will also display a set of granular risk assessments (email risk, phone risk, etc.) in the Dashboard for each session,…”
Document coverage — stories about document coverage in this arenaDocument coverage
Stories about document coverage in this arena
Doc types
ops leadThe platform verifies government IDs from a documented breadth of countries and document types — passports, national IDs, driver licenses, residence permits — with the supported list published
weight 3 · round to Entrust Identity Verification (Onfido)Docs confirm the platform lets ops configure accepted documents by issuing country and document type (docs-8), implying broad multi-country/document-type support, but no published list enumerating supported countries or specific document types (passports, national IDs, licenses, residence permits) is provided in the evidence. Missing for 10: a published country/document-type coverage list, explicit mention of all four document categories, and any breadth metric (e.g., number of countries/documents supported).
- [claimed-docs] “In your Dashboard, you can configure which documents you want to accept in your verification workflow, filtering according to issuing countr…”
- [claimed-docs] “NFC is **only available for integration via the Entrust Identity Verification mobile SDKs**.”
Plaid's docs assert it verifies 'identification documents' and 'global ID documents' broadly, but no evidence provides an actual published list of supported countries or document types (passports, national IDs, driver licenses, residence permits) as the story requires. missing for 10: a published country/document-type coverage list, explicit mention of residence permits or other document categories, independent corroboration of coverage breadth.
- [claimed-docs] “Using Identity Verification, you can verify identification documents, phone numbers, name, date of birth, ID numbers, addresses, and more.”
- [claimed-docs] “Authenticate IDs Verify that global ID documents are authentic and valid.”
- [claimed-docs] “You can combine multiple verification checks within a single Identity Verification template via the Workflow Management editor, and even run…”
Extraction
developerVerified sessions return the extracted document fields as structured data — name, date of birth, document number, address, expiry — retrievable via the API, not just a pass/fail flag
weight 2 · round to Plaid Identity VerificationEntrust Identity Verification (Onfido)none0/10The evidence describes workflow results retrievable via webhook or polling and a 'document report' concept, but nothing explicitly confirms that structured fields (name, DOB, document number, address, expiry) are returned as retrievable API data rather than a report/pass-fail outcome. Missing for 10: explicit API/webhook payload schema or docs showing per-field extracted data (name, DOB, doc number, address, expiry) returned to developers.
- [claimed-docs] “create an applicant → create a workflow run (returns an SDK token) → collect captures via SDK → retrieve results via webhook or polling”
- [claimed-docs] “Configuring webhooks – asynchronously monitor the status of identity verification workflows by configuring webhook events to notify you of c…”
- [claimed-docs] “In your Dashboard, you can configure which documents you want to accept in your verification workflow, filtering according to issuing countr…”
Docs confirm Plaid extracts and verifies fields like name, DOB, ID numbers, and address from documents, and risk scores/results are viewable in the Dashboard, implying this data exists per session. However, there's no explicit evidence that these individual extracted document fields are retrievable via API as structured data in the response payload (as opposed to just Dashboard viewing or an overall pass/fail status). Missing for 10: explicit API schema/response example showing per-field structured output (name, DOB, document number, address, expiry) retrievable via API call, independent developer confirmation of this data access pattern.
- [claimed-docs] “Using Identity Verification, you can verify identification documents, phone numbers, name, date of birth, ID numbers, addresses, and more.”
- [claimed-docs] “Identity Verification will also display a set of granular risk assessments (email risk, phone risk, etc.) in the Dashboard for each session,…”
- [claimed-docs] “Authenticate IDs Verify that global ID documents are authentic and valid.”
Idv agent access — stories about idv agent access in this arenaIdv agent access
Stories about idv agent access in this arena
Agent decisions
ai-native userVerification outcomes come back structured enough for an agent to decide on — machine-readable check results, risk signals, and failure reasons an automated onboarding flow can branch on
weight 2 · round drawnDocs show a structured, API-driven flow (workflow run → SDK token → webhook/polling → reports) with distinct report types (document, watchlist/PEP/sanctions/adverse media, facial similarity, repeat-fraud alerts) that provide machine-consumable results an automation could branch on. However, there is no explicit evidence of a documented schema for risk scores, standardized failure-reason codes, or example JSON payloads that an agent would parse to make branching decisions. Missing for 10: explicit result schema/field reference, enumerated failure/rejection reason codes, and sample structured payloads showing risk signal granularity.
- [claimed-docs] “create an applicant → create a workflow run (returns an SDK token) → collect captures via SDK → retrieve results via webhook or polling”
- [claimed-docs] “Configuring webhooks – asynchronously monitor the status of identity verification workflows by configuring webhook events to notify you of c…”
- [claimed-docs] “In your Dashboard, you can configure which documents you want to accept in your verification workflow, filtering according to issuing countr…”
- [claimed-docs] “Watchlist reports verify an applicant's records against a range of global watchlists, including: Sanctions... Politically Exposed Persons (P…”
- [claimed-docs] “The alerts you to faces which have already been through your identity verification flow, highlighting potential repeat identity fraud attemp…”
- [claimed-docs] “You can get the expected signature of the webhook by computing the HMAC of the event request body using the SHA256 algorithm, using the webh…”
Plaid IDV exposes structured webhook events (STEP_UPDATED, STATUS_UPDATED, RETRIED) and per-session risk signals (email/phone risk, overall risk score) that a workflow could branch on, plus conditional check logic in templates. However, evidence doesn't show a documented API response schema with explicit machine-readable failure-reason codes for programmatic branching, and there's no independent/hands-on confirmation of how granular or reliable these signals are for automated agent decisioning. Missing for 10: explicit API/webhook payload schema with structured failure-reason enums, and independent corroboration of agent-usable structured outputs.
- [claimed-docs] “For Identity Verification, there are three events: STEP_UPDATED, STATUS_UPDATED, RETRIED”
- [claimed-docs] “Identity Verification will also display a set of granular risk assessments (email risk, phone risk, etc.) in the Dashboard for each session,…”
- [claimed-docs] “You can combine multiple verification checks within a single Identity Verification template via the Workflow Management editor, and even run…”
- [claimed-docs] “onEvent will fire at certain points throughout the IDV flow with updates on the user's progress at each point.”
Agent operations
ai-native userAn agent can operate the verification pipeline — create sessions, poll outcomes, retrieve extracted data, and trigger re-checks through the API or an MCP surface with scoped credentials
weight 3 · round to Entrust Identity Verification (Onfido)The API supports the core pipeline: create applicant/workflow run, obtain SDK/OAuth tokens with scoped client-credentials grants, and retrieve results via webhook or polling (docs-2,3,4,6). However there is no evidence of an MCP surface for agent access, and no explicit documentation of a 're-check' trigger endpoint distinct from creating a new workflow run. missing for 10: MCP server/tool surface for agentic access, explicit re-check/re-verification API, and any agent-oriented orchestration examples.
- [claimed-docs] “Obtaining SDK tokens – SDK tokens are essential for authenticating and initializing the Entrust IDV SDKs”
- [claimed-docs] “create an applicant → create a workflow run (returns an SDK token) → collect captures via SDK → retrieve results via webhook or polling”
- [claimed-docs] “Configuring webhooks – asynchronously monitor the status of identity verification workflows by configuring webhook events to notify you of c…”
- [claimed-docs] “Entrust recommends generating short-lived OAuth access tokens for API authentication using client credentials grant.”
Plaid IDV has a documented API/webhook model (create sessions, poll status via STEP_UPDATED/STATUS_UPDATED/RETRIED events, retrieve data) and an official MCP server is referenced, suggesting some agent-friendly surface exists. However, there is no evidence describing scoped credentials for agent use, no documentation of MCP tools specifically exposing IDV session creation/polling/data retrieval/re-check triggers, and no confirmation of programmatic re-check triggering beyond dashboard override. missing for 10: MCP server tool documentation specific to IDV endpoints, scoped/least-privilege credential model for agents, programmatic re-check/retry trigger via API, independent confirmation of agent usage.
- [claimed-docs] “For Identity Verification, there are three events: STEP_UPDATED, STATUS_UPDATED, RETRIED”
- [claimed-docs] “you can override a failure via the Dashboard by clicking the Override Result button on the verification detail page in the Dashboard.”
- [probe] “official MCP server documented at https://plaid.com/docs/resources/mcp/”
Integration dx — sandboxes, test modes, webhooks, and how fast a developer gets to a working integrationIntegration dx
Sandboxes, test modes, webhooks, and how fast a developer gets to a working integration
Sandbox
developerA sandbox lets me exercise every outcome before going live — documented test documents, personas, or magic values that deterministically produce pass, fail, and review results
weight 3 · round to Plaid Identity VerificationEntrust Identity Verification (Onfido)none0/10No evidence of a sandbox environment with documented test documents, personas, or magic values that deterministically produce pass/fail/review outcomes; the pack only covers workflow setup, SDK tokens, webhooks, and report types. missing for 10: sandbox/test-mode documentation, sample test documents or personas, deterministic magic-value test data for triggering specific verification outcomes.
Plaid's docs explicitly document a Sandbox mode with a fixed set of inputs that deterministically produce specific Data Source and Documentary Verification check outcomes, directly matching the story's requirement for documented test values to exercise pass/fail scenarios. Missing for 10: explicit confirmation of a 'review' outcome test value and independent/hands-on developer corroboration beyond first-party docs.
- [claimed-docs] “In Sandbox mode, Identity Verification accepts the fixed set of inputs below in order to result in successful Data Source and Documentary Ve…”
Session api
developerThe whole verification lifecycle is drivable through the API — create a session, get its status, retrieve results and captured media, and cancel or redact it — with every step documented
weight 3 · round to Entrust Identity Verification (Onfido)Docs confirm core lifecycle steps — create applicant, create workflow run, obtain SDK token, retrieve results via webhook or polling — plus authentication (OAuth) and webhook signature verification are documented. However, explicit API-level documentation for retrieving captured media, and for cancel/redact operations, is not shown in the evidence pack. missing for 10: documented endpoint/example for retrieving captured media via API, documented cancel operation, documented redact/delete operation, and independent confirmation these work end-to-end.
- [claimed-docs] “Obtaining SDK tokens – SDK tokens are essential for authenticating and initializing the Entrust IDV SDKs”
- [claimed-docs] “create an applicant → create a workflow run (returns an SDK token) → collect captures via SDK → retrieve results via webhook or polling”
- [claimed-docs] “Configuring webhooks – asynchronously monitor the status of identity verification workflows by configuring webhook events to notify you of c…”
- [claimed-docs] “You can get the expected signature of the webhook by computing the HMAC of the event request body using the SHA256 algorithm, using the webh…”
- [claimed-docs] “Entrust recommends generating short-lived OAuth access tokens for API authentication using client credentials grant.”
Docs confirm session lifecycle events (webhooks for STEP_UPDATED/STATUS_UPDATED/RETRIED) and sandbox testing, implying some API-driven flow, but there is no explicit documentation of endpoints for creating a session, fetching status/results, retrieving captured media, or canceling/redacting a session via API — most control (overrides, flow editing) is shown as Dashboard/no-code actions rather than API calls. missing for 10: explicit API reference for create/get/retrieve-media/cancel/redact endpoints, first-party API examples for each lifecycle step.
- [claimed-docs] “For Identity Verification, there are three events: STEP_UPDATED, STATUS_UPDATED, RETRIED”
- [claimed-docs] “In Sandbox mode, Identity Verification accepts the fixed set of inputs below in order to result in successful Data Source and Documentary Ve…”
- [claimed-docs] “you can override a failure via the Dashboard by clicking the Override Result button on the verification detail page in the Dashboard.”
- [claimed-docs] “No-code editor to create and change verification flows”
Webhooks
developerVerification lifecycle events arrive as signed webhooks — created, processing, verified, requires-input — so my system reacts to outcomes without polling
weight 2 · round to Entrust Identity Verification (Onfido)Docs confirm webhooks can be configured to asynchronously notify status changes on workflow runs, with signed payloads verified via HMAC-SHA256, letting developers avoid polling. However, the pack never enumerates the specific lifecycle states (created, processing, verified, requires-input) claimed in the story, so exact event coverage is unconfirmed. missing for 10: explicit list of webhook event types/payload schema, independent confirmation of event granularity.
- [claimed-docs] “Configuring webhooks – asynchronously monitor the status of identity verification workflows by configuring webhook events to notify you of c…”
- [claimed-docs] “You can get the expected signature of the webhook by computing the HMAC of the event request body using the SHA256 algorithm, using the webh…”
- [claimed-docs] “create an applicant → create a workflow run (returns an SDK token) → collect captures via SDK → retrieve results via webhook or polling”
Plaid IDV documents webhook events (STEP_UPDATED, STATUS_UPDATED, RETRIED) that let a developer react to verification lifecycle changes without polling, but the evidence never confirms these webhooks are cryptographically signed nor does it list the specific status values (created, processing, verified, requires-input) named in the story. Missing for 10: explicit documentation of webhook signature verification, and confirmation of the exact lifecycle status enum matching the story's terms.
- [claimed-docs] “For Identity Verification, there are three events: STEP_UPDATED, STATUS_UPDATED, RETRIED”
- [claimed-docs] “onEvent will fire at certain points throughout the IDV flow with updates on the user's progress at each point.”
Openness — open source, data portability, and self-hosting storiesOpenness
Open source, data portability, and self-hosting stories
ai-native userDo everything through the API that I can do in the UI
weight 2 · round to Entrust Identity Verification (Onfido)Core verification actions (create applicant, start workflow run, obtain SDK token, retrieve results via webhook/polling) are documented as API operations, but Workflow Studio (workflow building) and Dashboard-based document-acceptance configuration are explicitly positioned as no-code/low-code UI tools 'without the need for developer involvement,' with no documented API equivalent for authoring or editing workflows/rules themselves. Missing for 10: API/SDK endpoints for programmatically creating or editing workflows and document-acceptance rules equivalent to what Workflow Studio and the Dashboard provide, and confirmation that NFC or other SDK-only features are reachable via pure API calls.
- [claimed-docs] “It's a no-code, drag and drop interface that allows you to build, maintain and update workflows seamlessly without the need for developer in…”
- [claimed-docs] “create an applicant → create a workflow run (returns an SDK token) → collect captures via SDK → retrieve results via webhook or polling”
- [claimed-docs] “Smart Capture Link is a low- to no-code frontend solution complementing Workflow Studio, allowing you to verify individuals with or without …”
- [claimed-docs] “In your Dashboard, you can configure which documents you want to accept in your verification workflow, filtering according to issuing countr…”
- [claimed-docs] “NFC is **only available for integration via the Entrust Identity Verification mobile SDKs**.”
Plaid Identity Verificationnone0/10Evidence shows several capabilities are explicitly UI/Dashboard-only — e.g., the no-code Workflow Management editor for creating flows (plaid-idv-docs-8) and overriding failed verifications 'via the Dashboard by clicking the Override Result button' (plaid-idv-docs-7) — with no documented API equivalent for either. There is no evidence of a full API surface mirroring these UI actions, so the story is not shown to be delivered.
- [claimed-docs] “you can override a failure via the Dashboard by clicking the Override Result button on the verification detail page in the Dashboard.”
- [claimed-docs] “No-code editor to create and change verification flows”
- [probe] “PROBE openapi: all candidate paths 404 (https://plaid.com/openapi.json, https://plaid.com/swagger.json, https://plaid.com/api/openapi.json, …”
Privacy posture — data-handling and privacy storiesPrivacy posture
Data-handling and privacy stories
ai-native userChoose where my data is stored (region/residency)
weight 2 · round drawnEntrust Identity Verification (Onfido)none0/10No evidence in the pack mentions data residency, regional storage options, or data localization controls for Entrust Identity Verification; the docs cover workflow building, SDK tokens, webhooks, and verification reports but say nothing about where data is stored or user choice of region.
ai-native userControl data retention and deletion
weight 2 · round drawnEntrust Identity Verification (Onfido)none0/10The evidence pack covers workflow building, SDK/API auth, webhooks, document/watchlist checks, and fraud detection, but contains no mention of data retention policies, deletion controls, or user-facing privacy/data lifecycle management. No documentation excerpt addresses how users or AI-native integrators can configure retention periods or trigger deletion of collected identity data.
Plaid Identity Verificationnone0/10The evidence pack contains no documentation of data retention settings, deletion APIs, or user-facing controls for purging identity verification data — only unrelated docs on verification checks, webhooks, and dashboard workflows. The negative community comment expresses general distrust but is not concrete evidence of a retention/deletion feature failing, so it doesn't support 'disputed'; it simply confirms no capability is evidenced.
- [claimed-docs] “Using Identity Verification, you can verify identification documents, phone numbers, name, date of birth, ID numbers, addresses, and more.”
- [claimed-docs] “Identity Verification will also display a set of granular risk assessments (email risk, phone risk, etc.) in the Dashboard for each session,…”
- [community] “Wow. I truly hate having to use plaid. This is disappointing. I have zero faith that they hold my data safely or that it won't be stolen or …”
Privacy retention — stories about privacy retention in this arenaPrivacy retention
Stories about privacy retention in this arena
Consent
founderThe vendor documents how biometric data is handled lawfully — GDPR bases, US biometric statutes like BIPA, and the consent language my flow needs — so legal review has something to review
weight 2 · round drawnEntrust Identity Verification (Onfido)none0/10The evidence pack covers technical integration (SDKs, webhooks, workflow studio, watchlist/document reports) but contains no documentation addressing GDPR legal bases, BIPA or other US biometric statutes, or consent language guidance for biometric data handling.
Plaid Identity Verificationnone0/10The evidence pack contains only general product/API documentation (verification checks, webhooks, sandbox testing, dashboard features) with no mention of GDPR legal bases, BIPA or other biometric statutes, or required consent language for biometric data collection. Community items are off-topic sentiment about data trust, not legal compliance documentation.
Redaction
ops leadControl what happens to collected identity data — documented retention windows and a redaction or deletion API that scrubs PII on demand
weight 2 · round drawnEntrust Identity Verification (Onfido)none0/10None of the evidence mentions documented data retention windows or a redaction/deletion API for PII; the docs cover workflow building, SDK tokens, webhooks, watchlist reports, and biometric features but nothing about data lifecycle controls. missing for 10: retention policy documentation, deletion/redaction API endpoints, and any mention of PII scrubbing on demand.
Plaid Identity Verificationnone0/10The evidence pack covers verification checks, webhooks, dashboards, and risk scoring, but contains no documentation of data retention windows or a redaction/deletion API for scrubbing PII on demand. The community comments express general distrust about data safety but do not concretely confirm or deny a deletion/retention mechanism, so they cannot be used to dispute the claim either way.
- [claimed-docs] “Using Identity Verification, you can verify identification documents, phone numbers, name, date of birth, ID numbers, addresses, and more.”
- [claimed-docs] “Identity Verification will also display a set of granular risk assessments (email risk, phone risk, etc.) in the Dashboard for each session,…”
Verification flows — stories about verification flows in this arenaVerification flows
Stories about verification flows in this arena
Hosted flows
developerLaunch a complete document-plus-selfie verification with a hosted or drop-in flow — create a session server-side, redirect or embed, and read the result — without building capture UI myself
weight 3 · round to Entrust Identity Verification (Onfido)Docs describe the full server-side flow: create applicant, create workflow run (returns SDK token), collect document+selfie captures via drop-in/hosted SDK, and retrieve results via webhook or polling — exactly the no-build-your-own-capture-UI flow described in the story. Also supports Smart Capture Link as a hosted no-code option and webhook signature verification for secure result reads. missing for 10: no independent/hands-on developer corroboration (blog posts, sample repos, or third-party integration reports) confirming the drop-in/hosted redirect flow works end-to-end in practice.
- [claimed-docs] “create an applicant → create a workflow run (returns an SDK token) → collect captures via SDK → retrieve results via webhook or polling”
- [claimed-docs] “Obtaining SDK tokens – SDK tokens are essential for authenticating and initializing the Entrust IDV SDKs”
- [claimed-docs] “Configuring webhooks – asynchronously monitor the status of identity verification workflows by configuring webhook events to notify you of c…”
- [claimed-docs] “You can get the expected signature of the webhook by computing the HMAC of the event request body using the SHA256 algorithm, using the webh…”
- [claimed-docs] “Smart Capture Link is a low- to no-code frontend solution complementing Workflow Studio, allowing you to verify individuals with or without …”
Docs show a Link-based embeddable flow (onEvent updates), webhook events to read session status, and document/ID verification checks, indicating Plaid provides the capture UI and hosted/drop-in flow with server-driven session lifecycle. However, evidence never explicitly confirms a selfie/facial biometric step combined with document checks, nor explicitly describes server-side session creation API or a hosted redirect option (only Link embed and no-code editor are mentioned). Missing for 10: explicit selfie/liveness verification documentation, explicit server-side create-session API reference, and confirmation of a hosted (non-Link) redirect flow.
- [claimed-docs] “Using Identity Verification, you can verify identification documents, phone numbers, name, date of birth, ID numbers, addresses, and more.”
- [claimed-docs] “onEvent will fire at certain points throughout the IDV flow with updates on the user's progress at each point.”
- [claimed-docs] “For Identity Verification, there are three events: STEP_UPDATED, STATUS_UPDATED, RETRIED”
- [claimed-docs] “Authenticate IDs Verify that global ID documents are authentic and valid.”
- [claimed-docs] “No-code editor to create and change verification flows”
Native sdks
developerI get native iOS, Android, and web SDKs with guided camera capture — glare, blur, and edge detection coaching the user to a usable document photo on the first try
weight 2 · round to Entrust Identity Verification (Onfido)Evidence confirms native mobile SDKs (with NFC only via mobile SDK) and an SDK-token based capture flow, and the product name 'Smart Capture' implies guided capture, but there is no explicit documentation of glare/blur/edge-detection coaching or confirmation of iOS, Android, and web SDK parity. missing for 10: explicit glare/blur/edge-detection coaching documentation, confirmation of web SDK support, first-try capture UX detail.
- [claimed-docs] “Obtaining SDK tokens – SDK tokens are essential for authenticating and initializing the Entrust IDV SDKs”
- [claimed-docs] “create an applicant → create a workflow run (returns an SDK token) → collect captures via SDK → retrieve results via webhook or polling”
- [claimed-docs] “NFC is **only available for integration via the Entrust Identity Verification mobile SDKs**.”
- [claimed-docs] “migration guide to support migrations from the latest Smart Capture SDKs to the new Entrust IDV SDKs and highlight all new features”
- [claimed-docs] “Smart Capture Link is a low- to no-code frontend solution complementing Workflow Studio, allowing you to verify individuals with or without …”
Plaid Identity Verificationnone0/10The evidence confirms Plaid IDV supports document verification and has Link SDK flows with event callbacks (onEvent), but nothing describes native iOS/Android/web SDKs offering guided camera capture with glare, blur, or edge-detection coaching. Missing for 10: mention of native mobile SDKs, in-flow camera guidance features, and any glare/blur/edge detection capability documentation.
- [claimed-docs] “onEvent will fire at certain points throughout the IDV flow with updates on the user's progress at each point.”
- [claimed-docs] “In Sandbox mode, Identity Verification accepts the fixed set of inputs below in order to result in successful Data Source and Documentary Ve…”
No code
ops leadSend a verification to someone with a no-code link or QR code — no engineering ticket to verify a one-off customer, contractor, or seller
weight 2 · round to Entrust Identity Verification (Onfido)Smart Capture Link is documented as a low-/no-code frontend that lets ops verify individuals without engineering effort, aligning with the no-code link concept, and Workflow Studio supports drag-and-drop workflow setup without developers. However, there is no explicit mention of a shareable QR code option or a simple 'send a one-off link' flow from a dashboard for ad-hoc individuals like contractors or sellers. missing for 10: explicit QR code generation/sharing feature, documentation of an ops-friendly one-off invite/send flow, independent or hands-on confirmation of ease-of-use for non-technical ops staff.
- [claimed-docs] “Smart Capture Link is a low- to no-code frontend solution complementing Workflow Studio, allowing you to verify individuals with or without …”
- [claimed-docs] “It's a no-code, drag and drop interface that allows you to build, maintain and update workflows seamlessly without the need for developer in…”
Plaid documents a no-code editor for building verification flows and a Dashboard for managing sessions, suggesting some non-engineering control, but there is no explicit evidence of an ops-facing feature to generate a shareable verification link or QR code for a one-off customer/contractor without engineering involvement. Missing for 10: explicit dashboard 'send link/QR code' feature, evidence of ops-only workflow without developer setup, and confirmation that Link integration isn't required for a single verification.
- [claimed-docs] “No-code editor to create and change verification flows”
- [claimed-docs] “You can combine multiple verification checks within a single Identity Verification template via the Workflow Management editor, and even run…”
Reuse
developerA person verified once can be recognized and reused across sessions or products — documented re-verification and reuse of a prior passed check instead of forcing a full re-run
weight 2 · round drawnEntrust Identity Verification (Onfido)none0/10The docs describe repeat-face detection for fraud purposes (flagging faces that already went through verification) but this is a fraud-detection alert, not a documented mechanism for reusing a prior passed check to skip re-verification across sessions or products. No evidence of a 'reusable identity' or portable verification token/credential feature.
- [claimed-docs] “The alerts you to faces which have already been through your identity verification flow, highlighting potential repeat identity fraud attemp…”
Plaid Identity Verificationnone0/10The evidence pack covers verification checks, workflows, webhooks, sandbox testing, and dashboard overrides, but nowhere documents a mechanism to recognize a previously verified user and reuse a passed check across sessions or products instead of re-running verification.
Verification orchestration — stories about verification orchestration in this arenaVerification orchestration
Stories about verification orchestration in this arena
Analytics
founderSee verification funnel analytics — pass rates, drop-off points, completion time by country and document type — to know what verification is costing me in signups
weight 2 · round to Plaid Identity VerificationEntrust Identity Verification (Onfido)none0/10Evidence covers workflow configuration, SDK/webhook integration, document/watchlist checks, and fraud detection, but nothing about a dashboard or reporting feature showing pass rates, drop-off funnels, or completion time broken down by country/document type. No analytics or reporting evidence exists to support this founder-facing metrics story.
Plaid documents a 'reporting' page defining conversion rate (session completion rate) and a Dashboard showing per-session risk scores, implying some analytics exist, but there is no evidence of drop-off-point analysis, completion-time metrics, or breakdowns by country or document type. missing for 10: drop-off funnel visualization, completion-time-by-country/document-type metrics, independent confirmation of dashboard analytics depth.
- [claimed-docs] “The conversion rate is defined as the percentage of sessions begun that were completed, regardless of whether the user passed or failed veri…”
- [claimed-docs] “Identity Verification will also display a set of granular risk assessments (email risk, phone risk, etc.) in the Dashboard for each session,…”
Review
ops leadBorderline verifications land in a manual review queue with the full evidence — document images, extracted fields, check results — and reviewer decisions feed back into the record
weight 2 · round to Plaid Identity VerificationEntrust Identity Verification (Onfido)none0/10The evidence pack documents workflow orchestration, SDKs, webhooks, watchlist/document reports, and dashboard configuration, but nowhere describes a manual review queue that surfaces document images, extracted fields, and check results together, nor a feedback loop where reviewer decisions update the record. Missing for 10: explicit manual review queue documentation, evidence bundling for reviewers, and reviewer decision feedback into the applicant record.
Docs confirm a Dashboard-based review path — failed verifications can be manually overridden and each session shows risk assessments and status updates via webhooks — implying some human-in-the-loop review, but there is no explicit description of a dedicated 'manual review queue' surfacing document images/extracted fields for borderline cases, nor documented mechanics for how reviewer decisions are recorded back into the verification record beyond a simple override click. missing for 10: explicit manual review queue UI, evidence bundling (docs+fields+checks) presented together for review, and documented reviewer-decision audit trail feeding back into the record.
- [claimed-docs] “you can override a failure via the Dashboard by clicking the Override Result button on the verification detail page in the Dashboard.”
- [claimed-docs] “Identity Verification will also display a set of granular risk assessments (email risk, phone risk, etc.) in the Dashboard for each session,…”
- [claimed-docs] “For Identity Verification, there are three events: STEP_UPDATED, STATUS_UPDATED, RETRIED”
- [claimed-docs] “The conversion rate is defined as the percentage of sessions begun that were completed, regardless of whether the user passed or failed veri…”
Workflows
ops leadConfigure verification logic without code — conditional steps, risk-based routing, country-specific requirements, and template changes that don't need an engineering deploy
weight 3 · round to Plaid Identity VerificationWorkflow Studio is explicitly documented as a no-code, drag-and-drop tool for building/maintaining/updating workflows without developer involvement, and the Dashboard lets ops filter accepted documents by issuing country — both directly support code-free verification-logic configuration. However, the evidence never explicitly confirms conditional branching or risk-based routing logic within Workflow Studio, only general workflow building and document/country filtering. Missing for 10: explicit documentation of conditional-step/risk-based routing configuration, and independent/hands-on confirmation that template changes deploy live without engineering involvement.
- [claimed-docs] “It's a no-code, drag and drop interface that allows you to build, maintain and update workflows seamlessly without the need for developer in…”
- [claimed-docs] “Smart Capture Link is a low- to no-code frontend solution complementing Workflow Studio, allowing you to verify individuals with or without …”
- [claimed-docs] “In your Dashboard, you can configure which documents you want to accept in your verification workflow, filtering according to issuing countr…”
Plaid's docs explicitly describe a no-code Workflow Management editor for building templates, combining conditional checks (run only if another fails or is high-risk), and country-based routing, plus a dashboard for overrides and risk scoring—matching the ops-lead story closely. missing for 10: independent/hands-on validation of the no-code editor's actual usability and confirmation that template changes deploy without any engineering involvement in practice.
- [claimed-docs] “You can combine multiple verification checks within a single Identity Verification template via the Workflow Management editor, and even run…”
- [claimed-docs] “No-code editor to create and change verification flows”
- [claimed-docs] “Identity Verification will also display a set of granular risk assessments (email risk, phone risk, etc.) in the Dashboard for each session,…”
- [claimed-docs] “you can override a failure via the Dashboard by clicking the Override Result button on the verification detail page in the Dashboard.”
Watchlist screening — stories about watchlist screening in this arenaWatchlist screening
Stories about watchlist screening in this arena
Monitoring
ops leadScreening is not one-shot — previously verified users are continuously re-screened against watchlist updates, and changes raise events I can act on
weight 2 · round drawnEntrust Identity Verification (Onfido)none0/10Evidence documents one-time Watchlist Reports (sanctions, PEP, monitored lists, adverse media) run during a verification workflow, plus webhooks that notify on workflow status changes — but nothing describes ongoing/continuous re-screening of previously verified applicants against watchlist updates or dedicated 'watchlist changed' events after the initial check.
- [claimed-docs] “Watchlist reports verify an applicant's records against a range of global watchlists, including: Sanctions... Politically Exposed Persons (P…”
- [claimed-docs] “Configuring webhooks – asynchronously monitor the status of identity verification workflows by configuring webhook events to notify you of c…”
Plaid Identity Verificationnone0/10Plaid IDV's webhooks (STEP_UPDATED, STATUS_UPDATED, RETRIED) fire during a verification session's flow, not as ongoing re-screening of already-verified users against new watchlist hits. The docs explicitly point to a separate product, Plaid Monitor, for continuous monitoring/KYC, implying IDV itself does not perform continuous re-screening.
- [claimed-docs] “For Identity Verification, there are three events: STEP_UPDATED, STATUS_UPDATED, RETRIED”
- [claimed-docs] “Monitor also integrates directly with Identity Verification for an end-to-end verification and KYC solution.”
Screening
ops leadScreen verified users against sanctions, PEP, and adverse-media watchlists as part of the same verification — one vendor, one API, one review surface
weight 2 · round to Entrust Identity Verification (Onfido)Docs explicitly describe Watchlist reports covering Sanctions, PEPs, Monitored Lists, and Adverse Media, integrated into the same workflow/API/dashboard used for identity verification (single vendor, single API, unified webhook/review surface). missing for 10: no independent/hands-on corroboration of the unified review UI or case-management workflow for screening hits.
- [claimed-docs] “Watchlist reports verify an applicant's records against a range of global watchlists, including: Sanctions... Politically Exposed Persons (P…”
- [claimed-docs] “create an applicant → create a workflow run (returns an SDK token) → collect captures via SDK → retrieve results via webhook or polling”
- [claimed-docs] “Configuring webhooks – asynchronously monitor the status of identity verification workflows by configuring webhook events to notify you of c…”
Plaid's docs show that its separate Monitor product 'integrates directly with Identity Verification for an end-to-end verification and KYC solution,' implying sanctions/PEP/adverse-media screening is available from the same vendor, but the evidence never describes this as a single unified API call or review surface — it reads as two distinct products stitched together rather than one seamless verification session. Missing for 10: explicit documentation of sanctions/PEP/adverse-media screening as a native check within the IDV template/workflow itself, unified webhook/events covering watchlist results, and independent confirmation of a single review surface across both products.
- [claimed-docs] “Monitor also integrates directly with Identity Verification for an end-to-end verification and KYC solution.”
- [claimed-docs] “You can combine multiple verification checks within a single Identity Verification template via the Workflow Management editor, and even run…”
- [claimed-docs] “Identity Verification will also display a set of granular risk assessments (email risk, phone risk, etc.) in the Dashboard for each session,…”
Not comparable on these axes
ai-native userPlug MCP servers into this product so it can use their tools
weight 3 · not comparableEntrust Identity Verification (Onfido)n/aEntrust Identity Verification is an identity-verification API/SDK platform, not an AI agent or assistant that consumes tools; MCP server integration is a wrong-axis question for this product category and there is no evidence of MCP support in the pack.
Plaid Identity Verificationn/aPlaid Identity Verification is a verification/KYC SaaS API, not an AI agent or assistant that itself consumes external tools via MCP; the evidence shows Plaid offers an MCP server (docs/resources/mcp) exposing its own APIs, which is the reverse (server) role, not the client-side 'plug MCP servers in so it can use their tools' capability this story asks about. This axis is a category error for a non-agentic verification product.
- [probe] “official MCP server documented at https://plaid.com/docs/resources/mcp/”
ai-native userGet AI-generated insights and suggestions from my data inside the product
weight 2 · not comparableEntrust Identity Verification (Onfido)n/aEntrust Identity Verification is an identity-proofing/verification API and SDK platform (document checks, facial similarity, watchlist screening, workflows), not a data-analytics or generative-AI insights product where users query their data for AI-generated suggestions. The story's axis is a category error for this product type.
- [claimed-docs] “It's a no-code, drag and drop interface that allows you to build, maintain and update workflows seamlessly without the need for developer in…”
- [claimed-docs] “Watchlist reports verify an applicant's records against a range of global watchlists, including: Sanctions... Politically Exposed Persons (P…”
- [claimed-docs] “The alerts you to faces which have already been through your identity verification flow, highlighting potential repeat identity fraud attemp…”
Plaid Identity Verificationnone0/10Evidence shows Plaid IDV as a verification/workflow product with risk scores, dashboards, and webhooks, but nothing about AI-generated insights or suggestions surfaced to end users within the product itself; the MCP server reference is about agent connectivity, not in-product AI insights.
- [claimed-docs] “Identity Verification will also display a set of granular risk assessments (email risk, phone risk, etc.) in the Dashboard for each session,…”
- [probe] “official MCP server documented at https://plaid.com/docs/resources/mcp/”
ai-native userDelegate tasks to a built-in AI assistant inside the product
weight 3 · not comparableEntrust Identity Verification (Onfido)n/aEntrust Identity Verification is an identity-verification API/SDK/workflow platform, not an AI assistant product; there is no built-in conversational AI assistant to delegate tasks to. This axis is a category error for this product type.
Plaid Identity Verificationn/aPlaid Identity Verification is a backend identity-verification/KYC API and dashboard product, not an AI assistant or agentic interface; delegating tasks to a built-in AI assistant is a category error for this type of product. Evidence shows no-code workflow editor and dashboard tools, not any conversational/agentic assistant.
- [claimed-docs] “No-code editor to create and change verification flows”
ai-native userSchedule recurring jobs or workflows
weight 2 · not comparableEntrust Identity Verification (Onfido)n/aEntrust Identity Verification is an identity verification/KYC API and SDK platform, not an automation/orchestration tool for scheduling recurring jobs or workflows; its 'workflows' refer to verification decision flows, not cron-like recurring job scheduling. This axis is a category error for this product type.
Plaid Identity Verificationn/aPlaid Identity Verification is a KYC/identity verification API/dashboard product, not an automation or workflow-scheduling platform; scheduling recurring jobs is outside its category (webhooks for event-driven updates exist, but not user-initiated recurring job scheduling).
ai-native userVersion, review, and roll back my automations
weight 1 · not comparableEntrust Identity Verification (Onfido)none0/10No evidence of version history, review workflows, or rollback capabilities for Workflow Studio automations; documentation focuses on building workflows via no-code interface but omits versioning/rollback features entirely.
ai-native userExport all of my data in open formats and leave
weight 3 · not comparableEntrust Identity Verification (Onfido)n/aEntrust Identity Verification is an identity-verification/KYC API and SDK platform, not a data-hosting product with a user-facing data export/portability feature for end users; 'export all data and leave' is a category error for this kind of B2B verification infrastructure.
ai-native userRead the product's source under an open license
weight 2 · not comparableEntrust Identity Verification (Onfido)n/aEntrust Identity Verification is a closed commercial SaaS/SDK identity-verification product; there is no indication it is or could be an open-source project. Source availability under an open license is not a relevant axis for this kind of proprietary vendor platform.
ai-native userSelf-host the core product
weight 3 · not comparableEntrust Identity Verification (Onfido)n/aEntrust Identity Verification (Onfido) is a cloud SaaS identity verification API/SDK platform; self-hosting the core product is not an offered deployment model and is a category error for this type of managed compliance/verification service, not a missing feature.
ai-native userPrevent my data from being used to train AI models
weight 3 · not comparableEntrust Identity Verification (Onfido)n/aThis story targets AI-native users seeking control over AI training data usage, which is not a relevant axis for an identity verification/KYC platform like Entrust Onfido; the evidence pack covers document verification, workflows, watchlists, and SDKs with no mention of AI training data opt-outs. This is a category mismatch rather than a missing capability.
ai-native userOpt out of telemetry and usage tracking
weight 2 · not comparableEntrust Identity Verification (Onfido)n/aEntrust Identity Verification (Onfido) is an identity-verification API/SDK platform, not an AI coding tool or agent product with telemetry/usage-tracking opt-out settings relevant to an AI-native developer workflow; this axis is a category error for this product type.