Rank #1 of 6 in Identity Verification & KYC

Entrust Identity Verification (Onfido)
EnterpriseEntrust Corporation · commercial
Access
Try itExperimental
See what an agent can do with Entrust Identity Verification (Onfido) before you ever sign up. Pick a story: recorded sessions replay real probe-harness transcripts; sandboxed self-drive sessions are designed and gated (docs/TRY-IT.md).
$curl -si https://api.eu.onfido.com/v3.6/applicants | head -2 # Onfido-era API host under Entrust, keyless → 401recorded session — replayed, not liveVerified integrations
No integration evidence found in our corpus for this product yet — that means none was found, never that it doesn’t integrate.
By theme — the product's score on each story themeBy theme
Agenticness — how well agents can access and operate the productAgenticnessevidence →
How well agents can access and operate the product
Automation depth — how much of the product can run unattendedAutomation depthevidence →
How much of the product can run unattended
Biometric liveness — stories about biometric liveness in this arenaBiometric livenessevidence →
Stories about biometric liveness in this arena
Data checks — stories about data checks in this arenaData checksevidence →
Stories about data checks in this arena
Document coverage — stories about document coverage in this arenaDocument coverageevidence →
Stories about document coverage in this arena
Idv agent access — stories about idv agent access in this arenaIdv agent accessevidence →
Stories about idv agent access in this arena
Integration dx — sandboxes, test modes, webhooks, and how fast a developer gets to a working integrationIntegration dxevidence →
Sandboxes, test modes, webhooks, and how fast a developer gets to a working integration
Openness — open source, data portability, and self-hosting storiesOpennessevidence →
Open source, data portability, and self-hosting stories
Privacy posture — data-handling and privacy storiesPrivacy postureevidence →
Data-handling and privacy stories
Privacy retention — stories about privacy retention in this arenaPrivacy retentionevidence →
Stories about privacy retention in this arena
Verification flows — stories about verification flows in this arenaVerification flowsevidence →
Stories about verification flows in this arena
Verification orchestration — stories about verification orchestration in this arenaVerification orchestrationevidence →
Stories about verification orchestration in this arena
Watchlist screening — stories about watchlist screening in this arenaWatchlist screeningevidence →
Stories about watchlist screening in this arena
Story verdicts — every judged story with its evidenceStory verdicts
Follow the green: where the map greys out is where Entrust Identity Verification (Onfido) stops today. ✓ full · ~ partial · ! disputed · — none · n/a not applicable.
Agenticness — how well agents can access and operate the productAgenticness
How well agents can access and operate the product
API surface
Drive the product through a documented public API
✓7/10
unlocks → MCP server · Machine-readable spec · API sandbox · Official CLI · A sandbox lets me exercise every outcome before going live — documented test documents, personas, or magic values that deterministically produce pass, fail, and review results · See verification funnel analytics — pass rates, drop-off points, completion time by country and document type — to know what verification is costing me in signups · Borderline verifications land in a manual review queue with the full evidence — document images, extracted fields, check results — and reviewer decisions feed back into the record
Subscribe to events via webhooks
✓7/10
Build against official SDKs
~6/10
Issue scoped/least-privilege API credentials for an agent
~4/10
Connect an agent via an official MCP server
—–
Download a machine-readable API spec (OpenAPI or equivalent)
—–
Rely on versioned APIs with a documented deprecation policy
~3/10
Test against a sandbox environment without touching production data
—–
Explore an interactive API reference with runnable examples
—–
Agentic features
Delegate tasks to a built-in AI assistant inside the product
n/an/a
Operate the product with natural-language commands
—–
Plug MCP servers into this product so it can use their tools
n/an/a
Get AI-generated insights and suggestions from my data inside the product
n/an/a
Set up automations that run autonomously in the background
~5/10
Automation depth — how much of the product can run unattendedAutomation depth
How much of the product can run unattended
Biometric liveness — stories about biometric liveness in this arenaBiometric liveness
Stories about biometric liveness in this arena
The vendor documents specific defenses against AI-generated faces, deepfakes, and camera-injection attacks — named detection capabilities, not just a marketing mention of fraud
—0/10
The platform detects repeat and duplicate identities across verifications — the same face or document resurfacing under different names is flagged automatically
~6/10
Selfie checks match the live user to the document portrait with liveness detection — documented defenses against printed photos, screens, and replayed video
~5/10
Data checks — stories about data checks in this arenaData checks
Stories about data checks in this arena
Verify identity against authoritative databases without documents — SSN, national registries, or credit-header data — for lower-friction flows where a doc scan is overkill
—–
Verify businesses, not just people — registry lookups, UBO identification, and documented KYB flows that chain into KYC on the owners
—–
Enrich verifications with phone, email, and device risk signals — carrier checks, address history, device fingerprint — as additional documented check types
—0/10
Document coverage — stories about document coverage in this arenaDocument coverage
Stories about document coverage in this arena
The platform verifies government IDs from a documented breadth of countries and document types — passports, national IDs, driver licenses, residence permits — with the supported list published
~4/10
Verified sessions return the extracted document fields as structured data — name, date of birth, document number, address, expiry — retrievable via the API, not just a pass/fail flag
—0/10
Idv agent access — stories about idv agent access in this arenaIdv agent access
Stories about idv agent access in this arena
Verification outcomes come back structured enough for an agent to decide on — machine-readable check results, risk signals, and failure reasons an automated onboarding flow can branch on
~6/10
An agent can operate the verification pipeline — create sessions, poll outcomes, retrieve extracted data, and trigger re-checks through the API or an MCP surface with scoped credentials
~5/10
Integration dx — sandboxes, test modes, webhooks, and how fast a developer gets to a working integrationIntegration dx
Sandboxes, test modes, webhooks, and how fast a developer gets to a working integration
A sandbox lets me exercise every outcome before going live — documented test documents, personas, or magic values that deterministically produce pass, fail, and review results
—–
The whole verification lifecycle is drivable through the API — create a session, get its status, retrieve results and captured media, and cancel or redact it — with every step documented
~6/10
Verification lifecycle events arrive as signed webhooks — created, processing, verified, requires-input — so my system reacts to outcomes without polling
~7/10
Openness — open source, data portability, and self-hosting storiesOpenness
Open source, data portability, and self-hosting stories
Privacy posture — data-handling and privacy storiesPrivacy posture
Data-handling and privacy stories
Privacy retention — stories about privacy retention in this arenaPrivacy retention
Stories about privacy retention in this arena
The vendor documents how biometric data is handled lawfully — GDPR bases, US biometric statutes like BIPA, and the consent language my flow needs — so legal review has something to review
—–
Control what happens to collected identity data — documented retention windows and a redaction or deletion API that scrubs PII on demand
—–
Verification flows — stories about verification flows in this arenaVerification flows
Stories about verification flows in this arena
Launch a complete document-plus-selfie verification with a hosted or drop-in flow — create a session server-side, redirect or embed, and read the result — without building capture UI myself
✓7/10
I get native iOS, Android, and web SDKs with guided camera capture — glare, blur, and edge detection coaching the user to a usable document photo on the first try
~4/10
Send a verification to someone with a no-code link or QR code — no engineering ticket to verify a one-off customer, contractor, or seller
~6/10
A person verified once can be recognized and reused across sessions or products — documented re-verification and reuse of a prior passed check instead of forcing a full re-run
—0/10
Verification orchestration — stories about verification orchestration in this arenaVerification orchestration
Stories about verification orchestration in this arena
See verification funnel analytics — pass rates, drop-off points, completion time by country and document type — to know what verification is costing me in signups
—–
Borderline verifications land in a manual review queue with the full evidence — document images, extracted fields, check results — and reviewer decisions feed back into the record
—–
Configure verification logic without code — conditional steps, risk-based routing, country-specific requirements, and template changes that don't need an engineering deploy
~7/10
Watchlist screening — stories about watchlist screening in this arenaWatchlist screening
Stories about watchlist screening in this arena
Screening is not one-shot — previously verified users are continuously re-screened against watchlist updates, and changes raise events I can act on
—0/10
Screen verified users against sanctions, PEP, and adverse-media watchlists as part of the same verification — one vendor, one API, one review surface
✓8/10
Sorted by importance (agentic first) (high → low) · 53/53 stories · click a row’s chevron for the rationale and evidence
Drive the product through a documented public API G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | full | 7/10 | Tprobed | |
Connect an agent via an official MCP server G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | none | untested | none yet | |
Delegate tasks to a built-in AI assistant inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | n/a | untested | none yet | |
Plug MCP servers into this product so it can use their tools G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | n/a | untested | none yet | |
Point an agent at llms.txt or agent-oriented docs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 8/10 | Tprobed | |
Subscribe to events via webhooks G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 7/10 | Cclaimed | |
Build against official SDKs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 6/10 | Cclaimed | |
Run the product headlessly / in CI for automation G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 5/10 | Cclaimed | |
Set up automations that run autonomously in the background G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 5/10 | Cclaimed | |
Issue scoped/least-privilege API credentials for an agent G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 4/10 | Cclaimed | |
Rely on versioned APIs with a documented deprecation policy G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 3/10 | Cclaimed | |
Get AI-generated insights and suggestions from my data inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | n/a | 0/10 | ||
Download a machine-readable API spec (OpenAPI or equivalent) G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | untested | none yet | |
Explore an interactive API reference with runnable examples G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | untested | none yet | |
Operate the product with natural-language commands G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | untested | none yet | |
Use an official CLI G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | untested | none yet | |
Test against a sandbox environment without touching production data G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 1 | none | untested | none yet | |
Configure verification logic without code — conditional steps, risk-based routing, country-specific requirements, and template changes that don't need an engineering deploy C Workflows | ops lead | Verification orchestration — stories about verification orchestration in this arenaVerification orchestration | 3 | partial | 7/10 | Cclaimed | |
Define rules that trigger actions automatically on events G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 3 | full | 7/10 | Cclaimed | |
Launch a complete document-plus-selfie verification with a hosted or drop-in flow — create a session server-side, redirect or embed, and read the result — without building capture UI myself C Hosted flows | developer | Verification flows — stories about verification flows in this arenaVerification flows | 3 | full | 7/10 | Cclaimed | |
The whole verification lifecycle is drivable through the API — create a session, get its status, retrieve results and captured media, and cancel or redact it — with every step documented C Session api | developer | Integration dx — sandboxes, test modes, webhooks, and how fast a developer gets to a working integrationIntegration dx | 3 | partial | 6/10 | Cclaimed | |
An agent can operate the verification pipeline — create sessions, poll outcomes, retrieve extracted data, and trigger re-checks through the API or an MCP surface with scoped credentials C Agent operations | ai-native user | Idv agent access — stories about idv agent access in this arenaIdv agent access | 3 | partial | 5/10 | Cclaimed | |
Selfie checks match the live user to the document portrait with liveness detection — documented defenses against printed photos, screens, and replayed video C Liveness | risk analyst | Biometric liveness — stories about biometric liveness in this arenaBiometric liveness | 3 | partial | 5/10 | Cclaimed | |
The platform verifies government IDs from a documented breadth of countries and document types — passports, national IDs, driver licenses, residence permits — with the supported list published C Doc types | ops lead | Document coverage — stories about document coverage in this arenaDocument coverage | 3 | partial | 4/10 | Cclaimed | |
A sandbox lets me exercise every outcome before going live — documented test documents, personas, or magic values that deterministically produce pass, fail, and review results C Sandbox | developer | Integration dx — sandboxes, test modes, webhooks, and how fast a developer gets to a working integrationIntegration dx | 3 | none | untested | none yet | |
Export all of my data in open formats and leave G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | n/a | untested | none yet | |
Prevent my data from being used to train AI models G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 3 | n/a | untested | none yet | |
Self-host the core product G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | n/a | untested | none yet | |
Screen verified users against sanctions, PEP, and adverse-media watchlists as part of the same verification — one vendor, one API, one review surface C Screening | ops lead | Watchlist screening — stories about watchlist screening in this arenaWatchlist screening | 2 | full | 8/10 | Cclaimed | |
Verification lifecycle events arrive as signed webhooks — created, processing, verified, requires-input — so my system reacts to outcomes without polling C Webhooks | developer | Integration dx — sandboxes, test modes, webhooks, and how fast a developer gets to a working integrationIntegration dx | 2 | partial | 7/10 | Cclaimed | |
Send a verification to someone with a no-code link or QR code — no engineering ticket to verify a one-off customer, contractor, or seller C No code | ops lead | Verification flows — stories about verification flows in this arenaVerification flows | 2 | partial | 6/10 | Cclaimed | |
The platform detects repeat and duplicate identities across verifications — the same face or document resurfacing under different names is flagged automatically C Duplicate detection | risk analyst | Biometric liveness — stories about biometric liveness in this arenaBiometric liveness | 2 | partial | 6/10 | Cclaimed | |
Verification outcomes come back structured enough for an agent to decide on — machine-readable check results, risk signals, and failure reasons an automated onboarding flow can branch on C Agent decisions | ai-native user | Idv agent access — stories about idv agent access in this arenaIdv agent access | 2 | partial | 6/10 | Cclaimed | |
Do everything through the API that I can do in the UI G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | partial | 5/10 | Cclaimed | |
I get native iOS, Android, and web SDKs with guided camera capture — glare, blur, and edge detection coaching the user to a usable document photo on the first try C Native sdks | developer | Verification flows — stories about verification flows in this arenaVerification flows | 2 | partial | 4/10 | Cclaimed | |
A person verified once can be recognized and reused across sessions or products — documented re-verification and reuse of a prior passed check instead of forcing a full re-run C Reuse | developer | Verification flows — stories about verification flows in this arenaVerification flows | 2 | none | 0/10 | ||
Enrich verifications with phone, email, and device risk signals — carrier checks, address history, device fingerprint — as additional documented check types C Risk signals | developer | Data checks — stories about data checks in this arenaData checks | 2 | none | 0/10 | ||
Perform bulk operations across many items at once G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | none | 0/10 | ||
Screening is not one-shot — previously verified users are continuously re-screened against watchlist updates, and changes raise events I can act on C Monitoring | ops lead | Watchlist screening — stories about watchlist screening in this arenaWatchlist screening | 2 | none | 0/10 | ||
The vendor documents specific defenses against AI-generated faces, deepfakes, and camera-injection attacks — named detection capabilities, not just a marketing mention of fraud C Deepfake defense | risk analyst | Biometric liveness — stories about biometric liveness in this arenaBiometric liveness | 2 | none | 0/10 | ||
Verified sessions return the extracted document fields as structured data — name, date of birth, document number, address, expiry — retrievable via the API, not just a pass/fail flag C Extraction | developer | Document coverage — stories about document coverage in this arenaDocument coverage | 2 | none | 0/10 | ||
Borderline verifications land in a manual review queue with the full evidence — document images, extracted fields, check results — and reviewer decisions feed back into the record C Review | ops lead | Verification orchestration — stories about verification orchestration in this arenaVerification orchestration | 2 | none | untested | none yet | |
Choose where my data is stored (region/residency) G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | untested | none yet | |
Control data retention and deletion G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | untested | none yet | |
Control what happens to collected identity data — documented retention windows and a redaction or deletion API that scrubs PII on demand C Redaction | ops lead | Privacy retention — stories about privacy retention in this arenaPrivacy retention | 2 | none | untested | none yet | |
Opt out of telemetry and usage tracking G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | n/a | untested | none yet | |
Read the product's source under an open license G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | n/a | untested | none yet | |
Schedule recurring jobs or workflows G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | n/a | untested | none yet | |
See verification funnel analytics — pass rates, drop-off points, completion time by country and document type — to know what verification is costing me in signups C Analytics | founder | Verification orchestration — stories about verification orchestration in this arenaVerification orchestration | 2 | none | untested | none yet | |
The vendor documents how biometric data is handled lawfully — GDPR bases, US biometric statutes like BIPA, and the consent language my flow needs — so legal review has something to review C Consent | founder | Privacy retention — stories about privacy retention in this arenaPrivacy retention | 2 | none | untested | none yet | |
Verify businesses, not just people — registry lookups, UBO identification, and documented KYB flows that chain into KYC on the owners C Kyb | ops lead | Data checks — stories about data checks in this arenaData checks | 2 | none | untested | none yet | |
Verify identity against authoritative databases without documents — SSN, national registries, or credit-header data — for lower-friction flows where a doc scan is overkill C Db checks | developer | Data checks — stories about data checks in this arenaData checks | 2 | none | untested | none yet | |
Version, review, and roll back my automations G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 1 | none | untested | none yet |
Opportunities — the stories that would move this product's scores, from its own judged verdictsOpportunitiestop 8 of 38 stories with headroom
What would move Entrust Identity Verification (Onfido)’s scores — derived from its own judged verdicts, biggest headroom first. Each line quotes what the judge found missing; shipping it (or evidencing it publicly) is the fix.
Agenticness — how well agents can access and operate the productConnect an agent via an official MCP server
nonemoves agent-readyimpact 45
The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na".
Integration dx — sandboxes, test modes, webhooks, and how fast a developer gets to a working integrationA sandbox lets me exercise every outcome before going live — documented test documents, personas, or magic values that deterministically produce pass, fail, and review results
nonemoves PA Scoreimpact 30
Missing: sandbox/test-mode documentation, sample test documents or personas, deterministic magic-value test data for triggering specific verification outcomes.
Agenticness — how well agents can access and operate the productOperate the product with natural-language commands
nonemoves Built-in AIimpact 30
The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na".
Agenticness — how well agents can access and operate the productUse an official CLI
nonemoves agent-readyimpact 30
The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na".
Agenticness — how well agents can access and operate the productExplore an interactive API reference with runnable examples
nonemoves API qualityimpact 30
The evidence pack shows conventional API/SDK documentation (auth, webhooks, workflow setup) but no mention of an interactive API reference, API explorer, or runnable code examples anywhere in the docs.
Agenticness — how well agents can access and operate the productDownload a machine-readable API spec (OpenAPI or equivalent)
nonemoves API qualityimpact 30
The evidence pack shows extensive API/webhook documentation but no mention of a downloadable OpenAPI/Swagger spec or other machine-readable API definition file.
Agenticness — how well agents can access and operate the productRely on versioned APIs with a documented deprecation policy
partialq3/10moves API qualityimpact 21
Missing: explicit versioned API scheme (e.g., v1/v2 endpoints), a published deprecation/sunset policy, and timelines for backward compatibility.
Automation depth — how much of the product can run unattendedPerform bulk operations across many items at once
nonemoves PA Scoreimpact 20
The evidence describes single-applicant workflows (create applicant → workflow run → SDK token → webhook) and no batch/bulk API endpoints, CSV bulk upload, or multi-item processing tools are documented.
Showing the top 8 of 38 — every none/partial verdict in the story verdicts table is headroom.
Think a verdict is wrong? Every verdicts-table row has a Flag link — see the methodology.
Coverage map — which docs area, API section, or community source covers which judged storiesCoverage map5 surfaces · 22 covered stories
Where the cited evidence behind each covered verdict came from — the same citations the verdicts table shows, no extra judging.
llms.txt15 stories
- Point an agent at llms.txt or agent-oriented docs
- Run the product headlessly / in CI for automation
- Drive the product through a documented public API
- Build against official SDKs
- Subscribe to events via webhooks
- Set up automations that run autonomously in the background
- Define rules that trigger actions automatically on events
- Verification outcomes come back structured enough for an agent to decide on — machine-readable check results, risk signals, and failure reasons an automated onboarding flow can branch on
- An agent can operate the verification pipeline — create sessions, poll outcomes, retrieve extracted data, and trigger re-checks through the API or an MCP surface with scoped credentials
- The whole verification lifecycle is drivable through the API — create a session, get its status, retrieve results and captured media, and cancel or redact it — with every step documented
- Verification lifecycle events arrive as signed webhooks — created, processing, verified, requires-input — so my system reacts to outcomes without polling
- Do everything through the API that I can do in the UI
- Launch a complete document-plus-selfie verification with a hosted or drop-in flow — create a session server-side, redirect or embed, and read the result — without building capture UI myself
- I get native iOS, Android, and web SDKs with guided camera capture — glare, blur, and edge detection coaching the user to a usable document photo on the first try
- Screen verified users against sanctions, PEP, and adverse-media watchlists as part of the same verification — one vendor, one API, one review surface
API reference15 stories
- Run the product headlessly / in CI for automation
- Drive the product through a documented public API
- Issue scoped/least-privilege API credentials for an agent
- Build against official SDKs
- Subscribe to events via webhooks
- Set up automations that run autonomously in the background
- Rely on versioned APIs with a documented deprecation policy
- Define rules that trigger actions automatically on events
- Verification outcomes come back structured enough for an agent to decide on — machine-readable check results, risk signals, and failure reasons an automated onboarding flow can branch on
- An agent can operate the verification pipeline — create sessions, poll outcomes, retrieve extracted data, and trigger re-checks through the API or an MCP surface with scoped credentials
- The whole verification lifecycle is drivable through the API — create a session, get its status, retrieve results and captured media, and cancel or redact it — with every step documented
- Verification lifecycle events arrive as signed webhooks — created, processing, verified, requires-input — so my system reacts to outcomes without polling
- Launch a complete document-plus-selfie verification with a hosted or drop-in flow — create a session server-side, redirect or embed, and read the result — without building capture UI myself
- I get native iOS, Android, and web SDKs with guided camera capture — glare, blur, and edge detection coaching the user to a usable document photo on the first try
- Screen verified users against sanctions, PEP, and adverse-media watchlists as part of the same verification — one vendor, one API, one review surface
Getting started docs10 stories
- Run the product headlessly / in CI for automation
- Set up automations that run autonomously in the background
- Define rules that trigger actions automatically on events
- The platform detects repeat and duplicate identities across verifications — the same face or document resurfacing under different names is flagged automatically
- Verification outcomes come back structured enough for an agent to decide on — machine-readable check results, risk signals, and failure reasons an automated onboarding flow can branch on
- Do everything through the API that I can do in the UI
- Launch a complete document-plus-selfie verification with a hosted or drop-in flow — create a session server-side, redirect or embed, and read the result — without building capture UI myself
- I get native iOS, Android, and web SDKs with guided camera capture — glare, blur, and edge detection coaching the user to a usable document photo on the first try
- Send a verification to someone with a no-code link or QR code — no engineering ticket to verify a one-off customer, contractor, or seller
- Configure verification logic without code — conditional steps, risk-based routing, country-specific requirements, and template changes that don't need an engineering deploy
Guide docs8 stories
- Build against official SDKs
- Selfie checks match the live user to the document portrait with liveness detection — documented defenses against printed photos, screens, and replayed video
- The platform verifies government IDs from a documented breadth of countries and document types — passports, national IDs, driver licenses, residence permits — with the supported list published
- Verification outcomes come back structured enough for an agent to decide on — machine-readable check results, risk signals, and failure reasons an automated onboarding flow can branch on
- Do everything through the API that I can do in the UI
- I get native iOS, Android, and web SDKs with guided camera capture — glare, blur, and edge detection coaching the user to a usable document photo on the first try
- Configure verification logic without code — conditional steps, risk-based routing, country-specific requirements, and template changes that don't need an engineering deploy
- Screen verified users against sanctions, PEP, and adverse-media watchlists as part of the same verification — one vendor, one API, one review surface
Probe proofs — replayable recordings from the probe harnessProbe proofs
Replayable recordings from our probe harness — see the Prove-It protocol to submit one.
$curl -si https://api.eu.onfido.com/v3.6/applicants | head -2 # Onfido-era API host under Entrust, keyless → 401reproduced$ curl -si https://api.eu.onfido.com/v3.6/applicants | head -2 # Onfido-era API host under Entrust, [redacted]less → 401 HTTP/2 401 content-type: application/json
$curl -sL https://documentation.identity.entrust.com/llms.txt | head -3reproduced$ curl -sL https://documentation.identity.entrust.com/llms.txt | head -3 # Entrust Identity Verification Documentation > Entrust Identity Verification is a comprehensive API and SDK platform for identity document verification, biometric checks, watchlist screening, and fraud detection. Customers integrate via REST API (v3.6 current) and native SDKs (Web, iOS, Android, React Native, Flutter), orchestrating verification flows through Workflow Studio.
Claims vs evidence — vendor claims reconciled against independent verdictsClaims vs evidence
0 of 10 testable claims verified · 0 contradicted → integrity 0/100
12 distinct capability claims found in Entrust Identity Verification (Onfido)’s own claimed-docs/GitHub materials, reconciled against our judge’s independent verdicts.
0
Verified
10
Unverified
0
Contradicted
12
Undersold
Unverified (13)
“No-code drag-and-drop workflow builder lets you create and update verification workflows without developers”
Configure verification logic without code — conditional steps, risk-based routing, country-specific requirements, and template changes that don't need an engineering deploypartialproof ↗
“SDK tokens are issued to authenticate and initialize the mobile/web verification SDKs”
Issue scoped/least-privilege API credentials for an agentpartialproof ↗
“Full verification lifecycle drivable via API: create applicant, start workflow run, get SDK token, collect captures, retrieve results via webhook or polling”
The whole verification lifecycle is drivable through the API — create a session, get its status, retrieve results and captured media, and cancel or redact it — with every step documentedpartialproof ↗
“Full verification lifecycle drivable via API: create applicant, start workflow run, get SDK token, collect captures, retrieve results via webhook or polling”
An agent can operate the verification pipeline — create sessions, poll outcomes, retrieve extracted data, and trigger re-checks through the API or an MCP surface with scoped credentialspartialproof ↗
“Webhooks can be configured to asynchronously notify you of workflow status changes”
Verification lifecycle events arrive as signed webhooks — created, processing, verified, requires-input — so my system reacts to outcomes without pollingpartialproof ↗
“Webhook payloads can be verified using an HMAC-SHA256 signature computed with a secret token”
Verification lifecycle events arrive as signed webhooks — created, processing, verified, requires-input — so my system reacts to outcomes without pollingpartialproof ↗
“Short-lived OAuth access tokens via client credentials grant are recommended for API authentication”
Issue scoped/least-privilege API credentials for an agentpartialproof ↗
“Smart Capture Link provides a low/no-code hosted frontend for verifying users without engineering effort”
Send a verification to someone with a no-code link or QR code — no engineering ticket to verify a one-off customer, contractor, or sellerpartialproof ↗
“Dashboard lets you configure which documents to accept by issuing country and document type”
Configure verification logic without code — conditional steps, risk-based routing, country-specific requirements, and template changes that don't need an engineering deploypartialproof ↗
“Watchlist reports screen applicants against sanctions, PEP, monitored lists, and adverse media”
Screen verified users against sanctions, PEP, and adverse-media watchlists as part of the same verification — one vendor, one API, one review surfacefullproof ↗
“System flags faces that have already passed through the identity verification flow to catch repeat fraud attempts”
The platform detects repeat and duplicate identities across verifications — the same face or document resurfacing under different names is flagged automaticallypartialproof ↗
“NFC chip reading is available only through the mobile SDKs”
I get native iOS, Android, and web SDKs with guided camera capture — glare, blur, and edge detection coaching the user to a usable document photo on the first trypartialproof ↗
“Motion liveness detection uses head-turn patterns or randomized head movements to assess liveness”
Selfie checks match the live user to the document portrait with liveness detection — documented defenses against printed photos, screens, and replayed videopartialproof ↗
Undersold (12)
Point an agent at llms.txt or agent-oriented docsfullproof ↗
Run the product headlessly / in CI for automationpartialproof ↗
Drive the product through a documented public APIfullproof ↗
Set up automations that run autonomously in the backgroundpartialproof ↗
Rely on versioned APIs with a documented deprecation policypartialproof ↗
Define rules that trigger actions automatically on eventsfullproof ↗
The platform verifies government IDs from a documented breadth of countries and document types — passports, national IDs, driver licenses, residence permits — with the supported list publishedpartialproof ↗
Verification outcomes come back structured enough for an agent to decide on — machine-readable check results, risk signals, and failure reasons an automated onboarding flow can branch onpartialproof ↗
Do everything through the API that I can do in the UIpartialproof ↗
Launch a complete document-plus-selfie verification with a hosted or drop-in flow — create a session server-side, redirect or embed, and read the result — without building capture UI myselffullproof ↗
Business model
Sales-only: onfido.com/pricing now redirects into entrust.com's quote-gated pricing with no published numbers — an enterprise IDV suite sold under Entrust since the $650M acquisition closed in April 2024.
pricing ↗Score trend
How this product’s scores have moved as evidence and verdicts are re-derived — a point per change, not per day.
Try Experimental
Run it in the microterminal →Recorded agent sessions — and a live MCP handshake where the vendor ships one.
Flag
⚑ Flag a verdictThink a verdict is wrong? Opens a prefilled GitHub issue — or use the ⚑ next to any verdict above.
For agents