Rank #3 of 6 in Identity Verification & KYC
Install
npm install stripeProducts
Stripe, product by product →Stripe ships more than one product — each judged line competes in its own arena on the same stories as everyone else.
| Line | Arena | Rank | PA Score | Agent-ready |
|---|---|---|---|---|
| Payments | Online Payments | #1/10 | 55/100 | 89/100 |
| Terminal | Mobile & In-Person Payments | #1/4 | 32/100 | 59/100 |
| Atlas | Startup Legal & Incorporation | #6/7 | 11/100 | 32/100 |
| Clerkyacquired | Startup Legal & Incorporation | #4/7 | 14/100 | 37/100 |
| Billing | Billing & Subscriptions | #3/7 | 28/100 | 65/100 |
| Metronomeacquired | Billing & Subscriptions | #5/7 | 21/100 | 28/100 |
| Connect | Marketplace & Platform Payments | #2/6 | 31/100 | 65/100 |
| Radar | Payment Fraud Prevention | #2/5 | 22/100 | 50/100 |
| Tax | Sales Tax Automation | #1/6 | 22/100 | 43/100 |
| TaxJaracquired | Sales Tax Automation | #6/6 | 13/100 | 26/100 |
| Issuing | Card Issuing Platforms | #1/5 | 33/100 | 65/100 |
| Treasury | Banking as a Service | #4/6 | 17/100 | 44/100 |
| Identitythis page | Identity Verification & KYC | #3/6 | 24/100 | 47/100 |
| Financial Connections | Banking Data APIs | #4/7 | 22/100 | 54/100 |
| Crypto & Stablecoins | Stablecoin Payments | #6/6 | 19/100 | 39/100 |
| Agentic Commerce | Agentic Commerce | #1/7 | 37/100 | 80/100 |
Not yet judged (10 — no arena where they compete): Invoicing · Capital · Revenue Recognition · Sigma · Data Pipeline · Managed Payments · Lemon Squeezy · Directory · Projects · Climate
Try itExperimental
See what an agent can do with Stripe Identity before you ever sign up. Pick a story: recorded sessions replay real probe-harness transcripts; the live MCP handshake runs real requests from our edge, right now — including, where the server allows it, one real read-only tool call (bring your own key for auth-gated servers); sandboxed self-drive sessions are designed and gated (docs/TRY-IT.md).
$curl -si https://api.stripe.com/v1/identity/verification_sessions | head -4 # Identity sessions API, keyless → 401recorded session — replayed, not liveVerified integrations
No integration evidence found in our corpus for this product yet — that means none was found, never that it doesn’t integrate.
By theme — the product's score on each story themeBy theme
Agenticness — how well agents can access and operate the productAgenticnessevidence →
How well agents can access and operate the product
Automation depth — how much of the product can run unattendedAutomation depthevidence →
How much of the product can run unattended
Biometric liveness — stories about biometric liveness in this arenaBiometric livenessevidence →
Stories about biometric liveness in this arena
Data checks — stories about data checks in this arenaData checksevidence →
Stories about data checks in this arena
Document coverage — stories about document coverage in this arenaDocument coverageevidence →
Stories about document coverage in this arena
Idv agent access — stories about idv agent access in this arenaIdv agent accessevidence →
Stories about idv agent access in this arena
Integration dx — sandboxes, test modes, webhooks, and how fast a developer gets to a working integrationIntegration dxevidence →
Sandboxes, test modes, webhooks, and how fast a developer gets to a working integration
Openness — open source, data portability, and self-hosting storiesOpennessevidence →
Open source, data portability, and self-hosting stories
Privacy posture — data-handling and privacy storiesPrivacy postureevidence →
Data-handling and privacy stories
Privacy retention — stories about privacy retention in this arenaPrivacy retentionevidence →
Stories about privacy retention in this arena
Verification flows — stories about verification flows in this arenaVerification flowsevidence →
Stories about verification flows in this arena
Verification orchestration — stories about verification orchestration in this arenaVerification orchestrationevidence →
Stories about verification orchestration in this arena
Watchlist screening — stories about watchlist screening in this arenaWatchlist screeningevidence →
Stories about watchlist screening in this arena
Story verdicts — every judged story with its evidenceStory verdicts
Follow the green: where the map greys out is where Stripe Identity stops today. ✓ full · ~ partial · ! disputed · — none · n/a not applicable.
Agenticness — how well agents can access and operate the productAgenticness
How well agents can access and operate the product
API surface
Drive the product through a documented public API
✓8/10
unlocks → Scoped API keys · Machine-readable spec · Versioning policy · API sandbox · Full data export · A sandbox lets me exercise every outcome before going live — documented test documents, personas, or magic values that deterministically produce pass, fail, and review results · See verification funnel analytics — pass rates, drop-off points, completion time by country and document type — to know what verification is costing me in signups
Subscribe to events via webhooks
✓7/10
Build against official SDKs
~5/10
Issue scoped/least-privilege API credentials for an agent
—–
Connect an agent via an official MCP server
~6/10
Download a machine-readable API spec (OpenAPI or equivalent)
—0/10
Rely on versioned APIs with a documented deprecation policy
—0/10
Test against a sandbox environment without touching production data
—–
Explore an interactive API reference with runnable examples
~4/10
Agentic features
Delegate tasks to a built-in AI assistant inside the product
n/an/a
Operate the product with natural-language commands
~5/10
Plug MCP servers into this product so it can use their tools
n/an/a
Get AI-generated insights and suggestions from my data inside the product
—–
Set up automations that run autonomously in the background
~5/10
Automation depth — how much of the product can run unattendedAutomation depth
How much of the product can run unattended
Biometric liveness — stories about biometric liveness in this arenaBiometric liveness
Stories about biometric liveness in this arena
The vendor documents specific defenses against AI-generated faces, deepfakes, and camera-injection attacks — named detection capabilities, not just a marketing mention of fraud
—0/10
The platform detects repeat and duplicate identities across verifications — the same face or document resurfacing under different names is flagged automatically
~3/10
Selfie checks match the live user to the document portrait with liveness detection — documented defenses against printed photos, screens, and replayed video
~4/10
Data checks — stories about data checks in this arenaData checks
Stories about data checks in this arena
Verify identity against authoritative databases without documents — SSN, national registries, or credit-header data — for lower-friction flows where a doc scan is overkill
~5/10
Verify businesses, not just people — registry lookups, UBO identification, and documented KYB flows that chain into KYC on the owners
—–
Enrich verifications with phone, email, and device risk signals — carrier checks, address history, device fingerprint — as additional documented check types
—–
Document coverage — stories about document coverage in this arenaDocument coverage
Stories about document coverage in this arena
The platform verifies government IDs from a documented breadth of countries and document types — passports, national IDs, driver licenses, residence permits — with the supported list published
!5/10
Verified sessions return the extracted document fields as structured data — name, date of birth, document number, address, expiry — retrievable via the API, not just a pass/fail flag
✓8/10
Idv agent access — stories about idv agent access in this arenaIdv agent access
Stories about idv agent access in this arena
Verification outcomes come back structured enough for an agent to decide on — machine-readable check results, risk signals, and failure reasons an automated onboarding flow can branch on
✓7/10
An agent can operate the verification pipeline — create sessions, poll outcomes, retrieve extracted data, and trigger re-checks through the API or an MCP surface with scoped credentials
~5/10
Integration dx — sandboxes, test modes, webhooks, and how fast a developer gets to a working integrationIntegration dx
Sandboxes, test modes, webhooks, and how fast a developer gets to a working integration
A sandbox lets me exercise every outcome before going live — documented test documents, personas, or magic values that deterministically produce pass, fail, and review results
—0/10
The whole verification lifecycle is drivable through the API — create a session, get its status, retrieve results and captured media, and cancel or redact it — with every step documented
~6/10
Verification lifecycle events arrive as signed webhooks — created, processing, verified, requires-input — so my system reacts to outcomes without polling
~6/10
Openness — open source, data portability, and self-hosting storiesOpenness
Open source, data portability, and self-hosting stories
Privacy posture — data-handling and privacy storiesPrivacy posture
Data-handling and privacy stories
Privacy retention — stories about privacy retention in this arenaPrivacy retention
Stories about privacy retention in this arena
The vendor documents how biometric data is handled lawfully — GDPR bases, US biometric statutes like BIPA, and the consent language my flow needs — so legal review has something to review
—–
Control what happens to collected identity data — documented retention windows and a redaction or deletion API that scrubs PII on demand
—0/10
Verification flows — stories about verification flows in this arenaVerification flows
Stories about verification flows in this arena
Launch a complete document-plus-selfie verification with a hosted or drop-in flow — create a session server-side, redirect or embed, and read the result — without building capture UI myself
✓7/10
I get native iOS, Android, and web SDKs with guided camera capture — glare, blur, and edge detection coaching the user to a usable document photo on the first try
—0/10
Send a verification to someone with a no-code link or QR code — no engineering ticket to verify a one-off customer, contractor, or seller
✓7/10
A person verified once can be recognized and reused across sessions or products — documented re-verification and reuse of a prior passed check instead of forcing a full re-run
—0/10
Verification orchestration — stories about verification orchestration in this arenaVerification orchestration
Stories about verification orchestration in this arena
See verification funnel analytics — pass rates, drop-off points, completion time by country and document type — to know what verification is costing me in signups
—0/10
Borderline verifications land in a manual review queue with the full evidence — document images, extracted fields, check results — and reviewer decisions feed back into the record
~5/10
Configure verification logic without code — conditional steps, risk-based routing, country-specific requirements, and template changes that don't need an engineering deploy
~3/10
Watchlist screening — stories about watchlist screening in this arenaWatchlist screening
Stories about watchlist screening in this arena
Screening is not one-shot — previously verified users are continuously re-screened against watchlist updates, and changes raise events I can act on
—0/10
Screen verified users against sanctions, PEP, and adverse-media watchlists as part of the same verification — one vendor, one API, one review surface
—–
Sorted by importance (agentic first) (high → low) · 53/53 stories · click a row’s chevron for the rationale and evidence
Drive the product through a documented public API G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | full | 8/10 | Tprobed | |
Connect an agent via an official MCP server G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | partial | 6/10 | Tprobed | |
Plug MCP servers into this product so it can use their tools G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | n/a | 0/10 | ||
Delegate tasks to a built-in AI assistant inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | n/a | untested | none yet | |
Point an agent at llms.txt or agent-oriented docs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 8/10 | Tprobed | |
Subscribe to events via webhooks G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 7/10 | Cclaimed | |
Run the product headlessly / in CI for automation G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 6/10 | Cclaimed | |
Use an official CLI G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 6/10 | Tprobed | |
Build against official SDKs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 5/10 | Tprobed | |
Operate the product with natural-language commands G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 5/10 | Tprobed | |
Set up automations that run autonomously in the background G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 5/10 | Tprobed | |
Explore an interactive API reference with runnable examples G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 4/10 | Tprobed | |
Download a machine-readable API spec (OpenAPI or equivalent) G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Rely on versioned APIs with a documented deprecation policy G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Get AI-generated insights and suggestions from my data inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | untested | none yet | |
Issue scoped/least-privilege API credentials for an agent G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | untested | none yet | |
Test against a sandbox environment without touching production data G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 1 | none | untested | none yet | |
Launch a complete document-plus-selfie verification with a hosted or drop-in flow — create a session server-side, redirect or embed, and read the result — without building capture UI myself C Hosted flows | developer | Verification flows — stories about verification flows in this arenaVerification flows | 3 | full | 7/10 | Xcommunity | |
The whole verification lifecycle is drivable through the API — create a session, get its status, retrieve results and captured media, and cancel or redact it — with every step documented C Session api | developer | Integration dx — sandboxes, test modes, webhooks, and how fast a developer gets to a working integrationIntegration dx | 3 | partial | 6/10 | Cclaimed | |
An agent can operate the verification pipeline — create sessions, poll outcomes, retrieve extracted data, and trigger re-checks through the API or an MCP surface with scoped credentials C Agent operations | ai-native user | Idv agent access — stories about idv agent access in this arenaIdv agent access | 3 | partial | 5/10 | Tprobed | |
Define rules that trigger actions automatically on events G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 3 | partial | 5/10 | Cclaimed | |
The platform verifies government IDs from a documented breadth of countries and document types — passports, national IDs, driver licenses, residence permits — with the supported list published C Doc types | ops lead | Document coverage — stories about document coverage in this arenaDocument coverage | 3 | disputed | 5/10 | Dcontradicted | |
Selfie checks match the live user to the document portrait with liveness detection — documented defenses against printed photos, screens, and replayed video C Liveness | risk analyst | Biometric liveness — stories about biometric liveness in this arenaBiometric liveness | 3 | partial | 4/10 | Tprobed | |
Configure verification logic without code — conditional steps, risk-based routing, country-specific requirements, and template changes that don't need an engineering deploy C Workflows | ops lead | Verification orchestration — stories about verification orchestration in this arenaVerification orchestration | 3 | partial | 3/10 | Xcommunity | |
A sandbox lets me exercise every outcome before going live — documented test documents, personas, or magic values that deterministically produce pass, fail, and review results C Sandbox | developer | Integration dx — sandboxes, test modes, webhooks, and how fast a developer gets to a working integrationIntegration dx | 3 | none | 0/10 | ||
Export all of my data in open formats and leave G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | none | 0/10 | ||
Prevent my data from being used to train AI models G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 3 | none | untested | none yet | |
Self-host the core product G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | n/a | untested | none yet | |
Verified sessions return the extracted document fields as structured data — name, date of birth, document number, address, expiry — retrievable via the API, not just a pass/fail flag C Extraction | developer | Document coverage — stories about document coverage in this arenaDocument coverage | 2 | full | 8/10 | Cclaimed | |
Send a verification to someone with a no-code link or QR code — no engineering ticket to verify a one-off customer, contractor, or seller C No code | ops lead | Verification flows — stories about verification flows in this arenaVerification flows | 2 | full | 7/10 | Xcommunity | |
Verification outcomes come back structured enough for an agent to decide on — machine-readable check results, risk signals, and failure reasons an automated onboarding flow can branch on C Agent decisions | ai-native user | Idv agent access — stories about idv agent access in this arenaIdv agent access | 2 | full | 7/10 | Xcommunity | |
Do everything through the API that I can do in the UI G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | partial | 6/10 | Tprobed | |
Verification lifecycle events arrive as signed webhooks — created, processing, verified, requires-input — so my system reacts to outcomes without polling C Webhooks | developer | Integration dx — sandboxes, test modes, webhooks, and how fast a developer gets to a working integrationIntegration dx | 2 | partial | 6/10 | Cclaimed | |
Borderline verifications land in a manual review queue with the full evidence — document images, extracted fields, check results — and reviewer decisions feed back into the record C Review | ops lead | Verification orchestration — stories about verification orchestration in this arenaVerification orchestration | 2 | partial | 5/10 | Cclaimed | |
Verify identity against authoritative databases without documents — SSN, national registries, or credit-header data — for lower-friction flows where a doc scan is overkill C Db checks | developer | Data checks — stories about data checks in this arenaData checks | 2 | partial | 5/10 | Cclaimed | |
The platform detects repeat and duplicate identities across verifications — the same face or document resurfacing under different names is flagged automatically C Duplicate detection | risk analyst | Biometric liveness — stories about biometric liveness in this arenaBiometric liveness | 2 | partial | 3/10 | Cclaimed | |
A person verified once can be recognized and reused across sessions or products — documented re-verification and reuse of a prior passed check instead of forcing a full re-run C Reuse | developer | Verification flows — stories about verification flows in this arenaVerification flows | 2 | none | 0/10 | ||
Control data retention and deletion G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | 0/10 | ||
Control what happens to collected identity data — documented retention windows and a redaction or deletion API that scrubs PII on demand C Redaction | ops lead | Privacy retention — stories about privacy retention in this arenaPrivacy retention | 2 | none | 0/10 | ||
I get native iOS, Android, and web SDKs with guided camera capture — glare, blur, and edge detection coaching the user to a usable document photo on the first try C Native sdks | developer | Verification flows — stories about verification flows in this arenaVerification flows | 2 | none | 0/10 | ||
Perform bulk operations across many items at once G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | none | 0/10 | ||
Screening is not one-shot — previously verified users are continuously re-screened against watchlist updates, and changes raise events I can act on C Monitoring | ops lead | Watchlist screening — stories about watchlist screening in this arenaWatchlist screening | 2 | none | 0/10 | ||
See verification funnel analytics — pass rates, drop-off points, completion time by country and document type — to know what verification is costing me in signups C Analytics | founder | Verification orchestration — stories about verification orchestration in this arenaVerification orchestration | 2 | none | 0/10 | ||
The vendor documents specific defenses against AI-generated faces, deepfakes, and camera-injection attacks — named detection capabilities, not just a marketing mention of fraud C Deepfake defense | risk analyst | Biometric liveness — stories about biometric liveness in this arenaBiometric liveness | 2 | none | 0/10 | ||
Choose where my data is stored (region/residency) G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | untested | none yet | |
Enrich verifications with phone, email, and device risk signals — carrier checks, address history, device fingerprint — as additional documented check types C Risk signals | developer | Data checks — stories about data checks in this arenaData checks | 2 | none | untested | none yet | |
Opt out of telemetry and usage tracking G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | untested | none yet | |
Read the product's source under an open license G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | n/a | untested | none yet | |
Schedule recurring jobs or workflows G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | n/a | untested | none yet | |
Screen verified users against sanctions, PEP, and adverse-media watchlists as part of the same verification — one vendor, one API, one review surface C Screening | ops lead | Watchlist screening — stories about watchlist screening in this arenaWatchlist screening | 2 | none | untested | none yet | |
The vendor documents how biometric data is handled lawfully — GDPR bases, US biometric statutes like BIPA, and the consent language my flow needs — so legal review has something to review C Consent | founder | Privacy retention — stories about privacy retention in this arenaPrivacy retention | 2 | none | untested | none yet | |
Verify businesses, not just people — registry lookups, UBO identification, and documented KYB flows that chain into KYC on the owners C Kyb | ops lead | Data checks — stories about data checks in this arenaData checks | 2 | none | untested | none yet | |
Version, review, and roll back my automations G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 1 | n/a | untested | none yet |
Opportunities — the stories that would move this product's scores, from its own judged verdictsOpportunitiestop 8 of 39 stories with headroom
What would move Stripe Identity’s scores — derived from its own judged verdicts, biggest headroom first. Each line quotes what the judge found missing; shipping it (or evidencing it publicly) is the fix.
Openness — open source, data portability, and self-hosting storiesExport all of my data in open formats and leave
nonemoves PA Scoreimpact 30
Stripe Identity is a KYC/identity-verification API for businesses, not a personal data platform; end users have no account or export mechanism, and evidence shows only programmatic access by the integrating business (via API/secret key), not data export/portability for the verified individual to leave with their data in open formats.
Privacy posture — data-handling and privacy storiesPrevent my data from being used to train AI models
nonemoves PA Scoreimpact 30
No evidence pack content addresses AI-model-training data usage, opt-out controls, or any privacy policy specific to AI training exclusion for Stripe Identity; the evidence only covers identity verification features, pricing, and integration mechanics.
Integration dx — sandboxes, test modes, webhooks, and how fast a developer gets to a working integrationA sandbox lets me exercise every outcome before going live — documented test documents, personas, or magic values that deterministically produce pass, fail, and review results
nonemoves PA Scoreimpact 30
No evidence of documented test/sandbox mode, magic values, or deterministic test personas for triggering pass/fail/review outcomes in Stripe Identity's docs; evidence only covers live verification flow, review tools, and API access, with community complaints about real-world verification failures (not sandbox testing).
Agenticness — how well agents can access and operate the productGet AI-generated insights and suggestions from my data inside the product
nonemoves Built-in AIimpact 30
No evidence that Stripe Identity itself generates AI-driven insights or suggestions from verification data; the docs describe verification, review tools, and manual override, not AI-generated analytics or recommendations.
Agenticness — how well agents can access and operate the productIssue scoped/least-privilege API credentials for an agent
nonemoves agent-readyimpact 30
The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na".
Agenticness — how well agents can access and operate the productDownload a machine-readable API spec (OpenAPI or equivalent)
nonemoves API qualityimpact 30
The evidence pack shows an explicit probe for OpenAPI/swagger spec files at standard paths, all returning 404, and no docs page or claim points to a downloadable machine-readable API spec for Identity; only human-readable curl examples and prose docs exist.
Agenticness — how well agents can access and operate the productRely on versioned APIs with a documented deprecation policy
nonemoves API qualityimpact 30
Missing: versioning scheme docs, deprecation policy docs, changelog/migration guides.
Verification orchestration — stories about verification orchestration in this arenaConfigure verification logic without code — conditional steps, risk-based routing, country-specific requirements, and template changes that don't need an engineering deploy
partialq3/10moves PA Scoreimpact 21
Missing: no-code conditional-step builder, risk-based routing rules, country-specific requirement configuration, and independent confirmation that Flows support these beyond simple reuse.
Showing the top 8 of 39 — every none/partial verdict in the story verdicts table is headroom.
Think a verdict is wrong? Every verdicts-table row has a Flag link — see the methodology.
Coverage map — which docs area, API section, or community source covers which judged storiesCoverage map6 surfaces · 25 covered stories
Where the cited evidence behind each covered verdict came from — the same citations the verdicts table shows, no extra judging.
Identity docs22 stories
- Point an agent at llms.txt or agent-oriented docs
- Run the product headlessly / in CI for automation
- Drive the product through a documented public API
- Build against official SDKs
- Subscribe to events via webhooks
- Set up automations that run autonomously in the background
- Explore an interactive API reference with runnable examples
- Define rules that trigger actions automatically on events
- The platform detects repeat and duplicate identities across verifications — the same face or document resurfacing under different names is flagged automatically
- Selfie checks match the live user to the document portrait with liveness detection — documented defenses against printed photos, screens, and replayed video
- Verify identity against authoritative databases without documents — SSN, national registries, or credit-header data — for lower-friction flows where a doc scan is overkill
- The platform verifies government IDs from a documented breadth of countries and document types — passports, national IDs, driver licenses, residence permits — with the supported list published
- Verified sessions return the extracted document fields as structured data — name, date of birth, document number, address, expiry — retrievable via the API, not just a pass/fail flag
- Verification outcomes come back structured enough for an agent to decide on — machine-readable check results, risk signals, and failure reasons an automated onboarding flow can branch on
- An agent can operate the verification pipeline — create sessions, poll outcomes, retrieve extracted data, and trigger re-checks through the API or an MCP surface with scoped credentials
- The whole verification lifecycle is drivable through the API — create a session, get its status, retrieve results and captured media, and cancel or redact it — with every step documented
- Verification lifecycle events arrive as signed webhooks — created, processing, verified, requires-input — so my system reacts to outcomes without polling
- Do everything through the API that I can do in the UI
- Launch a complete document-plus-selfie verification with a hosted or drop-in flow — create a session server-side, redirect or embed, and read the result — without building capture UI myself
- Send a verification to someone with a no-code link or QR code — no engineering ticket to verify a one-off customer, contractor, or seller
- Borderline verifications land in a manual review queue with the full evidence — document images, extracted fields, check results — and reviewer decisions feed back into the record
- Configure verification logic without code — conditional steps, risk-based routing, country-specific requirements, and template changes that don't need an engineering deploy
MCP docs8 stories
- Connect an agent via an official MCP server
- Drive the product through a documented public API
- Build against official SDKs
- Set up automations that run autonomously in the background
- Operate the product with natural-language commands
- Define rules that trigger actions automatically on events
- An agent can operate the verification pipeline — create sessions, poll outcomes, retrieve extracted data, and trigger re-checks through the API or an MCP surface with scoped credentials
- Do everything through the API that I can do in the UI
Hacker News5 stories
- The platform verifies government IDs from a documented breadth of countries and document types — passports, national IDs, driver licenses, residence permits — with the supported list published
- Verification outcomes come back structured enough for an agent to decide on — machine-readable check results, risk signals, and failure reasons an automated onboarding flow can branch on
- Launch a complete document-plus-selfie verification with a hosted or drop-in flow — create a session server-side, redirect or embed, and read the result — without building capture UI myself
- Send a verification to someone with a no-code link or QR code — no engineering ticket to verify a one-off customer, contractor, or seller
- Configure verification logic without code — conditional steps, risk-based routing, country-specific requirements, and template changes that don't need an engineering deploy
OpenAPI spec3 stories
Probe proofs — replayable recordings from the probe harnessProbe proofs
Replayable recordings from our probe harness — see the Prove-It protocol to submit one.
$curl -si https://api.stripe.com/v1/identity/verification_sessions | head -4 # Identity sessions API, keyless → 401reproduced$ curl -si https://api.stripe.com/v1/identity/verification_sessions | head -4 # Identity sessions API, [redacted]less → 401 HTTP/2 401 server: nginx date: Tue, 15 Sep 2026 19:35:46 GMT content-type: application/json
$curl -sL https://docs.stripe.com/llms.txt | head -3reproduced$ curl -sL https://docs.stripe.com/llms.txt | head -3 # Stripe Documentation When installing Stripe packages, always check the npm registry for the latest version rather than relying on memorized version numbers. Run `npm view stripe version` or check https://www.npmjs.com/package/stripe before pinning a version. For Python, check https://pypi.org/project/stripe/. Never hardcode an old version number from training data — always install with `@latest` or verify the current version first.
$curl -s -X POST https://mcp.stripe.com/ -H 'Content-Type: application/json' -d '<jsonrpc initialize>' # the remote MCP server Stripe documents at docs.stripe.com/mcpreproduced$ curl -s -X POST https://mcp.stripe.com/ -H 'Content-Type: application/json' -d '<jsonrpc initialize>' # the remote MCP server Stripe documents at docs.stripe.com/mcp
{"error":"Unauthorized. See https://docs.stripe.com/mcp for usage instructions."}
Claims vs evidence — vendor claims reconciled against independent verdictsClaims vs evidence
6 of 13 testable claims verified · 1 contradicted → integrity 31/100
13 distinct capability claims found in Stripe Identity’s own claimed-docs/GitHub materials, reconciled against our judge’s independent verdicts.
6
Verified
6
Unverified
1
Contradicted
12
Undersold
Verified (7)
“Captures government photo IDs via a conversion-optimized hosted verification flow”
Launch a complete document-plus-selfie verification with a hosted or drop-in flow — create a session server-side, redirect or embed, and read the result — without building capture UI myselffullproof ↗
“Matches government photo IDs against a selfie to confirm identity”
Selfie checks match the live user to the document portrait with liveness detection — documented defenses against printed photos, screens, and replayed videopartialproof ↗
“Create a verification session via a documented REST API call”
Drive the product through a documented public APIfullproof ↗
“Verification session details can be retrieved programmatically using an API secret key”
Drive the product through a documented public APIfullproof ↗
“Flows let you save and reuse a verification configuration across integration surfaces without code changes”
Configure verification logic without code — conditional steps, risk-based routing, country-specific requirements, and template changes that don't need an engineering deploypartialproof ↗
“A flow's static link can be shared to verify any number of users without engineering involvement”
Send a verification to someone with a no-code link or QR code — no engineering ticket to verify a one-off customer, contractor, or sellerfullproof ↗
“An official MCP server exposes Stripe API tools for AI agents to use”
Unverified (6)
“Validates Social Security numbers as a document-free identity check”
Verify identity against authoritative databases without documents — SSN, national registries, or credit-header data — for lower-friction flows where a doc scan is overkillpartialproof ↗
“Provides API access to collected ID images and extracted document data”
Verified sessions return the extracted document fields as structured data — name, date of birth, document number, address, expiry — retrievable via the API, not just a pass/fail flagfullproof ↗
“Create a verification session via a documented REST API call”
The whole verification lifecycle is drivable through the API — create a session, get its status, retrieve results and captured media, and cancel or redact it — with every step documentedpartialproof ↗
“Verification results can be received via webhook events to trigger automated reactions”
Verification lifecycle events arrive as signed webhooks — created, processing, verified, requires-input — so my system reacts to outcomes without pollingpartialproof ↗
“Reviewers can manually override the verification status decision”
Borderline verifications land in a manual review queue with the full evidence — document images, extracted fields, check results — and reviewer decisions feed back into the recordpartialproof ↗
“Documents can be added to a blocklist to automatically block future verifications using the same document”
The platform detects repeat and duplicate identities across verifications — the same face or document resurfacing under different names is flagged automaticallypartialproof ↗
Contradicted (1)
“Verifies authenticity of government-issued IDs from 120+ countries”
The platform verifies government IDs from a documented breadth of countries and document types — passports, national IDs, driver licenses, residence permits — with the supported list publisheddisputedproof ↗
Undersold (12)
Point an agent at llms.txt or agent-oriented docsfullproof ↗
Run the product headlessly / in CI for automationpartialproof ↗
Set up automations that run autonomously in the backgroundpartialproof ↗
Operate the product with natural-language commandspartialproof ↗
Explore an interactive API reference with runnable examplespartialproof ↗
Define rules that trigger actions automatically on eventspartialproof ↗
Verification outcomes come back structured enough for an agent to decide on — machine-readable check results, risk signals, and failure reasons an automated onboarding flow can branch onfullproof ↗
An agent can operate the verification pipeline — create sessions, poll outcomes, retrieve extracted data, and trigger re-checks through the API or an MCP surface with scoped credentialspartialproof ↗
Do everything through the API that I can do in the UIpartialproof ↗
Business model
Published usage-based pricing: $1.50 per document+selfie verification, 50¢ per ID-number lookup, first 50 verifications free; above ~2,000 verifications a month Stripe routes you to sales.
pricing ↗Score trend
How this product’s scores have moved as evidence and verdicts are re-derived — a point per change, not per day.
Try Experimental
Run it in the microterminal →Recorded agent sessions — and a live MCP handshake where the vendor ships one.
Flag
⚑ Flag a verdictThink a verdict is wrong? Opens a prefilled GitHub issue — or use the ⚑ next to any verdict above.
For agents
