Rank #2 of 6 in Identity Verification & KYC
Install
npm install @sumsub/websdkTry itExperimental
See what an agent can do with Sumsub before you ever sign up. Pick a story: recorded sessions replay real probe-harness transcripts; sandboxed self-drive sessions are designed and gated (docs/TRY-IT.md).
$curl -s https://api.sumsub.com/resources/applicants/x/one # keyless → 403 "Unauthorized (cfb)", not a plain 401recorded session — replayed, not liveVerified integrations
No integration evidence found in our corpus for this product yet — that means none was found, never that it doesn’t integrate.
By theme — the product's score on each story themeBy theme
Agenticness — how well agents can access and operate the productAgenticnessevidence →
How well agents can access and operate the product
Automation depth — how much of the product can run unattendedAutomation depthevidence →
How much of the product can run unattended
Biometric liveness — stories about biometric liveness in this arenaBiometric livenessevidence →
Stories about biometric liveness in this arena
Data checks — stories about data checks in this arenaData checksevidence →
Stories about data checks in this arena
Document coverage — stories about document coverage in this arenaDocument coverageevidence →
Stories about document coverage in this arena
Idv agent access — stories about idv agent access in this arenaIdv agent accessevidence →
Stories about idv agent access in this arena
Integration dx — sandboxes, test modes, webhooks, and how fast a developer gets to a working integrationIntegration dxevidence →
Sandboxes, test modes, webhooks, and how fast a developer gets to a working integration
Openness — open source, data portability, and self-hosting storiesOpennessevidence →
Open source, data portability, and self-hosting stories
Privacy posture — data-handling and privacy storiesPrivacy postureevidence →
Data-handling and privacy stories
Privacy retention — stories about privacy retention in this arenaPrivacy retentionevidence →
Stories about privacy retention in this arena
Verification flows — stories about verification flows in this arenaVerification flowsevidence →
Stories about verification flows in this arena
Verification orchestration — stories about verification orchestration in this arenaVerification orchestrationevidence →
Stories about verification orchestration in this arena
Watchlist screening — stories about watchlist screening in this arenaWatchlist screeningevidence →
Stories about watchlist screening in this arena
Story verdicts — every judged story with its evidenceStory verdicts
Follow the green: where the map greys out is where Sumsub stops today. ✓ full · ~ partial · ! disputed · — none · n/a not applicable.
Agenticness — how well agents can access and operate the productAgenticness
How well agents can access and operate the product
API surface
Drive the product through a documented public API
✓8/10
unlocks → Machine-readable spec · Versioning policy · Official CLI · Full data export · See verification funnel analytics — pass rates, drop-off points, completion time by country and document type — to know what verification is costing me in signups
Subscribe to events via webhooks
✓8/10
Build against official SDKs
~5/10
Issue scoped/least-privilege API credentials for an agent
~5/10
Connect an agent via an official MCP server
✓8/10
Download a machine-readable API spec (OpenAPI or equivalent)
—0/10
Rely on versioned APIs with a documented deprecation policy
—0/10
Test against a sandbox environment without touching production data
✓8/10
Explore an interactive API reference with runnable examples
—0/10
Agentic features
Delegate tasks to a built-in AI assistant inside the product
—0/10
Operate the product with natural-language commands
~6/10
Plug MCP servers into this product so it can use their tools
n/an/a
Get AI-generated insights and suggestions from my data inside the product
—0/10
Set up automations that run autonomously in the background
~5/10
Automation depth — how much of the product can run unattendedAutomation depth
How much of the product can run unattended
Biometric liveness — stories about biometric liveness in this arenaBiometric liveness
Stories about biometric liveness in this arena
The vendor documents specific defenses against AI-generated faces, deepfakes, and camera-injection attacks — named detection capabilities, not just a marketing mention of fraud
~6/10
The platform detects repeat and duplicate identities across verifications — the same face or document resurfacing under different names is flagged automatically
—–
Selfie checks match the live user to the document portrait with liveness detection — documented defenses against printed photos, screens, and replayed video
✓8/10
Data checks — stories about data checks in this arenaData checks
Stories about data checks in this arena
Verify identity against authoritative databases without documents — SSN, national registries, or credit-header data — for lower-friction flows where a doc scan is overkill
—–
Verify businesses, not just people — registry lookups, UBO identification, and documented KYB flows that chain into KYC on the owners
—–
Enrich verifications with phone, email, and device risk signals — carrier checks, address history, device fingerprint — as additional documented check types
—–
Document coverage — stories about document coverage in this arenaDocument coverage
Stories about document coverage in this arena
The platform verifies government IDs from a documented breadth of countries and document types — passports, national IDs, driver licenses, residence permits — with the supported list published
~6/10
Verified sessions return the extracted document fields as structured data — name, date of birth, document number, address, expiry — retrievable via the API, not just a pass/fail flag
—0/10
Idv agent access — stories about idv agent access in this arenaIdv agent access
Stories about idv agent access in this arena
Verification outcomes come back structured enough for an agent to decide on — machine-readable check results, risk signals, and failure reasons an automated onboarding flow can branch on
~6/10
An agent can operate the verification pipeline — create sessions, poll outcomes, retrieve extracted data, and trigger re-checks through the API or an MCP surface with scoped credentials
~6/10
Integration dx — sandboxes, test modes, webhooks, and how fast a developer gets to a working integrationIntegration dx
Sandboxes, test modes, webhooks, and how fast a developer gets to a working integration
A sandbox lets me exercise every outcome before going live — documented test documents, personas, or magic values that deterministically produce pass, fail, and review results
~4/10
The whole verification lifecycle is drivable through the API — create a session, get its status, retrieve results and captured media, and cancel or redact it — with every step documented
~5/10
Verification lifecycle events arrive as signed webhooks — created, processing, verified, requires-input — so my system reacts to outcomes without polling
~5/10
Openness — open source, data portability, and self-hosting storiesOpenness
Open source, data portability, and self-hosting stories
Privacy posture — data-handling and privacy storiesPrivacy posture
Data-handling and privacy stories
Privacy retention — stories about privacy retention in this arenaPrivacy retention
Stories about privacy retention in this arena
The vendor documents how biometric data is handled lawfully — GDPR bases, US biometric statutes like BIPA, and the consent language my flow needs — so legal review has something to review
—–
Control what happens to collected identity data — documented retention windows and a redaction or deletion API that scrubs PII on demand
—–
Verification flows — stories about verification flows in this arenaVerification flows
Stories about verification flows in this arena
Launch a complete document-plus-selfie verification with a hosted or drop-in flow — create a session server-side, redirect or embed, and read the result — without building capture UI myself
✓7/10
I get native iOS, Android, and web SDKs with guided camera capture — glare, blur, and edge detection coaching the user to a usable document photo on the first try
—0/10
Send a verification to someone with a no-code link or QR code — no engineering ticket to verify a one-off customer, contractor, or seller
—–
A person verified once can be recognized and reused across sessions or products — documented re-verification and reuse of a prior passed check instead of forcing a full re-run
✓8/10
Verification orchestration — stories about verification orchestration in this arenaVerification orchestration
Stories about verification orchestration in this arena
See verification funnel analytics — pass rates, drop-off points, completion time by country and document type — to know what verification is costing me in signups
—–
Borderline verifications land in a manual review queue with the full evidence — document images, extracted fields, check results — and reviewer decisions feed back into the record
~4/10
Configure verification logic without code — conditional steps, risk-based routing, country-specific requirements, and template changes that don't need an engineering deploy
~5/10
Watchlist screening — stories about watchlist screening in this arenaWatchlist screening
Stories about watchlist screening in this arena
Screening is not one-shot — previously verified users are continuously re-screened against watchlist updates, and changes raise events I can act on
~5/10
Screen verified users against sanctions, PEP, and adverse-media watchlists as part of the same verification — one vendor, one API, one review surface
✓8/10
Sorted by importance (agentic first) (high → low) · 53/53 stories · click a row’s chevron for the rationale and evidence
Connect an agent via an official MCP server G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | full | 8/10 | Tprobed | |
Drive the product through a documented public API G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | full | 8/10 | Tprobed | |
Delegate tasks to a built-in AI assistant inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | none | 0/10 | ||
Plug MCP servers into this product so it can use their tools G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | n/a | 0/10 | ||
Point an agent at llms.txt or agent-oriented docs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 9/10 | Tprobed | |
Subscribe to events via webhooks G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 8/10 | Cclaimed | |
Operate the product with natural-language commands G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 6/10 | Tprobed | |
Run the product headlessly / in CI for automation G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 6/10 | Cclaimed | |
Build against official SDKs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 5/10 | Tprobed | |
Issue scoped/least-privilege API credentials for an agent G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 5/10 | Tprobed | |
Set up automations that run autonomously in the background G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 5/10 | Tprobed | |
Download a machine-readable API spec (OpenAPI or equivalent) G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Explore an interactive API reference with runnable examples G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Get AI-generated insights and suggestions from my data inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Rely on versioned APIs with a documented deprecation policy G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Use an official CLI G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | untested | none yet | |
Test against a sandbox environment without touching production data G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 1 | full | 8/10 | Cclaimed | |
Selfie checks match the live user to the document portrait with liveness detection — documented defenses against printed photos, screens, and replayed video C Liveness | risk analyst | Biometric liveness — stories about biometric liveness in this arenaBiometric liveness | 3 | full | 8/10 | Cclaimed | |
Launch a complete document-plus-selfie verification with a hosted or drop-in flow — create a session server-side, redirect or embed, and read the result — without building capture UI myself C Hosted flows | developer | Verification flows — stories about verification flows in this arenaVerification flows | 3 | full | 7/10 | Cclaimed | |
An agent can operate the verification pipeline — create sessions, poll outcomes, retrieve extracted data, and trigger re-checks through the API or an MCP surface with scoped credentials C Agent operations | ai-native user | Idv agent access — stories about idv agent access in this arenaIdv agent access | 3 | partial | 6/10 | Tprobed | |
The platform verifies government IDs from a documented breadth of countries and document types — passports, national IDs, driver licenses, residence permits — with the supported list published C Doc types | ops lead | Document coverage — stories about document coverage in this arenaDocument coverage | 3 | partial | 6/10 | Cclaimed | |
Configure verification logic without code — conditional steps, risk-based routing, country-specific requirements, and template changes that don't need an engineering deploy C Workflows | ops lead | Verification orchestration — stories about verification orchestration in this arenaVerification orchestration | 3 | partial | 5/10 | Cclaimed | |
Define rules that trigger actions automatically on events G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 3 | partial | 5/10 | Cclaimed | |
The whole verification lifecycle is drivable through the API — create a session, get its status, retrieve results and captured media, and cancel or redact it — with every step documented C Session api | developer | Integration dx — sandboxes, test modes, webhooks, and how fast a developer gets to a working integrationIntegration dx | 3 | partial | 5/10 | Tprobed | |
A sandbox lets me exercise every outcome before going live — documented test documents, personas, or magic values that deterministically produce pass, fail, and review results C Sandbox | developer | Integration dx — sandboxes, test modes, webhooks, and how fast a developer gets to a working integrationIntegration dx | 3 | partial | 4/10 | Cclaimed | |
Export all of my data in open formats and leave G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | none | 0/10 | ||
Prevent my data from being used to train AI models G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 3 | none | untested | none yet | |
Self-host the core product G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | n/a | untested | none yet | |
A person verified once can be recognized and reused across sessions or products — documented re-verification and reuse of a prior passed check instead of forcing a full re-run C Reuse | developer | Verification flows — stories about verification flows in this arenaVerification flows | 2 | full | 8/10 | Cclaimed | |
Screen verified users against sanctions, PEP, and adverse-media watchlists as part of the same verification — one vendor, one API, one review surface C Screening | ops lead | Watchlist screening — stories about watchlist screening in this arenaWatchlist screening | 2 | full | 8/10 | Cclaimed | |
The vendor documents specific defenses against AI-generated faces, deepfakes, and camera-injection attacks — named detection capabilities, not just a marketing mention of fraud C Deepfake defense | risk analyst | Biometric liveness — stories about biometric liveness in this arenaBiometric liveness | 2 | partial | 6/10 | Cclaimed | |
Verification outcomes come back structured enough for an agent to decide on — machine-readable check results, risk signals, and failure reasons an automated onboarding flow can branch on C Agent decisions | ai-native user | Idv agent access — stories about idv agent access in this arenaIdv agent access | 2 | partial | 6/10 | Tprobed | |
Do everything through the API that I can do in the UI G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | partial | 5/10 | Tprobed | |
Screening is not one-shot — previously verified users are continuously re-screened against watchlist updates, and changes raise events I can act on C Monitoring | ops lead | Watchlist screening — stories about watchlist screening in this arenaWatchlist screening | 2 | partial | 5/10 | Cclaimed | |
Verification lifecycle events arrive as signed webhooks — created, processing, verified, requires-input — so my system reacts to outcomes without polling C Webhooks | developer | Integration dx — sandboxes, test modes, webhooks, and how fast a developer gets to a working integrationIntegration dx | 2 | partial | 5/10 | Cclaimed | |
Borderline verifications land in a manual review queue with the full evidence — document images, extracted fields, check results — and reviewer decisions feed back into the record C Review | ops lead | Verification orchestration — stories about verification orchestration in this arenaVerification orchestration | 2 | partial | 4/10 | Cclaimed | |
I get native iOS, Android, and web SDKs with guided camera capture — glare, blur, and edge detection coaching the user to a usable document photo on the first try C Native sdks | developer | Verification flows — stories about verification flows in this arenaVerification flows | 2 | none | 0/10 | ||
Perform bulk operations across many items at once G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | none | 0/10 | ||
Verified sessions return the extracted document fields as structured data — name, date of birth, document number, address, expiry — retrievable via the API, not just a pass/fail flag C Extraction | developer | Document coverage — stories about document coverage in this arenaDocument coverage | 2 | none | 0/10 | ||
Choose where my data is stored (region/residency) G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | untested | none yet | |
Control data retention and deletion G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | untested | none yet | |
Control what happens to collected identity data — documented retention windows and a redaction or deletion API that scrubs PII on demand C Redaction | ops lead | Privacy retention — stories about privacy retention in this arenaPrivacy retention | 2 | none | untested | none yet | |
Enrich verifications with phone, email, and device risk signals — carrier checks, address history, device fingerprint — as additional documented check types C Risk signals | developer | Data checks — stories about data checks in this arenaData checks | 2 | none | untested | none yet | |
Opt out of telemetry and usage tracking G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | untested | none yet | |
Read the product's source under an open license G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | n/a | untested | none yet | |
Schedule recurring jobs or workflows G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | none | untested | none yet | |
See verification funnel analytics — pass rates, drop-off points, completion time by country and document type — to know what verification is costing me in signups C Analytics | founder | Verification orchestration — stories about verification orchestration in this arenaVerification orchestration | 2 | none | untested | none yet | |
Send a verification to someone with a no-code link or QR code — no engineering ticket to verify a one-off customer, contractor, or seller C No code | ops lead | Verification flows — stories about verification flows in this arenaVerification flows | 2 | none | untested | none yet | |
The platform detects repeat and duplicate identities across verifications — the same face or document resurfacing under different names is flagged automatically C Duplicate detection | risk analyst | Biometric liveness — stories about biometric liveness in this arenaBiometric liveness | 2 | none | untested | none yet | |
The vendor documents how biometric data is handled lawfully — GDPR bases, US biometric statutes like BIPA, and the consent language my flow needs — so legal review has something to review C Consent | founder | Privacy retention — stories about privacy retention in this arenaPrivacy retention | 2 | none | untested | none yet | |
Verify businesses, not just people — registry lookups, UBO identification, and documented KYB flows that chain into KYC on the owners C Kyb | ops lead | Data checks — stories about data checks in this arenaData checks | 2 | none | untested | none yet | |
Verify identity against authoritative databases without documents — SSN, national registries, or credit-header data — for lower-friction flows where a doc scan is overkill C Db checks | developer | Data checks — stories about data checks in this arenaData checks | 2 | none | untested | none yet | |
Version, review, and roll back my automations G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 1 | none | untested | none yet |
Opportunities — the stories that would move this product's scores, from its own judged verdictsOpportunitiestop 8 of 41 stories with headroom
What would move Sumsub’s scores — derived from its own judged verdicts, biggest headroom first. Each line quotes what the judge found missing; shipping it (or evidencing it publicly) is the fix.
Agenticness — how well agents can access and operate the productDelegate tasks to a built-in AI assistant inside the product
nonemoves Built-in AIimpact 45
Evidence only shows an MCP server that lets external AI agents call Sumsub operations, which is the reverse of a built-in AI assistant that users delegate tasks to inside the product.
Openness — open source, data portability, and self-hosting storiesExport all of my data in open formats and leave
nonemoves PA Scoreimpact 30
Sumsub is a KYC/verification platform storing applicant data, but no evidence shows a user-facing data export feature in open/portable formats or an account-closure data portability workflow; only API access for processing applicant data during integration is documented, not a 'take your data and leave' capability.
Privacy posture — data-handling and privacy storiesPrevent my data from being used to train AI models
nonemoves PA Scoreimpact 30
No evidence in the pack addresses AI-training data usage or opt-out policies; Sumsub's docs cover verification, AML, and API features but nothing about preventing data from being used to train AI models.
Agenticness — how well agents can access and operate the productGet AI-generated insights and suggestions from my data inside the product
nonemoves Built-in AIimpact 30
Missing: any documented AI-generated analytics/insights feature, dashboard summarization, or recommendation engine within the Sumsub UI.
Agenticness — how well agents can access and operate the productUse an official CLI
nonemoves agent-readyimpact 30
The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na".
Agenticness — how well agents can access and operate the productExplore an interactive API reference with runnable examples
nonemoves API qualityimpact 30
There's mention of a REST API and docs, but no evidence of an interactive API reference with runnable examples (e.g., try-it-out console, embedded code sandbox); the OpenAPI/Swagger probe returned 404s, suggesting no interactive spec is publicly exposed.
Agenticness — how well agents can access and operate the productDownload a machine-readable API spec (OpenAPI or equivalent)
nonemoves API qualityimpact 30
Sumsub documents a RESTful API and provides llms.txt for markdown docs, but direct probes for OpenAPI/Swagger spec files all returned 404, and no evidence pack item points to a downloadable machine-readable API spec.
Agenticness — how well agents can access and operate the productRely on versioned APIs with a documented deprecation policy
nonemoves API qualityimpact 30
No evidence of API versioning scheme or a documented deprecation policy; OpenAPI spec probes returned 404s and docs only describe general REST usage, sandbox testing, and webhooks without mentioning version lifecycle or deprecation timelines.
Showing the top 8 of 41 — every none/partial verdict in the story verdicts table is headroom.
Think a verdict is wrong? Every verdicts-table row has a Flag link — see the methodology.
Coverage map — which docs area, API section, or community source covers which judged storiesCoverage map4 surfaces · 26 covered stories
Where the cited evidence behind each covered verdict came from — the same citations the verdicts table shows, no extra judging.
docs25 stories
- Run the product headlessly / in CI for automation
- Connect an agent via an official MCP server
- Drive the product through a documented public API
- Issue scoped/least-privilege API credentials for an agent
- Build against official SDKs
- Subscribe to events via webhooks
- Set up automations that run autonomously in the background
- Operate the product with natural-language commands
- Test against a sandbox environment without touching production data
- Define rules that trigger actions automatically on events
- The vendor documents specific defenses against AI-generated faces, deepfakes, and camera-injection attacks — named detection capabilities, not just a marketing mention of fraud
- Selfie checks match the live user to the document portrait with liveness detection — documented defenses against printed photos, screens, and replayed video
- The platform verifies government IDs from a documented breadth of countries and document types — passports, national IDs, driver licenses, residence permits — with the supported list published
- Verification outcomes come back structured enough for an agent to decide on — machine-readable check results, risk signals, and failure reasons an automated onboarding flow can branch on
- An agent can operate the verification pipeline — create sessions, poll outcomes, retrieve extracted data, and trigger re-checks through the API or an MCP surface with scoped credentials
- A sandbox lets me exercise every outcome before going live — documented test documents, personas, or magic values that deterministically produce pass, fail, and review results
- The whole verification lifecycle is drivable through the API — create a session, get its status, retrieve results and captured media, and cancel or redact it — with every step documented
- Verification lifecycle events arrive as signed webhooks — created, processing, verified, requires-input — so my system reacts to outcomes without polling
- Do everything through the API that I can do in the UI
- Launch a complete document-plus-selfie verification with a hosted or drop-in flow — create a session server-side, redirect or embed, and read the result — without building capture UI myself
- A person verified once can be recognized and reused across sessions or products — documented re-verification and reuse of a prior passed check instead of forcing a full re-run
- Borderline verifications land in a manual review queue with the full evidence — document images, extracted fields, check results — and reviewer decisions feed back into the record
- Configure verification logic without code — conditional steps, risk-based routing, country-specific requirements, and template changes that don't need an engineering deploy
- Screening is not one-shot — previously verified users are continuously re-screened against watchlist updates, and changes raise events I can act on
- Screen verified users against sanctions, PEP, and adverse-media watchlists as part of the same verification — one vendor, one API, one review surface
API reference9 stories
- Run the product headlessly / in CI for automation
- Drive the product through a documented public API
- Build against official SDKs
- Verification outcomes come back structured enough for an agent to decide on — machine-readable check results, risk signals, and failure reasons an automated onboarding flow can branch on
- An agent can operate the verification pipeline — create sessions, poll outcomes, retrieve extracted data, and trigger re-checks through the API or an MCP surface with scoped credentials
- The whole verification lifecycle is drivable through the API — create a session, get its status, retrieve results and captured media, and cancel or redact it — with every step documented
- Do everything through the API that I can do in the UI
- Launch a complete document-plus-selfie verification with a hosted or drop-in flow — create a session server-side, redirect or embed, and read the result — without building capture UI myself
- Screen verified users against sanctions, PEP, and adverse-media watchlists as part of the same verification — one vendor, one API, one review surface
llms.txt5 stories
- Point an agent at llms.txt or agent-oriented docs
- Issue scoped/least-privilege API credentials for an agent
- Build against official SDKs
- Do everything through the API that I can do in the UI
- Launch a complete document-plus-selfie verification with a hosted or drop-in flow — create a session server-side, redirect or embed, and read the result — without building capture UI myself
OpenAPI spec5 stories
- Drive the product through a documented public API
- Verification outcomes come back structured enough for an agent to decide on — machine-readable check results, risk signals, and failure reasons an automated onboarding flow can branch on
- An agent can operate the verification pipeline — create sessions, poll outcomes, retrieve extracted data, and trigger re-checks through the API or an MCP surface with scoped credentials
- The whole verification lifecycle is drivable through the API — create a session, get its status, retrieve results and captured media, and cancel or redact it — with every step documented
- Do everything through the API that I can do in the UI
Probe proofs — replayable recordings from the probe harnessProbe proofs
Replayable recordings from our probe harness — see the Prove-It protocol to submit one.
$curl -s https://api.sumsub.com/resources/applicants/x/one # keyless → 403 "Unauthorized (cfb)", not a plain 401reproduced$ curl -s https://api.sumsub.com/resources/applicants/x/one # [redacted]less → 403 "Unauthorized (cfb)", not a plain 401
{
"code" : 403,
"correlationId" : "fb0b6e1e3cd94759bc1769e36bd745a8",
"description" : "Unauthorized (cfb)"
}
$curl -sL https://docs.sumsub.com/llms.txt | head -3reproduced$ curl -sL https://docs.sumsub.com/llms.txt | head -3 # Sumsub Documentation > Documentation for Sumsub
$curl -s -X POST https://docs.sumsub.com/mcp -H 'Content-Type: application/json' -d '<jsonrpc initialize>' # JSON-RPC "Authorization required" authgatereproduced$ curl -s -X POST https://docs.sumsub.com/mcp -H 'Content-Type: application/json' -d '<jsonrpc initialize>' # JSON-RPC "Authorization required" authgate
{"jsonrpc":"2.0","error":{"code":-32001,"message":"Authorization required"},"id":null}
Claims vs evidence — vendor claims reconciled against independent verdictsClaims vs evidence
4 of 17 testable claims verified · 1 contradicted → integrity 12/100
13 distinct capability claims found in Sumsub’s own claimed-docs/GitHub materials, reconciled against our judge’s independent verdicts.
4
Verified
12
Unverified
1
Contradicted
10
Undersold
Verified (4)
“Applicant data and documents can be processed via RESTful APIs”
The whole verification lifecycle is drivable through the API — create a session, get its status, retrieve results and captured media, and cancel or redact it — with every step documentedpartialproof ↗
“Applicant data and documents can be processed via RESTful APIs”
Drive the product through a documented public APIfullproof ↗
“An MCP server lets AI agents perform Sumsub operations under your existing role permissions”
“An MCP server lets AI agents perform Sumsub operations under your existing role permissions”
An agent can operate the verification pipeline — create sessions, poll outcomes, retrieve extracted data, and trigger re-checks through the API or an MCP surface with scoped credentialspartialproof ↗
Unverified (12)
“Sandbox mode lets you test integrations before going live”
Test against a sandbox environment without touching production datafullproof ↗
“Sandbox mode lets you test integrations before going live”
A sandbox lets me exercise every outcome before going live — documented test documents, personas, or magic values that deterministically produce pass, fail, and review resultspartialproof ↗
“Webhooks automatically notify you of applicant verification events and status changes”
Verification lifecycle events arrive as signed webhooks — created, processing, verified, requires-input — so my system reacts to outcomes without pollingpartialproof ↗
“Webhooks automatically notify you of applicant verification events and status changes”
“Verification 'levels' define configurable multi-step flows including docs, selfie, liveness, video, questionnaire, and payment checks”
Configure verification logic without code — conditional steps, risk-based routing, country-specific requirements, and template changes that don't need an engineering deploypartialproof ↗
“Verification 'levels' define configurable multi-step flows including docs, selfie, liveness, video, questionnaire, and payment checks”
Launch a complete document-plus-selfie verification with a hosted or drop-in flow — create a session server-side, redirect or embed, and read the result — without building capture UI myselffullproof ↗
“AML screening can be configured against targeted lists/categories with adjustable fuzziness”
Screen verified users against sanctions, PEP, and adverse-media watchlists as part of the same verification — one vendor, one API, one review surfacefullproof ↗
“Reusable KYC lets clients share verification data via agreement and reuse applicant data across checks”
A person verified once can be recognized and reused across sessions or products — documented re-verification and reuse of a prior passed check instead of forcing a full re-runfullproof ↗
“Supports instant verification of 14,000+ document types from 220+ countries and territories”
The platform verifies government IDs from a documented breadth of countries and document types — passports, national IDs, driver licenses, residence permits — with the supported list publishedpartialproof ↗
“Liveness check confirms a real live person in under a second, detecting deepfakes, AI-generated images, paper masks, screen photos, and dolls”
The vendor documents specific defenses against AI-generated faces, deepfakes, and camera-injection attacks — named detection capabilities, not just a marketing mention of fraudpartialproof ↗
“Liveness check confirms a real live person in under a second, detecting deepfakes, AI-generated images, paper masks, screen photos, and dolls”
Selfie checks match the live user to the document portrait with liveness detection — documented defenses against printed photos, screens, and replayed videofullproof ↗
“Liveness check results for an applicant can be reviewed in the Applicant profile UI”
Borderline verifications land in a manual review queue with the full evidence — document images, extracted fields, check results — and reviewer decisions feed back into the recordpartialproof ↗
Contradicted (1)
“Web and Mobile SDKs can be customized with brand colors, styles, and instructions”
I get native iOS, Android, and web SDKs with guided camera capture — glare, blur, and edge detection coaching the user to a usable document photo on the first trynoneproof ↗
Undersold (10)
Point an agent at llms.txt or agent-oriented docsfullproof ↗
Run the product headlessly / in CI for automationpartialproof ↗
Issue scoped/least-privilege API credentials for an agentpartialproof ↗
Set up automations that run autonomously in the backgroundpartialproof ↗
Operate the product with natural-language commandspartialproof ↗
Define rules that trigger actions automatically on eventspartialproof ↗
Verification outcomes come back structured enough for an agent to decide on — machine-readable check results, risk signals, and failure reasons an automated onboarding flow can branch onpartialproof ↗
Do everything through the API that I can do in the UIpartialproof ↗
Screening is not one-shot — previously verified users are continuously re-screened against watchlist updates, and changes raise events I can act onpartialproof ↗
Claims outside our story set (2)
Real capability claims found in Sumsub’s own materials, but no story in this arena’s taxonomy covers them yet — that’s feedback on the taxonomy, not a mark against the product.
“Team members can be granted access to the Sumsub account”
source ↗“Security keys or biometrics can be used to protect account access”
source ↗
Business model
Published per-verification pricing: Basic $1.35 (min $149/month), Compliance $1.85 (min $299/month), custom above that; 14-day free trial with 50 checks; charged for successful verifications only.
pricing ↗Score trend
How this product’s scores have moved as evidence and verdicts are re-derived — a point per change, not per day.
Try Experimental
Run it in the microterminal →Recorded agent sessions — and a live MCP handshake where the vendor ships one.
Flag
⚑ Flag a verdictThink a verdict is wrong? Opens a prefilled GitHub issue — or use the ⚑ next to any verdict above.
For agents
