Identity Verification & KYC Arena
Identity Verification & KYC — procurement report
ProductArena · rankings as of 2026-09-15 · evidence as of 2026-09-15 · 6 products · 53 judged requirements · 318 judged cells
Methodology: Every product is judged against a shared taxonomy of user stories using cited evidence — hands-on probes > repository code > independent community sources > vendor claims — never opinion. Full writeup: https://ultrametric.ai/productarena/methodology
Leaderboard
| # | Product | PA Score | Coverage score | Applicable cells | Confidence |
|---|---|---|---|---|---|
| 1 | Entrust Identity Verification (Onfido) | 26.0 | 23.5 | 44/53 | C |
| 2 | Sumsub | 25.4 | 26.3 | 50/53 | B |
| 3 | Stripe Identity | 24.2 | 23.1 | 47/53 | B |
| 4 | Persona | 22.5 | 17.0 | 46/53 | D |
| 5 | Veriff | 18.9 | 18.3 | 48/53 | C |
| 6 | Plaid Identity Verification | 17.3 | 20.3 | 47/53 | B |
PA Score = agent-readiness blend (see methodology). Coverage score = weighted share of judged requirements met. Confidence = how much of the score rests on tested vs claimed evidence (A–D).
Uncertainty note
The current #1/#2 gap in this arena is not close enough to qualify for the multi-judge uncertainty pass (or the pass has not covered it yet) — no extra caveat applies beyond the per-product confidence grades above.
Buyer checklist (RFP)
The arena's 53 judged user stories as requirements, grouped by theme. Priorities mirror the story weights our scoring uses (3 = must-have, 2 = should-have, 1 = nice-to-have). Interactive version with per-requirement verdicts for the top products: /arena/identity-verification/checklist
Agenticness — how well agents can access and operate the productAgenticness
How well agents can access and operate the product
- ai-native userPlug MCP servers into this product so it can use their toolsmust-have
- ai-native userConnect an agent via an official MCP servermust-have
- ai-native userDrive the product through a documented public APImust-have
- ai-native userDelegate tasks to a built-in AI assistant inside the productmust-have
- ai-native userPoint an agent at llms.txt or agent-oriented docsshould-have
- ai-native userRun the product headlessly / in CI for automationshould-have
- ai-native userUse an official CLIshould-have
- ai-native userIssue scoped/least-privilege API credentials for an agentshould-have
- ai-native userBuild against official SDKsshould-have
- ai-native userSubscribe to events via webhooksshould-have
- ai-native userGet AI-generated insights and suggestions from my data inside the productshould-have
- ai-native userSet up automations that run autonomously in the backgroundshould-have
- ai-native userOperate the product with natural-language commandsshould-have
- ai-native userExplore an interactive API reference with runnable examplesshould-have
- ai-native userDownload a machine-readable API spec (OpenAPI or equivalent)should-have
- ai-native userRely on versioned APIs with a documented deprecation policyshould-have
- ai-native userTest against a sandbox environment without touching production datanice-to-have
Automation depth — how much of the product can run unattendedAutomation depth
How much of the product can run unattended
- ai-native userDefine rules that trigger actions automatically on eventsmust-have
- ai-native userPerform bulk operations across many items at onceshould-have
- ai-native userSchedule recurring jobs or workflowsshould-have
- ai-native userVersion, review, and roll back my automationsnice-to-have
Biometric liveness — stories about biometric liveness in this arenaBiometric liveness
Stories about biometric liveness in this arena
- risk analystSelfie checks match the live user to the document portrait with liveness detection — documented defenses against printed photos, screens, and replayed videomust-have
- risk analystThe vendor documents specific defenses against AI-generated faces, deepfakes, and camera-injection attacks — named detection capabilities, not just a marketing mention of fraudshould-have
- risk analystThe platform detects repeat and duplicate identities across verifications — the same face or document resurfacing under different names is flagged automaticallyshould-have
Data checks — stories about data checks in this arenaData checks
Stories about data checks in this arena
- developerVerify identity against authoritative databases without documents — SSN, national registries, or credit-header data — for lower-friction flows where a doc scan is overkillshould-have
- ops leadVerify businesses, not just people — registry lookups, UBO identification, and documented KYB flows that chain into KYC on the ownersshould-have
- developerEnrich verifications with phone, email, and device risk signals — carrier checks, address history, device fingerprint — as additional documented check typesshould-have
Document coverage — stories about document coverage in this arenaDocument coverage
Stories about document coverage in this arena
- ops leadThe platform verifies government IDs from a documented breadth of countries and document types — passports, national IDs, driver licenses, residence permits — with the supported list publishedmust-have
- developerVerified sessions return the extracted document fields as structured data — name, date of birth, document number, address, expiry — retrievable via the API, not just a pass/fail flagshould-have
Idv agent access — stories about idv agent access in this arenaIdv agent access
Stories about idv agent access in this arena
- ai-native userAn agent can operate the verification pipeline — create sessions, poll outcomes, retrieve extracted data, and trigger re-checks through the API or an MCP surface with scoped credentialsmust-have
- ai-native userVerification outcomes come back structured enough for an agent to decide on — machine-readable check results, risk signals, and failure reasons an automated onboarding flow can branch onshould-have
Integration dx — sandboxes, test modes, webhooks, and how fast a developer gets to a working integrationIntegration dx
Sandboxes, test modes, webhooks, and how fast a developer gets to a working integration
- developerA sandbox lets me exercise every outcome before going live — documented test documents, personas, or magic values that deterministically produce pass, fail, and review resultsmust-have
- developerThe whole verification lifecycle is drivable through the API — create a session, get its status, retrieve results and captured media, and cancel or redact it — with every step documentedmust-have
- developerVerification lifecycle events arrive as signed webhooks — created, processing, verified, requires-input — so my system reacts to outcomes without pollingshould-have
Openness — open source, data portability, and self-hosting storiesOpenness
Open source, data portability, and self-hosting stories
- ai-native userExport all of my data in open formats and leavemust-have
- ai-native userSelf-host the core productmust-have
- ai-native userDo everything through the API that I can do in the UIshould-have
- ai-native userRead the product's source under an open licenseshould-have
Privacy posture — data-handling and privacy storiesPrivacy posture
Data-handling and privacy stories
- ai-native userPrevent my data from being used to train AI modelsmust-have
- ai-native userChoose where my data is stored (region/residency)should-have
- ai-native userControl data retention and deletionshould-have
- ai-native userOpt out of telemetry and usage trackingshould-have
Privacy retention — stories about privacy retention in this arenaPrivacy retention
Stories about privacy retention in this arena
- founderThe vendor documents how biometric data is handled lawfully — GDPR bases, US biometric statutes like BIPA, and the consent language my flow needs — so legal review has something to reviewshould-have
- ops leadControl what happens to collected identity data — documented retention windows and a redaction or deletion API that scrubs PII on demandshould-have
Verification flows — stories about verification flows in this arenaVerification flows
Stories about verification flows in this arena
- developerLaunch a complete document-plus-selfie verification with a hosted or drop-in flow — create a session server-side, redirect or embed, and read the result — without building capture UI myselfmust-have
- developerI get native iOS, Android, and web SDKs with guided camera capture — glare, blur, and edge detection coaching the user to a usable document photo on the first tryshould-have
- ops leadSend a verification to someone with a no-code link or QR code — no engineering ticket to verify a one-off customer, contractor, or sellershould-have
- developerA person verified once can be recognized and reused across sessions or products — documented re-verification and reuse of a prior passed check instead of forcing a full re-runshould-have
Verification orchestration — stories about verification orchestration in this arenaVerification orchestration
Stories about verification orchestration in this arena
- ops leadConfigure verification logic without code — conditional steps, risk-based routing, country-specific requirements, and template changes that don't need an engineering deploymust-have
- founderSee verification funnel analytics — pass rates, drop-off points, completion time by country and document type — to know what verification is costing me in signupsshould-have
- ops leadBorderline verifications land in a manual review queue with the full evidence — document images, extracted fields, check results — and reviewer decisions feed back into the recordshould-have
Watchlist screening — stories about watchlist screening in this arenaWatchlist screening
Stories about watchlist screening in this arena
- ops leadScreening is not one-shot — previously verified users are continuously re-screened against watchlist updates, and changes raise events I can act onshould-have
- ops leadScreen verified users against sanctions, PEP, and adverse-media watchlists as part of the same verification — one vendor, one API, one review surfaceshould-have
Appendix: recorded probes
Hands-on probe recordings — transcripts/videos a human can replay, the strongest evidence tier. Watch them at https://ultrametric.ai/productarena/proofs
- Entrust Identity Verification (Onfido)
curl -si https://api.eu.onfido.com/v3.6/applicants | head -2 # Onfido-era API host under Entrust, keyless → 401terminal · recorded 2026-09-15 · exit 0 - Entrust Identity Verification (Onfido)
curl -sL https://documentation.identity.entrust.com/llms.txt | head -3terminal · recorded 2026-09-15 · exit 0 - Persona
curl -si https://api.withpersona.com/api/v1/inquiries | head -3 # keyless → 401terminal · recorded 2026-09-15 · exit 0 - Persona
curl -sL https://docs.withpersona.com/llms.txt | head -3terminal · recorded 2026-09-15 · exit 0 - Persona
curl -s -X POST https://docs.withpersona.com/mcp -H 'Content-Type: application/json' -d '<jsonrpc initialize>' # keyless initialize completes with serverInfoterminal · recorded 2026-09-15 · exit 0 - Plaid Identity Verification
curl -si -X POST https://production.plaid.com/identity_verification/list -H 'Content-Type: application/json' -d '{}' # keyless → 400 naming the missing credentialsterminal · recorded 2026-09-15 · exit 0 - Plaid Identity Verification
curl -sL https://plaid.com/docs/llms.txt | head -3terminal · recorded 2026-09-15 · exit 0 - Stripe Identity
curl -si https://api.stripe.com/v1/identity/verification_sessions | head -4 # Identity sessions API, keyless → 401terminal · recorded 2026-09-15 · exit 0 - Stripe Identity
curl -sL https://docs.stripe.com/llms.txt | head -3terminal · recorded 2026-09-15 · exit 0 - Stripe Identity
curl -s -X POST https://mcp.stripe.com/ -H 'Content-Type: application/json' -d '<jsonrpc initialize>' # the remote MCP server Stripe documents at docs.stripe.com/mcpterminal · recorded 2026-09-15 · exit 0 - Sumsub
curl -s https://api.sumsub.com/resources/applicants/x/one # keyless → 403 "Unauthorized (cfb)", not a plain 401terminal · recorded 2026-09-15 · exit 0 - Sumsub
curl -sL https://docs.sumsub.com/llms.txt | head -3terminal · recorded 2026-09-15 · exit 0 - Sumsub
curl -s -X POST https://docs.sumsub.com/mcp -H 'Content-Type: application/json' -d '<jsonrpc initialize>' # JSON-RPC "Authorization required" authgateterminal · recorded 2026-09-15 · exit 0 - Veriff
curl -si -X POST https://stationapi.veriff.com/v1/sessions -H 'Content-Type: application/json' -d '{}' # keyless → 401terminal · recorded 2026-09-15 · exit 0 - Veriff
curl -sL https://devdocs.veriff.com/llms.txt | head -3terminal · recorded 2026-09-15 · exit 0
Cite as: ProductArena by Ultrametric Inc, Identity Verification & KYC arena, rankings as of 2026-09-15 — https://ultrametric.ai/productarena/arena/identity-verification
License: © 2026 Ultrametric Inc. Brief quotation of individual verdicts, scores, or evidence excerpts is permitted with attribution to "ProductArena by Ultrametric Inc (ultrametric.ai/productarena)", as is use of the data to evaluate, contest, or contribute corrections. Bulk copying, redistribution, or use to build competing datasets requires prior written permission (see DATA-LICENSE in the repository).
No liability: rankings, verdicts, and scores are research outputs derived from the cited evidence at a point in time, provided "as is", without warranties. Ultrametric Inc accepts no responsibility for procurement, purchasing, or other decisions made in reliance on them — verify against the cited evidence before acting (https://ultrametric.ai/productarena/terms).