Didit review, pricing and limits

Identity verification, KYB, AML and transaction monitoring an agent can configure and run over a hosted MCP server.

  • integration
  • data
  • automation
  • developer

Choose Didit when an agent should configure and operate identity verification, not just call a check: workflows, review queues, compliance mapping and monitoring are all tools. More than 25 modules are priced publicly and a monthly free allowance covers testing. Keep tool-call review on, because the MCP writes and deletes as you.

Didit is an identity verification platform (KYC, KYB, AML, transaction and wallet monitoring, Travel Rule) that agents operate through mcp.didit.me, a hosted Model Context Protocol server entered by signing in with Didit over OAuth 2.1. Its 156 tools create and review sessions, build and publish workflows, run standalone checks, manage lists and webhooks and read analytics; a REST Sessions API with an x-api-key header serves backends.

Maker: Didit · Protocol: MCP · Auth: oauth

Compatible agents: Claude (web connector, Desktop, Claude Code), Cursor, VS Code, Windsurf, Zed, Any MCP client with OAuth 2.1, Coding agents via the didit-protocol/skills repository and the integration prompt

Required runtime: Any MCP client (Claude web and desktop via custom connector, Claude Code, Cursor, VS Code, Windsurf, Zed); nothing to install for the hosted server, Any HTTP client for the REST API; web and mobile SDKs for the end-user flow, Node or Docker only if you self-host the MCP server

About Didit

Didit is an identity and fraud platform: ID document checks, liveness, face match, proof of address, AML screening, KYB registry lookups, transaction monitoring, wallet screening and Travel Rule messaging, assembled into verification workflows that end users complete through a hosted link or SDK. The product lives at didit.me and business.didit.me; the older didit.co domain now returns an access-denied page. What makes it a skill is the hosted Model Context Protocol server at mcp.didit.me: an agent in Claude, Cursor, VS Code, Windsurf or Zed signs in with Didit by OAuth and can then build a KYC workflow from a prompt, create and review sessions, correct extracted data, back-test transaction rules, manage block and allow lists, register webhooks and read billing, across every organisation and app the user can reach. The server is read-and-write and acts as the signed-in user, not as an application, so the docs ask you to keep tool-call review switched on in your client.

The MCP exposes its tools in groups: discovery and cross-app search, sessions (create, decision, status, data correction, delete, PDF report, reviews, Reusable KYC sharing, bulk import, decision explanation and webhook replay), workflows (linear create, graph build, validate, edit, draft and publish), a compliance assistant that interviews you and generates a multi-country workflow with cited obligations, questionnaires, the standalone verification APIs (ID, proof of address, database validation, KYB search and select, passive liveness, face match and search, age, AML, email and phone codes), transaction monitoring with a rule library and backtests, Travel Rule settings and transfers, vendor users and businesses, lists, cases, reports and webhooks. Every tool carries a scope and role requirement, destructive ones need an explicit confirm, and each returns the verbatim JSON of the underlying endpoint. The server is stateless streamable HTTP with a public health check, and it can be self-hosted. Agents without MCP use the REST API with an x-api-key header: a Sessions API (POST /v3/session/ with a workflow_id creates a verification link and token), standalone server-to-server checks, and a management API for workflows, lists, users, transactions and webhook destinations. A copy-paste integration prompt and a skills repository for coding agents cover the SDK side.

Agent jobs that fit: a founder asking the assistant to stand up a KYC flow with ID scan and liveness and hand back a verification link; an operations agent listing in-review sessions across apps, explaining a decision and approving or declining it; a compliance agent running the interview, generating the workflow graph and checking a published version against obligations; a risk agent screening a wallet and adding it to the blocklist on a hit. On HokAI the nearest skills overlap only at the edges: Hunter and Tomba verify business emails and phones for prospecting rather than identity, Riveter researches companies but does not pull official registries, spicedb-dev covers authorisation once a user is verified, and Composio is where a verified-user event would fan out to other SaaS.

Pricing is public, per module and pay-as-you-go with no minimums or contracts; a free allowance of full KYC checks renews every month and never expires, and the first document checks each month draw on it. A full KYC bundle, which the vendor defines as a document check with liveness, a face comparison and device analysis, has one list price, and more than 25 modules are priced individually, from device analysis at a few cents to AML and proof of address at twenty. Volume discounts apply automatically; Enterprise adds annual committed-volume contracts, data residency and a shared Slack channel. The company announced a $7.5M seed round to build identity and fraud infrastructure.

The documentation is unusually agent-oriented: an llms.txt, a tools reference with scope and role per tool, example agent conversations, a Didit Academy lesson on the MCP, and sandbox scenarios that let create-session calls run without real users. If you are choosing between identity verification, contact verification and authorisation for a product, Smart Match separates them in five questions.

Key Features

  • Scoped MCP tools across the whole platform: Sessions, workflows, compliance assistant, questionnaires, standalone checks, transaction monitoring, Travel Rule, vendor records, list management, case handling, reporting and webhook destinations, each with a scope and role.
  • OAuth only, acting as you: The hosted server is a resource server against the Business Console; there is no API-key mode and nothing lands in client config.
  • Workflows from a prompt or a graph: Linear workflows from a feature list, or full branching graphs built, validated, edited, drafted and published by tool calls.
  • Compliance assistant: An adaptive interview derives your obligations with citations and generates a multi-country workflow, then checks a published version against them.
  • Document coverage claim: The vendor states its ID verification reads documents from more than 220 countries and 14,000-plus document types, including MRZ and barcode, with NFC chip reading as a module.
  • Certified liveness: Passive and active liveness are listed as iBeta Level 1 PAD certified, per the pricing page.
  • Reusable KYC and sandbox scenarios: Verified sessions can be shared across the partner network free, and sandbox slugs replay scripted outcomes without real users.

Use Cases

  • Stand up a KYC flow from a prompt: didit_workflow_create with an ordered feature list (ID verification, passive liveness, face match), then didit_session_create to get a verification URL for the first user.
  • Review queue in chat: didit_session_search for in-review sessions across apps, didit_session_explain_decision on each, then didit_session_update_status to approve or decline with a review note.
  • Compliance-driven workflow design: Answer didit_compliance_interview_next until done, store the profile, generate a multi-country graph and run didit_compliance_check_workflow before publishing.
  • Wallet risk with enforcement: didit_transaction_screen_wallet on an address, and on a hit add it to the blocklist and open a case, all from one agent turn.

Install

https://mcp.didit.me/mcp

Requirements

  • A Didit business account (business.didit.me, free, no card) with at least one application
  • Sign in with Didit (OAuth 2.1) when the MCP client prompts; there is no API-key mode for the MCP and nothing goes into client config
  • Keep tool-call review on in the client: the MCP is read-and-write and acts as you
  • For REST: an application API key from the console, sent as x-api-key from your backend only

Actions

Create Session (REST)

Creates a verification session for a workflow and returns the hosted URL and session token to hand to the end user.

curl -X POST https://verification.didit.me/v3/session/ \
  -H "x-api-key: $DIDIT_API_KEY" -H "Content-Type: application/json" \
  -d '{
    "workflow_id": "5a1c7e9e-0d3b-4a8f-9f2e-6b4c1d2e3f40",
    "vendor_data": "user_8842",
    "callback": "https://app.example.com/verified",
    "language": "en",
    "metadata": {"plan": "pro"}
  }'
  • workflow_id (string) — required: UUID of the workflow that defines the steps; KYC workflows create user sessions, KYB workflows business sessions.
  • vendor_data (string): Your identifier for the person or business; groups sessions and keys user records.
  • callback (string): Redirect after completion; verificationSessionId and status are appended.
  • callback_method (string): initiator or completer: which device receives the redirect.
  • metadata (object): Arbitrary JSON echoed in responses and webhooks.
  • language (string): ISO 639-1 code for the end-user interface.
  • contact_details (object): Email, phone and preferred language for notifications and prefill.
  • expected_details (object): Expected name, date of birth and other fields to cross-check against extracted data.
  • portrait_image (string): Base64 reference portrait (max 2 MB) for biometric authentication workflows.
  • sandbox_scenario (string): Sandbox-only slug that replays a scripted outcome.

didit_context_get

Returns every organisation and application the signed-in user can reach, with defaults; the docs say to call it first.

didit_context_get()

didit_session_create

Creates a verification session for a workflow through the MCP and returns session_id, url and token.

didit_session_create(workflow_id="9b0e4d21-7a5c-4f3e-8d2b-1c6f0a9e7b33", vendor_data="user_8842")
  • workflow_id (string) — required: Workflow to run.
  • vendor_data (string): Your user identifier.

didit_session_search

Searches verification sessions across all apps and organisations, newest first.

didit_session_search(status="In Review", limit=5)
  • status (string): Approved, Declined or In Review.

didit_session_get_decision

Returns the full decision and all extracted data for a session.

didit_session_get_decision(session_id="ses_3f9a")
  • session_id (string) — required: Session to read.

didit_session_explain_decision

Explains why a session ended Approved, Declined or In Review: the deciding feature and each warning that had an effect.

didit_session_explain_decision(session_id="ses_7c1d")
  • session_id (string) — required: Session to explain.

didit_session_update_status

Approves, declines or requests resubmission of a session (destructive; reviewer action).

didit_session_update_status(session_id="ses_9e4b", new_status="Approved", comment="Document glare only; face match 0.97")
  • session_id (string) — required: Session to decide.
  • new_status (string) — required: Approved, Declined or resubmission.

didit_session_delete

Permanently deletes one session with its data and media; needs confirm true.

didit_session_delete(session_id="ses_0b2c", confirm=True)
  • session_id (string) — required: Session to erase.
  • confirm (boolean) — required: Must be true.

didit_session_generate_pdf

Generates a compliance-ready PDF verification report for a session.

didit_session_generate_pdf(session_id="ses_2a6f")
  • session_id (string) — required: Session to report on.

didit_session_share

Shares a verified session with a trusted partner under Reusable KYC.

didit_session_share(session_id="ses_5d8c", partner_org_id="org_partner_17")
  • session_id (string) — required: Verified session to share.

didit_workflow_create

Creates a simple linear workflow from an ordered feature list and publishes it unless status is draft.

didit_workflow_create(label="Signup KYC", features=["ID_VERIFICATION", "PASSIVE_LIVENESS", "FACE_MATCH"], status="draft")
  • features (array) — required: Ordered verification features.
  • status (string): draft to hold publishing.

didit_workflow_build_graph

Builds a complete workflow graph from a plain feature spec without saving.

didit_workflow_build_graph(spec="ID scan, then liveness; if country is DE require proof of address")

didit_workflow_validate_graph

Dry-runs validation of a full workflow graph; saves nothing.

didit_workflow_validate_graph(workflow_id="c3d8f1a0-2e4b-4c6d-9f8a-5b7e2d1c0a44", graph=graph)
  • graph (object) — required: Candidate graph.

didit_workflow_publish

Publishes a workflow's pending draft so new sessions use it (destructive).

didit_workflow_publish(workflow_id="e7a2b5c9-1d3f-4e8a-b6c0-2f9d4a7e1b55")
  • workflow_id (string) — required: Workflow with a draft.

didit_compliance_interview_next

Returns the next question of the adaptive compliance interview, or done.

didit_compliance_interview_next(answers={"industry": "crypto_exchange", "countries": ["SG", "DE"]})
  • answers (object): Every answer so far.

didit_compliance_generate_workflow

Generates a multi-country workflow graph from the stored compliance profile: a common trunk plus per-country branches.

didit_compliance_generate_workflow()

didit_compliance_check_workflow

Checks which regulatory obligations a workflow version satisfies or violates, with citations.

didit_compliance_check_workflow(workflow_id="a1f6c3e8-9b2d-4a7f-8e5c-3d0b6f2a9c66")
  • workflow_id (string) — required: Workflow to audit.

didit_verify_id

Verifies an identity document from its front and optional back image (standalone, no session).

didit_verify_id(front_image=front_b64, back_image=back_b64)
  • front_image (string) — required: Document front.
  • back_image (string): Document back.

didit_verify_aml

Screens a name against sanctions, PEP and watchlists, optionally adverse media.

didit_verify_aml(full_name="Maya Rivera", date_of_birth="1988-04-02", nationality="ES")
  • full_name (string) — required: Name to screen.

didit_verify_kyb_search

Searches official company registries by name or registration number and returns candidates for didit_verify_kyb_select.

didit_verify_kyb_search(country="SG", query="Grab Holdings")
  • country (string) — required: Registry country.
  • query (string) — required: Name or registration number.

didit_verify_face_match

Compares two facial images one to one.

didit_verify_face_match(image_a=selfie_b64, image_b=document_portrait_b64)
  • image_a (string) — required: First face.
  • image_b (string) — required: Second face.

didit_transaction_screen_wallet

Screens a crypto wallet address for AML risk without creating a transaction.

didit_transaction_screen_wallet(address="0x4b7f...e21c", network="ethereum")
  • address (string) — required: Wallet address.

didit_transaction_rule_backtest

Dry-runs a hypothetical monitoring rule against up to the 10,000 most recent transactions; writes nothing.

didit_transaction_rule_backtest(rule={"condition": "amount > 9000 AND currency == \"USD\"", "window": "24h"})
  • rule (object) — required: Rule definition to test.

didit_vendor_user_update_status

Sets an end user's status to ACTIVE, FLAGGED or BLOCKED.

didit_vendor_user_update_status(vendor_data="user_8842", status="BLOCKED")
  • vendor_data (string) — required: Your user identifier.
  • status (string) — required: ACTIVE, FLAGGED or BLOCKED.

didit_analytics

Aggregates request breakdown, feature funnel and conversion rate for a date window across all apps.

didit_analytics(start="2026-09-26", end="2026-10-10")
  • start (string) — required: Window start.
  • end (string) — required: Window end.

How to Invoke

Hosted MCP server at https://mcp.didit.me/mcp (stateless streamable HTTP, OAuth 2.1 with PKCE against the Business Console; no API-key mode; self-hostable) exposing 156 scoped tools; or REST at api.didit.me with an x-api-key header: Sessions API (/v3/session/), standalone checks (/v3/id-verification/, /v3/aml/, /v3/face-match/ and others) and the management API.

Pricing

Public per-module prices, no minimums or contracts (didit.me/pricing, read 11 October 2026). Free: $0, no card, 500 full KYC verifications every month forever, workflow builder, case management, SDKs. Pay as you go after the allowance: full KYC bundle (ID verification, passive liveness, face match, device and IP) $0.33; ID verification $0.15; NFC chip read $0.15; proof of address $0.20; Document AI $0.20 per document; passive liveness $0.10; active liveness $0.15; face match $0.05; face search free; biometric authentication $0.10; age estimation $0.10; AML screening $0.20; ongoing AML monitoring $0.07 per user per year; device and IP $0.03; email verification $0.03; phone verification from $0.03; company and person AML $0.20 each; KYB document step $0.20, registry retrieval variable by country; transaction monitoring and Travel Rule $0.02 per transaction; wallet screening $0.15; white-label flow $0.20; Reusable KYC free. Volume discounts apply automatically. Enterprise: annual committed-volume contract, data residency, 24/7 support. The standalone server-to-server endpoints are listed with their own prices in the docs index.

Strengths

  • Every module price is on one public page, and the free allowance of full KYC checks renews monthly without expiry.
  • The MCP acts across all your organisations and apps at once, so one agent can review queues and billing everywhere.
  • Destructive tools require confirm and each tool declares its scope and role, which makes agent permissions auditable.

Weaknesses

  • The MCP has no API-key mode, so headless or service-account automation must use the REST API or a self-hosted server with a user token.
  • Rate limits are not published on the pages read, and a surface of well over a hundred tools is heavy for clients that load every tool into context.
  • KYB registry pricing is variable by country and marked as a staging catalogue, so KYB costs need a quote-like check before launch.

Frequently Asked Questions

What does Didit charge per check, and what is free?

Every account gets 500 full KYC verifications a month free, forever, with no card. Beyond that a full KYC bundle is $0.33, and modules are priced individually: ID verification $0.15, passive liveness $0.10, face match $0.05, proof of address and AML screening $0.20 each, device and IP analysis $0.03, transaction monitoring $0.02 per transaction and wallet screening $0.15. Discounts apply by volume and Enterprise moves to an annual contract.

How does an assistant connect to Didit?

Add the hosted server URL as a custom connector or MCP server in the client; Claude for web has a pre-filled connector link. The client opens a browser where you log in with Didit and approve the scopes, and from then on the tools run under your console account and roles. There is deliberately no API-key mode for the MCP; backends use the REST API with x-api-key instead.

Which agents and clients does Didit support?

The docs cover Claude (web, Desktop, Claude Code), Cursor, VS Code, Windsurf and Zed, and any MCP client that supports streamable HTTP with OAuth and PKCE. A skills repository and a copy-paste integration prompt help coding agents implement the SDKs, and the server can be self-hosted for stdio clients with a user token.

When is a different verification skill the better choice?

If you only need to know that a business email or phone number is real and deliverable for sales outreach, Hunter or Tomba do that in one call without onboarding a person. If you need company research rather than official registry records, Riveter is the fit. Didit is for regulated identity: documents, biometrics, sanctions and monitoring.

Didit or Hunter when a product needs to verify people?

They verify different things. Hunter confirms that a professional address exists and will deliver, which is a prospecting question. Didit confirms who a person is: a government document, a live face that matches it, a clean sanctions screen and, if you want, ongoing monitoring, with a decision you can approve or decline and a PDF report for auditors. Products that onboard customers under KYC rules need Didit; products that send cold email need Hunter.

Top Alternatives

  • Hunter: Hunter verifies a business email for outreach; Didit verifies the person behind it for regulatory onboarding, with documents, liveness and AML.
  • Tomba: Tomba's email and phone validation checks deliverability; Didit's email and phone modules confirm ownership with one-time codes as part of a KYC flow.

More Agent Skills on HokAI

View the official Didit skill page