Affinity
Search your CRM, prep for meetings and update deal records from your AI assistant.
Read KYC/AML verification data and create applicants from an AI agent.
Opens Agent Studio, where connecting is one click. The connector URL below works in any MCP client.
Paste it into any MCP client. Setup docs
The Sumsub MCP server connects a Sumsub account — a KYC, KYB and AML identity-verification platform — to Claude, ChatGPT and any MCP-compatible agent. Anthropic's directory lists 18 tools that read applicants, transactions, AML cases and fraud networks, and create applicants and verification links. Sign-in is OAuth behind a single scope.
Verified connector
Listed by Anthropic as a partner connector in its Connectors Directory.
Connection checked by Agentman on .
Anthropic states this reflects the level of review a connector received, not a security audit.
Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.
mcp names no object and no verb. Nothing at the grant separates reading an AML case from creating an applicant, and a future tool added to the server falls inside the same consent already given.applicant_moderation_state_list — is not in Anthropic's listing at all.how_to_sumsub, whose behaviour we could not characterise.xClientId values are API, Dashboard and SDK. You may not be able to separate agent actions from human ones.applicant_fraud_network_list may return nothing on an account without it.No tool among the 18 Anthropic lists carries an approve, reject, decline or reset verb. Sumsub's platform does support manual approval and rejection, but through the Dashboard and API endpoints that have no counterpart in this listing. The connector can read a verification verdict and create new applicants; it cannot change an existing applicant's status.
Identity document extractions, AML screening hits and fraud-network links about named people. Sumsub's applicant data response includes idDocs fields carrying first, middle and last names, issuing authority, issue and expiry dates, plus nfcInfo, beneficiaries and questionnaire answers. This is among the most sensitive personal data any connector in the directory reaches.
Not through any listed tool. The 18 names include no image, document-download or file-fetch verb, and applicant_get maps to Sumsub's applicant data endpoint, which returns structured fields extracted from documents rather than the scans themselves. Sumsub's separate document-image endpoints have no counterpart in this listing.
Two of the three write tools can start a billable check. Sumsub's published pricing is 1.35 to 1.85 US dollars per verification depending on plan, and its billing documentation states checks appear on the Billing page the following day, not the day they run. No tool in the listing reports balance, usage or cost.
Sumsub operates an audit trail API, but it is sold at additional cost and its documentation does not name MCP as a source. The event fields include an xClientId describing the source of an action, documented with the values API, Dashboard or SDK. Whether MCP calls appear, and under which value, is not documented.
One, and it names no object and no verb. The server's RFC 9728 descriptor advertised scopes_supported of exactly mcp on 2026-08-23. A single unqualified scope cannot separate reading an applicant from creating one, so consent is all-or-nothing across the whole tool surface.
A Dashboard role permission called Use MCP server, plus the role's existing permissions. Sumsub documents that the agent performs the actions allowed by your Sumsub role permissions, so the connector inherits rather than widens your access. The permission sits in the Manage group alongside managing dashboard users and application tokens.
We could not establish that it does, and the parameter is worth knowing about. verification_link_create maps to Sumsub's external WebSDK link endpoint, whose request body accepts applicantIdentifiers containing an email address and phone number. Sumsub's MCP documentation describes generating a link, not delivering it, and does not say whether supplying those identifiers triggers a message.
.md suffix the host advertises). docs.sumsub.com/robots.txt allows this path; the site's llms.txt names this as its only MCP page. · retrieved 2026-08-23llms.txt (retrieved 2026-08-23) · retrieved 2026-08-23initialize returned HTTP 401 "Authentication required"; RFC 9728 metadata at https://api.sumsub.com/.well-known/oauth-protected-resource/mcp; authorization server metadata at https://cockpit.sumsub.com/resources/api/oauth/.well-known/openid-configuration (2026-08-23) · retrieved 2026-08-23Connect Sumsub once and your agents call these tools on their own: on a schedule, in a workflow, with nobody at the keyboard.