Who Shufti Pro is
Shufti Pro, which now presents itself as Shufti, is an identity verification and AML company founded in 2017, with offices in London, Dubai, Singapore and other cities. Through one API it verifies documents, faces and addresses, screens people and businesses against sanctions, PEP and adverse media data, verifies companies and their owners, and collects electronic signatures.
Its services are built for fintechs, virtual asset service providers and banks, among others, with mobile SDKs and a no-code journey builder next to the API. That breadth, in a single request, is why it is one of the providers our KYC / AML module connects to.
What it does in your platform
KYC / AML
Verifies customers at sign-up with a document and a face check, and runs AML screening in the same request when your licence asks for it. The result lands in the module's review queue, with the reason Shufti gives for any decline.
How the connection works
The KYC / AML module sends verification requests to Shufti's API and receives signed callbacks. Shufti's keys stay in your platform's secrets; your app only receives a one-time access token.
One request
When a customer signs up, the module sends one verification request with the services your setup includes, such as the document, the face and AML screening, and its own reference.
A one-time token
For the apps, the module creates a temporary access token that your app can use once, within the hour. On the web, Shufti returns a verification link instead.
The customer is verified
Shufti's SDK guides the capture on iOS and Android, and in our Flutter apps through Shufti's Flutter plugin; on the web, its hosted verification page does.
A signed callback
Shufti sends the result to the module's callback URL with a signature header, and the module validates it before reading the outcome.
The decision
Accepted customers go ahead and declined ones stop with Shufti's reason. Anything your rules flag goes to the review queue in the backoffice.
Next to other providers
Shufti Pro can run next to other verification providers in the module. Customers are routed by country or risk to the provider that covers them best, with a fallback if a provider is unavailable.
The onboarding screens, the review queue and the audit trail belong to the module. Adding Shufti Pro, or moving away from it later, does not change your apps, and past checks stay linked to the provider that made them.
When Shufti Pro fits best
A strong fit when
- You want identity checks and AML screening in one API request.
- You serve customers in Europe and the UAE, and want a provider with offices in London and Dubai.
- Your apps run on Flutter or React Native, and you want a supported SDK for each.
Also worth a look
- A provider with deeper coverage in a market that matters to you, routed next to Shufti Pro for those customers.
- A dedicated screening provider, if your compliance team wants its own source of sanctions and PEP data.
How we get you live
The contract
We help you get your Shufti Pro account and contract in place, set up for your markets and your licence.
The services
We choose the services with you: which document, face, address and screening checks run, and for which customers.
The keys
The client ID and secret key go into your platform's secrets and nowhere else, and every callback's signature is checked before it is trusted.
A full test run
The whole flow runs with Shufti's test IDs, from sign-up to the review queue, before your first real customer.
