Now available

Connect AI agents to your KYC ops.

Verifa's MCP server lets Claude, Cursor, and any other agent that speaks the open Model Context Protocol work directly in your account — list sessions, review cases, manage screening, even handle compliance redactions — through structured tools, not LLM-generated cURL.

Start Building Free Read the Docs
45
tools
8
toolsets
4
safeguards for destructive ops
0
new credentials to provision

What your agent can actually do.

45 structured tools across eight toolsets — every action your reviewers take from the dashboard, plus the read paths your data engineers usually script against the REST API. Tools are grouped so you can hand an agent exactly the surface it needs and nothing more, set with one URL flag at connect time.

Organization

3 tools

Identify the calling key, list API keys, fetch usage stats.

Sessions

5 tools

List, fetch, follow event timelines, create new sessions, reprocess terminal ones.

Identities

5 tools

Search verified identities, fetch one by id or external ref, manage tags.

Cases

10 tools

Review queue read + claim, assign, comment, approve, reject, escalate.

Findings

4 tools

List Smart QA findings, acknowledge or dismiss with audit-recorded reason.

Checks

4 tools

Screening checks (AML, IP / phone / email risk) — list, drill into hits, rerun.

Workflows

3 tools

List workflow definitions, fetch one, trigger a re-run against a session.

Lists & Blocklist

6 tools

Screening lists, list items, the auto-deny blocklist — list, add, remove.

Destructive (opt-in only)

5 tools · off by default

Permanent deletions for GDPR right-to-erasure: redact session, redact identity, bulk redact, delete blocklist entry, revoke session link. Hidden from agents unless the connection URL explicitly names this toolset — and even then, gated by four independent safeguards.

One command. No new credentials.

The MCP server speaks the open Streamable HTTP transport at https://api.withverifa.com/mcp and authenticates via your existing API keys. Connect Claude Code in one line:

terminal
# Connect Claude Code to your Verifa account
claude mcp add --transport http verifa \
  "https://api.withverifa.com/mcp?toolsets=cases,findings&read_only=true" \
  --header "Authorization: Bearer vk_live_your_key"

Snippets for Cursor, Claude Desktop, and the Anthropic API connector are in the docs and on the in-app AI Integrations page.

Built for compliance from day one.

Agents get powerful, but they also get scoped, throttled, and audited. The five destructive tools sit behind four independent safeguards — every one of which must pass before a single redaction or blocklist delete can fire.

SAFEGUARD 01

Scope inheritance

The agent uses your normal API keys — same prefix, same hash verification, same expiry / IP allowlist / subscription gate. Per-tool scope checks reuse the existing vocabulary; destructive operations require a separate destructive:write scope that's never on by default and never available on publishable keys.

SAFEGUARD 02

Opt-in toolset

The destructive toolset is hidden from tools/list unless the connection URL explicitly names it (?toolsets=…,destructive). Read-only mode (?read_only=true) hides every write tool in one flag, regardless of the API key's grants.

SAFEGUARD 03

Per-key circuit breaker

Every MCP request burns one slot in a 120-requests / minute bucket separate from your REST quota. Destructive operations get a second, tighter cap: 5 per hour per key. A runaway agent can't burn either your billing or your compliance posture.

SAFEGUARD 04

Every call audited

Every tool invocation writes an mcp.<resource>.<verb> row to your audit log with the actor key, the input arguments (PII-scrubbed), and the outcome. Destructive tools additionally require a 10-character reason recorded in the same row. Filter to "MCP only" in the dashboard or via ?action_prefix=mcp on the events API.

PII-free by default.

REST gates sensitive-data access with cookie-bound user tokens and a per-route access-window check. MCP has only API-key auth — no per-end-user consent attestation flows through it — so the agent-facing surface starts from a more conservative posture: identifiers and metadata yes, PII no.

If a future MCP tool needs to return PII to the agent, the rules are written down: a dedicated pii:read scope (not reused from any existing *:read), a mandatory call to the access-window helper, a tighter rate-limit bucket than the default 120/min, and field-by-field disclosure in the integration guide.

Two related caveats:

Try it in five minutes.

Create a free Verifa account, mint a sandbox API key, and have Claude Code triaging your review queue before the kettle boils.