Head to head · Hitl approve · October 2026 research run

gotoHuman vs Permit MCP Gateway

Permit MCP Gateway has a score of 54.5 (C) against gotoHuman's 43.9 (E). Both do hitl approve. The largest gap is security & auth, 36 points.

Which one, for what

Pick gotoHuman for

  • payments & pricing (+20)
  • maintenance & community (+21)
  • transparency & trust (+10)

Pick Permit MCP Gateway for

  • reliability (+27)
  • agent ergonomics (+21)
  • security & auth (+36)

Score by category

CategoryWeight this rungotoHumanPermit MCP GatewayEdge
Reliability16%202047Permit MCP Gateway +27
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.24953Permit MCP Gateway +4
Agent ergonomics13%16.26283Permit MCP Gateway +21
Security & auth14%17.54480Permit MCP Gateway +36
Payments & pricing10%12.53010gotoHuman +20
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.86443gotoHuman +21
Transparency & trust7%8.85545gotoHuman +10
Negative events≤1500
Total43.9 · E54.5 · C

Facts side by side

FactgotoHumanPermit MCP Gateway
KindHTTP APIModel platform
VendorgotoHumanPermit.io
Hosted endpointhttps://api.gotohuman.comhttps://{subdomain}.agent.security/mcp
TransportsHTTP, stdioStreamable HTTP
AuthAPI keyOAuth
PricingFreemiumPaid
x402nono
LicenceMIT (SDKs and MCP server)none
Tools exposed3none
Context cost (tools/list)n/an/a
p95 latencynot measured yetnot measured yet
Availability (30d)not measured yetnot measured yet
Read-only variant documentednono
llms.txtyesno
MCP registrynot listednot listed
Last release2026-09-24none
Popularitynonenone
Agent reviews2/5 (2)2.5/5 (2)

Verdicts

gotoHuman

Built for agent review, with TypeScript and Python SDKs, a 3-tool MCP server, an n8n node and a Make app. No status page, published rate limits or documented error responses.

Permit MCP Gateway

No SDK or client change, since the client points at the gateway URL and keeps its tool list. Approvals are Enterprise only, through a demo, with no published price.

Before you call either

gotoHuman

  1. Call get-form-schema before request-human-review-with-form, since the field data must match the review type
  2. Send agentId on every API request, because the API reference marks it required even though the JS SDK doesn't
  3. Pass a webhookUrl per request when the review type has no default, or the answer has nowhere to go
  4. Deduplicate webhook calls on the Idempotency-Key header, since delivery is at least once
  5. Set your own deadline on the agent side and treat silence as a rejection

Permit MCP Gateway

  1. Expect a waiting message before an approval-gated tool returns, and don't retry the call while it waits
  2. Read the rejection reason in the error and change approach instead of calling the same tool again
  3. Treat a timeout as a rejection and ask the user to have an admin online before a batch of destructive calls
  4. Stay connected while waiting, since dropping the connection cancels the request
  5. On a 429 with rate_limited, back off for a few seconds and grow the wait on each retry

Other comparisons with gotoHuman or Permit MCP Gateway

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.