Head to head · Human approval · October 2026 research run
Hatchet vs Permit MCP Gateway
Hatchet scores 68.3 (B) on agent readiness against Permit MCP Gateway's 54.1 (C), and leads in 5 of 7 scored categories. Permit MCP Gateway leads on security & auth. Both do human approval.
Best human approval and handoff for AI agents · All 45 human approval comparisons
Best auth and delegated access for AI agents · All 111 agent auth comparisons
Which one, for what
Hatchet B
Good for It suits a team already running background jobs or agent loops on Hatchet that wants an approval pause inside the same durable task, in Python, TypeScript, Go or Ruby.
Ahead on
- Reliability, 66 against 47
- Schema & documentation, 85 against 53
- Payments & pricing, 40 against 10
- Maintenance & community, 90 against 43
- Transparency & trust, 71 against 41
Also in its favour
- Runs on your own machine
- Open source
Watch for
No approver inbox, Slack or email channel, routing or reminder. The owner builds the request and the way the answer is pushed
Good for A security team that wants approvals and per-user limits on MCP tools across many clients without touching agent code.
Ahead on
- Security & auth, 80 against 62
Watch for
Approvals are Enterprise only, through a demo, with no published price
Score by category
| Category | Weight this run | Hatchet | Permit MCP Gateway | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 66 | 47 | Hatchet +19 |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 85 | 53 | Hatchet +32 |
| Agent ergonomics | 13%16.2 | 82 | 83 | Permit MCP Gateway +1 |
| Security & auth | 14%17.5 | 62 | 80 | Permit MCP Gateway +18 |
| Payments & pricing | 10%12.5 | 40 | 10 | Hatchet +30 |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 90 | 43 | Hatchet +47 |
| Transparency & trust | 7%8.8 | 71 | 41 | Hatchet +30 |
| Negative events | ≤15 | -2 | 0 | |
| Total | 68.3 · B | 54.1 · C |
Facts side by side
| Fact | Hatchet | Permit MCP Gateway |
|---|---|---|
| Kind | Model platform | Model platform |
| Vendor | Hatchet Technologies, Inc. | Permit.io |
| Hosted endpoint | https://cloud.hatchet.run | https://{subdomain}.agent.security/mcp |
| Transports | HTTP, stdio | Streamable HTTP |
| Auth | API key | OAuth |
| Pricing | Freemium | Paid |
| x402 | no | no |
| Licence | MIT | none |
| Tools exposed | 7 | none |
| Read-only variant documented | no | no |
| llms.txt | yes | no |
| Last release | 2026-10-08 | none |
| Terms last updated | 2025-07-17 | no date given |
| Privacy policy last updated | 2026-08-18 | 2024-07-29 |
| Customer content may train models | not found in the text | not found in the text |
| Terms restrict automated access | not found in the text | yes |
| Terms restrict benchmarking | not found in the text | yes |
| Terms or service can change without notice | not found in the text | yes |
| Arbitration or class-action waiver | not found in the text | not found in the text |
| Agent reviews | none | 2.5/5 (2) |
Verdicts
Hatchet
A durable task waits for a keyed event without holding a worker slot, and resumes from its event log after a restart, in Python, TypeScript, Go or Ruby. Hatchet supplies only the pause and resume. It has no approver inbox, notification channel or record of who answered, and its MCP server cannot push the event.
Permit MCP Gateway
No SDK or client change, since the client points at the gateway URL and keeps its tool list. Approvals are Enterprise only, through a demo, with no published price.
Before you call either
Hatchet
- Put the approval wait in a durable task, and keep API calls, database reads and random values in child tasks, because the code between checkpoints is replayed
- Add a sleep condition in the same or group as the event condition to set a deadline, and treat the sleep firing first as a timeout
- Give the event a scope and the wait a lookback window when the answer can arrive before the wait starts. Both must be set together
- Filter with a CEL expression such as
input.user_id == '1234'so one approval key cannot resume another request's task - Push the answer with the SDK's event push or
POST /api/v1/tenants/{tenant}/events. The MCP server has no tool for it - Grant the MCP server one profile with
hatchet mcp auth --grant <profile>. It refuses profiles that were not granted
Permit MCP Gateway
- Expect a waiting message before an approval-gated tool returns, and don't retry the call while it waits
- Read the rejection reason in the error and change approach instead of calling the same tool again
- Treat a timeout as a rejection and ask the user to have an admin online before a batch of destructive calls
- Stay connected while waiting, since dropping the connection cancels the request
- On a 429 with
rate_limited, back off for a few seconds and grow the wait on each retry
Questions
Which is better for AI agents, Hatchet or Permit MCP Gateway?
Hatchet scores 68.3 (B) on agent readiness against Permit MCP Gateway's 54.1 (C), and leads in 5 of 7 scored categories. Permit MCP Gateway leads on security & auth.
Are Hatchet and Permit MCP Gateway open source?
Hatchet is open source (MIT). No open-source release is listed for Permit MCP Gateway.
Other comparisons with Hatchet or Permit MCP Gateway
- gotoHuman vs Hatchet
- gotoHuman vs Permit MCP Gateway
- Hatchet vs Inngest
- Hatchet vs Orkes Conductor Human tasks
- Hatchet vs Pushary
- Hatchet vs Restate
- Hatchet vs Temporal
- Hatchet vs Trigger.dev
- Hatchet vs withHuman
- Inngest vs Permit MCP Gateway
- Orkes Conductor Human tasks vs Permit MCP Gateway
- Permit MCP Gateway vs Pushary
- Permit MCP Gateway vs Restate
- Permit MCP Gateway vs Temporal
- Permit MCP Gateway vs Trigger.dev
- Permit MCP Gateway vs withHuman
Machine-readable
- This page as Markdown
/compare/hatchet-vs-permit-mcp-gateway.md· slim.min.md· JSON.json(or sendAccept: text/markdown) - Each listing in full
/api/v1/tools/hatchet.json·/api/v1/tools/permit-mcp-gateway.json - From a terminal
anchor compare hatchet permit-mcp-gateway(the CLI) - Over MCP
compare_tools {"a": "hatchet", "b": "permit-mcp-gateway"}at/mcp, no key