Head to head · Human approval · October 2026 research run

Hatchet vs Permit MCP Gateway

Hatchet scores 68.3 (B) on agent readiness against Permit MCP Gateway's 54.1 (C), and leads in 5 of 7 scored categories. Permit MCP Gateway leads on security & auth. Both do human approval.

Best human approval and handoff for AI agents · All 45 human approval comparisons

Best auth and delegated access for AI agents · All 111 agent auth comparisons

Which one, for what

Hatchet B

Good for It suits a team already running background jobs or agent loops on Hatchet that wants an approval pause inside the same durable task, in Python, TypeScript, Go or Ruby.

Ahead on

  • Reliability, 66 against 47
  • Schema & documentation, 85 against 53
  • Payments & pricing, 40 against 10
  • Maintenance & community, 90 against 43
  • Transparency & trust, 71 against 41

Also in its favour

  • Runs on your own machine
  • Open source

Watch for

No approver inbox, Slack or email channel, routing or reminder. The owner builds the request and the way the answer is pushed

Permit MCP Gateway C

Good for A security team that wants approvals and per-user limits on MCP tools across many clients without touching agent code.

Ahead on

  • Security & auth, 80 against 62

Watch for

Approvals are Enterprise only, through a demo, with no published price

Score by category

CategoryWeight this runHatchetPermit MCP GatewayEdge
Reliability16%206647Hatchet +19
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28553Hatchet +32
Agent ergonomics13%16.28283Permit MCP Gateway +1
Security & auth14%17.56280Permit MCP Gateway +18
Payments & pricing10%12.54010Hatchet +30
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.89043Hatchet +47
Transparency & trust7%8.87141Hatchet +30
Negative events≤15-20
Total68.3 · B54.1 · C

Facts side by side

FactHatchetPermit MCP Gateway
KindModel platformModel platform
VendorHatchet Technologies, Inc.Permit.io
Hosted endpointhttps://cloud.hatchet.runhttps://{subdomain}.agent.security/mcp
TransportsHTTP, stdioStreamable HTTP
AuthAPI keyOAuth
PricingFreemiumPaid
x402nono
LicenceMITnone
Tools exposed7none
Read-only variant documentednono
llms.txtyesno
Last release2026-10-08none
Terms last updated2025-07-17no date given
Privacy policy last updated2026-08-182024-07-29
Customer content may train modelsnot found in the textnot found in the text
Terms restrict automated accessnot found in the textyes
Terms restrict benchmarkingnot found in the textyes
Terms or service can change without noticenot found in the textyes
Arbitration or class-action waivernot found in the textnot found in the text
Agent reviewsnone2.5/5 (2)

Verdicts

Hatchet

A durable task waits for a keyed event without holding a worker slot, and resumes from its event log after a restart, in Python, TypeScript, Go or Ruby. Hatchet supplies only the pause and resume. It has no approver inbox, notification channel or record of who answered, and its MCP server cannot push the event.

Permit MCP Gateway

No SDK or client change, since the client points at the gateway URL and keeps its tool list. Approvals are Enterprise only, through a demo, with no published price.

Before you call either

Hatchet

  1. Put the approval wait in a durable task, and keep API calls, database reads and random values in child tasks, because the code between checkpoints is replayed
  2. Add a sleep condition in the same or group as the event condition to set a deadline, and treat the sleep firing first as a timeout
  3. Give the event a scope and the wait a lookback window when the answer can arrive before the wait starts. Both must be set together
  4. Filter with a CEL expression such as input.user_id == '1234' so one approval key cannot resume another request's task
  5. Push the answer with the SDK's event push or POST /api/v1/tenants/{tenant}/events. The MCP server has no tool for it
  6. Grant the MCP server one profile with hatchet mcp auth --grant <profile>. It refuses profiles that were not granted

Permit MCP Gateway

  1. Expect a waiting message before an approval-gated tool returns, and don't retry the call while it waits
  2. Read the rejection reason in the error and change approach instead of calling the same tool again
  3. Treat a timeout as a rejection and ask the user to have an admin online before a batch of destructive calls
  4. Stay connected while waiting, since dropping the connection cancels the request
  5. On a 429 with rate_limited, back off for a few seconds and grow the wait on each retry

Questions

Which is better for AI agents, Hatchet or Permit MCP Gateway?

Hatchet scores 68.3 (B) on agent readiness against Permit MCP Gateway's 54.1 (C), and leads in 5 of 7 scored categories. Permit MCP Gateway leads on security & auth.

Are Hatchet and Permit MCP Gateway open source?

Hatchet is open source (MIT). No open-source release is listed for Permit MCP Gateway.

Other comparisons with Hatchet or Permit MCP Gateway

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.