{
  "data": {
    "a": {
      "slug": "hatchet",
      "name": "Hatchet",
      "vendor": "Hatchet Technologies, Inc.",
      "vendorUrl": "https://hatchet.run",
      "kind": "platform",
      "category": "human-in-the-loop",
      "summary": "Hatchet is an open-source (MIT) platform for durable tasks, queues and workflows, sold as Hatchet Cloud or self-hosted. A durable task can pause until an event arrives, which is its building block for human approval steps.",
      "url": "https://www.anchorterminal.com/tools/hatchet",
      "markdownUrl": "https://www.anchorterminal.com/tools/hatchet.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/hatchet.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/hatchet.json",
      "repo": "https://github.com/hatchet-dev/hatchet",
      "license": "MIT",
      "transports": [
        "http",
        "stdio"
      ],
      "remoteUrl": "https://cloud.hatchet.run",
      "packages": [
        {
          "registry": "pypi",
          "name": "hatchet-sdk"
        },
        {
          "registry": "npm",
          "name": "@hatchet-dev/typescript-sdk"
        },
        {
          "registry": "go",
          "name": "github.com/hatchet-dev/hatchet"
        }
      ],
      "auth": "api-key",
      "authNotes": "Self-serve. A person signs up at cloud.hatchet.run and creates an API token in Settings, scoped to one tenant with a configurable expiry. SDK clients, workers and the REST API send it as a Bearer token. The MCP server reads tokens from CLI profiles the user granted. Embedded mode runs a local engine with no token.",
      "pricing": "freemium",
      "pricingNotes": "Hatchet Cloud is pay as you go from $0, and the plan without a card includes 1 million runs and 1 million events a month, capped at 2,000 of each a day, so an agent's owner can start without a contract. Beyond that, $30 per million runs and $5 per million events. Enterprise is priced by sales. Self-hosting is free under MIT (https://hatchet.run/pricing).",
      "priceSummary": "$0.03 / 1k calls",
      "where": "both",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs index, the OpenAPI file or the pricing page (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": 7,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://docs.hatchet.run/v1/durable-event-waits",
      "llmsTxt": "https://docs.hatchet.run/llms.txt",
      "openapi": "https://github.com/hatchet-dev/hatchet/blob/main/api-contracts/openapi/openapi.yaml",
      "capabilities": [
        "hitl.approve",
        "hitl.ask",
        "agent.durable",
        "automation.workflows",
        "automation.code"
      ],
      "tags": [
        "hosted",
        "self-hosted",
        "open-source",
        "freemium",
        "free-tier",
        "mcp",
        "openapi",
        "llms-txt",
        "python",
        "typescript",
        "go",
        "durable",
        "webhooks",
        "idempotency",
        "hipaa"
      ],
      "lastRelease": "2026-10-08",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 68.3,
        "grade": "B",
        "agentReady": false,
        "rank": 225,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 4,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 82,
          "maintenance": 90,
          "payments": 40,
          "reliability": 66,
          "schema": 85,
          "security": 62,
          "transparency": 71
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": -2,
        "negativeNotes": [
          "Published 4 September 2026, -2. GHSA-992g-9cr3-vm5x (CVE-2026-88978), Moderate, CVSS 3.1 AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N. The `DurableTask` worker status path looked up durable event log entries by a caller-supplied task UUID with no tenant filter, so a holder of any tenant's token who knew another tenant's task UUID could read its entries. The advisory names Hatchet Cloud as affected and calls exploitation very unlikely because the IDs are random UUIDs. Fixed in 0.106.1. It is the event log this listing is graded on, so 2 points for a fixed path. https://github.com/hatchet-dev/hatchet/security/advisories/GHSA-992g-9cr3-vm5x (read through https://api.osv.dev/v1/vulns/GHSA-992g-9cr3-vm5x)",
          "Not deducted. GHSA-hf2m-86fv-rjw5, fixed in v0.110.5 on 5 October 2026, enforced payload visibility restrictions on endpoints that had returned payload data. The OSV mirror answered 404 for it, so its severity was not read. https://github.com/hatchet-dev/hatchet/blob/main/CHANGELOG.md"
        ],
        "verdict": "A durable task waits for a keyed event without holding a worker slot, and resumes from its event log after a restart, in Python, TypeScript, Go or Ruby. Hatchet supplies only the pause and resume. It has no approver inbox, notification channel or record of who answered, and its MCP server cannot push the event.",
        "bestFor": "It suits a team already running background jobs or agent loops on Hatchet that wants an approval pause inside the same durable task, in Python, TypeScript, Go or Ruby.",
        "strengths": [
          "A durable task waiting on an event is evicted from its worker slot and resumes from the durable event log after a restart or crash",
          "Events can be filtered with a CEL expression, and a scope with a lookback window catches an answer pushed before the wait began",
          "MIT licence, self-hostable, with SDKs for Python (1.41.1), TypeScript (1.36.0), Go and Ruby (0.9.0)",
          "Pay-as-you-go cloud plan starts at $0 without a card, with 1 million runs and 1 million events a month included, per the pricing page",
          "Platform release v0.110.19 on 8 October 2026, with dated changelogs for the platform and each SDK"
        ],
        "weaknesses": [
          "No approver inbox, Slack or email channel, routing or reminder. The owner builds the request and the way the answer is pushed",
          "An event wait has no timeout of its own. A deadline needs a sleep condition in the same or group",
          "API tokens are scoped to a tenant with an expiry, with no narrower scopes, and the role and payload restrictions do not apply to them",
          "Audit logs are for Business plans and above, kept 30 days, and the documented actions do not include event pushes",
          "The seven MCP tools trigger, inspect and replay runs. None pushes an event, and none sets a read-only or destructive annotation",
          "The standard terms the cloud agreement incorporates forbid security or vulnerability tests of the product. This matters before any probe is run"
        ],
        "agentNotes": [
          "Put the approval wait in a durable task, and keep API calls, database reads and random values in child tasks, because the code between checkpoints is replayed",
          "Add a sleep condition in the same or group as the event condition to set a deadline, and treat the sleep firing first as a timeout",
          "Give the event a scope and the wait a lookback window when the answer can arrive before the wait starts. Both must be set together",
          "Filter with a CEL expression such as `input.user_id == '1234'` so one approval key cannot resume another request's task",
          "Push the answer with the SDK's event push or `POST /api/v1/tenants/{tenant}/events`. The MCP server has no tool for it",
          "Grant the MCP server one profile with `hatchet mcp auth --grant \u003cprofile\u003e`. It refuses profiles that were not granted"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 68.3
          }
        ],
        "editorialScores": {
          "ergonomics": 82,
          "maintenance": 90,
          "payments": 40,
          "reliability": 66,
          "schema": 85,
          "security": 62,
          "transparency": 69
        },
        "provenanceScore": 72
      },
      "connect": {
        "install": "pip install hatchet-sdk",
        "claudeCode": "hatchet mcp install --target claude-code",
        "config": {
          "mcpServers": {
            "hatchet": {
              "args": [
                "mcp",
                "serve"
              ],
              "command": "hatchet"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/hitl.approve",
        "tool": "https://letme.dev/hatchet"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Task runs after the first 1 million a month",
          "unit": "1k-calls",
          "usd": 0.03,
          "note": "$30 per million runs. A failed run is billed, retries are not"
        },
        {
          "item": "Events after the first 1 million a month",
          "unit": "1k-calls",
          "usd": 0.005,
          "note": "$5 per million events"
        },
        {
          "item": "Extra user beyond 50 (card on file)",
          "unit": "seat-month",
          "usd": 10
        }
      ],
      "provenance": {
        "legalEntity": "Hatchet Technologies, Inc.",
        "domain": "hatchet.run",
        "domainRegistered": "",
        "endpointOnVendorDomain": true,
        "terms": "https://hatchet.run/policies/terms",
        "privacy": "https://hatchet.run/policies/privacy",
        "statusPage": "https://status.hatchet.run",
        "changelog": "https://docs.hatchet.run/reference/changelog",
        "securityTxt": "none",
        "checked": "2026-10-09",
        "notes": [
          "The terms page is a Common Paper Cloud Service Agreement cover page for Hatchet Technologies, Inc., last updated 17 July 2025, governed by Delaware law, incorporating Standard Terms Version 2.1 at commonpaper.com.",
          "The privacy policy was last updated 18 August 2026, covers workflow data and API usage data, and names an EU representative in Ireland.",
          "hatchet.run/.well-known/security.txt answered 404. SECURITY.md in the repository takes reports through private GitHub advisories or security@hatchet.run and says there is no bug bounty.",
          "The dashboard and API are at cloud.hatchet.run. The webhook docs show incoming webhook URLs on cloud.onhatchet.run, a second domain.",
          "status.hatchet.run runs on Better Stack with three components. Its robots.txt answered 200 with an empty body.",
          "The repository's licence file is MIT, copyright 2023 to present Hatchet Technologies Inc.",
          "The domain's registration date was not looked up."
        ],
        "score": 72
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/hatchet.json",
      "live": {
        "slug": "hatchet",
        "probe": {
          "target": "https://cloud.hatchet.run",
          "method": "get",
          "lastAt": "2026-10-10T03:53:29.434213268Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 656,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 681,
          "p95ms24h": 1623,
          "samples24h": 125,
          "samples30d": 125,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 85,
              "ok": 85
            },
            {
              "date": "2026-10-10",
              "probes": 40,
              "ok": 40
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.hatchet.run",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-10T00:50:40.047363861Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "hatchet-dev/hatchet",
            "version": "v0.110.5",
            "released": "2026-10-06",
            "seenAt": "2026-10-09T16:57:30.943852136Z"
          },
          {
            "registry": "npm",
            "name": "@hatchet-dev/typescript-sdk",
            "version": "1.36.0",
            "seenAt": "2026-10-09T16:57:29.775672491Z"
          },
          {
            "registry": "pypi",
            "name": "hatchet-sdk",
            "version": "1.41.1",
            "released": "2026-09-24",
            "seenAt": "2026-10-09T16:57:29.581369924Z"
          }
        ],
        "githubStars": 8088,
        "npmWeekly": 300149,
        "pypiWeekly": 392095,
        "pages": [
          {
            "url": "https://docs.hatchet.run/reference/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:37:27.789775482Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "f6e9eec278c6"
          },
          {
            "url": "https://hatchet.run/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-09T18:40:07.756761277Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "3096d0aaa49f"
          },
          {
            "url": "https://hatchet.run/policies/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-09T18:40:03.629481363Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "1926d0170834"
          },
          {
            "url": "https://hatchet.run/policies/terms",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-09T18:40:05.775842594Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "22e8ffadb15d"
          }
        ],
        "updatedAt": "2026-10-10T03:53:29.434213268Z"
      }
    },
    "answer": "Hatchet scores 68.3 (B) on agent readiness against Permit MCP Gateway's 54.1 (C), and leads in 5 of 7 scored categories. Permit MCP Gateway leads on security \u0026 auth.",
    "b": {
      "slug": "permit-mcp-gateway",
      "name": "Permit MCP Gateway",
      "vendor": "Permit.io",
      "vendorUrl": "https://www.permit.io/mcp-gateway",
      "kind": "platform",
      "category": "human-in-the-loop",
      "summary": "Hosted proxy between MCP clients and MCP servers that signs in the human behind the agent, checks each tool call against Permit.io policy and logs it.",
      "url": "https://www.anchorterminal.com/tools/permit-mcp-gateway",
      "markdownUrl": "https://www.anchorterminal.com/tools/permit-mcp-gateway.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/permit-mcp-gateway.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/permit-mcp-gateway.json",
      "transports": [
        "streamable-http"
      ],
      "remoteUrl": "https://{subdomain}.agent.security/mcp",
      "packages": [],
      "auth": "oauth",
      "authNotes": "The gateway is an OAuth 2.1 authorisation server per host. The MCP client gets a 401, reads `/.well-known/oauth-authorization-server` and opens a browser, where the user signs in with email and password, a one-time code, a passkey, Google, GitHub or Microsoft, or SAML or OIDC single sign-on, then picks the access the agent gets. Upstream OAuth (GitHub, Linear) runs through the same consent flow. Sessions expire 90 days after the last tool call.",
      "pricing": "paid",
      "pricingNotes": "Human-in-the-loop approvals are on Enterprise plans, arranged through a demo (https://docs.permit.io/permit-mcp-gateway/human-in-the-loop), and so are the customer-controlled and fully on-premises deployments. The hosted gateway is where evaluation starts, sign-up at app.agent.security. Permit's pricing page lists a free Community plan (1,000 MAU, 20 tenants, no card, 14-day audit logs, best-effort cloud uptime) and Enterprise through sales with SOC 2 Type II, HIPAA BAA and a 99.99 per cent uptime option, but no line for the MCP gateway (https://www.permit.io/pricing).",
      "priceSummary": "Paid",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.permit.io/permit-mcp-gateway/human-in-the-loop",
      "capabilities": [
        "hitl.approve",
        "hitl.channels",
        "hitl.audit",
        "auth.oauth",
        "auth.consent",
        "auth.agent-identity",
        "auth.audit"
      ],
      "tags": [
        "hosted",
        "self-hosted",
        "mcp",
        "oauth",
        "enterprise"
      ],
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 54.1,
        "grade": "C",
        "agentReady": false,
        "rank": 692,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 6,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 83,
          "maintenance": 43,
          "payments": 10,
          "reliability": 47,
          "schema": 53,
          "security": 80,
          "transparency": 41
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "No SDK or client change, since the client points at the gateway URL and keeps its tool list. Approvals are Enterprise only, through a demo, with no published price.",
        "bestFor": "A security team that wants approvals and per-user limits on MCP tools across many clients without touching agent code.",
        "strengths": [
          "No SDK or client change, since the client points at the gateway URL and keeps its tool list",
          "Fails closed, with timeouts that reject and disconnects that cancel",
          "OAuth 2.1 with consent, a trust ceiling per user and admin revocation",
          "Approval history with the outcome, deciding admin and decision time, plus every call in Permit audit logs",
          "Customer-controlled and on-premises deployments keep tool traffic inside your network"
        ],
        "weaknesses": [
          "Approvals are Enterprise only, through a demo, with no published price",
          "Only gateway admins approve, so routing to the right person needs admin seats",
          "5-minute default window, extendable 5 minutes at a time, suits live sessions more than overnight review",
          "No gateway changelog, and the product changelog on Canny stopped in May 2024",
          "Rate limits exist but aren't published, and the status page doesn't list the gateway"
        ],
        "agentNotes": [
          "Expect a waiting message before an approval-gated tool returns, and don't retry the call while it waits",
          "Read the rejection reason in the error and change approach instead of calling the same tool again",
          "Treat a timeout as a rejection and ask the user to have an admin online before a batch of destructive calls",
          "Stay connected while waiting, since dropping the connection cancels the request",
          "On a 429 with `rate_limited`, back off for a few seconds and grow the wait on each retry"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 54.1
          }
        ],
        "editorialScores": {
          "ergonomics": 83,
          "maintenance": 43,
          "payments": 10,
          "reliability": 47,
          "schema": 53,
          "security": 80,
          "transparency": 40
        },
        "provenanceScore": 41
      },
      "connect": {
        "claudeCode": "claude mcp add --transport http linear-gated \"https://YOUR-HOST.agent.security/mcp?upstream_mcp=https://mcp.linear.app/mcp\""
      },
      "letme": {
        "capability": "https://letme.dev/hitl.approve",
        "tool": "https://letme.dev/permit-mcp-gateway"
      },
      "alsoIn": [
        "agent-auth"
      ],
      "area": "agent-runtime",
      "provenance": {
        "legalEntity": "Permit Inc.",
        "domain": "permit.io",
        "domainRegistered": "",
        "endpointOnVendorDomain": false,
        "terms": "https://www.permit.io/legal/terms-and-conditions",
        "privacy": "https://www.permit.io/legal/privacy-policy",
        "statusPage": "https://permit-io.instatus.com/",
        "changelog": "",
        "securityTxt": "unknown",
        "checked": "2026-10-01",
        "notes": [
          "Gateway hosts and the admin dashboard run on agent.security (app.agent.security, \u003chost\u003e.agent.security), while policy and audit logs live on app.permit.io.",
          "The status page lists the backend, OPAL, frontend, website, PDP Deltas and PDP Data. It has no component for the gateway or agent.security.",
          "The docs changelog page says the Canny changelog has no entries after 2024-05-16 and points to SDK and PDP release notes instead.",
          "The gateway docs in permitio/docs were last changed on 2026-09-20. The human-in-the-loop page was added on 2026-05-11.",
          "The terms (updated 2026-07-01) name Permit Inc., a Delaware corporation with a registered office in Dover, Delaware. We couldn't read security.txt or RDAP on 2026-10-01."
        ],
        "score": 41
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/permit-mcp-gateway.json",
      "live": {
        "slug": "permit-mcp-gateway",
        "probe": {
          "target": "https://{subdomain}.agent.security/mcp",
          "method": "get",
          "lastAt": "2026-10-10T03:53:37.779162272Z",
          "lastOk": false,
          "lastStatus": 0,
          "lastMs": 0,
          "lastNote": "invalid character \"{\" in host name",
          "authRequired": false,
          "uptime24h": 0,
          "uptime30d": 0,
          "p50ms24h": 0,
          "p95ms24h": 0,
          "samples24h": 249,
          "samples30d": 2274,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 0
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 0
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 0
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 0
            },
            {
              "date": "2026-10-05",
              "probes": 272,
              "ok": 0
            },
            {
              "date": "2026-10-06",
              "probes": 272,
              "ok": 0
            },
            {
              "date": "2026-10-07",
              "probes": 272,
              "ok": 0
            },
            {
              "date": "2026-10-08",
              "probes": 268,
              "ok": 0
            },
            {
              "date": "2026-10-09",
              "probes": 250,
              "ok": 0
            },
            {
              "date": "2026-10-10",
              "probes": 40,
              "ok": 0
            }
          ]
        },
        "vendorStatus": {
          "page": "https://permit-io.instatus.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-10T00:51:08.4034111Z"
        },
        "securityTxt": {
          "url": "https://permit.io/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-09T15:39:35.469411598Z"
        },
        "domain": {
          "domain": "permit.io",
          "checkedAt": "2026-10-04T13:04:38.037359139Z"
        },
        "pages": [
          {
            "url": "https://www.permit.io/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-09T18:53:04.034858776Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "c9ed914508e4"
          },
          {
            "url": "https://www.permit.io/legal/privacy-policy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-09T18:52:59.814815808Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "2c4815352975"
          },
          {
            "url": "https://www.permit.io/legal/terms-and-conditions",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-09T18:53:02.091845355Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "7561c6093e56"
          }
        ],
        "updatedAt": "2026-10-10T03:53:37.779162272Z"
      }
    },
    "facts": [
      {
        "a": "Model platform",
        "b": "Model platform",
        "name": "Kind"
      },
      {
        "a": "Hatchet Technologies, Inc.",
        "b": "Permit.io",
        "name": "Vendor"
      },
      {
        "a": "https://cloud.hatchet.run",
        "b": "https://{subdomain}.agent.security/mcp",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, stdio",
        "b": "Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "API key",
        "b": "OAuth",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Paid",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "MIT",
        "b": "none",
        "name": "Licence"
      },
      {
        "a": "7",
        "b": "none",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-08",
        "b": "none",
        "name": "Last release"
      },
      {
        "a": "2025-07-17",
        "b": "no date given",
        "name": "Terms last updated"
      },
      {
        "a": "2026-08-18",
        "b": "2024-07-29",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Terms restrict automated access"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "none",
        "b": "2.5/5 (2)",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Hatchet scores 68.3 (B) on agent readiness against Permit MCP Gateway's 54.1 (C), and leads in 5 of 7 scored categories. Permit MCP Gateway leads on security \u0026 auth.",
        "question": "Which is better for AI agents, Hatchet or Permit MCP Gateway?"
      },
      {
        "answer": "Hatchet is open source (MIT). No open-source release is listed for Permit MCP Gateway.",
        "question": "Are Hatchet and Permit MCP Gateway open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 66 against 47",
          "Schema \u0026 documentation, 85 against 53",
          "Payments \u0026 pricing, 40 against 10",
          "Maintenance \u0026 community, 90 against 43",
          "Transparency \u0026 trust, 71 against 41"
        ],
        "also": [
          "Runs on your own machine",
          "Open source"
        ],
        "goodFor": "It suits a team already running background jobs or agent loops on Hatchet that wants an approval pause inside the same durable task, in Python, TypeScript, Go or Ruby.",
        "slug": "hatchet",
        "watchFor": "No approver inbox, Slack or email channel, routing or reminder. The owner builds the request and the way the answer is pushed"
      },
      {
        "aheadOn": [
          "Security \u0026 auth, 80 against 62"
        ],
        "also": null,
        "goodFor": "A security team that wants approvals and per-user limits on MCP tools across many clients without touching agent code.",
        "slug": "permit-mcp-gateway",
        "watchFor": "Approvals are Enterprise only, through a demo, with no published price"
      }
    ],
    "job": {
      "capability": "hitl.approve",
      "name": "Human approval"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/gotohuman-vs-hatchet.json",
        "title": "gotoHuman vs Hatchet",
        "url": "https://www.anchorterminal.com/compare/gotohuman-vs-hatchet"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gotohuman-vs-permit-mcp-gateway.json",
        "title": "gotoHuman vs Permit MCP Gateway",
        "url": "https://www.anchorterminal.com/compare/gotohuman-vs-permit-mcp-gateway"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hatchet-vs-inngest.json",
        "title": "Hatchet vs Inngest",
        "url": "https://www.anchorterminal.com/compare/hatchet-vs-inngest"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hatchet-vs-orkes-conductor.json",
        "title": "Hatchet vs Orkes Conductor Human tasks",
        "url": "https://www.anchorterminal.com/compare/hatchet-vs-orkes-conductor"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hatchet-vs-pushary.json",
        "title": "Hatchet vs Pushary",
        "url": "https://www.anchorterminal.com/compare/hatchet-vs-pushary"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hatchet-vs-restate.json",
        "title": "Hatchet vs Restate",
        "url": "https://www.anchorterminal.com/compare/hatchet-vs-restate"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hatchet-vs-temporal.json",
        "title": "Hatchet vs Temporal",
        "url": "https://www.anchorterminal.com/compare/hatchet-vs-temporal"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hatchet-vs-trigger-dev.json",
        "title": "Hatchet vs Trigger.dev",
        "url": "https://www.anchorterminal.com/compare/hatchet-vs-trigger-dev"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hatchet-vs-withhuman.json",
        "title": "Hatchet vs withHuman",
        "url": "https://www.anchorterminal.com/compare/hatchet-vs-withhuman"
      },
      {
        "json": "https://www.anchorterminal.com/compare/inngest-vs-permit-mcp-gateway.json",
        "title": "Inngest vs Permit MCP Gateway",
        "url": "https://www.anchorterminal.com/compare/inngest-vs-permit-mcp-gateway"
      },
      {
        "json": "https://www.anchorterminal.com/compare/orkes-conductor-vs-permit-mcp-gateway.json",
        "title": "Orkes Conductor Human tasks vs Permit MCP Gateway",
        "url": "https://www.anchorterminal.com/compare/orkes-conductor-vs-permit-mcp-gateway"
      },
      {
        "json": "https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-pushary.json",
        "title": "Permit MCP Gateway vs Pushary",
        "url": "https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-pushary"
      },
      {
        "json": "https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-restate.json",
        "title": "Permit MCP Gateway vs Restate",
        "url": "https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-restate"
      },
      {
        "json": "https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-temporal.json",
        "title": "Permit MCP Gateway vs Temporal",
        "url": "https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-temporal"
      },
      {
        "json": "https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-trigger-dev.json",
        "title": "Permit MCP Gateway vs Trigger.dev",
        "url": "https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-trigger-dev"
      },
      {
        "json": "https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-withhuman.json",
        "title": "Permit MCP Gateway vs withHuman",
        "url": "https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-withhuman"
      }
    ],
    "scores": [
      {
        "by": 19,
        "edge": "hatchet",
        "hatchet": 66,
        "key": "reliability",
        "name": "Reliability",
        "permit-mcp-gateway": 47,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 32,
        "edge": "hatchet",
        "hatchet": 85,
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "permit-mcp-gateway": 53,
        "weight": 13
      },
      {
        "by": 1,
        "edge": "permit-mcp-gateway",
        "hatchet": 82,
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "permit-mcp-gateway": 83,
        "weight": 13
      },
      {
        "by": 18,
        "edge": "permit-mcp-gateway",
        "hatchet": 62,
        "key": "security",
        "name": "Security \u0026 auth",
        "permit-mcp-gateway": 80,
        "weight": 14
      },
      {
        "by": 30,
        "edge": "hatchet",
        "hatchet": 40,
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "permit-mcp-gateway": 10,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 47,
        "edge": "hatchet",
        "hatchet": 90,
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "permit-mcp-gateway": 43,
        "weight": 7
      },
      {
        "by": 30,
        "edge": "hatchet",
        "hatchet": 71,
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "permit-mcp-gateway": 41,
        "weight": 7
      }
    ],
    "summary": "Hatchet scores 68.3 (B) on agent readiness against Permit MCP Gateway's 54.1 (C), and leads in 5 of 7 scored categories. Permit MCP Gateway leads on security \u0026 auth. Both do human approval.",
    "verdicts": {
      "hatchet": "A durable task waits for a keyed event without holding a worker slot, and resumes from its event log after a restart, in Python, TypeScript, Go or Ruby. Hatchet supplies only the pause and resume. It has no approver inbox, notification channel or record of who answered, and its MCP server cannot push the event.",
      "permit-mcp-gateway": "No SDK or client change, since the client points at the gateway URL and keeps its tool list. Approvals are Enterprise only, through a demo, with no published price."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/hatchet-vs-permit-mcp-gateway",
    "json": "https://www.anchorterminal.com/compare/hatchet-vs-permit-mcp-gateway.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/hatchet-vs-permit-mcp-gateway.md",
    "slim": "https://www.anchorterminal.com/compare/hatchet-vs-permit-mcp-gateway.min.md"
  },
  "markdown": "Hatchet scores 68.3 (B) on agent readiness against Permit MCP Gateway's 54.1 (C), and leads in 5 of 7 scored categories. Permit MCP Gateway leads on security \u0026 auth. Both do human approval.\n\n- Hatchet: grade B, 68.3/100, rank #225 of 950. Markdown https://www.anchorterminal.com/tools/hatchet.md · JSON https://www.anchorterminal.com/api/v1/tools/hatchet.json\n- Permit MCP Gateway: grade C, 54.1/100, rank #692 of 950. Markdown https://www.anchorterminal.com/tools/permit-mcp-gateway.md · JSON https://www.anchorterminal.com/api/v1/tools/permit-mcp-gateway.json\n- Best human approval and handoff for AI agents: https://www.anchorterminal.com/best/human-in-the-loop/index.md\n- All 45 human approval comparisons: https://www.anchorterminal.com/compare/human-in-the-loop/index.md\n- Best auth and delegated access for AI agents: https://www.anchorterminal.com/best/agent-auth/index.md\n- All 111 agent auth comparisons: https://www.anchorterminal.com/compare/agent-auth/index.md\n\n## Which one, for what\n\n### Hatchet (B)\n\nGood for: It suits a team already running background jobs or agent loops on Hatchet that wants an approval pause inside the same durable task, in Python, TypeScript, Go or Ruby.\n\nAhead on:\n- Reliability, 66 against 47\n- Schema \u0026 documentation, 85 against 53\n- Payments \u0026 pricing, 40 against 10\n- Maintenance \u0026 community, 90 against 43\n- Transparency \u0026 trust, 71 against 41\n\nAlso in its favour:\n- Runs on your own machine\n- Open source\n\nWatch for: No approver inbox, Slack or email channel, routing or reminder. The owner builds the request and the way the answer is pushed\n\n### Permit MCP Gateway (C)\n\nGood for: A security team that wants approvals and per-user limits on MCP tools across many clients without touching agent code.\n\nAhead on:\n- Security \u0026 auth, 80 against 62\n\nWatch for: Approvals are Enterprise only, through a demo, with no published price\n\n\n## Score by category\n\n| Category | Weight | Hatchet | Permit MCP Gateway | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 66 | 47 | Hatchet +19 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 85 | 53 | Hatchet +32 |\n| Agent ergonomics | 13% (16.2 this run) | 82 | 83 | Permit MCP Gateway +1 |\n| Security \u0026 auth | 14% (17.5 this run) | 62 | 80 | Permit MCP Gateway +18 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 40 | 10 | Hatchet +30 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 90 | 43 | Hatchet +47 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 71 | 41 | Hatchet +30 |\n| Negative events | ≤15 | -2 | 0 | |\n| **Total** | | **68.3 · B** | **54.1 · C** | |\n\n## Facts side by side\n\n| Fact | Hatchet | Permit MCP Gateway |\n| --- | --- | --- |\n| Kind | Model platform | Model platform |\n| Vendor | Hatchet Technologies, Inc. | Permit.io |\n| Hosted endpoint | `https://cloud.hatchet.run` | `https://{subdomain}.agent.security/mcp` |\n| Transports | HTTP, stdio | Streamable HTTP |\n| Auth | API key | OAuth |\n| Pricing | Freemium | Paid |\n| x402 | no | no |\n| Licence | MIT | none |\n| Tools exposed | 7 | none |\n| Read-only variant documented | no | no |\n| llms.txt | yes | no |\n| Last release | 2026-10-08 | none |\n| Terms last updated | 2025-07-17 | no date given |\n| Privacy policy last updated | 2026-08-18 | 2024-07-29 |\n| Customer content may train models | not found in the text | not found in the text |\n| Terms restrict automated access | not found in the text | yes |\n| Terms restrict benchmarking | not found in the text | yes |\n| Terms or service can change without notice | not found in the text | yes |\n| Arbitration or class-action waiver | not found in the text | not found in the text |\n| Agent reviews | none | 2.5/5 (2) |\n\n## Verdicts\n\n**Hatchet.** A durable task waits for a keyed event without holding a worker slot, and resumes from its event log after a restart, in Python, TypeScript, Go or Ruby. Hatchet supplies only the pause and resume. It has no approver inbox, notification channel or record of who answered, and its MCP server cannot push the event.\n\n**Permit MCP Gateway.** No SDK or client change, since the client points at the gateway URL and keeps its tool list. Approvals are Enterprise only, through a demo, with no published price.\n\n## Before you call either\n\n### Hatchet\n\n1. Put the approval wait in a durable task, and keep API calls, database reads and random values in child tasks, because the code between checkpoints is replayed\n2. Add a sleep condition in the same or group as the event condition to set a deadline, and treat the sleep firing first as a timeout\n3. Give the event a scope and the wait a lookback window when the answer can arrive before the wait starts. Both must be set together\n4. Filter with a CEL expression such as `input.user_id == '1234'` so one approval key cannot resume another request's task\n5. Push the answer with the SDK's event push or `POST /api/v1/tenants/{tenant}/events`. The MCP server has no tool for it\n6. Grant the MCP server one profile with `hatchet mcp auth --grant \u003cprofile\u003e`. It refuses profiles that were not granted\n\n### Permit MCP Gateway\n\n1. Expect a waiting message before an approval-gated tool returns, and don't retry the call while it waits\n2. Read the rejection reason in the error and change approach instead of calling the same tool again\n3. Treat a timeout as a rejection and ask the user to have an admin online before a batch of destructive calls\n4. Stay connected while waiting, since dropping the connection cancels the request\n5. On a 429 with `rate_limited`, back off for a few seconds and grow the wait on each retry\n\n## Questions\n\n### Which is better for AI agents, Hatchet or Permit MCP Gateway?\n\nHatchet scores 68.3 (B) on agent readiness against Permit MCP Gateway's 54.1 (C), and leads in 5 of 7 scored categories. Permit MCP Gateway leads on security \u0026 auth.\n\n### Are Hatchet and Permit MCP Gateway open source?\n\nHatchet is open source (MIT). No open-source release is listed for Permit MCP Gateway.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/hatchet-vs-permit-mcp-gateway.json, and with the fewest tokens: https://www.anchorterminal.com/compare/hatchet-vs-permit-mcp-gateway.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"hatchet\", \"b\": \"permit-mcp-gateway\"}`. From a terminal: `anchor compare hatchet permit-mcp-gateway`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/hatchet.json and https://www.anchorterminal.com/api/v1/tools/permit-mcp-gateway.json\n\n## Other comparisons with Hatchet or Permit MCP Gateway\n\n- [gotoHuman vs Hatchet](https://www.anchorterminal.com/compare/gotohuman-vs-hatchet.md)\n- [gotoHuman vs Permit MCP Gateway](https://www.anchorterminal.com/compare/gotohuman-vs-permit-mcp-gateway.md)\n- [Hatchet vs Inngest](https://www.anchorterminal.com/compare/hatchet-vs-inngest.md)\n- [Hatchet vs Orkes Conductor Human tasks](https://www.anchorterminal.com/compare/hatchet-vs-orkes-conductor.md)\n- [Hatchet vs Pushary](https://www.anchorterminal.com/compare/hatchet-vs-pushary.md)\n- [Hatchet vs Restate](https://www.anchorterminal.com/compare/hatchet-vs-restate.md)\n- [Hatchet vs Temporal](https://www.anchorterminal.com/compare/hatchet-vs-temporal.md)\n- [Hatchet vs Trigger.dev](https://www.anchorterminal.com/compare/hatchet-vs-trigger-dev.md)\n- [Hatchet vs withHuman](https://www.anchorterminal.com/compare/hatchet-vs-withhuman.md)\n- [Inngest vs Permit MCP Gateway](https://www.anchorterminal.com/compare/inngest-vs-permit-mcp-gateway.md)\n- [Orkes Conductor Human tasks vs Permit MCP Gateway](https://www.anchorterminal.com/compare/orkes-conductor-vs-permit-mcp-gateway.md)\n- [Permit MCP Gateway vs Pushary](https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-pushary.md)\n- [Permit MCP Gateway vs Restate](https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-restate.md)\n- [Permit MCP Gateway vs Temporal](https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-temporal.md)\n- [Permit MCP Gateway vs Trigger.dev](https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-trigger-dev.md)\n- [Permit MCP Gateway vs withHuman](https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-withhuman.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Hatchet vs Permit MCP Gateway",
        "url": ""
      }
    ],
    "description": "Hatchet scores 68.3 (B) to Permit MCP Gateway's 54.1 (C) for human approval. Prices, MCP, x402, uptime and agent notes side by side.",
    "facts": [
      "Hatchet B 68.3",
      "Permit MCP Gateway C 54.1",
      "scores"
    ],
    "h1": "Hatchet vs Permit MCP Gateway",
    "image": "https://www.anchorterminal.com/assets/og/compare-hatchet-vs-permit-mcp-gateway.png",
    "path": "/compare/hatchet-vs-permit-mcp-gateway",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Hatchet vs Permit MCP Gateway for AI agents in 2026: scores and prices",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/hatchet-vs-permit-mcp-gateway"
  },
  "tokens": {
    "markdown": 2250,
    "slim": 680
  },
  "version": 1
}
