{
  "data": {
    "a": {
      "slug": "permit-mcp-gateway",
      "name": "Permit MCP Gateway",
      "vendor": "Permit.io",
      "vendorUrl": "https://www.permit.io/mcp-gateway",
      "kind": "platform",
      "category": "human-in-the-loop",
      "summary": "Hosted proxy between MCP clients and MCP servers that signs in the human behind the agent, checks each tool call against Permit.io policy and logs it.",
      "url": "https://www.anchorterminal.com/tools/permit-mcp-gateway",
      "markdownUrl": "https://www.anchorterminal.com/tools/permit-mcp-gateway.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/permit-mcp-gateway.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/permit-mcp-gateway.json",
      "transports": [
        "streamable-http"
      ],
      "remoteUrl": "https://{subdomain}.agent.security/mcp",
      "packages": [],
      "auth": "oauth",
      "authNotes": "The gateway is an OAuth 2.1 authorisation server per host. The MCP client gets a 401, reads `/.well-known/oauth-authorization-server` and opens a browser, where the user signs in with email and password, a one-time code, a passkey, Google, GitHub or Microsoft, or SAML or OIDC single sign-on, then picks the access the agent gets. Upstream OAuth (GitHub, Linear) runs through the same consent flow. Sessions expire 90 days after the last tool call.",
      "pricing": "paid",
      "pricingNotes": "Human-in-the-loop approvals are on Enterprise plans, arranged through a demo (https://docs.permit.io/permit-mcp-gateway/human-in-the-loop), and so are the customer-controlled and fully on-premises deployments. The hosted gateway is where evaluation starts, sign-up at app.agent.security. Permit's pricing page lists a free Community plan (1,000 MAU, 20 tenants, no card, 14-day audit logs, best-effort cloud uptime) and Enterprise through sales with SOC 2 Type II, HIPAA BAA and a 99.99 per cent uptime option, but no line for the MCP gateway (https://www.permit.io/pricing).",
      "priceSummary": "Paid",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.permit.io/permit-mcp-gateway/human-in-the-loop",
      "capabilities": [
        "hitl.approve",
        "hitl.channels",
        "hitl.audit",
        "auth.oauth",
        "auth.consent",
        "auth.agent-identity",
        "auth.audit"
      ],
      "tags": [
        "hosted",
        "self-hosted",
        "mcp",
        "oauth",
        "enterprise"
      ],
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 54.1,
        "grade": "C",
        "agentReady": false,
        "rank": 534,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 5,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 83,
          "maintenance": 43,
          "payments": 10,
          "reliability": 47,
          "schema": 53,
          "security": 80,
          "transparency": 41
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "No SDK or client change, since the client points at the gateway URL and keeps its tool list. Approvals are Enterprise only, through a demo, with no published price.",
        "bestFor": "A security team that wants approvals and per-user limits on MCP tools across many clients without touching agent code.",
        "strengths": [
          "No SDK or client change, since the client points at the gateway URL and keeps its tool list",
          "Fails closed, with timeouts that reject and disconnects that cancel",
          "OAuth 2.1 with consent, a trust ceiling per user and admin revocation",
          "Approval history with the outcome, deciding admin and decision time, plus every call in Permit audit logs",
          "Customer-controlled and on-premises deployments keep tool traffic inside your network"
        ],
        "weaknesses": [
          "Approvals are Enterprise only, through a demo, with no published price",
          "Only gateway admins approve, so routing to the right person needs admin seats",
          "5-minute default window, extendable 5 minutes at a time, suits live sessions more than overnight review",
          "No gateway changelog, and the product changelog on Canny stopped in May 2024",
          "Rate limits exist but aren't published, and the status page doesn't list the gateway"
        ],
        "agentNotes": [
          "Expect a waiting message before an approval-gated tool returns, and don't retry the call while it waits",
          "Read the rejection reason in the error and change approach instead of calling the same tool again",
          "Treat a timeout as a rejection and ask the user to have an admin online before a batch of destructive calls",
          "Stay connected while waiting, since dropping the connection cancels the request",
          "On a 429 with `rate_limited`, back off for a few seconds and grow the wait on each retry"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 54.1
          }
        ],
        "editorialScores": {
          "ergonomics": 83,
          "maintenance": 43,
          "payments": 10,
          "reliability": 47,
          "schema": 53,
          "security": 80,
          "transparency": 40
        },
        "provenanceScore": 41
      },
      "connect": {
        "claudeCode": "claude mcp add --transport http linear-gated \"https://YOUR-HOST.agent.security/mcp?upstream_mcp=https://mcp.linear.app/mcp\""
      },
      "letme": {
        "capability": "https://letme.dev/hitl.approve",
        "tool": "https://letme.dev/permit-mcp-gateway"
      },
      "alsoIn": [
        "agent-auth"
      ],
      "area": "agent-runtime",
      "provenance": {
        "legalEntity": "Permit Inc.",
        "domain": "permit.io",
        "domainRegistered": "",
        "endpointOnVendorDomain": false,
        "terms": "https://www.permit.io/legal/terms-and-conditions",
        "privacy": "https://www.permit.io/legal/privacy-policy",
        "statusPage": "https://permit-io.instatus.com/",
        "changelog": "",
        "securityTxt": "unknown",
        "checked": "2026-10-01",
        "notes": [
          "Gateway hosts and the admin dashboard run on agent.security (app.agent.security, \u003chost\u003e.agent.security), while policy and audit logs live on app.permit.io.",
          "The status page lists the backend, OPAL, frontend, website, PDP Deltas and PDP Data. It has no component for the gateway or agent.security.",
          "The docs changelog page says the Canny changelog has no entries after 2024-05-16 and points to SDK and PDP release notes instead.",
          "The gateway docs in permitio/docs were last changed on 2026-09-20. The human-in-the-loop page was added on 2026-05-11.",
          "The terms (updated 2026-07-01) name Permit Inc., a Delaware corporation with a registered office in Dover, Delaware. We couldn't read security.txt or RDAP on 2026-10-01."
        ],
        "score": 41
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/permit-mcp-gateway.json",
      "live": {
        "slug": "permit-mcp-gateway",
        "probe": {
          "target": "https://{subdomain}.agent.security/mcp",
          "method": "get",
          "lastAt": "2026-10-08T19:52:58.746637525Z",
          "lastOk": false,
          "lastStatus": 0,
          "lastMs": 0,
          "lastNote": "invalid character \"{\" in host name",
          "authRequired": false,
          "uptime24h": 0,
          "uptime30d": 0,
          "p50ms24h": 0,
          "p95ms24h": 0,
          "samples24h": 272,
          "samples30d": 1941,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 0
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 0
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 0
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 0
            },
            {
              "date": "2026-10-05",
              "probes": 272,
              "ok": 0
            },
            {
              "date": "2026-10-06",
              "probes": 272,
              "ok": 0
            },
            {
              "date": "2026-10-07",
              "probes": 272,
              "ok": 0
            },
            {
              "date": "2026-10-08",
              "probes": 225,
              "ok": 0
            }
          ]
        },
        "vendorStatus": {
          "page": "https://permit-io.instatus.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-08T19:39:02.527783366Z"
        },
        "securityTxt": {
          "url": "https://permit.io/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:53.197667522Z"
        },
        "domain": {
          "domain": "permit.io",
          "checkedAt": "2026-10-04T13:04:38.037359139Z"
        },
        "pages": [
          {
            "url": "https://www.permit.io/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:29:38.410140158Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "c9ed914508e4"
          },
          {
            "url": "https://www.permit.io/legal/privacy-policy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:29:34.176220109Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "2c4815352975"
          },
          {
            "url": "https://www.permit.io/legal/terms-and-conditions",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:29:36.663304672Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "7561c6093e56"
          }
        ],
        "updatedAt": "2026-10-08T19:52:58.746637525Z"
      }
    },
    "answer": "Restate scores 73.3 (BB) on agent readiness against Permit MCP Gateway's 54.1 (C), and leads in 5 of 7 scored categories. Permit MCP Gateway leads on security \u0026 auth.",
    "b": {
      "slug": "restate",
      "name": "Restate",
      "vendor": "Restate GmbH",
      "vendorUrl": "https://restate.dev",
      "kind": "platform",
      "category": "human-in-the-loop",
      "summary": "Durable execution runtime from Restate GmbH in Berlin, run as Restate Cloud, in the customer's own cloud account or self-hosted. Handlers pause on durable promises (awakeables and signals) and resume when a person answers over HTTP.",
      "url": "https://www.anchorterminal.com/tools/restate",
      "markdownUrl": "https://www.anchorterminal.com/tools/restate.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/restate.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/restate.json",
      "repo": "https://github.com/restatedev/restate",
      "license": "BSL 1.1 converting to Apache-2.0 four years after release (server), MIT (SDKs)",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "@restatedev/restate-sdk"
        },
        {
          "registry": "pypi",
          "name": "restate-sdk"
        },
        {
          "registry": "npm",
          "name": "@restatedev/restate-sdk-clients"
        }
      ],
      "auth": "api-key",
      "authNotes": "Restate Cloud takes an API key (`key_...`) as a Bearer token on each environment's ingress at `https://\u003cenv_id\u003e.env.\u003cregion\u003e.restate.cloud:8080` and its Admin API on port 9070. Keys are created self-serve in the Developers tab of the Cloud UI with a role (the docs show Full and Admin). Access is self-serve after a browser signup, with no review. A self-hosted server has no authentication on its ingress or admin ports, and the docs expect a reverse proxy in front (https://docs.restate.dev/cloud/getting-started, https://docs.restate.dev/server/security).",
      "pricing": "freemium",
      "pricingNotes": "Free $0 with 100,000 durable actions a month, 1 GB of storage and 1-day history, no card, so an agent's owner can start without a contract. Starter $75 a month with 5 million actions, Business $300 with 20 million, Premium $1,000 with 50 million, Enterprise on request. Extra actions cost $25 per million on Starter and Business and $15 on Premium. One action is an invocation, a completion, a step, a sleep, a call or an awakeable, counted per started 64 KiB. Self-hosting is free under BSL 1.1 (https://restate.dev/pricing).",
      "priceSummary": "$75 / mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs or on the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 4530,
        "npmWeekly": 329023,
        "pypiWeekly": 76080,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.restate.dev/ai/patterns/human-in-the-loop",
      "llmsTxt": "https://docs.restate.dev/llms.txt",
      "openapi": "https://docs.restate.dev/schemas/openapi-admin.json",
      "capabilities": [
        "hitl.approve",
        "hitl.ask",
        "agent.durable",
        "automation.workflows",
        "automation.code"
      ],
      "tags": [
        "hosted",
        "self-hosted",
        "source-available",
        "freemium",
        "free-tier",
        "no-card",
        "llms-txt",
        "openapi",
        "typescript",
        "python",
        "java",
        "go",
        "rust",
        "status-page"
      ],
      "lastRelease": "2026-10-01",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 73.3,
        "grade": "BB",
        "agentReady": true,
        "rank": 78,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 3,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 81,
          "maintenance": 92,
          "payments": 40,
          "reliability": 91,
          "schema": 85,
          "security": 61,
          "transparency": 50
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "An awakeable pauses a handler at no compute cost and resumes it from one HTTP request, with a durable timeout, on a free plan of 100,000 actions a month. Restate sends nothing to the approver, so the Slack message, email or inbox is the builder's code, and the published terms and privacy statement predate the paid plans.",
        "bestFor": "A team that already writes agent steps as durable handlers and wants a long, cheap wait for a human answer in TypeScript, Python, Java, Go or Rust, with the option to self-host.",
        "strengths": [
          "One HTTP request resolves or rejects an awakeable, and the waiting handler resumes after restarts or redeployment",
          "`orTimeout` puts a durable timer on the wait, so the remaining time survives a crash",
          "Free plan of 100,000 actions a month with no card, and $25 per extra million actions on Starter and Business",
          "Cloud Environments shows 100 per cent on the status page for the 90 days to 8 October 2026",
          "MIT SDKs for TypeScript, Python, Java and Kotlin, Go and Rust, with llms.txt and Markdown copies of every docs page"
        ],
        "weaknesses": [
          "No reviewer inbox, Slack app or email. The approval request and the reply endpoint are the builder's code",
          "Signals can't be resolved over HTTP yet, only from another handler (open issue of 5 October 2026)",
          "Self-hosted ingress and admin ports have no authentication, so the awakeable ID alone resolves a wait there",
          "The terms say Restate Cloud is free of charge and the privacy statement of 23 February 2022 covers only the website",
          "Server under BSL 1.1, which isn't an OSI licence, with no security.txt or SECURITY.md found"
        ],
        "agentNotes": [
          "Create the awakeable, send its ID inside `ctx.run`, then await the promise, so a retry doesn't send a second approval request",
          "Resolve with `POST /restate/awakeables/\u003cid\u003e/resolve` and a JSON body, or `/reject` with a text reason, which throws a terminal error in the handler",
          "On Restate Cloud send `Authorization: Bearer key_...` to `https://\u003cenv_id\u003e.env.\u003cregion\u003e.restate.cloud:8080`. On a self-hosted server put an authenticating proxy in front of port 8080",
          "Wrap the wait in `orTimeout` and decide what a timeout means. Without it the handler waits with no limit",
          "Retry ingress errors only on 408, 425, 429 or 5xx, and only when `x-restate-error-source` isn't `invocation`"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 73.3
          }
        ],
        "editorialScores": {
          "ergonomics": 81,
          "maintenance": 92,
          "payments": 40,
          "reliability": 91,
          "schema": 85,
          "security": 61,
          "transparency": 46
        },
        "provenanceScore": 54
      },
      "connect": {
        "install": "npm install --global @restatedev/restate-server@latest @restatedev/restate@latest",
        "http": "curl localhost:8080/restate/awakeables/sign_1M28aqY6ZfuwBmRnmyP/resolve --json 'true'",
        "claudeCode": "claude mcp add --transport http restate-docs https://docs.restate.dev/mcp"
      },
      "letme": {
        "capability": "https://letme.dev/hitl.approve",
        "tool": "https://letme.dev/restate"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Starter plan",
          "unit": "month",
          "usd": 75,
          "note": "5 million actions, 50 actions a second, 5 GB, 3-day history"
        },
        {
          "item": "Business plan",
          "unit": "month",
          "usd": 300,
          "note": "20 million actions, 200 actions a second, 20 GB, 7-day history"
        },
        {
          "item": "Premium plan",
          "unit": "month",
          "usd": 1000,
          "note": "50 million actions, 500 actions a second, 50 GB, 30-day history"
        },
        {
          "item": "Extra durable actions on Starter and Business",
          "unit": "1k-calls",
          "usd": 0.025,
          "note": "$25 per million actions, $15 per million on Premium"
        },
        {
          "item": "Extra virtual object storage",
          "unit": "gb-month",
          "usd": 0.5
        }
      ],
      "provenance": {
        "legalEntity": "Restate GmbH",
        "domain": "restate.dev",
        "domainRegistered": "2022-02-11",
        "endpointOnVendorDomain": false,
        "terms": "https://restate.dev/terms-and-conditions",
        "privacy": "",
        "statusPage": "https://status.restate.dev",
        "changelog": "https://docs.restate.dev/changelog/server",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The imprint names Restate GmbH, Knaackstr. 92, 10435 Berlin, Amtsgericht Charlottenburg HRB 240580 B. The server licence names Restate Software, Inc. and Restate GmbH as licensors.",
          "The general terms and conditions cover Restate Cloud by name, under German law with Berlin as the place of jurisdiction, and say its use is free of charge, which the pricing page no longer matches.",
          "No privacy field. The privacy statement at https://restate.dev/privacy is dated 23 February 2022 and covers the website, the newsletter and early code access, not customer data in Restate Cloud, and no other privacy policy was found.",
          "Restate Cloud environments answer at \u003cenv_id\u003e.env.\u003cregion\u003e.restate.cloud, a different domain from restate.dev.",
          "https://restate.dev/.well-known/security.txt returned 404 on 2026-10-08. The trust centre at trust.restate.dev is hosted by Vanta and didn't load in our reader.",
          "RDAP gives 2022-02-11 as the registration date of restate.dev."
        ],
        "score": 54
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/restate.json",
      "live": {
        "slug": "restate",
        "vendorStatus": {
          "page": "https://status.restate.dev",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T19:51:00.923121694Z"
        },
        "pages": [
          {
            "url": "https://docs.restate.dev/changelog/server",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:19:19.75301134Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "1213cece2209"
          },
          {
            "url": "https://restate.dev/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:23:44.722910015Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "6eb8d04dcfe6"
          },
          {
            "url": "https://restate.dev/terms-and-conditions",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:23:46.891274553Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "32e2a89f3bf3"
          }
        ],
        "updatedAt": "2026-10-08T19:51:00.923121694Z"
      }
    },
    "facts": [
      {
        "a": "Model platform",
        "b": "Model platform",
        "name": "Kind"
      },
      {
        "a": "Permit.io",
        "b": "Restate GmbH",
        "name": "Vendor"
      },
      {
        "a": "https://{subdomain}.agent.security/mcp",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "Streamable HTTP",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth",
        "b": "API key",
        "name": "Auth"
      },
      {
        "a": "Paid",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "none",
        "b": "BSL 1.1 converting to Apache-2.0 four years after release (server), MIT (SDKs)",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "no",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "none",
        "b": "2026-10-01",
        "name": "Last release"
      },
      {
        "a": "no date given",
        "b": "couldn't be read",
        "name": "Terms last updated"
      },
      {
        "a": "2024-07-29",
        "b": "no document linked",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "couldn't be read",
        "name": "Customer content may train models"
      },
      {
        "a": "yes",
        "b": "couldn't be read",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "couldn't be read",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "yes",
        "b": "couldn't be read",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "couldn't be read",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "none",
        "b": "4.5k stars, 329k npm/wk, 76k PyPI/wk",
        "name": "Popularity"
      },
      {
        "a": "2.5/5 (2)",
        "b": "none",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Restate scores 73.3 (BB) on agent readiness against Permit MCP Gateway's 54.1 (C), and leads in 5 of 7 scored categories. Permit MCP Gateway leads on security \u0026 auth.",
        "question": "Which is better for AI agents, Permit MCP Gateway or Restate?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Security \u0026 auth, 80 against 61"
        ],
        "also": [
          "A hosted endpoint, with nothing to install"
        ],
        "goodFor": "A security team that wants approvals and per-user limits on MCP tools across many clients without touching agent code.",
        "slug": "permit-mcp-gateway",
        "watchFor": "Approvals are Enterprise only, through a demo, with no published price"
      },
      {
        "aheadOn": [
          "Reliability, 91 against 47",
          "Schema \u0026 documentation, 85 against 53",
          "Payments \u0026 pricing, 40 against 10",
          "Maintenance \u0026 community, 92 against 43",
          "Transparency \u0026 trust, 50 against 41"
        ],
        "also": [
          "Agent-ready, a grade of BB or better",
          "Free to start without a card"
        ],
        "goodFor": "A team that already writes agent steps as durable handlers and wants a long, cheap wait for a human answer in TypeScript, Python, Java, Go or Rust, with the option to self-host.",
        "slug": "restate",
        "watchFor": "No reviewer inbox, Slack app or email. The approval request and the reply endpoint are the builder's code"
      }
    ],
    "job": {
      "capability": "hitl.approve",
      "name": "Hitl approve"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/gotohuman-vs-permit-mcp-gateway.json",
        "title": "gotoHuman vs Permit MCP Gateway",
        "url": "https://www.anchorterminal.com/compare/gotohuman-vs-permit-mcp-gateway"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gotohuman-vs-restate.json",
        "title": "gotoHuman vs Restate",
        "url": "https://www.anchorterminal.com/compare/gotohuman-vs-restate"
      },
      {
        "json": "https://www.anchorterminal.com/compare/inngest-vs-permit-mcp-gateway.json",
        "title": "Inngest vs Permit MCP Gateway",
        "url": "https://www.anchorterminal.com/compare/inngest-vs-permit-mcp-gateway"
      },
      {
        "json": "https://www.anchorterminal.com/compare/inngest-vs-restate.json",
        "title": "Inngest vs Restate",
        "url": "https://www.anchorterminal.com/compare/inngest-vs-restate"
      },
      {
        "json": "https://www.anchorterminal.com/compare/orkes-conductor-vs-permit-mcp-gateway.json",
        "title": "Orkes Conductor Human tasks vs Permit MCP Gateway",
        "url": "https://www.anchorterminal.com/compare/orkes-conductor-vs-permit-mcp-gateway"
      },
      {
        "json": "https://www.anchorterminal.com/compare/orkes-conductor-vs-restate.json",
        "title": "Orkes Conductor Human tasks vs Restate",
        "url": "https://www.anchorterminal.com/compare/orkes-conductor-vs-restate"
      },
      {
        "json": "https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-pushary.json",
        "title": "Permit MCP Gateway vs Pushary",
        "url": "https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-pushary"
      },
      {
        "json": "https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-temporal.json",
        "title": "Permit MCP Gateway vs Temporal",
        "url": "https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-temporal"
      },
      {
        "json": "https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-trigger-dev.json",
        "title": "Permit MCP Gateway vs Trigger.dev",
        "url": "https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-trigger-dev"
      },
      {
        "json": "https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-withhuman.json",
        "title": "Permit MCP Gateway vs withHuman",
        "url": "https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-withhuman"
      },
      {
        "json": "https://www.anchorterminal.com/compare/pushary-vs-restate.json",
        "title": "Pushary vs Restate",
        "url": "https://www.anchorterminal.com/compare/pushary-vs-restate"
      },
      {
        "json": "https://www.anchorterminal.com/compare/restate-vs-temporal.json",
        "title": "Restate vs Temporal",
        "url": "https://www.anchorterminal.com/compare/restate-vs-temporal"
      },
      {
        "json": "https://www.anchorterminal.com/compare/restate-vs-trigger-dev.json",
        "title": "Restate vs Trigger.dev",
        "url": "https://www.anchorterminal.com/compare/restate-vs-trigger-dev"
      },
      {
        "json": "https://www.anchorterminal.com/compare/restate-vs-withhuman.json",
        "title": "Restate vs withHuman",
        "url": "https://www.anchorterminal.com/compare/restate-vs-withhuman"
      }
    ],
    "scores": [
      {
        "by": 44,
        "edge": "restate",
        "key": "reliability",
        "name": "Reliability",
        "permit-mcp-gateway": 47,
        "restate": 91,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 32,
        "edge": "restate",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "permit-mcp-gateway": 53,
        "restate": 85,
        "weight": 13
      },
      {
        "by": 2,
        "edge": "permit-mcp-gateway",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "permit-mcp-gateway": 83,
        "restate": 81,
        "weight": 13
      },
      {
        "by": 19,
        "edge": "permit-mcp-gateway",
        "key": "security",
        "name": "Security \u0026 auth",
        "permit-mcp-gateway": 80,
        "restate": 61,
        "weight": 14
      },
      {
        "by": 30,
        "edge": "restate",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "permit-mcp-gateway": 10,
        "restate": 40,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 49,
        "edge": "restate",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "permit-mcp-gateway": 43,
        "restate": 92,
        "weight": 7
      },
      {
        "by": 9,
        "edge": "restate",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "permit-mcp-gateway": 41,
        "restate": 50,
        "weight": 7
      }
    ],
    "summary": "Restate scores 73.3 (BB) on agent readiness against Permit MCP Gateway's 54.1 (C), and leads in 5 of 7 scored categories. Permit MCP Gateway leads on security \u0026 auth. Both do hitl approve.",
    "verdicts": {
      "permit-mcp-gateway": "No SDK or client change, since the client points at the gateway URL and keeps its tool list. Approvals are Enterprise only, through a demo, with no published price.",
      "restate": "An awakeable pauses a handler at no compute cost and resumes it from one HTTP request, with a durable timeout, on a free plan of 100,000 actions a month. Restate sends nothing to the approver, so the Slack message, email or inbox is the builder's code, and the published terms and privacy statement predate the paid plans."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-restate",
    "json": "https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-restate.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-restate.md",
    "slim": "https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-restate.min.md"
  },
  "markdown": "Restate scores 73.3 (BB) on agent readiness against Permit MCP Gateway's 54.1 (C), and leads in 5 of 7 scored categories. Permit MCP Gateway leads on security \u0026 auth. Both do hitl approve.\n\n- Permit MCP Gateway: grade C, 54.1/100, rank #534 of 722. Markdown https://www.anchorterminal.com/tools/permit-mcp-gateway.md · JSON https://www.anchorterminal.com/api/v1/tools/permit-mcp-gateway.json\n- Restate: grade BB, 73.3/100, rank #78 of 722. Markdown https://www.anchorterminal.com/tools/restate.md · JSON https://www.anchorterminal.com/api/v1/tools/restate.json\n\n## Which one, for what\n\n### Permit MCP Gateway (C)\n\nGood for: A security team that wants approvals and per-user limits on MCP tools across many clients without touching agent code.\n\nAhead on:\n- Security \u0026 auth, 80 against 61\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n\nWatch for: Approvals are Enterprise only, through a demo, with no published price\n\n### Restate (BB)\n\nGood for: A team that already writes agent steps as durable handlers and wants a long, cheap wait for a human answer in TypeScript, Python, Java, Go or Rust, with the option to self-host.\n\nAhead on:\n- Reliability, 91 against 47\n- Schema \u0026 documentation, 85 against 53\n- Payments \u0026 pricing, 40 against 10\n- Maintenance \u0026 community, 92 against 43\n- Transparency \u0026 trust, 50 against 41\n\nAlso in its favour:\n- Agent-ready, a grade of BB or better\n- Free to start without a card\n\nWatch for: No reviewer inbox, Slack app or email. The approval request and the reply endpoint are the builder's code\n\n\n## Score by category\n\n| Category | Weight | Permit MCP Gateway | Restate | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 47 | 91 | Restate +44 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 53 | 85 | Restate +32 |\n| Agent ergonomics | 13% (16.2 this run) | 83 | 81 | Permit MCP Gateway +2 |\n| Security \u0026 auth | 14% (17.5 this run) | 80 | 61 | Permit MCP Gateway +19 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 10 | 40 | Restate +30 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 43 | 92 | Restate +49 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 41 | 50 | Restate +9 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **54.1 · C** | **73.3 · BB** | |\n\n## Facts side by side\n\n| Fact | Permit MCP Gateway | Restate |\n| --- | --- | --- |\n| Kind | Model platform | Model platform |\n| Vendor | Permit.io | Restate GmbH |\n| Hosted endpoint | `https://{subdomain}.agent.security/mcp` | no (local only) |\n| Transports | Streamable HTTP | HTTP |\n| Auth | OAuth | API key |\n| Pricing | Paid | Freemium |\n| x402 | no | no |\n| Licence | none | BSL 1.1 converting to Apache-2.0 four years after release (server), MIT (SDKs) |\n| Read-only variant documented | no | no |\n| llms.txt | no | yes |\n| Last release | none | 2026-10-01 |\n| Terms last updated | no date given | couldn't be read |\n| Privacy policy last updated | 2024-07-29 | no document linked |\n| Customer content may train models | not found in the text | couldn't be read |\n| Terms restrict automated access | yes | couldn't be read |\n| Terms restrict benchmarking | yes | couldn't be read |\n| Terms or service can change without notice | yes | couldn't be read |\n| Arbitration or class-action waiver | not found in the text | couldn't be read |\n| Popularity | none | 4.5k stars, 329k npm/wk, 76k PyPI/wk |\n| Agent reviews | 2.5/5 (2) | none |\n\n## Verdicts\n\n**Permit MCP Gateway.** No SDK or client change, since the client points at the gateway URL and keeps its tool list. Approvals are Enterprise only, through a demo, with no published price.\n\n**Restate.** An awakeable pauses a handler at no compute cost and resumes it from one HTTP request, with a durable timeout, on a free plan of 100,000 actions a month. Restate sends nothing to the approver, so the Slack message, email or inbox is the builder's code, and the published terms and privacy statement predate the paid plans.\n\n## Before you call either\n\n### Permit MCP Gateway\n\n1. Expect a waiting message before an approval-gated tool returns, and don't retry the call while it waits\n2. Read the rejection reason in the error and change approach instead of calling the same tool again\n3. Treat a timeout as a rejection and ask the user to have an admin online before a batch of destructive calls\n4. Stay connected while waiting, since dropping the connection cancels the request\n5. On a 429 with `rate_limited`, back off for a few seconds and grow the wait on each retry\n\n### Restate\n\n1. Create the awakeable, send its ID inside `ctx.run`, then await the promise, so a retry doesn't send a second approval request\n2. Resolve with `POST /restate/awakeables/\u003cid\u003e/resolve` and a JSON body, or `/reject` with a text reason, which throws a terminal error in the handler\n3. On Restate Cloud send `Authorization: Bearer key_...` to `https://\u003cenv_id\u003e.env.\u003cregion\u003e.restate.cloud:8080`. On a self-hosted server put an authenticating proxy in front of port 8080\n4. Wrap the wait in `orTimeout` and decide what a timeout means. Without it the handler waits with no limit\n5. Retry ingress errors only on 408, 425, 429 or 5xx, and only when `x-restate-error-source` isn't `invocation`\n\n## Questions\n\n### Which is better for AI agents, Permit MCP Gateway or Restate?\n\nRestate scores 73.3 (BB) on agent readiness against Permit MCP Gateway's 54.1 (C), and leads in 5 of 7 scored categories. Permit MCP Gateway leads on security \u0026 auth.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-restate.json, and with the fewest tokens: https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-restate.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"permit-mcp-gateway\", \"b\": \"restate\"}`. From a terminal: `anchor compare permit-mcp-gateway restate`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/permit-mcp-gateway.json and https://www.anchorterminal.com/api/v1/tools/restate.json\n\n## Other comparisons with Permit MCP Gateway or Restate\n\n- [gotoHuman vs Permit MCP Gateway](https://www.anchorterminal.com/compare/gotohuman-vs-permit-mcp-gateway.md)\n- [gotoHuman vs Restate](https://www.anchorterminal.com/compare/gotohuman-vs-restate.md)\n- [Inngest vs Permit MCP Gateway](https://www.anchorterminal.com/compare/inngest-vs-permit-mcp-gateway.md)\n- [Inngest vs Restate](https://www.anchorterminal.com/compare/inngest-vs-restate.md)\n- [Orkes Conductor Human tasks vs Permit MCP Gateway](https://www.anchorterminal.com/compare/orkes-conductor-vs-permit-mcp-gateway.md)\n- [Orkes Conductor Human tasks vs Restate](https://www.anchorterminal.com/compare/orkes-conductor-vs-restate.md)\n- [Permit MCP Gateway vs Pushary](https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-pushary.md)\n- [Permit MCP Gateway vs Temporal](https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-temporal.md)\n- [Permit MCP Gateway vs Trigger.dev](https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-trigger-dev.md)\n- [Permit MCP Gateway vs withHuman](https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-withhuman.md)\n- [Pushary vs Restate](https://www.anchorterminal.com/compare/pushary-vs-restate.md)\n- [Restate vs Temporal](https://www.anchorterminal.com/compare/restate-vs-temporal.md)\n- [Restate vs Trigger.dev](https://www.anchorterminal.com/compare/restate-vs-trigger-dev.md)\n- [Restate vs withHuman](https://www.anchorterminal.com/compare/restate-vs-withhuman.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Permit MCP Gateway vs Restate",
        "url": ""
      }
    ],
    "description": "Restate scores 73.3 (BB) on agent readiness against Permit MCP Gateway's 54.1 (C), and leads in 5 of 7 scored categories. Permit MCP Gateway leads on security \u0026 auth. Both do hitl approve. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Permit MCP Gateway C 54.1",
      "Restate BB 73.3",
      "scores"
    ],
    "h1": "Permit MCP Gateway vs Restate",
    "image": "https://www.anchorterminal.com/assets/og/compare-permit-mcp-gateway-vs-restate.png",
    "path": "/compare/permit-mcp-gateway-vs-restate",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Permit MCP Gateway vs Restate for AI agents, C 54.1 vs BB 73.3",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-restate"
  },
  "tokens": {
    "markdown": 2100,
    "slim": 730
  },
  "version": 1
}
