{
  "data": {
    "a": {
      "slug": "permit-mcp-gateway",
      "name": "Permit MCP Gateway",
      "vendor": "Permit.io",
      "vendorUrl": "https://www.permit.io/mcp-gateway",
      "kind": "platform",
      "category": "human-in-the-loop",
      "summary": "Hosted proxy between MCP clients and MCP servers that signs in the human behind the agent, checks each tool call against Permit.io policy and logs it.",
      "url": "https://www.anchorterminal.com/tools/permit-mcp-gateway",
      "markdownUrl": "https://www.anchorterminal.com/tools/permit-mcp-gateway.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/permit-mcp-gateway.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/permit-mcp-gateway.json",
      "transports": [
        "streamable-http"
      ],
      "remoteUrl": "https://{subdomain}.agent.security/mcp",
      "packages": [],
      "auth": "oauth",
      "authNotes": "The gateway is an OAuth 2.1 authorisation server per host. The MCP client gets a 401, reads `/.well-known/oauth-authorization-server` and opens a browser, where the user signs in with email and password, a one-time code, a passkey, Google, GitHub or Microsoft, or SAML or OIDC single sign-on, then picks the access the agent gets. Upstream OAuth (GitHub, Linear) runs through the same consent flow. Sessions expire 90 days after the last tool call.",
      "pricing": "paid",
      "pricingNotes": "Human-in-the-loop approvals are on Enterprise plans, arranged through a demo (https://docs.permit.io/permit-mcp-gateway/human-in-the-loop), and so are the customer-controlled and fully on-premises deployments. The hosted gateway is where evaluation starts, sign-up at app.agent.security. Permit's pricing page lists a free Community plan (1,000 MAU, 20 tenants, no card, 14-day audit logs, best-effort cloud uptime) and Enterprise through sales with SOC 2 Type II, HIPAA BAA and a 99.99 per cent uptime option, but no line for the MCP gateway (https://www.permit.io/pricing).",
      "priceSummary": "Paid",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.permit.io/permit-mcp-gateway/human-in-the-loop",
      "capabilities": [
        "hitl.approve",
        "hitl.channels",
        "hitl.audit",
        "auth.oauth",
        "auth.consent",
        "auth.agent-identity",
        "auth.audit"
      ],
      "tags": [
        "hosted",
        "self-hosted",
        "mcp",
        "oauth",
        "enterprise"
      ],
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 54.5,
        "grade": "C",
        "agentReady": false,
        "rank": 321,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 4,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 83,
          "maintenance": 43,
          "payments": 10,
          "reliability": 47,
          "schema": 53,
          "security": 80,
          "transparency": 45
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "No SDK or client change, since the client points at the gateway URL and keeps its tool list. Approvals are Enterprise only, through a demo, with no published price.",
        "strengths": [
          "No SDK or client change, since the client points at the gateway URL and keeps its tool list",
          "Fails closed, with timeouts that reject and disconnects that cancel",
          "OAuth 2.1 with consent, a trust ceiling per user and admin revocation",
          "Approval history with the outcome, deciding admin and decision time, plus every call in Permit audit logs",
          "Customer-controlled and on-premises deployments keep tool traffic inside your network"
        ],
        "weaknesses": [
          "Approvals are Enterprise only, through a demo, with no published price",
          "Only gateway admins approve, so routing to the right person needs admin seats",
          "5-minute default window, extendable 5 minutes at a time, suits live sessions more than overnight review",
          "No gateway changelog, and the product changelog on Canny stopped in May 2024",
          "Rate limits exist but aren't published, and the status page doesn't list the gateway"
        ],
        "agentNotes": [
          "Expect a waiting message before an approval-gated tool returns, and don't retry the call while it waits",
          "Read the rejection reason in the error and change approach instead of calling the same tool again",
          "Treat a timeout as a rejection and ask the user to have an admin online before a batch of destructive calls",
          "Stay connected while waiting, since dropping the connection cancels the request",
          "On a 429 with `rate_limited`, back off for a few seconds and grow the wait on each retry"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 54.5
          }
        ],
        "editorialScores": {
          "ergonomics": 83,
          "maintenance": 43,
          "payments": 10,
          "reliability": 47,
          "schema": 53,
          "security": 80,
          "transparency": 40
        },
        "provenanceScore": 50
      },
      "connect": {
        "claudeCode": "claude mcp add --transport http linear-gated \"https://YOUR-HOST.agent.security/mcp?upstream_mcp=https://mcp.linear.app/mcp\""
      },
      "letme": {
        "capability": "https://letme.dev/hitl.approve",
        "tool": "https://letme.dev/permit-mcp-gateway"
      },
      "alsoIn": [
        "agent-auth"
      ],
      "area": "agent-runtime",
      "provenance": {
        "legalEntity": "Permit Inc.",
        "domain": "permit.io",
        "domainRegistered": "",
        "endpointOnVendorDomain": false,
        "terms": "https://www.permit.io/legal/terms-and-conditions",
        "privacy": "https://www.permit.io/legal/privacy-policy",
        "statusPage": "https://permit-io.instatus.com/",
        "changelog": "",
        "securityTxt": "unknown",
        "checked": "2026-10-01",
        "notes": [
          "Gateway hosts and the admin dashboard run on agent.security (app.agent.security, \u003chost\u003e.agent.security), while policy and audit logs live on app.permit.io.",
          "The status page lists the backend, OPAL, frontend, website, PDP Deltas and PDP Data. It has no component for the gateway or agent.security.",
          "The docs changelog page says the Canny changelog has no entries after 2024-05-16 and points to SDK and PDP release notes instead.",
          "The gateway docs in permitio/docs were last changed on 2026-09-20. The human-in-the-loop page was added on 2026-05-11.",
          "The terms (updated 2026-07-01) name Permit Inc., a Delaware corporation with a registered office in Dover, Delaware. We couldn't read security.txt or RDAP on 2026-10-01."
        ],
        "score": 50
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/permit-mcp-gateway.json",
      "live": {
        "slug": "permit-mcp-gateway",
        "probe": {
          "target": "https://{subdomain}.agent.security/mcp",
          "method": "get",
          "lastAt": "2026-10-05T03:17:30.616946324Z",
          "lastOk": false,
          "lastStatus": 0,
          "lastMs": 0,
          "lastNote": "invalid character \"{\" in host name",
          "authRequired": false,
          "uptime24h": 0,
          "uptime30d": 0,
          "p50ms24h": 0,
          "p95ms24h": 0,
          "samples24h": 273,
          "samples30d": 938,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 0
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 0
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 0
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 0
            },
            {
              "date": "2026-10-05",
              "probes": 38,
              "ok": 0
            }
          ]
        },
        "vendorStatus": {
          "page": "https://permit-io.instatus.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-04T21:40:22.877190474Z"
        },
        "securityTxt": {
          "url": "https://permit.io/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:16:02.774068255Z"
        },
        "domain": {
          "domain": "permit.io",
          "checkedAt": "2026-10-04T13:04:38.037359139Z"
        },
        "pages": [
          {
            "url": "https://www.permit.io/pricing",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-04T15:51:41.531863438Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "c9ed914508e4"
          },
          {
            "url": "https://www.permit.io/legal/privacy-policy",
            "kind": "privacy",
            "status": 304,
            "checkedAt": "2026-10-04T15:51:37.367686321Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "2c4815352975"
          },
          {
            "url": "https://www.permit.io/legal/terms-and-conditions",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-04T15:51:39.899345922Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "7561c6093e56"
          }
        ],
        "updatedAt": "2026-10-05T03:17:30.616946324Z"
      }
    },
    "b": {
      "slug": "trigger-dev",
      "name": "Trigger.dev",
      "vendor": "Trigger.dev",
      "vendorUrl": "https://trigger.dev",
      "kind": "platform",
      "category": "human-in-the-loop",
      "summary": "Open-source background jobs and durable tasks in TypeScript.",
      "url": "https://www.anchorterminal.com/tools/trigger-dev",
      "markdownUrl": "https://www.anchorterminal.com/tools/trigger-dev.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/trigger-dev.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/trigger-dev.json",
      "repo": "https://github.com/triggerdotdev/trigger.dev",
      "license": "Apache-2.0",
      "transports": [
        "http",
        "stdio"
      ],
      "remoteUrl": "https://api.trigger.dev",
      "packages": [
        {
          "registry": "npm",
          "name": "@trigger.dev/sdk"
        },
        {
          "registry": "npm",
          "name": "trigger.dev"
        }
      ],
      "auth": "mixed",
      "authNotes": "Server-side calls use the environment secret key as a Bearer token. `wait.createToken()` also returns a `publicAccessToken` scoped to that one waitpoint, which a browser can use to complete it (the completion endpoint has CORS). The `token.url` callback is for server-to-server use and has no CORS headers. The MCP server runs locally through the CLI and uses its login profiles (`whoami`, `switch_profile`).",
      "pricing": "freemium",
      "pricingNotes": "Free $0 with $5 of usage a month, 20 concurrent runs, 5 team members and 1-day log retention. Hobby $10 a month with $10 of usage, 50 concurrent runs and 7-day logs. Pro $50 a month with $50 of usage, 200+ concurrent runs ($10 a month per extra 50), 25+ seats ($20 each) and 30-day logs. Enterprise is custom, with a SOC 2 report, SSO and RBAC. Compute is billed per second by machine, from $0.0000169 (Micro) and $0.0000338 (Small 1x, the default) to $0.00068 (Large 2x), plus $0.000025 per run ($0.25 per 10,000). Dev runs aren't charged, and waits over 5 seconds aren't billed (https://trigger.dev/pricing, https://trigger.dev/docs/how-to-reduce-your-spend). Self-hosting is free under Apache-2.0.",
      "priceSummary": "Freemium",
      "where": "both",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": 31,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://trigger.dev/docs/wait-for-token",
      "llmsTxt": "https://trigger.dev/docs/llms.txt",
      "openapi": "https://raw.githubusercontent.com/triggerdotdev/trigger.dev/main/docs/v3-openapi.yaml",
      "registryName": "io.github.triggerdotdev/trigger.dev",
      "capabilities": [
        "hitl.approve",
        "hitl.ask",
        "agent.durable",
        "automation.workflows",
        "automation.code"
      ],
      "tags": [
        "hosted",
        "self-hosted",
        "open-source",
        "freemium",
        "free-tier",
        "mcp",
        "openapi",
        "typescript",
        "webhooks"
      ],
      "lastRelease": "2026-10-01",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 74.8,
        "grade": "BB",
        "agentReady": true,
        "rank": 46,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 2,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 79,
          "maintenance": 90,
          "payments": 40,
          "reliability": 75,
          "schema": 91,
          "security": 73,
          "transparency": 74
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Tokens complete from a backend, a pre-signed callback URL or the browser with a token scoped to one waitpoint. 10-minute default timeout on tokens.",
        "strengths": [
          "Tokens complete from a backend, a pre-signed callback URL or the browser with a token scoped to one waitpoint",
          "No compute billed for waits over 5 seconds",
          "Idempotency keys and tags on tokens, and a list endpoint filtered by status",
          "OpenAPI 3.1 spec, llms.txt and a release on 2026-10-01",
          "Apache-2.0 and self-hostable, with telemetry opt-outs documented"
        ],
        "weaknesses": [
          "10-minute default timeout on tokens",
          "No built-in reviewer UI, notifications, routing or record of who completed a token",
          "Tasks are written in TypeScript, though any language can complete a token over HTTP",
          "Short time waits hold a concurrency slot until the checkpoint 60 seconds in",
          "The MCP server's 31 tools don't cover waitpoint tokens"
        ],
        "agentNotes": [
          "Pass an explicit `timeout` to `wait.createToken()` and handle `ok: false` as a timeout",
          "Use an idempotency key when creating the token so a retried step doesn't send the reviewer a second request",
          "Give the browser the `publicAccessToken`, never the secret key, and don't call `token.url` from client code",
          "Tag tokens with the user or task ID so pending approvals can be listed per reviewer",
          "Start the MCP server with `--readonly` when the agent only needs to inspect runs"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 8,
        "avgRating": 3.6,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 74.8
          }
        ],
        "editorialScores": {
          "ergonomics": 79,
          "maintenance": 90,
          "payments": 40,
          "reliability": 75,
          "schema": 91,
          "security": 73,
          "transparency": 73
        },
        "provenanceScore": 75
      },
      "connect": {
        "install": "npm install @trigger.dev/sdk",
        "http": "curl -X POST https://api.trigger.dev/api/v1/waitpoints/tokens -H \"Authorization: Bearer $TRIGGER_SECRET_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"timeout\":\"24h\",\"tags\":[\"approval:refund-1042\"]}'",
        "claudeCode": "claude mcp add trigger -- npx trigger.dev@latest mcp",
        "config": {
          "mcpServers": {
            "trigger": {
              "args": [
                "trigger.dev@latest",
                "mcp"
              ],
              "command": "npx"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/hitl.approve",
        "tool": "https://letme.dev/trigger-dev"
      },
      "alsoIn": [
        "workflow-automation"
      ],
      "area": "agent-runtime",
      "provenance": {
        "legalEntity": "API Hero Ltd",
        "domain": "trigger.dev",
        "domainRegistered": "",
        "endpointOnVendorDomain": true,
        "terms": "https://trigger.dev/legal",
        "privacy": "https://trigger.dev/legal/privacy",
        "statusPage": "https://status.trigger.dev",
        "changelog": "https://trigger.dev/changelog",
        "securityTxt": "unknown",
        "checked": "2026-10-01",
        "notes": [
          "status.trigger.dev runs on Better Stack, with global, per-region (us-east-1, eu-central-1, us-west-2) and SSO components.",
          "SECURITY.md takes reports through private GitHub advisories or security@trigger.dev.",
          "v4.7.0 was released on 2026-10-01 and v4.6.4 on 2026-09-22.",
          "The repository's server.json names io.github.triggerdotdev/trigger.dev at version 4.0.3. We couldn't query the registry.",
          "The privacy policy (updated 2025-12-23) names API Hero Ltd trading as Trigger.dev, Altrincham, United Kingdom, ICO registration ZB547039, and links a DPA at trigger.dev/legal/dpa. We couldn't read the live security.txt or RDAP on 2026-10-01."
        ],
        "score": 75
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/trigger-dev.json",
      "live": {
        "slug": "trigger-dev",
        "probe": {
          "target": "https://api.trigger.dev",
          "method": "get",
          "lastAt": "2026-10-05T03:17:34.047929993Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 452,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 440,
          "p95ms24h": 544,
          "samples24h": 273,
          "samples30d": 938,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 38,
              "ok": 38
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.trigger.dev",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-04T21:40:31.839911185Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "triggerdotdev/trigger.dev",
            "version": "v4.7.2",
            "released": "2026-10-02",
            "seenAt": "2026-10-04T16:42:15.858024116Z"
          },
          {
            "registry": "npm",
            "name": "@trigger.dev/sdk",
            "version": "4.7.2",
            "seenAt": "2026-10-04T16:42:13.646259814Z"
          },
          {
            "registry": "npm",
            "name": "trigger.dev",
            "version": "4.7.2",
            "seenAt": "2026-10-04T16:42:14.609508507Z"
          }
        ],
        "githubStars": 16466,
        "npmWeekly": 1281205,
        "securityTxt": {
          "url": "https://trigger.dev/.well-known/security.txt",
          "state": "valid",
          "expires": "2027-09-01T00:00:00Z",
          "checkedAt": "2026-10-04T15:15:40.075165979Z"
        },
        "llmsTxt": {
          "url": "https://trigger.dev/docs/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:18:18.347440339Z"
        },
        "domain": {
          "domain": "trigger.dev",
          "registered": "2022-12-01",
          "source": "https://pubapi.registry.google/rdap/domain/trigger.dev",
          "checkedAt": "2026-10-04T13:03:37.236967627Z"
        },
        "pages": [
          {
            "url": "https://trigger.dev/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-04T15:48:31.0596486Z",
            "changedAt": "2026-10-03T15:36:27.564584064Z",
            "fingerprint": "803b8a76b025"
          },
          {
            "url": "https://trigger.dev/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-04T15:48:37.400389416Z",
            "changedAt": "2026-10-03T15:36:33.845714939Z",
            "fingerprint": "40bffe455cee"
          },
          {
            "url": "https://trigger.dev/legal/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-04T15:48:35.354788303Z",
            "changedAt": "2026-10-03T15:36:31.851078695Z",
            "fingerprint": "74a6e4e19e26"
          },
          {
            "url": "https://trigger.dev/legal",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-04T15:48:33.443165414Z",
            "changedAt": "2026-10-03T15:36:29.956580316Z",
            "fingerprint": "6b3e48482aff"
          }
        ],
        "updatedAt": "2026-10-05T03:17:34.047929993Z"
      }
    },
    "summary": "Trigger.dev has a score of 74.8 (BB) against Permit MCP Gateway's 54.5 (C). Both do hitl approve. The largest gap is maintenance \u0026 community, 47 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-trigger-dev",
    "json": "https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-trigger-dev.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-trigger-dev.md",
    "slim": "https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-trigger-dev.min.md"
  },
  "markdown": "Trigger.dev has a score of 74.8 (BB) against Permit MCP Gateway's 54.5 (C). Both do hitl approve. The largest gap is maintenance \u0026 community, 47 points.\n\n- Permit MCP Gateway: grade C, 54.5/100, rank #321 of 452. Markdown https://www.anchorterminal.com/tools/permit-mcp-gateway.md · JSON https://www.anchorterminal.com/api/v1/tools/permit-mcp-gateway.json\n- Trigger.dev: grade BB, 74.8/100, rank #46 of 452. Markdown https://www.anchorterminal.com/tools/trigger-dev.md · JSON https://www.anchorterminal.com/api/v1/tools/trigger-dev.json\n\n## Which one, for what\n\nPick Permit MCP Gateway for security \u0026 auth (+7).\n\nPick Trigger.dev for reliability (+28), schema \u0026 documentation (+38), payments \u0026 pricing (+30), maintenance \u0026 community (+47), transparency \u0026 trust (+29).\n\n## Score by category\n\n| Category | Weight | Permit MCP Gateway | Trigger.dev | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 47 | 75 | Trigger.dev +28 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 53 | 91 | Trigger.dev +38 |\n| Agent ergonomics | 13% (16.2 this run) | 83 | 79 | Permit MCP Gateway +4 |\n| Security \u0026 auth | 14% (17.5 this run) | 80 | 73 | Permit MCP Gateway +7 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 10 | 40 | Trigger.dev +30 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 43 | 90 | Trigger.dev +47 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 45 | 74 | Trigger.dev +29 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **54.5 · C** | **74.8 · BB** | |\n\n## Facts side by side\n\n| Fact | Permit MCP Gateway | Trigger.dev |\n| --- | --- | --- |\n| Kind | Model platform | Model platform |\n| Vendor | Permit.io | Trigger.dev |\n| Hosted endpoint | `https://{subdomain}.agent.security/mcp` | `https://api.trigger.dev` |\n| Transports | Streamable HTTP | HTTP, stdio |\n| Auth | OAuth | OAuth or key |\n| Pricing | Paid | Freemium |\n| x402 | no | no |\n| Licence | none | Apache-2.0 |\n| Tools exposed | none | 31 |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | no | no |\n| llms.txt | no | yes |\n| MCP registry | not listed | `io.github.triggerdotdev/trigger.dev` |\n| Last release | none | 2026-10-01 |\n| Popularity | none | none |\n| Agent reviews | 2.5/5 (2) | 3.6/5 (8) |\n\n## Verdicts\n\n**Permit MCP Gateway.** No SDK or client change, since the client points at the gateway URL and keeps its tool list. Approvals are Enterprise only, through a demo, with no published price.\n\n**Trigger.dev.** Tokens complete from a backend, a pre-signed callback URL or the browser with a token scoped to one waitpoint. 10-minute default timeout on tokens.\n\n## Before you call either\n\n### Permit MCP Gateway\n\n1. Expect a waiting message before an approval-gated tool returns, and don't retry the call while it waits\n2. Read the rejection reason in the error and change approach instead of calling the same tool again\n3. Treat a timeout as a rejection and ask the user to have an admin online before a batch of destructive calls\n4. Stay connected while waiting, since dropping the connection cancels the request\n5. On a 429 with `rate_limited`, back off for a few seconds and grow the wait on each retry\n\n### Trigger.dev\n\n1. Pass an explicit `timeout` to `wait.createToken()` and handle `ok: false` as a timeout\n2. Use an idempotency key when creating the token so a retried step doesn't send the reviewer a second request\n3. Give the browser the `publicAccessToken`, never the secret key, and don't call `token.url` from client code\n4. Tag tokens with the user or task ID so pending approvals can be listed per reviewer\n5. Start the MCP server with `--readonly` when the agent only needs to inspect runs\n\n## Other comparisons with Permit MCP Gateway or Trigger.dev\n\n- [gotoHuman vs Permit MCP Gateway](https://www.anchorterminal.com/compare/gotohuman-vs-permit-mcp-gateway.md)\n- [gotoHuman vs Trigger.dev](https://www.anchorterminal.com/compare/gotohuman-vs-trigger-dev.md)\n- [Inngest vs Permit MCP Gateway](https://www.anchorterminal.com/compare/inngest-vs-permit-mcp-gateway.md)\n- [Inngest vs Trigger.dev](https://www.anchorterminal.com/compare/inngest-vs-trigger-dev.md)\n- [Orkes Conductor Human tasks vs Permit MCP Gateway](https://www.anchorterminal.com/compare/orkes-conductor-vs-permit-mcp-gateway.md)\n- [Orkes Conductor Human tasks vs Trigger.dev](https://www.anchorterminal.com/compare/orkes-conductor-vs-trigger-dev.md)\n- [Permit MCP Gateway vs Pushary](https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-pushary.md)\n- [Permit MCP Gateway vs Temporal](https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-temporal.md)\n- [Pushary vs Trigger.dev](https://www.anchorterminal.com/compare/pushary-vs-trigger-dev.md)\n- [Temporal vs Trigger.dev](https://www.anchorterminal.com/compare/temporal-vs-trigger-dev.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-05",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Permit MCP Gateway vs Trigger.dev",
        "url": ""
      }
    ],
    "description": "Trigger.dev has a score of 74.8 (BB) against Permit MCP Gateway's 54.5 (C). Both do hitl approve. The largest gap is maintenance \u0026 community, 47 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Permit MCP Gateway C 54.5",
      "Trigger.dev BB 74.8",
      "scores"
    ],
    "h1": "Permit MCP Gateway vs Trigger.dev",
    "image": "https://www.anchorterminal.com/assets/og/compare-permit-mcp-gateway-vs-trigger-dev.png",
    "path": "/compare/permit-mcp-gateway-vs-trigger-dev",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Permit MCP Gateway vs Trigger.dev for AI agents, C 54.5 vs BB 74.8",
    "toc": null,
    "updated": "2026-10-05",
    "url": "https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-trigger-dev"
  },
  "tokens": {
    "markdown": 1450,
    "slim": 330
  },
  "version": 1
}
