{
  "data": {
    "a": {
      "slug": "permit-mcp-gateway",
      "name": "Permit MCP Gateway",
      "vendor": "Permit.io",
      "vendorUrl": "https://www.permit.io/mcp-gateway",
      "kind": "platform",
      "category": "human-in-the-loop",
      "summary": "Hosted proxy between MCP clients and MCP servers that signs in the human behind the agent, checks each tool call against Permit.io policy and logs it.",
      "url": "https://www.anchorterminal.com/tools/permit-mcp-gateway",
      "markdownUrl": "https://www.anchorterminal.com/tools/permit-mcp-gateway.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/permit-mcp-gateway.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/permit-mcp-gateway.json",
      "transports": [
        "streamable-http"
      ],
      "remoteUrl": "https://{subdomain}.agent.security/mcp",
      "packages": [],
      "auth": "oauth",
      "authNotes": "The gateway is an OAuth 2.1 authorisation server per host. The MCP client gets a 401, reads `/.well-known/oauth-authorization-server` and opens a browser, where the user signs in with email and password, a one-time code, a passkey, Google, GitHub or Microsoft, or SAML or OIDC single sign-on, then picks the access the agent gets. Upstream OAuth (GitHub, Linear) runs through the same consent flow. Sessions expire 90 days after the last tool call.",
      "pricing": "paid",
      "pricingNotes": "Human-in-the-loop approvals are on Enterprise plans, arranged through a demo (https://docs.permit.io/permit-mcp-gateway/human-in-the-loop), and so are the customer-controlled and fully on-premises deployments. The hosted gateway is where evaluation starts, sign-up at app.agent.security. Permit's pricing page lists a free Community plan (1,000 MAU, 20 tenants, no card, 14-day audit logs, best-effort cloud uptime) and Enterprise through sales with SOC 2 Type II, HIPAA BAA and a 99.99 per cent uptime option, but no line for the MCP gateway (https://www.permit.io/pricing).",
      "priceSummary": "Paid",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.permit.io/permit-mcp-gateway/human-in-the-loop",
      "capabilities": [
        "hitl.approve",
        "hitl.channels",
        "hitl.audit",
        "auth.oauth",
        "auth.consent",
        "auth.agent-identity",
        "auth.audit"
      ],
      "tags": [
        "hosted",
        "self-hosted",
        "mcp",
        "oauth",
        "enterprise"
      ],
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 54.1,
        "grade": "C",
        "agentReady": false,
        "rank": 534,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 5,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 83,
          "maintenance": 43,
          "payments": 10,
          "reliability": 47,
          "schema": 53,
          "security": 80,
          "transparency": 41
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "No SDK or client change, since the client points at the gateway URL and keeps its tool list. Approvals are Enterprise only, through a demo, with no published price.",
        "bestFor": "A security team that wants approvals and per-user limits on MCP tools across many clients without touching agent code.",
        "strengths": [
          "No SDK or client change, since the client points at the gateway URL and keeps its tool list",
          "Fails closed, with timeouts that reject and disconnects that cancel",
          "OAuth 2.1 with consent, a trust ceiling per user and admin revocation",
          "Approval history with the outcome, deciding admin and decision time, plus every call in Permit audit logs",
          "Customer-controlled and on-premises deployments keep tool traffic inside your network"
        ],
        "weaknesses": [
          "Approvals are Enterprise only, through a demo, with no published price",
          "Only gateway admins approve, so routing to the right person needs admin seats",
          "5-minute default window, extendable 5 minutes at a time, suits live sessions more than overnight review",
          "No gateway changelog, and the product changelog on Canny stopped in May 2024",
          "Rate limits exist but aren't published, and the status page doesn't list the gateway"
        ],
        "agentNotes": [
          "Expect a waiting message before an approval-gated tool returns, and don't retry the call while it waits",
          "Read the rejection reason in the error and change approach instead of calling the same tool again",
          "Treat a timeout as a rejection and ask the user to have an admin online before a batch of destructive calls",
          "Stay connected while waiting, since dropping the connection cancels the request",
          "On a 429 with `rate_limited`, back off for a few seconds and grow the wait on each retry"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 54.1
          }
        ],
        "editorialScores": {
          "ergonomics": 83,
          "maintenance": 43,
          "payments": 10,
          "reliability": 47,
          "schema": 53,
          "security": 80,
          "transparency": 40
        },
        "provenanceScore": 41
      },
      "connect": {
        "claudeCode": "claude mcp add --transport http linear-gated \"https://YOUR-HOST.agent.security/mcp?upstream_mcp=https://mcp.linear.app/mcp\""
      },
      "letme": {
        "capability": "https://letme.dev/hitl.approve",
        "tool": "https://letme.dev/permit-mcp-gateway"
      },
      "alsoIn": [
        "agent-auth"
      ],
      "area": "agent-runtime",
      "provenance": {
        "legalEntity": "Permit Inc.",
        "domain": "permit.io",
        "domainRegistered": "",
        "endpointOnVendorDomain": false,
        "terms": "https://www.permit.io/legal/terms-and-conditions",
        "privacy": "https://www.permit.io/legal/privacy-policy",
        "statusPage": "https://permit-io.instatus.com/",
        "changelog": "",
        "securityTxt": "unknown",
        "checked": "2026-10-01",
        "notes": [
          "Gateway hosts and the admin dashboard run on agent.security (app.agent.security, \u003chost\u003e.agent.security), while policy and audit logs live on app.permit.io.",
          "The status page lists the backend, OPAL, frontend, website, PDP Deltas and PDP Data. It has no component for the gateway or agent.security.",
          "The docs changelog page says the Canny changelog has no entries after 2024-05-16 and points to SDK and PDP release notes instead.",
          "The gateway docs in permitio/docs were last changed on 2026-09-20. The human-in-the-loop page was added on 2026-05-11.",
          "The terms (updated 2026-07-01) name Permit Inc., a Delaware corporation with a registered office in Dover, Delaware. We couldn't read security.txt or RDAP on 2026-10-01."
        ],
        "score": 41
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/permit-mcp-gateway.json",
      "live": {
        "slug": "permit-mcp-gateway",
        "probe": {
          "target": "https://{subdomain}.agent.security/mcp",
          "method": "get",
          "lastAt": "2026-10-08T21:12:18.250380056Z",
          "lastOk": false,
          "lastStatus": 0,
          "lastMs": 0,
          "lastNote": "invalid character \"{\" in host name",
          "authRequired": false,
          "uptime24h": 0,
          "uptime30d": 0,
          "p50ms24h": 0,
          "p95ms24h": 0,
          "samples24h": 271,
          "samples30d": 1955,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 0
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 0
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 0
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 0
            },
            {
              "date": "2026-10-05",
              "probes": 272,
              "ok": 0
            },
            {
              "date": "2026-10-06",
              "probes": 272,
              "ok": 0
            },
            {
              "date": "2026-10-07",
              "probes": 272,
              "ok": 0
            },
            {
              "date": "2026-10-08",
              "probes": 239,
              "ok": 0
            }
          ]
        },
        "vendorStatus": {
          "page": "https://permit-io.instatus.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-08T19:39:02.527783366Z"
        },
        "securityTxt": {
          "url": "https://permit.io/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:53.197667522Z"
        },
        "domain": {
          "domain": "permit.io",
          "checkedAt": "2026-10-04T13:04:38.037359139Z"
        },
        "pages": [
          {
            "url": "https://www.permit.io/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:29:38.410140158Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "c9ed914508e4"
          },
          {
            "url": "https://www.permit.io/legal/privacy-policy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:29:34.176220109Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "2c4815352975"
          },
          {
            "url": "https://www.permit.io/legal/terms-and-conditions",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:29:36.663304672Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "7561c6093e56"
          }
        ],
        "updatedAt": "2026-10-08T21:12:18.250380056Z"
      }
    },
    "answer": "Permit MCP Gateway scores 54.1 (C) on agent readiness against withHuman's 51.8 (D), and leads in 3 of 7 scored categories. withHuman leads on schema \u0026 documentation, payments \u0026 pricing, maintenance \u0026 community and transparency \u0026 trust.",
    "b": {
      "slug": "withhuman",
      "name": "withHuman",
      "vendor": "Metoro Inc",
      "vendorUrl": "https://withhuman.ai",
      "kind": "http-api",
      "category": "human-in-the-loop",
      "summary": "withHuman is a hosted approval service for AI agents from Metoro Inc. It holds an agent's tool calls for a person to approve or deny through the Agent Approval Protocol API, coding-agent hooks, an MCP gateway and an MCP server.",
      "url": "https://www.anchorterminal.com/tools/withhuman",
      "markdownUrl": "https://www.anchorterminal.com/tools/withhuman.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/withhuman.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/withhuman.json",
      "license": "Proprietary hosted service under Metoro Inc's terms. The site describes an open-source edition, but the repository it links to returned 404 on 8 October 2026",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://app.withhuman.ai",
      "packages": [],
      "auth": "mixed",
      "authNotes": "Five credentials, all sent as `Authorization: Bearer`. An agent credential (`whc_`) is bound to one agent instance and can only create approval requests and wait for decisions. A provisioner token (`whp_`) can only create and manage instances of its agent. A personal API key (`whk_`) follows its owner's permissions, can be narrowed to chosen actions and expires after 90 days by default. An organisation API key (`who_`, Scale plan and above) carries its own permission policies and cannot decide requests. The MCP server at `/api/mcp/v1` signs in with OAuth (authorisation code with PKCE and dynamic client registration) or takes an API key as a bearer token. A person signs up in the browser and connects the first agent.",
      "pricing": "freemium",
      "pricingNotes": "Free hosted plan at $0 for up to 5 members, with unlimited agents and approval requests, email, Slack and Discord, the audit log and the MCP gateway. Scale is $20 per user a month and adds the phone apps, organisation and scoped API keys, single sign-on and directory sync. Enterprise is a custom annual contract. New organisations start on a trial and move to Free without a subscription. Monthly allowances for gateway tool calls and phone messages exist but their numbers aren't on the pricing page (https://withhuman.ai/pricing, checked 2026-10-08).",
      "priceSummary": "$20 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs, the OpenAPI document or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://withhuman.ai/docs",
      "llmsTxt": "https://withhuman.ai/llms.txt",
      "openapi": "https://withhuman.ai/openapi.yaml",
      "capabilities": [
        "hitl.approve",
        "hitl.channels",
        "hitl.audit"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "mcp",
        "oauth",
        "openapi",
        "llms-txt",
        "webhooks",
        "enterprise",
        "early-access"
      ],
      "lastRelease": "2026-10-08",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 51.8,
        "grade": "D",
        "agentReady": false,
        "rank": 573,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 7,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 74,
          "maintenance": 49,
          "payments": 30,
          "reliability": 16,
          "schema": 81,
          "security": 73,
          "transparency": 53
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -2,
        "negativeNotes": [
          "8 October 2026. The home page and pricing page describe an open-source, self-hostable edition and link https://github.com/withHumanAI/withHuman, which returned 404. The withHumanAI organisation listed no public repositories and the protocol repository https://github.com/agentapprovalprotocol/agentapprovalprotocol also returned 404. Counted as a claim the public cannot verify today (-2). Sources https://withhuman.ai/pricing and https://github.com/withHumanAI"
        ],
        "verdict": "The approval API is small and carefully specified, with a public OpenAPI 3.1 document, mandatory idempotency keys and agent credentials that can never approve. The service is in early access under its own terms, with no status page, published rate limits or changelog, and the open-source repository the site links to returned 404 on 8 October 2026.",
        "bestFor": "Teams that want tool calls from coding agents or their own agents held for approval by rules, with escalation and an audit log, and no review UI to build.",
        "strengths": [
          "Public OpenAPI 3.1 document with 116 operations and 148 schemas, plus llms.txt and a Markdown copy of every docs page",
          "`Idempotency-Key` is required on request creation, instance creation and decisions, and a reused key with changed input answers 409",
          "An agent credential can only create requests and wait for decisions. Approving or denying needs a signed-in person or a personal key",
          "The MCP server signs in with OAuth, PKCE and dynamic client registration, across 35 scopes, with access lasting 90 days or until revoked",
          "Free hosted plan at $0 for up to 5 members with unlimited agents and approval requests, per the pricing page"
        ],
        "weaknesses": [
          "The terms say the service is in early access, and the API document is version 0.1.0",
          "No status page, published request rate limits, SLA outside an enterprise contract, or changelog found",
          "The GitHub repository the site links as its open-source edition returned 404 on 8 October 2026, and the organisation lists no public repositories",
          "No SDK found on npm or PyPI. Integration is the HTTP API, the CLI hooks or the MCP gateway",
          "The site footer says SOC 2 Type II with no report, auditor or trust page, and neither host serves a security.txt"
        ],
        "agentNotes": [
          "Send an `Idempotency-Key` header on `POST /api/aap/v1/requests`. The call answers 400 without one",
          "Read the decision with `GET /api/aap/v1/requests/{id}?wait=30s` and repeat while `status` is `pending`. `wait` is capped at 30 seconds",
          "Set `timeout` between one second and seven days, and treat `expired` and `cancelled` as a refusal",
          "Start an approved call within five minutes of `decided_at`, because the decision carries an `expires_at`",
          "Cancel a request when you stop waiting, so reviewers stop seeing it"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "D",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 51.8
          }
        ],
        "editorialScores": {
          "ergonomics": 74,
          "maintenance": 49,
          "payments": 30,
          "reliability": 16,
          "schema": 81,
          "security": 73,
          "transparency": 52
        },
        "provenanceScore": 53
      },
      "connect": {
        "install": "curl -fsSL https://downloads.withhuman.ai/install.sh | sh -s -- onboard",
        "http": "curl -X POST \"https://app.withhuman.ai/api/aap/v1/requests\" \\\n  -H \"Authorization: Bearer $WITHHUMAN_TOKEN\" \\\n  -H \"Idempotency-Key: 4f1c9a2e-7b3d-4e8f-a1c5-2d6b8e0f9a31\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{ \"tool\": \"Bash\", \"arguments\": { \"command\": \"rm -rf build\" }, \"timeout\": \"30m\" }'",
        "claudeCode": "claude mcp add --transport http --scope user withhuman https://app.withhuman.ai/api/mcp/v1",
        "config": {
          "mcpServers": {
            "withhuman": {
              "url": "https://app.withhuman.ai/api/mcp/v1"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/hitl.approve",
        "tool": "https://letme.dev/withhuman"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Scale plan",
          "unit": "seat-month",
          "usd": 20,
          "note": "Free plan covers up to 5 members"
        }
      ],
      "provenance": {
        "legalEntity": "Metoro Inc",
        "domain": "withhuman.ai",
        "domainRegistered": "2026-07-13",
        "endpointOnVendorDomain": true,
        "terms": "https://withhuman.ai/terms",
        "privacy": "https://withhuman.ai/privacy",
        "statusPage": "",
        "changelog": "",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The terms (effective 4 September 2026) are between the user and Metoro Inc, which operates withHuman, and cover the hosted service, the iPhone app and the website. Delaware law governs.",
          "The privacy policy (effective 4 September 2026) calls Metoro Inc a Delaware corporation and covers approval requests, decisions and audit records as well as the website.",
          "RDAP for withhuman.ai gives a registration date of 2026-07-13.",
          "https://withhuman.ai/.well-known/security.txt and https://app.withhuman.ai/.well-known/security.txt both returned 404 on 2026-10-08.",
          "No status page is linked from the site, the docs or the support page, and status.withhuman.ai did not connect. No changelog was found, and the blog says coming soon.",
          "The API and the MCP server answer at app.withhuman.ai, and the CLI downloads from downloads.withhuman.ai."
        ],
        "score": 53
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/withhuman.json",
      "live": {
        "slug": "withhuman",
        "probe": {
          "target": "https://app.withhuman.ai",
          "method": "get",
          "lastAt": "2026-10-08T21:12:25.989084443Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 184,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 168,
          "p95ms24h": 230,
          "samples24h": 21,
          "samples30d": 21,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 21,
              "ok": 21
            }
          ]
        },
        "updatedAt": "2026-10-08T21:12:25.989084443Z"
      }
    },
    "facts": [
      {
        "a": "Model platform",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Permit.io",
        "b": "Metoro Inc",
        "name": "Vendor"
      },
      {
        "a": "https://{subdomain}.agent.security/mcp",
        "b": "https://app.withhuman.ai",
        "name": "Hosted endpoint"
      },
      {
        "a": "Streamable HTTP",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Paid",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "none",
        "b": "Proprietary hosted service under Metoro Inc's terms. The site describes an open-source edition, but the repository it links to returned 404 on 8 October 2026",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "no",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "none",
        "b": "2026-10-08",
        "name": "Last release"
      },
      {
        "a": "no date given",
        "b": "2026-09-04",
        "name": "Terms last updated"
      },
      {
        "a": "2024-07-29",
        "b": "2026-09-04",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "2.5/5 (2)",
        "b": "none",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Permit MCP Gateway scores 54.1 (C) on agent readiness against withHuman's 51.8 (D), and leads in 3 of 7 scored categories. withHuman leads on schema \u0026 documentation, payments \u0026 pricing, maintenance \u0026 community and transparency \u0026 trust.",
        "question": "Which is better for AI agents, Permit MCP Gateway or withHuman?"
      },
      {
        "answer": "Yes. Permit MCP Gateway has a hosted endpoint at https://{subdomain}.agent.security/mcp and withHuman at https://app.withhuman.ai.",
        "question": "Can an agent call Permit MCP Gateway and withHuman without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 47 against 16",
          "Agent ergonomics, 83 against 74",
          "Security \u0026 auth, 80 against 73"
        ],
        "also": null,
        "goodFor": "A security team that wants approvals and per-user limits on MCP tools across many clients without touching agent code.",
        "slug": "permit-mcp-gateway",
        "watchFor": "Approvals are Enterprise only, through a demo, with no published price"
      },
      {
        "aheadOn": [
          "Schema \u0026 documentation, 81 against 53",
          "Payments \u0026 pricing, 30 against 10",
          "Maintenance \u0026 community, 49 against 43",
          "Transparency \u0026 trust, 53 against 41"
        ],
        "also": null,
        "goodFor": "Teams that want tool calls from coding agents or their own agents held for approval by rules, with escalation and an audit log, and no review UI to build.",
        "slug": "withhuman",
        "watchFor": "The terms say the service is in early access, and the API document is version 0.1.0"
      }
    ],
    "job": {
      "capability": "hitl.approve",
      "name": "Hitl approve"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/gotohuman-vs-permit-mcp-gateway.json",
        "title": "gotoHuman vs Permit MCP Gateway",
        "url": "https://www.anchorterminal.com/compare/gotohuman-vs-permit-mcp-gateway"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gotohuman-vs-withhuman.json",
        "title": "gotoHuman vs withHuman",
        "url": "https://www.anchorterminal.com/compare/gotohuman-vs-withhuman"
      },
      {
        "json": "https://www.anchorterminal.com/compare/inngest-vs-permit-mcp-gateway.json",
        "title": "Inngest vs Permit MCP Gateway",
        "url": "https://www.anchorterminal.com/compare/inngest-vs-permit-mcp-gateway"
      },
      {
        "json": "https://www.anchorterminal.com/compare/inngest-vs-withhuman.json",
        "title": "Inngest vs withHuman",
        "url": "https://www.anchorterminal.com/compare/inngest-vs-withhuman"
      },
      {
        "json": "https://www.anchorterminal.com/compare/orkes-conductor-vs-permit-mcp-gateway.json",
        "title": "Orkes Conductor Human tasks vs Permit MCP Gateway",
        "url": "https://www.anchorterminal.com/compare/orkes-conductor-vs-permit-mcp-gateway"
      },
      {
        "json": "https://www.anchorterminal.com/compare/orkes-conductor-vs-withhuman.json",
        "title": "Orkes Conductor Human tasks vs withHuman",
        "url": "https://www.anchorterminal.com/compare/orkes-conductor-vs-withhuman"
      },
      {
        "json": "https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-pushary.json",
        "title": "Permit MCP Gateway vs Pushary",
        "url": "https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-pushary"
      },
      {
        "json": "https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-restate.json",
        "title": "Permit MCP Gateway vs Restate",
        "url": "https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-restate"
      },
      {
        "json": "https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-temporal.json",
        "title": "Permit MCP Gateway vs Temporal",
        "url": "https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-temporal"
      },
      {
        "json": "https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-trigger-dev.json",
        "title": "Permit MCP Gateway vs Trigger.dev",
        "url": "https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-trigger-dev"
      },
      {
        "json": "https://www.anchorterminal.com/compare/pushary-vs-withhuman.json",
        "title": "Pushary vs withHuman",
        "url": "https://www.anchorterminal.com/compare/pushary-vs-withhuman"
      },
      {
        "json": "https://www.anchorterminal.com/compare/restate-vs-withhuman.json",
        "title": "Restate vs withHuman",
        "url": "https://www.anchorterminal.com/compare/restate-vs-withhuman"
      },
      {
        "json": "https://www.anchorterminal.com/compare/temporal-vs-withhuman.json",
        "title": "Temporal vs withHuman",
        "url": "https://www.anchorterminal.com/compare/temporal-vs-withhuman"
      },
      {
        "json": "https://www.anchorterminal.com/compare/trigger-dev-vs-withhuman.json",
        "title": "Trigger.dev vs withHuman",
        "url": "https://www.anchorterminal.com/compare/trigger-dev-vs-withhuman"
      }
    ],
    "scores": [
      {
        "by": 31,
        "edge": "permit-mcp-gateway",
        "key": "reliability",
        "name": "Reliability",
        "permit-mcp-gateway": 47,
        "weight": 16,
        "withhuman": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 28,
        "edge": "withhuman",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "permit-mcp-gateway": 53,
        "weight": 13,
        "withhuman": 81
      },
      {
        "by": 9,
        "edge": "permit-mcp-gateway",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "permit-mcp-gateway": 83,
        "weight": 13,
        "withhuman": 74
      },
      {
        "by": 7,
        "edge": "permit-mcp-gateway",
        "key": "security",
        "name": "Security \u0026 auth",
        "permit-mcp-gateway": 80,
        "weight": 14,
        "withhuman": 73
      },
      {
        "by": 20,
        "edge": "withhuman",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "permit-mcp-gateway": 10,
        "weight": 10,
        "withhuman": 30
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 6,
        "edge": "withhuman",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "permit-mcp-gateway": 43,
        "weight": 7,
        "withhuman": 49
      },
      {
        "by": 12,
        "edge": "withhuman",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "permit-mcp-gateway": 41,
        "weight": 7,
        "withhuman": 53
      }
    ],
    "summary": "Permit MCP Gateway scores 54.1 (C) on agent readiness against withHuman's 51.8 (D), and leads in 3 of 7 scored categories. withHuman leads on schema \u0026 documentation, payments \u0026 pricing, maintenance \u0026 community and transparency \u0026 trust. Both do hitl approve.",
    "verdicts": {
      "permit-mcp-gateway": "No SDK or client change, since the client points at the gateway URL and keeps its tool list. Approvals are Enterprise only, through a demo, with no published price.",
      "withhuman": "The approval API is small and carefully specified, with a public OpenAPI 3.1 document, mandatory idempotency keys and agent credentials that can never approve. The service is in early access under its own terms, with no status page, published rate limits or changelog, and the open-source repository the site links to returned 404 on 8 October 2026."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-withhuman",
    "json": "https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-withhuman.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-withhuman.md",
    "slim": "https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-withhuman.min.md"
  },
  "markdown": "Permit MCP Gateway scores 54.1 (C) on agent readiness against withHuman's 51.8 (D), and leads in 3 of 7 scored categories. withHuman leads on schema \u0026 documentation, payments \u0026 pricing, maintenance \u0026 community and transparency \u0026 trust. Both do hitl approve.\n\n- Permit MCP Gateway: grade C, 54.1/100, rank #534 of 722. Markdown https://www.anchorterminal.com/tools/permit-mcp-gateway.md · JSON https://www.anchorterminal.com/api/v1/tools/permit-mcp-gateway.json\n- withHuman: grade D, 51.8/100, rank #573 of 722. Markdown https://www.anchorterminal.com/tools/withhuman.md · JSON https://www.anchorterminal.com/api/v1/tools/withhuman.json\n\n## Which one, for what\n\n### Permit MCP Gateway (C)\n\nGood for: A security team that wants approvals and per-user limits on MCP tools across many clients without touching agent code.\n\nAhead on:\n- Reliability, 47 against 16\n- Agent ergonomics, 83 against 74\n- Security \u0026 auth, 80 against 73\n\nWatch for: Approvals are Enterprise only, through a demo, with no published price\n\n### withHuman (D)\n\nGood for: Teams that want tool calls from coding agents or their own agents held for approval by rules, with escalation and an audit log, and no review UI to build.\n\nAhead on:\n- Schema \u0026 documentation, 81 against 53\n- Payments \u0026 pricing, 30 against 10\n- Maintenance \u0026 community, 49 against 43\n- Transparency \u0026 trust, 53 against 41\n\nWatch for: The terms say the service is in early access, and the API document is version 0.1.0\n\n\n## Score by category\n\n| Category | Weight | Permit MCP Gateway | withHuman | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 47 | 16 | Permit MCP Gateway +31 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 53 | 81 | withHuman +28 |\n| Agent ergonomics | 13% (16.2 this run) | 83 | 74 | Permit MCP Gateway +9 |\n| Security \u0026 auth | 14% (17.5 this run) | 80 | 73 | Permit MCP Gateway +7 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 10 | 30 | withHuman +20 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 43 | 49 | withHuman +6 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 41 | 53 | withHuman +12 |\n| Negative events | ≤15 | 0 | -2 | |\n| **Total** | | **54.1 · C** | **51.8 · D** | |\n\n## Facts side by side\n\n| Fact | Permit MCP Gateway | withHuman |\n| --- | --- | --- |\n| Kind | Model platform | HTTP API |\n| Vendor | Permit.io | Metoro Inc |\n| Hosted endpoint | `https://{subdomain}.agent.security/mcp` | `https://app.withhuman.ai` |\n| Transports | Streamable HTTP | HTTP |\n| Auth | OAuth | OAuth or key |\n| Pricing | Paid | Freemium |\n| x402 | no | no |\n| Licence | none | Proprietary hosted service under Metoro Inc's terms. The site describes an open-source edition, but the repository it links to returned 404 on 8 October 2026 |\n| Read-only variant documented | no | no |\n| llms.txt | no | yes |\n| Last release | none | 2026-10-08 |\n| Terms last updated | no date given | 2026-09-04 |\n| Privacy policy last updated | 2024-07-29 | 2026-09-04 |\n| Customer content may train models | not found in the text | not found in the text |\n| Terms restrict automated access | yes | not found in the text |\n| Terms restrict benchmarking | yes | not found in the text |\n| Terms or service can change without notice | yes | not found in the text |\n| Arbitration or class-action waiver | not found in the text | not found in the text |\n| Agent reviews | 2.5/5 (2) | none |\n\n## Verdicts\n\n**Permit MCP Gateway.** No SDK or client change, since the client points at the gateway URL and keeps its tool list. Approvals are Enterprise only, through a demo, with no published price.\n\n**withHuman.** The approval API is small and carefully specified, with a public OpenAPI 3.1 document, mandatory idempotency keys and agent credentials that can never approve. The service is in early access under its own terms, with no status page, published rate limits or changelog, and the open-source repository the site links to returned 404 on 8 October 2026.\n\n## Before you call either\n\n### Permit MCP Gateway\n\n1. Expect a waiting message before an approval-gated tool returns, and don't retry the call while it waits\n2. Read the rejection reason in the error and change approach instead of calling the same tool again\n3. Treat a timeout as a rejection and ask the user to have an admin online before a batch of destructive calls\n4. Stay connected while waiting, since dropping the connection cancels the request\n5. On a 429 with `rate_limited`, back off for a few seconds and grow the wait on each retry\n\n### withHuman\n\n1. Send an `Idempotency-Key` header on `POST /api/aap/v1/requests`. The call answers 400 without one\n2. Read the decision with `GET /api/aap/v1/requests/{id}?wait=30s` and repeat while `status` is `pending`. `wait` is capped at 30 seconds\n3. Set `timeout` between one second and seven days, and treat `expired` and `cancelled` as a refusal\n4. Start an approved call within five minutes of `decided_at`, because the decision carries an `expires_at`\n5. Cancel a request when you stop waiting, so reviewers stop seeing it\n\n## Questions\n\n### Which is better for AI agents, Permit MCP Gateway or withHuman?\n\nPermit MCP Gateway scores 54.1 (C) on agent readiness against withHuman's 51.8 (D), and leads in 3 of 7 scored categories. withHuman leads on schema \u0026 documentation, payments \u0026 pricing, maintenance \u0026 community and transparency \u0026 trust.\n\n### Can an agent call Permit MCP Gateway and withHuman without installing anything?\n\nYes. Permit MCP Gateway has a hosted endpoint at https://{subdomain}.agent.security/mcp and withHuman at https://app.withhuman.ai.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-withhuman.json, and with the fewest tokens: https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-withhuman.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"permit-mcp-gateway\", \"b\": \"withhuman\"}`. From a terminal: `anchor compare permit-mcp-gateway withhuman`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/permit-mcp-gateway.json and https://www.anchorterminal.com/api/v1/tools/withhuman.json\n\n## Other comparisons with Permit MCP Gateway or withHuman\n\n- [gotoHuman vs Permit MCP Gateway](https://www.anchorterminal.com/compare/gotohuman-vs-permit-mcp-gateway.md)\n- [gotoHuman vs withHuman](https://www.anchorterminal.com/compare/gotohuman-vs-withhuman.md)\n- [Inngest vs Permit MCP Gateway](https://www.anchorterminal.com/compare/inngest-vs-permit-mcp-gateway.md)\n- [Inngest vs withHuman](https://www.anchorterminal.com/compare/inngest-vs-withhuman.md)\n- [Orkes Conductor Human tasks vs Permit MCP Gateway](https://www.anchorterminal.com/compare/orkes-conductor-vs-permit-mcp-gateway.md)\n- [Orkes Conductor Human tasks vs withHuman](https://www.anchorterminal.com/compare/orkes-conductor-vs-withhuman.md)\n- [Permit MCP Gateway vs Pushary](https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-pushary.md)\n- [Permit MCP Gateway vs Restate](https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-restate.md)\n- [Permit MCP Gateway vs Temporal](https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-temporal.md)\n- [Permit MCP Gateway vs Trigger.dev](https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-trigger-dev.md)\n- [Pushary vs withHuman](https://www.anchorterminal.com/compare/pushary-vs-withhuman.md)\n- [Restate vs withHuman](https://www.anchorterminal.com/compare/restate-vs-withhuman.md)\n- [Temporal vs withHuman](https://www.anchorterminal.com/compare/temporal-vs-withhuman.md)\n- [Trigger.dev vs withHuman](https://www.anchorterminal.com/compare/trigger-dev-vs-withhuman.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Permit MCP Gateway vs withHuman",
        "url": ""
      }
    ],
    "description": "Permit MCP Gateway scores 54.1 (C) on agent readiness against withHuman's 51.8 (D), and leads in 3 of 7 scored categories. withHuman leads on schema \u0026 documentation, payments \u0026 pricing, maintenance \u0026 community and transparency \u0026 trust. Both do hitl approve. Category scores…",
    "facts": [
      "Permit MCP Gateway C 54.1",
      "withHuman D 51.8",
      "scores"
    ],
    "h1": "Permit MCP Gateway vs withHuman",
    "image": "https://www.anchorterminal.com/assets/og/compare-permit-mcp-gateway-vs-withhuman.png",
    "path": "/compare/permit-mcp-gateway-vs-withhuman",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Permit MCP Gateway vs withHuman for AI agents, C 54.1 vs D 51.8",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-withhuman"
  },
  "tokens": {
    "markdown": 2100,
    "slim": 730
  },
  "version": 1
}
