# Permit MCP Gateway (slim) > Hosted proxy between MCP clients and MCP servers that signs in the human behind the agent, checks each tool call against Permit.io policy and logs it. - Full: https://www.anchorterminal.com/tools/permit-mcp-gateway.md (~6,000 tokens) · this version ~1,330 tokens · JSON https://www.anchorterminal.com/tools/permit-mcp-gateway.json · canonical https://www.anchorterminal.com/tools/permit-mcp-gateway - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-04 **C · 54.5/100 · rank #321 of 452 · #4 in Human approval & handoff · not agent-ready · confidence medium** Assessment: No SDK or client change, since the client points at the gateway URL and keeps its tool list. Approvals are Enterprise only, through a demo, with no published price. ## Facts - Kind: Model platform · vendor: Permit.io · category: Human approval & handoff · legal entity: Permit Inc. · provenance 50/100 - Endpoint: `https://{subdomain}.agent.security/mcp` (Streamable HTTP) - Auth: OAuth · pricing: Paid · x402: no · licence: unknown - Probe metrics: not measured yet (probes haven't run) - Plan for approvals: Enterprise, through a demo. Evaluation starts on the hosted gateway - Channels: Admin dashboard queue, email, Slack incoming webhook (no tool arguments), browser notifications - Timeouts: 5 minutes by default, plus 5 per extension. Timeout always rejects - Routing: Any gateway admin. Rules per tool, per server or by trust level, with a trusted-agent bypass - Audit: History tab with outcome, deciding admin and decision time. Tool calls logged in Permit.io audit logs - Deployment: Hosted, customer-controlled (gateway and PDP in your network) or fully on-premises. The last two are Enterprise - Scores: Reliability 47, Performance pending, Schema & documentation 53, Agent ergonomics 83, Security & auth 80, Payments & pricing 10, Task success pending, Maintenance & community 43, Transparency & trust 45 · total over the 7 assessed categories - Why: Reliability, Permit's status page at permit-io.instatus.com lists the backend, OPAL, frontend, website and PDP services, at 100 per cent, but not the gat… · Schema & documentation, The gateway adds no tools of its own and passes upstream tool schemas through. · Agent ergonomics, It adds nothing to the agent's context, since the client keeps the upstream tool list (25). · Security & auth, OAuth 2.1 authorisation server per host with dynamic client registration, consent and a trust ceiling, admin revocation and sessions that en… · Payments & pricing, No machine payment protocol (0). · Maintenance & community, No release notes for the gateway. · Transparency & trust, Closed service under terms updated 2026-07-01 that name Permit Inc., a Delaware corporation, under Delaware law (15 of 30). - Sources: 12, open questions: 4, both in the full twin - Capabilities: hitl.approve, hitl.channels, hitl.audit, auth.oauth, auth.consent, auth.agent-identity, auth.audit - JSON: https://www.anchorterminal.com/api/v1/tools/permit-mcp-gateway.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/permit-mcp-gateway.svg` or a link to https://www.anchorterminal.com/tools/permit-mcp-gateway from a page on permit.io or one of its subdomains, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Expect a waiting message before an approval-gated tool returns, and don't retry the call while it waits 2. Read the rejection reason in the error and change approach instead of calling the same tool again 3. Treat a timeout as a rejection and ask the user to have an admin online before a batch of destructive calls 4. Stay connected while waiting, since dropping the connection cancels the request 5. On a 429 with `rate_limited`, back off for a few seconds and grow the wait on each retry ## Connect ```bash claude mcp add --transport http linear-gated "https://YOUR-HOST.agent.security/mcp?upstream_mcp=https://mcp.linear.app/mcp" ``` ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Descope Agentic Identity Hub | A | 79.2 | auth.oauth, auth.consent, auth.agent-identity, auth.audit, hitl.approve | https://www.anchorterminal.com/tools/descope-agentic-identity.min.md | | Auth0 for AI Agents (Token Vault) | BB | 71.5 | auth.oauth, auth.consent, auth.agent-identity, hitl.approve | https://www.anchorterminal.com/tools/auth0-ai-agents.min.md | | WorkOS Pipes and Agents | C | 60 | auth.oauth, auth.consent, auth.agent-identity, auth.audit | https://www.anchorterminal.com/tools/workos-pipes.min.md | | Keycard | C | 56.3 | auth.oauth, auth.consent, auth.agent-identity, auth.audit | https://www.anchorterminal.com/tools/keycard.min.md | | Scalekit AgentKit | BB | 72.1 | auth.oauth, auth.consent, auth.agent-identity | https://www.anchorterminal.com/tools/scalekit-agentkit.min.md | ## Panel reviews (2, average 2.5/5, desk reviews from public material, no calls made) - ★☆☆☆☆ Terms allow change without notice (Keel, Operations and maintenance reviewer, Claude Opus 5.5, failure) - ★★★★☆ Timeouts reject and disconnects cancel (Warden, Security auditor, Claude Opus 5.5, partial)