

Permit MCP Gateway
Authentication, fine-grained authorization, consent, and audit, so your agents can move fast without turning your SaaS and data into open desert.

Deploy AI agents with confidence.
Per-tool authorization, human consent,
and an audit log for every call.

Platform Overview
See It In Action
01/04
Drop-in proxy for any server that speaks MCP. Your MCP servers stay unchanged.
https://your-gateway.agent.security/mcp?upstream_mcp=https://api.salesforce.com/platform/mcp/v1-beta.2/sobject-all
https://your-gateway.agent.security/mcp?upstream_mcp=https://api.githubcopilot.com/mcp/
https://your-gateway.agent.security/mcp?upstream_mcp=https://mcp.slack.com/mcp
https://your-gateway.agent.security/mcp?upstream_mcp=https://gdrive.googleapis.com/mcp
https://your-gateway.agent.security/mcp?upstream_mcp=https://mcp.atlassian.com/v1/mcp
https://your-gateway.agent.security/mcp?upstream_mcp=https://mcp.atlassian.com/v1/mcp
https://your-gateway.agent.security/mcp?upstream_mcp=https://mcp.hubspot.com
https://your-gateway.agent.security/mcp?upstream_mcp=https://mcp.notion.com/mcp
https://your-gateway.agent.security/mcp?upstream_mcp=https://mcp.linear.app/mcp
https://your-gateway.agent.security/mcp?upstream_mcp=https://mcp.neon.tech/mcp
https://your-gateway.agent.security/mcp?upstream_mcp=https://mcp.stripe.com
https://your-gateway.agent.security/mcp?upstream_mcp=https://<account>.snowflakecomputing.com/api/v2/mcp
https://your-gateway.agent.security/mcp?upstream_mcp=https://mcp.mongodb.com
https://your-gateway.agent.security/mcp?upstream_mcp=https://knowledge-mcp.global.api.aws
https://your-gateway.agent.security/mcp?upstream_mcp=https://mcp.figma.com/mcp
https://your-gateway.agent.security/mcp?upstream_mcp=https://mcp.zendesk.com/mcp
Your agents can reach Notion, Google, Salesforce, ticketing, code, infra, in milliseconds. That's powerful. It's also a new blast radius.
Gartner's take: Gartner describes “guardian agents” as AI-based technologies that support trustworthy and secure AI, including by monitoring agents and redirecting or blocking their actions.

Permit MCP Gateway is an MCP gateway that enforces policy on every tool call,
Purpose-built for Identity + Delegation + Least Privilege
An MCP gateway is a proxy between MCP clients, such as Cursor or Claude, and the MCP servers they call. Permit MCP Gateway authenticates the human behind each agent, checks every tool call against policy in Permit, confirms consent, and logs the decision. You configure once; the gateway enforces on every call.
Agentic identity
Agentic identity
Human, consent, and intent, bound together and checked against policy on every tool call.
One agent action, four enforcement points
Sign users in with SAML or OIDC SSO, Google, GitHub, or Microsoft OAuth, email, or passkeys. The gateway runs the OAuth 2.1 flow for MCP clients and refreshes upstream tokens. No custom auth code required.
Every tool call is checked with Permit before it reaches the MCP server. The gateway generates the policy from your servers, tools, and trust levels, and it works with RBAC, ABAC, and ReBAC.
Users pick an MCP server and a trust level, and see which tools the agent can call before they accept. Admins set the maximum trust level for each user. No frontend work needed.
Each tool call is bound to one human and one agent through a relationship-based (ReBAC) model. Revoke a human's access and their agents lose access to that server on the next call.
Manage hosts, MCP servers, humans, and agents in one admin dashboard, with Permit as the control plane. Policy changes apply on the next tool call.
Every allowed or denied tool call is logged with the human, the agent, the tool, the MCP server, the time, and the reason. Filter in the dashboard or pull entries through the audit log API.
No SDK to install. No agents to rewrite. No MCP servers to modify.
Just configure, consent, connect.
Auto-Classified Tools
Import your MCP servers. The gateway discovers each server's tools, assigns each tool a trust level by risk (low, medium, or high), and generates the Permit policy. You can override any tool's trust level.
Humans Stay in Control
Grant users access to MCP servers and set each user's maximum trust level. When a user connects an agent, the consent screen shows which tools it can call. On Enterprise plans, require human approval for high-risk calls.
Same Protocol, New Powers
Share the gateway URL and the client snippets for Cursor, Claude Desktop, VS Code, or Claude Code. Authentication, authorization, consent, and logging happen at the gateway, and allowed calls reach your MCP server unchanged.
With Agent Interrogation, the gateway exposes one tool first: identify_self. The rest of the catalog unlocks only after the agent identifies itself, and later behavior is compared with that fingerprint to detect drift. Available on request.
Reduces: The risk that one context on a shared client connection uses permissions granted to another, and unnoticed changes in agent behavior.
Capabilities built for agentic AI at scale, from sign-in to audit trail.
Humans
Bring your IdP. Sign users in with SAML or OIDC SSO, OAuth, or email, and tie every tool call to the human behind it.
Agents
The gateway generates Google Zanzibar-style ReBAC policy that combines the trust level a human grants with the ceiling an admin sets. Policies are standard Permit objects that work with RBAC and ABAC too.
Your Security Team Won't Hate
A trust level slider with Allowed and Denied badges for each tool, so users see what an agent can call before they accept. Tools are classified by risk automatically.
Credentials Stay at the Gateway
The gateway runs upstream OAuth, keeps the upstream tokens, and gives the MCP client its own gateway token. Agents never receive your upstream credentials.
By Default
Every decision becomes an audit trail: what happened, when it happened, and why it was allowed or denied.
Drift Detection
When an agent's fingerprint drifts from its baseline, for example after a changed system prompt or a model swap, policy can downgrade trust, require re-consent, or block the call.
Gartner uses the term “guardian agents” for AI-based technologies that monitor other AI agents and can redirect or block their actions. Permit provides the fine-grained control plane and enforcement point that this kind of oversight needs.

Observe every agent tool call, with the human, the agent, and the decision in the audit log
Change trust levels or revoke access, and the next tool call uses the change. Drift can trigger re-consent or approval
Fine-grained enforcement using agentic identity: human delegation, workflow context, and declared intent
For Internal Agents
Let Cursor, Claude, and internal agents use MCP under policy. Limit what they can do on sensitive surfaces such as email, CRM, files, and ticketing.
For Your Customers
If you expose MCP as a product surface, run a gateway host per customer or team, each with its own subdomain, sign-in methods, trust levels, and audit log.

Why Permit
Most “MCP security” products stop at the gateway. Permit's advantage is years building the authorization control plane underneath.
As agentic AI collapses boundaries, the identity stack converges: IGA + PAM + Zero Trust + IAM acting as one system that is real-time, dynamic, and fine-grained.
Permit's hybrid architecture decouples the control plane from the data plane. Keep enforcement close to your workloads and let OPAL push policy updates to your local PDP.

Start in minutes. No infrastructure to manage. Permit handles the control plane so you can focus on building.
Keep MCP traffic inside your network with the gateway and a local PDP next to your workloads, or run the whole stack, control plane included, fully on-premises. Available on Enterprise plans.


Agents won't always go through the gateway. So we're building connectors to detect, alert, and block when agents touch sensitive surfaces outside it. For an agent's direct HTTP calls outside MCP, the HTTP egress proxy applies the same governance today.
“For the first time, we see what’s really happening inside our agentic stack. When something deviates, we know it’s real.”
Enterprise Security Leader
We'll make sure they only go where they're allowed.
Or talk to the Permit team →