Runtime authorization & controls

Permit MCP Gateway

Enforcement proxy placed between MCP clients such as Cursor or Claude Desktop and upstream MCP servers. It authenticates the human behind an agent, checks each tool call against fine-grained policy, records allow and deny decisions, and requires no change to existing MCP servers. Policy authoring depends on Permit's control plane.

commercial · generally available · Research snapshot 2026-09-06

Visit the official product source ↗

Where it fits

Runtime authorization & controls · Agent identity & access

Useful conversation with: IAM manager, Application security lead, Platform engineer.

Ask for a demonstration

Show me a Cursor session where a write-capable MCP tool is denied by policy while a read tool succeeds, then show the audit entry naming the agent and the authorizing human.

Capabilities and evidence

Support labels reflect the supplied research. Documentation and vendor claims are not independent product tests. “Not established” means the researcher did not find support; it does not prove a capability is absent.

Documented by provider

Every MCP tool call proxied through the gateway is authorized in real time against fine-grained Permit.io policy, and denied calls are blocked before reaching the upstream server with a permission error.

Limit: Documentation does not establish enforcement throughput, latency, or behaviour when the policy service is unreachable.

Source s1

Documented by provider

The gateway authenticates users via SSO/OAuth, collects explicit consent, and logs each decision with agent identity, human identity, tool name, MCP server, timestamp and result.

Limit: The retention period and export format of decision logs are not documented on the fetched page.

Source s1

Vendor claim

Existing MCP clients are redirected to a hosted gateway URL that proxies to the upstream MCP server without modifying the server or the tools.

Limit: The product page asserts compatibility with a long list of third-party MCP servers; those specific integrations were not independently verified.

Source s2

Limitations to discuss

Sources

  1. Permit MCP Gateway Overview · Permit.io · official docs
    Access date reported by researcher: 2026-09-06
  2. Permit MCP Gateway | Drop-in Trust for AI Agents · Permit.io · official product
    Access date reported by researcher: 2026-09-06

Listing does not imply partnership, supplier status, a working DutyGraph integration, or a compliance certification.

Suggest a correction