# Permit.io

**Canonical:** https://apis.io/providers/permit-io/  
**Website:** https://www.permit.io  
**APIs profiled:** 43

Permit.io is an authorization-as-a-service platform that helps developers build, manage, and enforce fine-grained access control in their applications. It provides a Policy Decision Point (PDP), management API, REST API, and permission query APIs for role-based, attribute-based, and relationship-based access control with support for bulk checks, data filtering, and URL-based enforcement.

## Kin Score — 40.8 / 100 (developing)

Scored 2026-08-25 under rubric 0.14.0. Trend: flat (+0.0 from 40.8).

| Facet | Score |
|---|---|
| Discoverability | 74.1 |
| Contract Quality | 55.3 |
| Governance | 0.0 |
| Contract Governance | 0.0 |
| Operational Transparency | 21.1 |
| Developer Ergonomics | 31.0 |
| Commercial Clarity | 47.4 |
| Access Clarity | 47.4 |

Regulatory layer — **Insurance**: 34.8 (matched via tags).

## Agent readiness — 32.3 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | documented |
| MCP Server | no |
| Auth Clarity | bearer |
| Idempotency | no |
| Error Semantics | verified |
| OpenAPI Examples | verified |
| Rate Limit Signal | documented |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |
| Delegated Identity | no |
| Protected Resource Metadata | no |
| Dynamic Client Registration | no |
| Agentic Commerce | no |

## Access

Freemium · Self-serve signup — onboarding: self-serve, pricing: freemium, trial: no (confidence: high).

## APIs (43)

- **Permit.io Access Requests (EAP) API** — None
- **Permit.io Activity Log API** — The Activity Log API from Permit.io — 2 operation(s) for activity log.
- **Permit.io API History API** — The API History API from Permit.io — 4 operation(s) for api history.
- **Permit.io API Keys API** — The API Keys API from Permit.io — 5 operation(s) for api keys.
- **Permit.io Audit Elements Data API** — The Audit Elements Data API from Permit.io — 1 operation(s) for audit elements data.
- **Permit.io Audit Log Replay API** — The Audit Log Replay API from Permit.io — 1 operation(s) for audit log replay.
- **Permit.io Audit Logs API** — The Audit Logs API from Permit.io — 2 operation(s) for audit logs.
- **Permit.io Bulk Operations API** — None
- **Permit.io Condition Set Rules API** — Represents a "mini" ABAC rule comprised of (UserSet, Action, ResourceSet). If such tuple exists, it means all users matching the UserSet can perform the Action on the resources ...
- **Permit.io Condition Sets API** — Condition sets are sets of objects that are dynamically defined based on conditions on the objects' attributes. Conditions sets allows you the flexibility of ABAC with the simpl...
- **Permit.io Deprecated API** — The Deprecated API from Permit.io — 6 operation(s) for deprecated.
- **Permit.io Elements Configs (EAP) API** — The Elements Configs (EAP) API from Permit.io — 4 operation(s) for elements configs (eap).
- **Permit.io Email Configurations API** — None
- **Permit.io Email Templates API** — None
- **Permit.io Environments API** — Environments are silos contained within projects that enables you to safely iterate on changes. Environments allow you to manage your policy throughout your entire development l...
- **Permit.io Groups API** — The Groups API from Permit.io — 10 operation(s) for groups.
- **Permit.io Implicit Grants API** — The Implicit Grants API from Permit.io — 2 operation(s) for implicit grants.
- **Permit.io Invites API** — The Invites API from Permit.io — 2 operation(s) for invites.
- **Permit.io Members API** — The Members API from Permit.io — 3 operation(s) for members.
- **Permit.io OPAL Data ( EAP ) API** — The OPAL Data ( EAP ) API from Permit.io — 6 operation(s) for opal data ( eap ).
- **Permit.io Operation Approval (EAP) API** — The Operation Approval (EAP) API from Permit.io — 6 operation(s) for operation approval (eap).
- **Permit.io Organizations API** — The Organizations API gives you access to control and manage your Permit organizations. An organization represents a **single billable account** (i.e: a company using Permit). Y...
- **Permit.io Policy Decision Points API** — The Policy Decision Points API from Permit.io — 6 operation(s) for policy decision points.
- **Permit.io Policy Git Repositories API** — The Policy Git Repositories API from Permit.io — 5 operation(s) for policy git repositories.
- **Permit.io Policy Guards (EAP) API** — The Policy Guards (EAP) API from Permit.io — 5 operation(s) for policy guards (eap).
- **Permit.io Projects API** — Projects let you manage permissions for different business objectives from a single Permit account. For example, you can create one project called "Billing App" and another proj...
- **Permit.io Proxy Config API** — Proxy Config is set to enable the Permit Proxy to make proxied requests as part of the Frontend AuthZ.
- **Permit.io Relationship tuples API** — The Relationship tuples API from Permit.io — 3 operation(s) for relationship tuples.
- **Permit.io Resource Action Groups API** — Resource Action Groups are groups of actions that are assigned to a role as one action.
- **Permit.io Resource Actions API** — Actions are the various ways you can interact with a resource or affect the resource. Each (resource, action) pair defines a unique permission level.
- **Permit.io Resource Attributes API** — Resource attributes allow you to specify an arbitrary schema attributes that are part of the definition of resource and must be included in any of its instances. Attributes are ...
- **Permit.io Resource Instances API** — Resource instances are instances of resource types. An instance represents **a single object** in your system on which you'd want to enforce authorization. You can use this API ...
- **Permit.io Resource Relations API** — The Resource Relations API from Permit.io — 2 operation(s) for resource relations.
- **Permit.io Resource Roles API** — Roles allow you to associate permissions indirectly via a job function. Resource roles allow you to grant roles that are scoped to a resource, thus expressing ownership or arbit...
- **Permit.io Resources API** — Resources are *types* of objects or feature names that you wish to protect (or gate) with permissions. For example, if you build a document-sharing app like google docs, you mig...
- **Permit.io Role Assignments API** — Role Assignments are RBAC-constructs that state that a actor (i.e: user) is assigned a role within a tenant. With role assignments you can assign or unassign roles to a user. Ro...
- **Permit.io Roles API** — Roles allow you to associate permissions indirectly via a job function. The Roles API allows you to manipulate roles: assign or unassign permissions to a role, define hierarchy ...
- **Permit.io Scope Configurations API** — The Scope Configurations API from Permit.io — 1 operation(s) for scope configurations.
- **Permit.io Tenants API** — A tenant is a group of users that share a common organizational identity. Each tenant is a silo that can enforce strict boundaries between your customers. You can associate your...
- **Permit.io User Attributes API** — User attributes allow you to specify an arbitrary schema attributes that are part of the definition of the User resource. Attributes are used to enforce attribute-based access c...
- …and 3 more, listed in full on the page.

## Agentic access (1)

- **Permit Io Agentic Access** — 258 operations · 146 acting · 3 human-in-the-loop

## Security (4)

- **Permit Io Authentication** — http · 1 scheme
- **Permit Io Domain Security** — TLSv1.3 · HSTS · DMARC
- **Permit Io Vulnerability Disclosure** — disclosure policy published
- **Permit Io Trust Center** — SOC 2, HIPAA, GDPR

## Plans (1)

- **Permit Io Plans Pricing**

## Tags

Access Control, Authorization, Identity, Policy, Security

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/permit-io/). Scores are computed from the provider's own public artifacts under a published rubric.
