Permit.io
Permit.io provides a full-stack authorization platform for cloud-native applications and AI agent workflows, offering RBAC, ABAC, and ReBAC policy enforcement via an MCP Gateway, PDP, and policy editor, serving enterprise, fintech, healthcare, and government customers.
- Company typePrivate
- Founded2021
- HeadquartersTel Aviv, Israel
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What Permit.io does
Permit.io is a Tel Aviv-based, venture-backed private company founded in 2021 that provides a full-stack authorization platform for cloud-native applications, microservices, and AI agent workflows. The platform is built on the Open Policy Agent (OPA) and the company's own Open Policy Administration Layer (OPAL) and delivers a Policy Decision Point (PDP) supporting RBAC, ABAC, and ReBAC models with hybrid deployment options (managed cloud or self-hosted in-VPC), claiming sub-50ms decision latency at hundreds-of-millions-of-identities scale. Core products include the MCP Gateway for AI agent authorization, Elements low-code policy editor, Audit Logs, a CLI for developer workflows, and the open-source OPAL and OPTOGGLES projects.
The company monetizes through SaaS subscriptions on the cloud PDP and enterprise licensing for self-hosted deployments, with a free tier at app.permit.io and tiered packages whose pricing is not publicly disclosed. Its go-to-market is hybrid product-led growth and community-led: a self-serve platform, a 2,938+ member Slack developer community, GitHub open-source distribution (OPAL is used by Tesla and Zapier), technical documentation at docs.permit.io, and direct enterprise engagement via Slack-based expert access. Marketing channels are heavily developer-focused, including technical blog content, YouTube tutorials, social media, and conference/webinar presence.
Permit.io serves enterprise platform engineering teams, AI agent security buyers, and regulated-vertical customers in healthcare (HIPAA-compliant), government (SOC 2 Type II), fintech, and insurance. Named customer logos span Maricopa County Recorder Office, Salt Security, Honeycomb Insurance, Rivulis, Hipp Health, Centauri AI, Granulate, the US Department of Energy (via TechSource), and Buzzer, with brand signals on the website including Cisco, Intel, BP, Palo Alto, and Stigg. The company is incorporated as Permit Inc. in Delaware (US) and Permit.io Ltd. in Israel, and has raised approximately $14 million across a 2022 seed led by NFX and a 2024 round co-led by NFX and Scale Venture Partners.
Permit.io firmographics
Firmographics- Name
- Permit.io
- Legal name
- Permit Inc.
- Website
- https://permit.io
- Company type
- Private
- Founded year
- 2021
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Permit.io provides a full-stack authorization platform for cloud-native applications and AI agent workflows, offering RBAC, ABAC, and ReBAC policy enforcement via an MCP Gateway, PDP, and policy editor, serving enterprise, fintech, healthcare, and government customers.
- Ownership category
- akta.pro rank
Permit.io industry classification
Industry- Product category
- Authorization Platform
- NAICS
- Software Publishers (513210)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Cloud Identity & Access Management Infrastructure (IAM/IdP/MFA) (HDABAHAF)
- akta.pro secondary industries
- Cloud Compliance, Audit & Continuous Controls Monitoring (CCM/GRC) (HDABAHAI), Confidential AI & Privacy-Preserving ML (federated learning, MPC, HE, TEEs) (HDAAAKAI)
Keywords
Where Permit.io is headquartered
LocationHeadquarters
- HQ city
- Tel Aviv
- HQ country
- Israel
- HQ region
- Middle East
Offices2 records
Markets served
Permit.io business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Infrastructure, Operations, Others
Revenue model
- SaaS Subscription (Cloud PDP): Permit.io operates a cloud-hosted service where customers pay subscription fees for access to the Permit platform, policy management UI, cloud PDP, and API access. The Terms of Service reference 'monthly subscription fees' and 'packages, schemes, amounts and subscription cycle presented to you upon registration,' indicating tiered subscription plans. The free tier (app.permit.io) is available for self-serve onboarding.
- Self-hosted PDP (Hybrid Deployment): Enterprise customers can deploy the PDP within their own VPC (self-hosted/infrastructure), while still using Permit.io's cloud-based policy management and configuration layer. This likely generates additional revenue through enterprise licensing or usage-based billing for self-hosted deployments.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Monthly | Free tier for developers and small teams to get started |
| Subscription | Annual | Paid subscription plans for teams and enterprises |
Go-to-market motion2 records
Distribution channels4 records
Marketing channels8 records
Permit.io product offering
Product offeringCore offering
Permit.io sells a full-stack authorization platform that lets developers embed fine-grained permissions (RBAC, ABAC, ReBAC) into cloud-native applications and govern AI agent actions in real time. The platform combines a no-code/low-code policy editor, distributed Policy Decision Point (PDP) with sub-50ms latency, audit logging, and a new MCP Gateway that creates agentic identities bound to intent, sold primarily as tiered SaaS subscriptions with a free tier for self-serve onboarding.
Product overview
Permit.io is a full-stack authorization platform providing infrastructure for building and implementing end-to-end permissions with low-code interfaces. The platform consists of core products (MCP Gateway for AI agent security, App and API Permissions, and AI Agent Security), platform components (Policy Engine built on OPA, Elements policy editor, Audit Logs, and CLI), and open-source projects (OPAL and OPTOGGLES). The platform supports RBAC, ABAC, and ReBAC authorization models and is designed for enterprise, fintech, healthcare, and government sectors.
Differentiator
Problem solved
Functional benefit
Brands
- OPAL: Open Policy Administration Layer - an administration layer for Open Policy Agent (OPA) that detects changes in policies and policy data in real-time and pushes live updates to agents.
- OPToggles
Products and services
- MCP Gateway A trust and enforcement layer for the Model Context Protocol (MCP) that brings identity, consent, fine-grained authorization, auditability, and runtime control to AI agent actions. It creates dynamic agentic identities bound to intent, enables prompt-injection detection, and enforces policy at every MCP tool call for enterprise, fintech, healthcare, and government users deploying AI agents.
- App and API Permissions Full-stack authorization framework for building and implementing end-to-end permissions with low-code interfaces to enhance fine-grained access controls in cloud-native applications. Supports RBAC, ABAC, and ReBAC models across microservices, APIs, and data layers for platform engineering teams and product teams.
- AI Agent Security Permissions infrastructure designed for the AI era that controls what AI agents can do at action time across every system they touch. Includes agentic identity creation, runtime policy evaluation, human-to-agent delegation with consent framework, and zero-standing permissions for organizations deploying AI agents in sensitive environments.
- OPAL (Open Policy Administration Layer) Open-source administration layer for Open Policy Agent (OPA) that detects changes in policies and policy data in real time and pushes live updates to agents. Syncs authorization data from APIs, databases, Git, S3, and third-party SaaS services, and is used in production by companies including Tesla and Zapier. Built and maintained by Permit.io.
- OPTOGGLES Open-source project that syncs OPA policy decisions to frontend feature flags, enabling permission-aware UI rendering based on backend authorization. Uses OPA as the source of truth and OPAL for real-time policy and data updates; built by Permit.io.
Quantifiable outcome
- Reduces authorization implementation time from months to days (Centauri AI implemented Permit in 1 day, deployed in 2 days total)
- +4 more outcomes
Companies that use Permit.io
Customer profileNamed customers13 records
Segments4 records
Ideal customer profiles4 records
Permit.io technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration6 records
AI capability5 records
Feature8 records
Permit.io partnerships and signals
Strategic signalPartnerships
Two partnerships are on record, tiered core.
- OPA (Open Policy Agent) / CNCFcorePermit.io is built on OPA (Open Policy Agent), a CNCF-graduated project. The platform's PDP uses OPA as its policy evaluation engine. OPA's open-source ecosystem provides the foundation for Permit.io's policy decision capabilities.
- OPAL (Open Policy Administration Layer)coreOPAL is Permit.io's own open-source project — an administration layer for OPA that detects changes in policies and policy data in real-time and pushes live updates to agents. Used in production by Tesla and Zapier. OPAL is a key component of Permit.io's architecture and a major community asset.
Scale indicators5 records
Recent moves6 records
Expansion highlights6 records
Permit.io competitors and assessment
Company assessmentBroad incumbents
- Okta (Auth0): Okta — including the Auth0 developer identity platform — is the dominant cloud IAM vendor with broad authentication, authorization, and identity-governance capabilities. It competes with Permit.io across customer identity and fine-grained authorization use cases.
- Cloudflare One / Access: Cloudflare Access is a zero-trust access and authorization product embedded in the Cloudflare network. It competes with Permit.io's policy enforcement plane for application access control, particularly for cloud-native and remote-workforce use cases.
- Microsoft Entra: Microsoft Entra (formerly Azure AD) is a broad workforce and CIAM platform with conditional access, identity governance, and emerging fine-grained authorization features. It competes with Permit.io for enterprise identity budgets and is bundled into Microsoft 365 deals.
- AWS IAM (Identity and Access Management): AWS IAM and IAM Identity Center provide native cloud authorization for AWS workloads. As a hyperscaler incumbent, AWS can absorb fine-grained and agent-authorization capabilities into its native platform, posing a competitive risk to Permit.io's hybrid-cloud PDP positioning.
Direct peers
- Styra: Styra is the commercial sponsor of OPA and sells an enterprise policy-as-code platform built directly on the same engine that Permit.io's PDP uses. It competes in the cloud-native authorization space and shares the OPA technical foundation.
- Cerbos: Cerbos provides a decoupled, policy-decision-point (PDP) authorization layer that integrates with OPA and supports RBAC/ABAC. It directly competes with Permit.io's policy engine, targeting similar developer and platform-engineering buyers with both managed and self-hosted PDPs.
- Aserto: Aserto provides an authorization service for cloud-native applications that combines an OPA-based PDP with a policy editor and developer APIs. It targets the same platform-engineering and product teams with a comparable hybrid deployment model.
- Oso: Oso offers an authorization-as-a-service platform with a developer-friendly library and PDP that supports RBAC, ReBAC, and ABAC. It targets the same cloud-native developer and product engineering buyer with a comparable full-stack value proposition.
Emerging players
- Stytch: Stytch provides developer-first authentication and authorization APIs targeting product and engineering teams. While primarily an authentication platform, it increasingly overlaps with Permit.io in fine-grained, application-level authorization for SaaS applications.
- AuthZed (OpenFGA): AuthZed commercializes OpenFGA, an open-source ReBAC authorization engine inspired by Google's Zanzibar. It overlaps with Permit.io on relationship-based authorization and developer-focused fine-grained access control.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat6 records
Key risks6 records
Key highlights6 records
Customer concentration
Permit.io social profiles
Digital presencePermit.io compliance and trust
Trust signalCompliance5 records
Permit.io financial estimates
Financial estimateRevenue estimate
Valuation estimate
Permit.io leadership team
Management profileNumber of profiles
Profiles2 records
Permit.io funding detail
Funding detailFunding overview
Funding rounds2 records
Investors7 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Permit.io M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Permit.io
What does Permit.io do?
Permit.io sells a full-stack authorization platform that lets developers embed fine-grained permissions (RBAC, ABAC, ReBAC) into cloud-native applications and govern AI agent actions in real time. The platform combines a no-code/low-code policy editor, distributed Policy Decision Point (PDP) with sub-50ms latency, audit logging, and a new MCP Gateway that creates agentic identities bound to intent, sold primarily as tiered SaaS subscriptions with a free tier for self-serve onboarding.
Is Permit.io a public or private company?
Permit.io is a private company. It is classified as venture growth investor backed and is currently operating.
When was Permit.io founded?
Permit.io was founded in 2021. It employs 11 to 50 people.
Where is Permit.io based?
Permit.io is headquartered in Tel Aviv, Israel, in the Middle East region.
How does Permit.io make money?
Two revenue lines are on record. SaaS Subscription (Cloud PDP) is the primary driver. The others are self-hosted PDP (Hybrid Deployment).
Who are Permit.io's main competitors?
Broad incumbents on record are Okta (Auth0), Cloudflare One / Access, Microsoft Entra and AWS IAM (Identity and Access Management). Direct peers are Styra, Cerbos, Aserto and Oso. Emerging players are Stytch and AuthZed (OpenFGA).
Does Permit.io have an API?
Yes. Permit.io provides a REST API for authorization management, policy configuration, and runtime permission checks. The API enables developers to integrate fine-grained authorization into applications via SDKs in Python, Golang, Node.js, and other languages. Documentation is available at docs.permit.io. MCP (Model Context Protocol) Gateway is offered for AI agent security, enabling real-time authorization at action time for AI agents. Developer documentation is at docs.permit.io.
What industry is Permit.io in?
Permit.io's product category is Authorization Platform. Its primary akta.pro industry code is HDABAHAF, Cloud Identity & Access Management Infrastructure (IAM/IdP/MFA), with a secondary code of HDABAHAI, Cloud Compliance, Audit & Continuous Controls Monitoring (CCM/GRC). Its NAICS code is 513210 and its SIC code is 7372.