# permit.io > AI-optimized mirror of permit.io containing 50 pages totalling 91,826 words of clean markdown content, structured data, and semantic HTML. Original source: https://permit.io. Last updated: 2026-09-07T03:29:13.151Z. Each page is available as HTML (with JSON-LD structured data) and Markdown (text-only, ideal for LLMs and RAG). ## Homepage - [Permit.io | Authorization Infrastructure for Developers](/content/site-root.html): Fine-grained authorization as a service. RBAC, ABAC, and ReBAC for applications, APIs, and AI agents. Policy as code, a no-code editor, and local PDPs. (1,105 words) ## Articles & Blog Posts - [OAuth on MCP: The Comprehensive Implementation Guide](/content/blog/oauth-on-mcp/index.html): OAuth 2.1 is the right foundation for MCP security, but most implementations stop one layer too early. This guide covers every spec-required piece: protected resource metadata, authorization server discovery, PKCE, dynamic client registration, resource indicators, and where fine-grained authorization picks up where OAuth ends. (5,543 words) - [Agent Identity Security: Authentication, Authorization, and Trust in AI Systems](/content/blog/agent-identity-security/index.html): AI agents acting across tools, APIs, and multi-agent pipelines raise hard questions about identity, authentication, and authorization. This article covers agentic identity (delegating human + workflow context + intent), agent interrogation, SPIFFE, OAuth token exchange, least privilege at runtime, and what audit actually means for agentic systems. (4,405 words) - [Best Practices for AI Identity Governance](/content/blog/best-practices-ai-identity-governance/index.html): AI agents acting on behalf of users need more than authentication — they need governance. This article covers the Permit.io agentic identity model, policy-as-code lifecycle, MCP Gateway enforcement, zero standing credentials, Guardian Agents, and what an audit trail must contain to be meaningful. (3,976 words) - [A poisoned Linear ticket told our AI agent to leak the team. It tried three ways. None worked.](/content/blog/poisoned-linear-ticket-mcp-agent/index.html): It had every permission it needed and a ticket telling it exactly what to do. Blocked once, it reworded the request to fool the check. Blocked again, it asked me to switch the check off. This is the call-by-call trace of why nothing left Linear — and the design decision that made "reword it until it's allowed" a dead end. (2,570 words) - [Agent Identity Is Becoming a Protocol Layer, but Tool Calls Still Need Runtime Authorization](/content/blog/agent-identity-protocol-mcp-runtime-authorization/index.html): The IETF SD Agent draft and Microsoft Entra Agent ID are turning agent identity into real infrastructure. But a verified Agent Card or sponsored enterprise identity still doesn't answer whether an agent may call a specific MCP tool right now — that requires runtime authorization. (2,705 words) - [Securing Coding Agents: What You Need to Know](/content/blog/securing-coding-agents-what-you-need-to-know/index.html): Coding agents execute code, run commands, and call APIs — not just generate text. This guide covers the real security risks, why authorization must happen at the tool-call level, and how Permit.io and the Permit MCP Gateway enforce least-privilege access for agentic workflows. (4,091 words) - [company/index.html](/content/company/index.html) (362 words) - [Zero Standing Privileges: What It Is, How to Implement It, and Why AI Agents Need It](/content/blog/zero-standing-privileges/index.html): Zero Standing Privileges (ZSP) means no identity holds usable access between tasks. This article explains how ZSP differs from least privilege, how to implement it with ephemeral credentials and runtime policy enforcement, and why AI agents running on MCP make standing access a new category of operational risk. (3,267 words) - [Least Privilege in AI Agents and Agentic Identity](/content/blog/least-privilege-ai-agents-agentic-identity/index.html): AI agents break the traditional least-privilege model. This article explains why, defines agentic identity (delegating human + workflow context + declared intent), and shows how Permit.io enforces zero standing privileges through gateway-vaulted credentials, the PDP, MCP Gateway, and downscoped delegation chains. (2,523 words) - [Agent Identity Is Not Agent Authorization: What Entra Agent ID Still Leaves to Runtime Policy](/content/blog/agent-identity-vs-agent-authorization/index.html): Microsoft Entra Agent ID and SD-JWT agent identity solve registration, governance, and authentication — but they don't decide whether a specific MCP tool call is permissible right now. This article explains the gap and the runtime authorization architecture needed to close it. (2,924 words) - [Agent Identity vs. Service Accounts: Why Scoped Tokens Still Need Runtime Authorization](/content/blog/agent-identity-vs-service-accounts/index.html): Treating AI agents like service accounts is a useful starting point — but it fails at runtime. Here's why scoped tokens are necessary but not sufficient, and how runtime authorization fills the gap. (1,767 words) - [Tool-Call Safety Is Not Text Safety: Why Coding Agents Need Action-Time Authorization](/content/blog/tool-call-safety-is-not-text-safety-action-time-authorization.html): Text refusal and tool behavior can diverge in coding agents. This article explains why runtime, action-time authorization is the real security boundary for Codex, Claude Code, Cursor, and MCP tool calls. (1,501 words) - [OPA for Protecting AI Agents and Agentic Stacks](/content/blog/opa-for-protecting-ai-agents-and-agentic-stacks/index.html): If you already run OPA, AI agents don't require a new policy engine — they require a richer input schema, ephemeral identity, and enforcement at every layer. Learn how to evolve your OPA setup for delegated, multi-hop agentic authorization with Zero Standing Permissions, production-grade Rego, and OPAL-backed real-time enforcement. (2,197 words) - [Read-Only Is a Trust Level, Not a Feeling: How to Govern AI Ops Agents Before They Remediate Production](/content/blog/read-only-trust-level-ai-ops-agents/index.html): AI incident-response agents should not inherit remediation authority by default. This guide defines a practical trust-level taxonomy for MCP tool calls, shows where policy step-up approvals are required, and explains what enterprise audit trails must capture before any production mutation. (1,607 words) - [Authentication vs. Authorization in MCP: What Atlassian Rovo Shows About OAuth, API Tokens, and Tool Calls](/content/blog/mcp-authentication-vs-authorization-atlassian-rovo/index.html): Atlassian Rovo's MCP server makes a precise security tradeoff visible: OAuth 2.1 handles identity and consent; API tokens handle non-interactive automation. Neither governs what agents can actually do at tool-call time. Here is what that gap looks like in practice. (2,673 words) - [When AI Subagents Call MCP Tools, Who Owns the Permission Decision?](/content/blog/subagent-mcp-permission-decision/index.html): Subagents are delegated actors, not implementation details. This guide explains how to design MCP permission delegation, OAuth token brokering, approval routing, and audit trails to avoid silent stalls and privilege expansion. (1,489 words) - [RBAC vs ReBAC for AI Agents: Best Authorization Model for Secure Agentic Systems](/content/blog/rbac-vs-rebac-for-ai-agents/index.html): RBAC is useful for coarse AI agent guardrails, but ReBAC is needed for delegated, tenant-aware, resource-level authorization. Learn when to use RBAC, ReBAC, and both for secure agentic systems. (1,485 words) - [Coding Agent Sandboxes Don't Solve Credential Authorization](/content/blog/coding-agent-sandboxes-credentials/index.html): Sandboxing a coding agent isolates it from the host—but the real blast radius is the credentials it holds. GitHub tokens, cloud keys, MCP connections, and CI/CD access define what an agent can actually do. Here's the runtime permission model that closes the gap. (1,990 words) - [Agent-Generated APIs Need Governance Before They Become Agent-Callable Tools](/content/blog/agent-generated-apis-governance-before-mcp-tools/index.html): Coding agents can generate OpenAPI specs faster than most governance programs can review them. This article explains how to connect design-time API governance to runtime MCP tool authorization with policy decisions, constrained credentials, and audit receipts. (1,700 words) - [Trust Levels for Coding Agents: How to Decide Which Commands and MCP Tools Can Run Automatically](/content/blog/coding-agent-trust-levels/index.html): Coding agents are operational actors, not just assistants. This guide presents a practical trust-level taxonomy for agent commands and MCP tools, explains why human approval prompts degrade at scale, and shows how runtime authorization policy enforces trust levels without relying on click fatigue. (1,900 words) - [Best Practices for Multi-Tenant Authorization](/content/blog/best-practices-for-multi-tenant-authorization/index.html): Multi-tenant authorization combined with Role-Based Access Control (RBAC) simplifies user permissions management across different accounts, organizations, or groups. In this guide, we’ll explore why and how to implement Multi-Tenant authorization using Permit.io. (2,335 words) - [MCP Auth vs Tool-Call Authorization After the 2026-07-28 Spec](/content/blog/mcp-auth-vs-tool-call-authorization-2026-07-28/index.html): The MCP 2026-07-28 spec hardened authentication and routing, but OAuth alone still cannot decide whether a specific tool call should run. This guide explains the authn-vs-authz split and shows how to enforce runtime policy on tools/call. (1,326 words) - [Zero Standing Permissions for AI Agents: Lessons from Hermes Blank Slate and Toolset Pinning](/content/blog/zero-standing-permissions-ai-agents-hermes-blank-slate.html): Hermes Agent's Blank Slate direction shows why teams are moving from broad default tool access to zero standing permissions with config pinning and runtime authorization. This guide explains the safest local defaults, risk-tiered tool access, and practical temporary grant patterns for web, browser, terminal, MCP, memory, and delegation. (1,491 words) - [Implementing Fine-Grained Postgres Permissions for Multi-Tenant Applications](/content/blog/implementing-fine-grained-postgres-permissions-for-multi-tenant-applications.html): Learn how to implement fine-grained Postgres permissions for multi-tenant SaaS apps using roles, grants, and row-level security (RLS). Ensure tenant isolation and secure access control with PostgreSQL. (2,295 words) - [Can AI Generate Authorization Policy Safely?](/content/blog/can-ai-generate-authorization-policy-safely/index.html): LLMs can draft authorization policy, but safe policy authoring for AI agents still depends on explicit intent, verifier-guided synthesis, and runtime PDP decisions on real tool calls. (1,473 words) - [Permit.io Blog - Authorization Guides, Tutorials and News](/content/blog/index.html): Read the Permit.io Blog for expert guides, step-by-step tutorials, best practices, and the latest news on everything Authorization, IAM, and Software Development (668 words) - [MCP in ERP: Why Agentic Business Workflows Need Runtime Authorization](/content/blog/mcp-in-erp-runtime-authorization/index.html): MCP is making agentic ERP integration easier, but security now depends on runtime authorization at the tool-call layer. Learn how to model scoped permissions, trust levels, and audit evidence for finance, HR, procurement, and payroll workflows. (1,298 words) - [Payment Is Not Permission: How to Authorize Paid MCP Tool Calls](/content/blog/payment-is-not-permission-authorize-paid-mcp-tool-calls.html): Cloudflare's x402 and paid MCP tooling make agentic payments real, but payment proof is not runtime permission. This guide explains spend authorization, consent tiers, and audit requirements for paid tool calls. (1,083 words) - [What the NSA Agentic AI Advisory Actually Requires](/content/blog/nsa-agentic-ai-authorization-2026/index.html): In April 2026, the NSA published 'Careful Adoption of Agentic AI Services' — the first intelligence-community advisory specifically targeting AI agent authorization failures. Here is what it actually demands and why most engineering teams are not close to meeting it. (1,716 words) - [MCP Server Supply Chain Is Runtime Supply Chain: Tool Manifests Need Policy and Evidence](/content/blog/mcp-server-supply-chain-is-runtime-supply-chain/index.html): MCP risk is not frozen at build time. This article explains how to vet third-party MCP servers, treat manifests as security boundaries, enforce runtime authorization, and preserve incident-grade audit evidence. (1,040 words) - [Shared Agent Memory Is a Permissions Problem](/content/blog/shared-agent-memory-is-a-permissions-problem/index.html): Shared coding-agent memory over MCP improves velocity, but every retrieval is a delegated access decision. This guide explains runtime authorization, ReBAC modeling, inheritance boundaries, revocation, and audit design for secure team memory. (1,191 words) - [How Security Teams Review an MCP Gateway for SOC 2 + HIPAA](/content/blog/mcp-gateway-soc2-hipaa/index.html): A practical review guide for security, privacy, and procurement teams evaluating whether an MCP gateway can meet SOC 2, HIPAA, and privacy requirements — with concrete examples from Permit MCP Gateway. (1,697 words) - [When the AI Gateway Becomes the Blast Radius: Lessons from the LiteLLM MCP RCE Chain](/content/blog/litellm-mcp-rce-ai-gateway-blast-radius/index.html): The LiteLLM CVE-2026-42271 and Starlette BadHost CVE-2026-48710 chain turned authenticated command injection into unauthenticated RCE. The deeper lesson: AI gateways hold model credentials, route sensitive traffic, and expose MCP utility endpoints — and need action-time authorization, not flat API keys. (1,540 words) - [Claude Code MCP Token Theft Shows Why OAuth Tokens Need Runtime Tool-Call Authorization](/content/blog/claude-code-mcp-token-theft-oauth-runtime-authorization.html): The Claude Code MCP OAuth token theft chain is an authorization failure, not just a credential leak. OAuth got the agent connected, but it never constrained which tool calls remained valid after the routing layer was tampered with — and that is the gap runtime policy enforcement must close. (1,737 words) - [Agent Identity Is Not Enough: From DIDs and AI Control Towers to Runtime Permissions](/content/blog/agent-identity-not-enough-runtime-permissions/index.html): DIDs, verifiable credentials, and AI control towers are foundational for agent governance, but they still do not decide whether a specific agent action is allowed right now. This article explains the runtime authorization model enterprises need for delegated AI execution. (1,504 words) - [MCP Auth vs Agent Authorization: Why OAuth Alone Doesn’t Solve Agent Security](/content/blog/mcp-auth-vs-agent-authorization/index.html): MCP auth is necessary, but it is not the same thing as agent authorization. If you want secure agent systems, you need identity, delegation, policy, and runtime enforcement beyond OAuth. (1,331 words) - [Prompt Injection Is an Authority-Promotion Failure, Not Just a Bad Prompt](/content/blog/prompt-injection-authority-promotion-failure/index.html): Prompt injection becomes a security incident when untrusted content is promoted across authority boundaries into actions. This article shows how to enforce RAG and MCP promotion gates with runtime authorization outside the model. (1,468 words) - [OpenAPI-to-MCP Turns Every API Into an Agent Tool. The Missing Piece Is Endpoint-Level Policy](/content/blog/openapi-to-mcp-endpoint-level-policy/index.html): OpenAPI-to-MCP gateways can instantly expose REST endpoints as agent tools, but endpoint filtering alone does not enforce least privilege. This guide shows how to classify generated tools by risk, enforce runtime policy per delegator and intent, keep credentials server-side, and log auditable MCP decisions. (1,365 words) - [Zero Standing Permissions for Coding and Automation Agents](/content/blog/zero-standing-permissions-coding-automation-agents/index.html): Specs and PRDs make coding agents more accurate, but not inherently safe. This guide explains how to secure MCP-enabled coding and workflow agents with short-lived delegated access, runtime policy decisions, and auditable zero standing permissions. (1,496 words) - [Permit.io Customers](/content/customers/index.html): Find why leading development teams choose Permit Authorization as a Service for their fine-grained authorization solution. Watch testimonial videos and read case studies and user quotes. (805 words) - [OPAL + OPA VS XACML](/content/blog/opal-opa-vs-xacml/index.html): A view of OPAL + OPA as an alternative to XACML (1,560 words) - [Agent Audit Logs Need a Causal Commit Log, Not Just Tool Traces](/content/blog/agent-audit-logs-causal-commit-log/index.html): Agent traces are observability signals, not accountability evidence. This guide defines a causal, replayable authorization commit log for MCP tool calls so teams can prove who delegated access, why policy allowed an action, and what happened next. (1,434 words) - [CVE-2026-49257: Why MCP Database Servers Need Fail-Closed Authorization](/content/blog/cve-2026-49257-mcp-database-fail-closed-authorization.html): CVE-2026-49257 in mcp-pinot shows why network-reachable MCP database servers must fail closed: secure startup, endpoint authentication, and per-tool runtime authorization are all mandatory. This guide breaks down the confused-deputy pattern, risk-tiered tool policy for read vs schema/admin operations, and the audit model needed for real incident forensics. (1,410 words) - [MCP Auth Bypasses Show Why Tool Calls Need Runtime Authorization](/content/blog/mcp-auth-bypasses-tool-call-runtime-authorization/index.html): The fast-mcp-telegram and LiteLLM CVE chains show that authentication failures rapidly become unauthorized tool execution. The fix is fail-closed, runtime tool-call authorization at the MCP boundary. (1,321 words) - [OPAL - an Authorization Service for Fine-Grained Permissions](/content/blog/introduction-to-opal/index.html): Open Policy Administration Layer (OPAL) is an open-source administration layer for OPA and AWS' Cedar Agent that allows you to keep your authorization layer up-to-date in real time (1,612 words) - [MCP Gateway vs MCP Proxy: What’s the Difference, and Why It Matters in Production](/content/blog/mcp-gateway-vs-mcp-proxy/index.html): If you are comparing an MCP gateway to a basic MCP proxy, the real difference is not routing. It is identity, authorization, consent, auditability, and runtime control for agent actions. (1,786 words) - [How to Govern AI Agents Operating Cloud and API Control Planes Through MCP](/content/blog/govern-ai-agents-cloud-api-control-planes-mcp/index.html): MCP servers are now operational control surfaces for cloud and API platforms. This article explains the trust model, control stack, and audit architecture enterprises need before AI agents can safely execute infrastructure actions. (1,073 words) ## Listings & Categories - [Gabriel L. Manor - Permit.io Blog Authors](/content/author/gemanor/index.html): Full-Stack Software Technical Leader | Security, JavaScript, DevRel, OPA | Writer and Public Speaker (591 words) ## About Pages - [Company, Team & Vision | Permit.io](/content/about/index.html): We founded Permit.io after building IAM again and again. Authorization infrastructure for developers — RBAC, ABAC, ReBAC, and first-class agents. (400 words) ## Resources - [Full Page Index](/index.html): Browse all cached pages with rich metadata - [About This Cache](/about.html): Methodology, technical details, and usage guidelines - [XML Sitemap](/sitemap.xml): Machine-readable sitemap for crawler discovery - [Robots.txt](/robots.txt): Crawler directives - [AgentSite Network](https://agentsite.network/network.html): Public index of AgentSites and their machine-readable resources