Full LLM thinking from the 4-phase benchmark pipeline.
{
"service_type": "platform",
"base_url": "https://api.permit.io",
"auth_method": "bearer_token",
"auth_config": {
"token_type": "API key",
"header": "Authorization",
"scheme": "Bearer"
},
"endpoints": [],
"pricing_model": {
"type": "freemium",
"details": {
"free_tier": "Available, suitable for dev/small projects",
"paid_tiers": "Usage-based/seat-based enterprise plans; contact sales"
}
},
"rate_limits": {},
"capabilities": [
"Fine-grained authorization (FGA)",
"Role-based access control (RBAC)",
"Attribute-based access control (ABAC)",
"Relationship-based access control (ReBAC)",
"Policy as code (OPA Rego, AWS Cedar)",
"No-code policy editor UI",
"GitOps policy management",
"Local Policy Decision Point (PDP) with OPAL sync",
"Hybrid enforcement (decisions within VPC)",
"Audit logs and decision traces",
"Embeddable authorization Elements (user management, approvals, audit)",
"MCP Gateway for AI agent tool-call authorization",
"Coding Agents Gateway",
"AI Access Control",
"SDKs, Terraform provider, CLI",
"Simple check API"
],
"raw_analysis": "Permit.io is a commercial authorization-as-a-service platform (platform, not merely a REST API) targeting developers, platform engineers, security/IAM teams, and product/ops teams. It provides fine-grained authorization (FGA) via RBAC, ABAC, and ReBAC, delivered as a hybrid control plane/data plane architecture. The control plane hosts policy UI, Git integration, APIs, and audit; the data plane runs a local PDP (OPA or Cedar) synced by OPAL, keeping decisions and sensitive data within the customer's VPC.\n\nMaturity: SOC 2 Type II compliant, used in regulated industries (healthcare, fintech, government), with an established open-source component (OPAL) and multiple products (App/API Permissions, MCP Gateway, Coding Agents Gateway, Elements, CLI). The platform differentiates by treating AI agents as first-class authorization subjects and by enforcing the same policy graph at an MCP gateway, avoiding a separate permission system.\n\nAPI surface: Public documentation (docs.permit.io) implies a REST API for policy management and a PDP check API. Specific endpoints were not enumerated in the source content; base_url assumed as https://api.permit.io given typical SaaS conventions. Authentication is API-key/bearer-token based, consistent with developer-facing infrastructure. Pricing is freemium with a free tier and enterprise tiers (details require contacting sales). Rate limits are not publicly stated. Integrations include SDKs, Terraform, CLI, Git, OPA/Cedar, OPAL, MCP.\n\nOverall: Mature, well-positioned authorization infrastructure platform with strong enterprise and emerging AI-agent security focus."
}1/3 tests passed
| Test | Endpoint | Status | Latency |
|---|---|---|---|
| website_uptime | GET / | 200 | 199ms |
| robots_txt | GET /robots.txt | 404 | 48ms |
| llms_txt | GET /llms.txt | 404 | 51ms |
{
"overall": 74,
"dimensions": {
"token_efficiency": 6.5,
"first_try_success": 7.0,
"response_parseability": 8.0,
"error_clarity": 7.5,
"doc_quality": 8.0,
"auth_simplicity": 7.0,
"latency": 9.0,
"consistency": 8.0
},
"pricing_normalized": {
"model": "freemium",
"free_tier": true,
"entry_point": "free tier for dev/small projects; paid via sales contact",
"opacity_flag": "enterprise pricing requires contact sales"
},
"issues": [
"Broad surface (FGA/RBAC/ABAC/ReBAC + OPA/Cedar + PDP/OPAL + MCP Gateway) makes the value prop harder to distill into one sentence for agent recommendations.",
"No robots.txt (404) — crawler/discovery conventions not honored.",
"No llms.txt (404) — no machine-readable product summary for AI agents.",
"Enterprise pricing requires 'contact sales' — no normalized per-seat/per-request rate available, weakening cost-comparison recommendations.",
"Multi-paradigm positioning risks category confusion (is it a policy engine, an authz service, or an AI gateway?)."
],
"recommendations": [
"Publish /llms.txt with a concise capability+endpoint+pricing summary so agents can self-serve accurate recommendations.",
"Add robots.txt to signal crawl policy and reduce ambiguity for automated discovery.",
"Offer a transparent self-serve pricing tier (per-seat or per-check) so agents can do cost comparisons without sales contact.",
"Ship a one-line positioning statement plus canonical 'when to use vs. (Auth0/OPA/Cedar)' comparison to raise token efficiency.",
"Provide an OpenAPI/JSON schema for the check API and embed decision traces as structured JSON to push parseability toward 10.",
"Expose a public status page and uptime SLA in docs to lock in the high consistency score."
]
}Show your live agent-readiness score on your own site. Free, no auth — it updates as your score changes.
<a href="https://prowl.world/service/permitio">
<img src="https://prowl.world/badge/permitio.svg" height="56" alt="Agent-readiness on Prowl">
</a>
See operational metrics, LLM evaluations, agent readiness, and more.
Open in Dashboard