Permit.IO - MCP Proxy Gateway
This morning, Permit announced an MCP Proxy Gateway. It offers:
Centralized proxy for all MCPs that an organization might use
Interacts with existing authentication tokens, binding every AI action to a human identity
Sophisticated, user-consent managed access to various MCPs
All tool calls are logged in a compliance-friendly manner
A control plane for managing MCPs, and the tools associated with them
It stands in front of existing MCPs, with minimal-to-no configuration
Sophisticated authorization policies for accessing various MCPs
First Impressions
Honestly, this is something that I’ve been working on myself. A centralized MCP proxy auth solution is probably one of the biggest hurdles to enterprise MCP adoption at scale. The ability to put all of the MCPs behind a proxy, log every action that is being taken and ensure that user identity is attached to every MCP request, is useful and important for both security and compliance. I like that this can be managed in the cloud, or on-prem.
Observations
It appears to authorize access at the tool level, not the elements inside the requests. If I am a high-privilege DBA, and I authorize the ‘Drop Database’ tool because I want to drop my local test database, and the AI hallucinates and drops a production database, it is unclear that this would prevent that. Having said that, this is a relatively rare scenario.
Possibly related - the website implies that the authorization rules are all pre-written. It is unclear if you can customize the rules to your enterprise needs, or perhaps the nature of the solution means that further customization isn’t helpful.
Locality - some MCPs help a user interact with local resources (for example, an MCP that searches a user’s filesystem looking for particular files). It sounds like this architecture would have every request go to a central authority for approval, which could cause latency.
Concerns
There are a couple of claims from the website that gave me pause:
Drift Detection - depending on how this is implemented, this sounds like AI agents monitoring the MCP requests to look for suspicious (hallucinatory) activity in real-time. Given that I spent $10 in tokens in an hour last night just trying out Goose, that could get expensive very quickly
Guardian Agents - ‘AI-native watchers that observe every action and adjust policies on the fly’. This also sounds expensive, and seems like it creates another thing that has to be locked down and monitored for hallucination.
Nifty Ideas
If you offer MCPs as a product, they are claiming that this would offer ‘customer-specific consent and trust tiers’ - so your customers could control how their agents interact with your MCP tools. I wonder if the customers would also have to use the Permit MCP Gateway for this to work. TBD.
Rate-Limiting - the MCP Gateway can meter how frequently an IP address hits the gateway
Things that make me go “Hmmmm.”
IGA / PAM Connectors for Shadow MCP
“Agents won’t always go through the gateway. So we’re adding connectors that detect, alert and block when agents touch sensitive surfaces outside”
This seems tangential to the core of this offering, and, like Onyx Security’s solution, seems like it would require very intrusive network access and packet inspection
Independent of Permit’s authorization solution, or not?
Ideally, I would like to use this without having to adopt Permit’s authorization solution across the board. I can see reasons why it would be better if you also use Permit’s authorization system. But if I have an existing authorization framework, I don’t want to have to dual-manage them.
This may not even be a concern. TBD.
Assessment
This is pretty cool! Definitely worth a look. MCP Proxy Gateways appear to be the New Thing(tm), and it is not surprising that Permit is at the forefront of this market. If you are working on integrating MCPs into your enterprise in a structured way, this should help with security and audit concerns. There may be other, similar products announced as we approach AI and Security convention season.
Additional Readings
https://docs.permit.io/permit-mcp-gateway/overview/
Possibly the most WTF video I have watched in some time:

