CONNECT APP
Build with Permit.io
Developer Tools
- API key
MCP
Give your agent Permit.io tools
Every Permit.io action is exposed as an MCP tool on Pipedream's remote server. Point a client at it with your end user's ID and Connect resolves that user's Permit.io account for each tool call — you store no tokens.
// accessToken: mint a short-lived token with the Connect SDK — see the MCP guide
const transport = new StreamableHTTPClientTransport(
new URL("https://remote.mcp.pipedream.net/v3"),
{
requestInit: {
headers: {
Authorization: `Bearer ${accessToken}`,
"x-pd-project-id": "{project_id}",
"x-pd-environment": "production",
"x-pd-external-user-id": "{external_user_id}", // any stable ID for this user in your system
"x-pd-app-slug": "permit_io",
},
},
},
)
const mcp = new Client({ name: "my-agent", version: "1.0.0" })
await mcp.connect(transport)
const { tools } = await mcp.listTools()
// e.g. run Assign Role:
const result = await mcp.callTool({
name: "permit_io-assign-role",
arguments: {
projId: "Project ID",
envId: "Environment ID",
},
})# access_token: mint a short-lived token with the Connect SDK — see the MCP guide
headers = {
"Authorization": f"Bearer {access_token}",
"x-pd-project-id": "{project_id}",
"x-pd-environment": "production",
"x-pd-external-user-id": "{external_user_id}", # any stable ID for this user in your system
"x-pd-app-slug": "permit_io",
}
async with streamablehttp_client("https://remote.mcp.pipedream.net/v3", headers=headers) as (read, write, _):
async with ClientSession(read, write) as session:
await session.initialize()
tools = await session.list_tools()
# e.g. run Assign Role:
result = await session.call_tool("permit_io-assign-role", {
"projId": "Project ID",
"envId": "Environment ID",
})API PROXY
Call the Permit.io API directly
For an endpoint with no pre-built tool, the Connect proxy forwards your request to the Permit.io API with the connected user's credentials attached. You store no tokens and write no refresh logic.
const resp = await pd.proxy.get({
externalUserId: "{external_user_id}", // any stable ID for this user in your system
accountId: "apn_xxxxxxx",
url: "https://api.permit.io/v2/api-key/scope",
})
// Any allowed Permit.io endpoint works here. Pipedream attaches the
// connected account's credentials to the outgoing request.# The path segment is the target URL, URL-safe base64 encoded:
# https://api.permit.io/v2/api-key/scope
curl "https://api.pipedream.com/v1/connect/{project_id}/proxy/aHR0cHM6Ly9hcGkucGVybWl0LmlvL3YyL2FwaS1rZXkvc2NvcGU?external_user_id={external_user_id}&account_id=apn_xxxxxxx" \
-H "Authorization: Bearer {access_token}" \
-H "x-pd-environment: production"SDK
Run Permit.io actions from your backend
Connect a user's Permit.io account once, then run Assign Role on their behalf from your own code — TypeScript, Python, or plain HTTP.
import { PipedreamClient } from "@pipedream/sdk"
const pd = new PipedreamClient({
projectId: process.env.PIPEDREAM_PROJECT_ID!,
clientId: process.env.PIPEDREAM_CLIENT_ID!,
clientSecret: process.env.PIPEDREAM_CLIENT_SECRET!,
projectEnvironment: "production",
})
const result = await pd.actions.run({
id: "permit_io-assign-role",
externalUserId: "{external_user_id}", // any stable ID for this user in your system
configuredProps: {
permit_io: { authProvisionId: "apn_xxxxxxx" },
projId: "Project ID",
envId: "Environment ID",
},
})from pipedream import Pipedream
pd = Pipedream(
client_id="{oauth_client_id}",
client_secret="{oauth_client_secret}",
project_id="{project_id}",
project_environment="production",
)
result = pd.actions.run(
id="permit_io-assign-role",
external_user_id="{external_user_id}", # any stable ID for this user in your system
configured_props={
"permit_io": {"authProvisionId": "apn_xxxxxxx"},
"projId": "Project ID",
"envId": "Environment ID",
},
)curl -X POST https://api.pipedream.com/v1/connect/{project_id}/actions/run \
-H "Content-Type: application/json" \
-H "X-PD-Environment: production" \
-H "Authorization: Bearer {access_token}" \
-d '{
"external_user_id": "{external_user_id}",
"id": "permit_io-assign-role",
"configured_props": {
"permit_io": { "authProvisionId": "apn_xxxxxxx" },
"projId": "Project ID",
"envId": "Environment ID"
}
}'TOOLS
Permit.io actions
On-demand operations your product or agent can configure and run on behalf of a connected user.
-
Assign Role
actionGrants a specific role to a user within a tenant to enable immediate access to protected resources. See the documentationWritev0.0.2 -
Create Relationship Tuple
actionDefines a granular relationship between two resources, enabling advanced Relationship-Based Access Control (ReBAC). See the documentationWritev0.0.2 -
Create Tenant
actionMints a new isolated silo (such as a Customer Account or Organization) to manage multi-tenant permissions. See the documentationWritev0.0.2 -
List Project ID Options
actionRetrieves available options for the Project ID field.Read-onlyv0.0.1 -
Remove Role
actionRevokes a user's role assignment to instantly offboard them or downgrade their access level. See the documentationWritev0.0.2
EVENTS
Permit.io triggers
Event sources your backend can deploy for users and receive through a webhook.
No Permit.io triggers are available yet.
- App slug
- permit_io
- Authentication
- API key
- Categories
- Developer Tools
- Actions
- 5
- Triggers
- 0
- API proxy
- Available