Define roles, set permissions, run tests. Permitta automatically verifies your RBAC rules work exactly as intended. Catch permission bugs before they hit production.
Built for teams of all sizes
From simple role checks to complex permission matrices, Permitta handles it all.
Visual grid to define which roles should access which endpoints. ALLOW or DENY with one click.
Run hundreds of permission tests in seconds. Every role against every endpoint, automatically.
Set up hourly, daily, or weekly test runs. Get notified when permissions drift.
API access for Jenkins, GitHub Actions, and any CI pipeline. Fail builds on permission errors.
Invite your team with role-based access. Share projects and test results securely.
Get instant alerts when tests fail. Integrate with your existing workflow.
No complex setup. No infrastructure to manage. Just results.
Add your API base URL and choose your authentication type (Bearer, API Key, Basic Auth, or custom headers).
Add the endpoints you want to test. Import from OpenAPI/Swagger or add manually.
Create roles like Admin, Editor, Viewer. Add their authentication tokens or API keys.
Use the visual matrix to define which roles should be allowed or denied for each endpoint.
Execute tests on-demand or on a schedule. Get instant results and track changes over time.
Start free, upgrade when you need more
Perfect for trying out Permitta
For professional developers
For growing teams
Postman is for general API testing - you write individual test scripts. Permitta is specifically for authorization testing - define your roles and permissions once, and we auto-generate tests for every role×endpoint combination. It's the difference between writing 100 tests manually vs. clicking one button.
Yes! Permitta works with any auth system - Keycloak, Auth0, Okta, Firebase, custom JWT, API keys, you name it. We just need the tokens your roles use to authenticate.
Absolutely. Generate an API key and call our REST API from GitHub Actions, Jenkins, GitLab CI, or any other pipeline. Fail your builds when permission tests don't pass.
Set up hourly, daily, or weekly test runs. When permissions drift or someone misconfigures access, you'll get a Slack or email notification immediately.
We never store your API responses - only pass/fail results. Auth tokens are encrypted at rest. We recommend using test-specific tokens with limited permissions.
Yes! The Free tier gives you 2 projects and 50 tests/month - enough to fully evaluate Permitta. No credit card required.
Join developers who trust Permitta to verify their authorization logic.
Get Started FreeNo credit card required