Define roles, set permissions, run tests. Permitta automatically verifies your RBAC rules work exactly as intended — so you catch permission bugs before they hit production.
| Endpoint | Admin | Editor | Viewer |
|---|---|---|---|
| GET/api/users | |||
| POST/api/users | |||
| DELETE/api/users/:id | |||
| PUT/api/settings |
Built for teams of all sizes
From simple role checks to complex permission matrices, Permitta handles it all.
Visual grid to define which roles should access which endpoints. ALLOW or DENY with one click.
Run hundreds of permission tests in seconds. Every role against every endpoint, automatically.
Set up hourly, daily, or weekly test runs. Get notified when permissions drift.
API access for Jenkins, GitHub Actions, and any CI pipeline. Fail builds on permission errors.
Invite your team with role-based access. Share projects and test results securely.
Get instant alerts when tests fail. Integrate with your existing workflow.
Whether you're a solo dev or a platform team, Permitta fits into how you already work.
You built the API and the auth logic. Now verify it actually works the way you intended — across every role and endpoint.
Add permission tests to your CI/CD pipeline. Catch authorization regressions on every deploy, not after.
Broken access control is the #1 OWASP risk. Scheduled tests and drift detection keep your permissions honest.
No complex setup. No infrastructure to manage. Just results.
Add your API base URL and choose your authentication type (Bearer, API Key, Basic Auth, or custom headers).
Add the endpoints you want to test. Import from OpenAPI/Swagger or add manually.
Create roles like Admin, Editor, Viewer. Add their authentication tokens or API keys.
Use the visual matrix to define which roles should be allowed or denied for each endpoint.
Execute tests on-demand or on a schedule. Get instant results and track changes over time.
Permitta isn't a one-time audit. It's continuous confidence that your permissions are correct.
Permissions change as teams ship. Scheduled tests catch regressions the moment they happen — not when a customer reports a data leak.
Every test run is recorded. See exactly when permissions changed and what broke — invaluable for compliance and incident response.
Add new endpoints and roles as your API evolves. Permitta scales your permission testing automatically — no extra test scripts to maintain.
Slack and email notifications mean your team knows the moment something breaks — before it becomes an incident.
Start free, upgrade when you need more
Perfect for trying out Permitta
For professional developers
For growing teams
We take data protection seriously. Here's how Permitta keeps your information safe.
Your auth tokens and API keys are encrypted before they ever touch our database.
We only store pass/fail results and status codes. Your actual API responses never hit our servers.
We recommend using test-specific tokens with limited permissions — never your production master keys.
Postman is for general API testing - you write individual test scripts. Permitta is specifically for authorization testing - define your roles and permissions once, and we auto-generate tests for every role×endpoint combination. It's the difference between writing 100 tests manually vs. clicking one button.
Yes! Permitta works with any auth system - Keycloak, Auth0, Okta, Firebase, custom JWT, API keys, you name it. We just need the tokens your roles use to authenticate.
Absolutely. Generate an API key and call our REST API from GitHub Actions, Jenkins, GitLab CI, or any other pipeline. Fail your builds when permission tests don't pass.
Set up hourly, daily, or weekly test runs. When permissions drift or someone misconfigures access, you'll get a Slack or email notification immediately.
We never store your API responses - only pass/fail results. Auth tokens are encrypted at rest. We recommend using test-specific tokens with limited permissions.
Yes! The Free tier gives you 2 projects and 50 tests/month - enough to fully evaluate Permitta. No credit card required.
Join developers who use Permitta to catch broken access control before it hits production.
Get Started FreeNo credit card required