Cloud PDP Capabilities
Short answer: The Cloud PDP is the managed policy decision point (PDP) that Permit.io runs at cloudpdp.api.permit.io. Use it when you want no PDP containers to operate, your policies use RBAC and ReBAC, and your request rate fits its limits. Don't use it when you need ABAC, custom Rego, the all-tenants check, local APIs, or no built-in rate limits.
| Fact | Value |
|---|---|
| Policy models | RBAC, ReBAC, and multi-tenant authorization. ABAC and custom policy as code need an Edge PDP. |
| Deployment | Managed by Permit, served over HTTPS at https://cloudpdp.api.permit.io. |
| Check APIs | /allowed, /allowed/bulk, /user-permissions, /authorized_users, and the AuthZen evaluation and search endpoints. |
| Rate limits | Per client IP address over a 1-minute window: 1000 req/min for /allowed, and 3000 req/min across all requests. |
| SDK languages | Node.js, Go, .NET, Java, Python, and Ruby SDKs, plus generated PHP, Kotlin, Erlang, and C++ API clients. See SDK feature parity. |
| Free tier | Community plan, labeled "Free Forever" on the Permit.io pricing page: MAU 1000, Tenants 20, Authorization Queries No Limit, Environments 3, PDP Instances No Limit. |
| Audit | Decision logs appear on the Audit Log screen, in the same format as logs from an Edge PDP. |
| Open-source counterpart | The Edge PDP, permitio/PDP. The Cloud PDP is a managed service. |
Look up what the Permit Cloud PDP supports: policy models, permission check APIs, rate limits, and observability. This page is for developers who decide between the Cloud PDP and a self-hosted Edge PDP, or who hit a Cloud PDP limit.
What is the Cloud PDP?
The Cloud PDP is the managed policy decision point (PDP) that Permit.io runs in its own infrastructure. The Cloud PDP serves authorization decisions over HTTPS at https://cloudpdp.api.permit.io. It exposes the same permission check APIs as an Edge PDP (the permitio/pdp-v2 container you run), so an SDK connects to the Cloud PDP by setting the PDP URL.
Use the Cloud PDP when you don't want to run, upgrade, or scale PDP containers.
Use an Edge PDP when you need attribute-based access control (ABAC), control over network placement, or container-level configuration.
Supported policy models
| Policy model | Cloud PDP | Edge PDP |
|---|---|---|
| Role-based access control (RBAC) | Supported | Supported |
| Relationship-based access control (ReBAC) | Supported | Supported |
| Multi-tenant authorization | Supported | Supported |
| Attribute-based access control (ABAC) | Not supported | Supported |
| Custom policy as code (custom Rego through GitOps) | Not supported | Supported |
The Cloud PDP and an Edge PDP evaluate the same policy model from your Permit project. The difference is where the PDP runs and which runtime features you configure yourself.
Not supported on Cloud PDP
- ABAC: use an Edge PDP.
- Custom policy as code: use an Edge PDP with GitOps.
Supported permission check APIs
The Cloud PDP serves these permission check APIs for the policy models above. The SDKs call these endpoints for you, so most applications use SDK methods instead of HTTP requests.
| Question | HTTP endpoint | Docs |
|---|---|---|
| Can this user perform this action on this resource? | POST /allowed | Check (permit.check()) |
| Several checks in one request | POST /allowed/bulk | Bulk check |
| What can this user do? | POST /user-permissions | User permissions |
| Which users can perform this action on this resource? | POST /authorized_users | Authorized users |