Skip to main content

Access Requests & Approvals

Short answer: Permit.io access requests let a user ask for a role from inside your application, and an admin approve or deny the request, using embeddable Permit Elements. Use them when you want roles, user management, and approvals in your product without building the interface. Don't use them when your application has no user sign-in, or when approvals must run entirely outside Permit.

FactValue
Elements usedUser Management and Access Request for role requests. Operation Approval and Approval Management for approving a single action.
Policy modelsThe User Management element supports RBAC or ReBAC permission models.
How you embed itAn iframe per element, plus permit.elements.login() from the @permitio/permit-js package in your frontend.
IdentityYour authentication provider issues JWTs. Permit verifies them against the JWKS you configure for the environment.
DeploymentEach element loads in an iframe from embed.permit.io. Your backend runs the SDK and a PDP, so your application enforces the same policy.
SDK languagesNode.js, Go, .NET, Java, Python, and Ruby SDKs, plus generated PHP, Kotlin, Erlang, and C++ API clients. See SDK feature parity.
Free tierThe Community plan on the Permit.io pricing page lists "Embeddable Authorization Interfaces (e.g., User Management)". Limits: MAU 1000, Tenants 20.
AuditEach check appears on the Audit Log screen. Webhooks report element events. See Elements webhooks.
Open sourceThe Access Request MCP server for AI agents (permitio/permit-mcp) is open source. See Access Request MCP.

Add an access request and approval flow to your application with Permit.io. Your users request access from inside your application, and admins approve or deny each request. This walkthrough is for developers who have a Permit policy and an application with user sign-in. Each step has short instructions, a link to the page with the full reference, and a video.

Prerequisites​

  • An application where users sign in and your authentication provider issues JSON Web Tokens (JWTs)
  • Your users synced to Permit, with the same user key as the JWT sub claim (Sync users)
  • Roles in your Permit policy (Configure your first RBAC policy)

What are Permit Elements?​

Permit Elements are embeddable UI components for access management. You embed an element in your application as an iframe. Your policy in Permit decides what each user can do in the element. For access requests, you use two elements:

ElementWho uses itWhat it does
User ManagementAdmins in your applicationLists users and their roles, and shows pending access requests to approve or deny.
Access RequestUsers who lack accessSends a request for access, for example for a role the user doesn't have.

To require approval for a single action instead of a role, for example a large funds transfer, use the Operation Approval and Approval Management elements.

Demo of Permit Elements​

1

1. Configure JWKS for your environment​

A JSON Web Key Set (JWKS) is the set of public keys that verify the JWTs your authentication provider issues. Permit uses your JWKS to confirm that a user who logs in to an element holds a valid token.

  1. In the Permit dashboard, open Settings and select JWKS Config.
  2. Paste your JWKS for the environment and click Save.
  3. Confirm that each user's key in Permit matches the sub claim of the user's JWT. If the key is in another claim, pass that claim name as userKeyClaim when you log the user in (step 5).

See Configuring JWKS for your environment.

2

2. Connect your application to Permit​

Install the Permit SDK in your backend and run a policy decision point (PDP), so your application enforces the same policy the elements manage. Then install the @permitio/permit-js package in your frontend. The frontend uses it to log users in to the elements.

See Use the Permit API and SDK, Run the PDP, and Installing Permit-js.

3

3. Build the authorization policy​

Define what users can do in your application. In Policy, create the resources, their actions, and the roles, and grant each role its permissions in the Policy Editor. Then assign roles to your users in Directory.

The roles are what users request. For example, a user with the viewer role can't write blog posts, and requests the editor role through the Access Request element.

See Configure your first RBAC policy.

4

4. Create and configure the elements​

Create a User Management element first. The Access Request element connects to it.

  1. Open the Elements screen. Under User Management, click Create Element.
  2. Enter a Name, select the Permission Model (RBAC or ReBAC), and set the Role Levels, which map your roles to permission levels in the element. Click Save.
  3. On the Elements screen, under Access Request, click Create Element.
  4. Select the User Management element to connect, enter a name, and click Create.
  5. Open the User Management element again. Under Approval Component in user management, select the Access Request element you created.

Each element has settings for its look and text: background and button colors, the title, the message, and the button text. See Access Request element customization.

5

5. Embed the elements and log users in​

  1. Open each element and click Generate Code. Permit generates an iframe snippet. In the snippet's src, set the tenant key the element applies to. See Creating an iFrame.
  2. Add the iframe snippets to your application's pages: the Access Request element where users ask for access, and the User Management element in your admin area.
  3. Log the signed-in user in to the elements before the iframes load. With the client-side login method, call permit.elements.login() from @permitio/permit-js with the user's JWT, the tenant key, and your environment ID. See Login method.

After a successful login, the element acts on behalf of the signed-in user.

Log the user in to the elements in code​

This is the frontend login call from step 5 for the frontendOnly method. Install the package first with npm install @permitio/permit-js. Replace <YOUR_USER_JWT> with the signed-in user's JWT, <TENANT_KEY> with the tenant the element shows, and <YOUR_ENV_ID> with your Permit environment ID. Render the element iframe after the promise resolves:

import permit, { LoginMethod } from "@permitio/permit-js";

permit.elements
.login({
loginMethod: LoginMethod.frontendOnly,
userJwt: "<YOUR_USER_JWT>",
tenant: "<TENANT_KEY>",
envId: "<YOUR_ENV_ID>",
})
.then((loggedIn: boolean) => {
// Render the element iframe here
})
.catch((err: unknown) => {
console.error("Permit Elements login failed", err);
});

The iframe snippet that Generate Code produces has this form. Replace the placeholders with the values from the dialog:

<iframe
title="Permit Element Name"
src="https://embed.permit.io/<ELEMENT_NAME>?envId=<SOME_UNIQUE_ID>&darkMode=false&tenantKey=<TENANT_KEY>"
width="100%"
height="100%"
style="border: none;"
/>

For the other login methods, see Log users in to Permit Elements.

Verify the approval flow​

  1. Sign in to your application as a user without the role to request, for example a viewer. In the Access Request element, click Request Access.
  2. Sign in as a user whose role is at Level 1 in the User Management element, for example an admin. The request appears in the element's list of pending users.
  3. Approve the request.
  4. In the Permit dashboard, open Directory. The requesting user has the approved role.

What you built​

  • Configured JWKS, so Permit verifies the users who log in to elements.
  • Created a User Management element and an Access Request element connected to it.
  • Embedded both elements in your application and logged users in to them.

Frequently asked questions​

How do I add a permissions UI with roles, invites, and access requests to my SaaS app?​

Embed the Permit Elements User Management and Access Request elements in your application. Admins in your application list users, assign roles, and approve or deny pending requests in the User Management element. Users who lack a role request it in the Access Request element. Your Permit policy decides what each user can do in the elements.

How does a user request access in Permit Elements?​

The Access Request element sends a request for a role the user doesn't have. The request appears in the User Management element, where an admin with the required level approves or denies it.

Can I require approval for one action instead of a role?​

Yes. Use the Operation Approval and Approval Management elements, for example for a large funds transfer. See Operation Approval.

What does my application need before I can use access requests?​

Users who sign in to your application with JSON Web Tokens (JWTs), users synced to Permit with the same user key as the JWT sub claim, and roles in your Permit policy.

How do AI agents request access?​

Use the Access Request MCP server, which exposes access request and approval APIs as MCP tools. See Access Request MCP and the Access Request MCP overview.

Is there a free tier for Permit Elements?​

The Community plan on the Permit.io pricing page includes "Embeddable Authorization Interfaces (e.g., User Management)", with MAU 1000 and Tenants 20.