PermDock
Research

Ecosystem index

Every third-party tool, platform and product the PermDock documentation names, grouped by category, with how PermDock composes with each (standard security fields, the Overlay, subjectFromJwt, ApprovalStore, DecisionSink, MCP, AuthZEN, a compiler target or a recipe) and the page that owns the recipe.

This is the single list of third-party tools the docs name. Each row names the tool, what it is, the mechanism PermDock reaches it through, and the page that owns the recipe or verdict. A tool named anywhere in the docs gets a row here in the same change. Prior-art analysis of competing libraries and vendors is on landscape.

PermDock composes through wire formats and interfaces, and ships a package entry only for the adapters on the adapters matrix.

MechanismMeaning
securityThe tool reads standard OpenAPI security and securitySchemes from the applied description; nothing PermDock-specific
OverlayThe tool applies or consumes PermDock's OpenAPI Overlay
x-permdock-*The tool reads a PermDock extension (only the OpenAPI-to-MCP bridges need one)
subjectFromJwtThe tool issues JWTs verified by permdock/jwt against its JWKS
authInfoThe tool issues the access tokens permdock/mcp receives as AuthInfo
MCPThe tool consumes or hosts MCP servers, so protectServer already guards it
AI SDKThe tool builds on the AI SDK, so permdock/ai-sdk applies
AuthZENThe tool is an AuthZEN policy enforcement point or decision point (AuthZEN)
ApprovalStoreThe tool holds or delivers approvals through the approvals interface
DecisionSinkThe tool receives decision events through a sink recipe or OpenTelemetry (audit)
where targetThe tool is a compile target for portable conditions, shipped or candidate
HookThe tool has an in-process hook a shipped adapter fills
LoaderA framework loader calls getSnapshot(request) from permdock/server and hands the snapshot to a UI adapter
RecipeDocumented composition; no package
TrackingNamed and watched; nothing to do yet

OpenAPI producers

ToolWhat it isMechanismOwning page
next-openapi-genRoute scanner for Next.js, TanStack Start, React Router, Remix, SvelteKit, Nuxt, Astro, Hono, Express; applies Overlays; scaffolds Scalar; compiles ArazzoOverlayNext.js adapter, OpenAPI adapter
hono-openapi, @hono/zod-openapiHono spec generatorsHook (describe, security)Hono adapter
@orpc/openapioRPC spec generatoropenapi() meta helperoRPC adapter
trpc-to-openapitRPC spec generator; boolean protect onlyHook plus Overlay for per-scopetRPC adapter
@elysia/openapiElysia spec generator; Scalar by defaultHookElysia adapter
@fastify/swagger, @nestjs/swaggerFastify and Nest spec generatorsHookFastify, Nest
TypeSpecDesign-first API language (1.0 GA), emits OpenAPI 3.0 to 3.2Overlay on emitter outputOpenAPI adapter
tsoa, ts-rest, Effect HttpApi, feTSCode-first producers without a per-route hookOverlayOpenAPI adapter
Hand-written YAML or JSONDesign-first descriptionsOverlayOpenAPI adapter
x-gnap (community GNAP security-scheme extension)Vendor extension describing a GNAP deployment on a security scheme; no OpenAPI Initiative standingTracking (never emitted; preserved untouched by the importer)watch list, OpenAPI 3.2 and 3.3

Overlay appliers

ToolWhat it isMechanismOwning page
next-openapi-gen overlay.applyApplies inside generate; Overlay 1.0 to 1.2OverlayNext.js adapter
Redocly CLI join --overlayLint, bundle, generate pipelines (experimental flag)OverlayCLI: openapi
Bump.sh CLI bump overlay, GitHub ActionApplies at docs deployOverlayCLI: openapi
Speakeasy CLI overlay applySDK generation workflows; chains with Speakeasy's own overlaysOverlayCLI: openapi
Zuplo CLIApplies before gateway importOverlayOpenAPI adapter
overlays-js, openapi-format, oas-patchVendor-neutral appliers; overlays-js is the reference JavaScript implementationOverlayCLI: openapi
Scalar CLIDocs and registry; no Overlay support yetTrackingOpenAPI adapter

SDK generators

ToolWhat it isMechanismOwning page
Hey API (@hey-api/openapi-ts)Typed SDKs, TanStack Query, validatorssecurityOpenAPI adapter
OrvalClients, TanStack Query, MSW mocks, MCP serverssecurity; x-permdock-* for MCP outputOpenAPI adapter, MCP adapter
KubbPlugin-based generator including MCP and Redoc outputsecurity; x-permdock-* for MCP outputOpenAPI adapter
openapi-typescript, openapi-fetchTypes-only generation and a typed fetch wrapper (maintenance mode)Nothing to doOpenAPI adapter
OpenAPI Generator, KiotaMulti-language generatorssecurityOpenAPI adapter
Redocly generate-clientClientssecurityOpenAPI adapter
Fern, SpeakeasyCommercial SDK, docs and MCP generatorssecurity; never their namespacesOpenAPI adapter
StainlessSDK generator; acquired by Anthropic, hosted product wound downx-stainless-* never writtenOpenAPI registries

Docs UIs and hosts

ToolWhat it isMechanismOwning page
ScalarAPI reference and client; renders x-badgessecurity, optional x-badges hintOpenAPI adapter
Swagger UI, Redoc, Stoplight Elements, RapiDoc, fumadocs-openapi, ZudokuOpen-source docs UIssecurityOpenAPI adapter
MintlifyHosted docs; x-mint, x-mcp; generates an MCP serversecurity; never its namespacesOpenAPI adapter
Bump.shHosted docs and changelog; appliersecurity, OverlayOpenAPI adapter
Fern docs, Redocly Realm, Docusaurus OpenAPI, GitBook, PostmanHosted or static docssecurityOpenAPI adapter
ReadMeHosted docs; x-readmeNever writtenOpenAPI registries

OpenAPI-to-MCP bridges and MCP hosts

ToolWhat it isMechanismOwning page
Orval, Kubb, Scalar, Speakeasy, Fern, Mintlify, Postman MCP GeneratorGenerate an MCP server from a descriptionx-permdock-permissions bound as each tool's permissionMCP adapter, OpenAPI adapter
Zuplo (x-zuplo-route.mcp), Kong openapi2mcp and ai-mcp-proxyGateway-hosted MCP from a descriptionx-permdock-permissions; gateway extensions never writtenOpenAPI adapter
AWS Bedrock AgentCore GatewayOpenAPI, Lambda and MCP targets as MCP tools; Cedar policy on context.toolName (the operationId)MCP when self-hosted; security and operationId otherwiseOpenAPI adapter
mcp-handler (Vercel)Fetch handler for MCP servers on Next.js, Nuxt, SvelteKit, Hono; withMcpAuth, protectedResourceHandlerMCP (protectServer inside createMcpHandler)MCP adapter, Next.js adapter
@modelcontextprotocol/server 2.xOfficial TypeScript SDK v2; scopeChallenge on registerToolTypes-only optional peer of permdock/mcpMCP adapter, installation
Official Express middleware, Cloudflare McpAgent, FastMCP (TypeScript), xmcpOther MCP hostsMCPMCP adapter
@hono/node-serverNode.js server for Hono with WebSocket upgrade over wsRecipe (permdock/hono connection and socket)Hono adapter
wsWebSocket server for Node.jsTransport under @hono/node-server; the socket is closed with 1008 on denial or revocationHono adapter
mcp-remotestdio bridge for remote serversNothing to doMCP adapter

Linters, testing and diff

ToolWhat it isMechanismOwning page
Spectral, Redocly lint, vacuumOpenAPI lintersPermDock ruleset fileCLI: openapi
Schemathesis ignored_authProperty-based API tests; verifies protected operations reject anonymous callsRecipe in CICLI: openapi
oasdiffBreaking-change diff; security removals are breakingRecipe in CICLI: openapi
Prism, MicrocksMock servers honouring securitysecurityOpenAPI adapter
MSWRequest mocking used by permdock/testing fixturesRecipetesting

Authorization engines, gateways and decision services

ToolWhat it isMechanismOwning page
Kong, Envoy ext_authz, Tyk, Zuplo, WSO2Gateways with AuthZEN enforcement pointsAuthZEN (in-app handler or PermDock Cloud ADS)AuthZEN adapter
WorkOS FGAResource-scoped RBAC API (check, list resources, list memberships)Positioning; question-shaped verbslandscape, comparison
OpenFGA, Auth0 FGA (Okta FGA)Zanzibar relation-graph engine and its hosted serviceopenfga({ url, storeId, map }) in permdock/pdp: HTTP check per row, list-objects for filter and where; tested against the openfga/openfga container. Recipe, not an entry: a RelationSource whose related reads one object's tuples (POST /stores/{id}/read with tuple_key.object) and whose ancestors follows the parent tuples up to depth, so PermDock keeps the decision and the model keeps the graphpdp, relationships
SpiceDB (AuthZed)Zanzibar relation-graph engine with CEL caveatsspicedb({ url, token, map }) in permdock/pdp: HTTP gateway CheckPermission per row, LookupResources for filter and where; tested against the authzed/spicedb container. Recipe, not an entry: a RelationSource over ReadRelationships for one object (related) and the parent relationships walked up to depth (ancestors); caveats stay in SpiceDB and are not mirrored as periodpdp, relationships
Cerbos, Permit.io, AuthZed (SpiceDB), Oso, OpenFGA, Auth0 FGA, Topaz, Keycloak, casbinAuthorization products and enginesAuthZEN through permdock/pdp; positioninglandscape, comparison
Cedar, Amazon Verified Permissions, AgentCore PolicyPolicy language and its hosted enginesCompile target considered, not scheduledlandscape, comparison
Open Policy Agent, @ai-sdk/policy-opaRego engine; AI SDK tool-approval adapter over it that fails open on unrecognised decisionsPositioning; the fail-closed permdock/ai-sdk is the alternativelandscape, AI SDK adapter
Gateway import namespaces (x-amazon-apigateway-*, x-google-*, x-kong-*, x-zuplo-*, x-ms-*)Vendor extensions in descriptionsNever writtenOpenAPI registries
Aserto (Topaz), Styra (OPA)Standalone authorization companies that shut down or were acqui-hired; Topaz and OPA remain open sourcePositioning onlylandscape
Pomerium, Cloudflare AccessIdentity-aware proxiesPositioning only; the verified identity they forward as a header or JWT is read by subjectFromJwt, and they never decide for PermDocklandscape
Keycard, Natoma, TrueFoundry, Kong AI Gateway, Cloudflare AI Gateway, Solo agentgateway, Aembit, Snowflake MCP gateway, NewCoreMCP and agent-identity gatewaysPositioning only; tokens they mint reach permdock/mcp as authInfo, calls they forward reach protectServerlandscape, MCP adapter
Arcade, Composio, Permit MCP Gateway, Oso for AgentsHosted tool-auth proxiesPositioning onlylandscape

Identity providers and agent identity

ToolWhat it isMechanismOwning page
Supabase Auth, Clerk, Better Auth, ConvexProviders with an in-process verification hookAdapter (subjectFrom*)authentication, provider pages
@supabase/middlewareSupabase's Web-Fetch middleware engine, 1.0.0 (defineMiddleware, pipeline, typed ctx contributions, seedContext and bufferRequest for framework bridges)Adapter: permdock/supabase/middleware (withPermDock), optional peerSupabase provider
@supabase/server (withSupabase, withClaims, withRequiredClaims, withPostgresClient, withPostgresAdminClient, withOAuthProtectedResource, withFeatureFlag)Stateless header-based Supabase auth, 1.9.1; JWKS-verified jwtClaims, RLS-scoped clients, RFC 9728 metadata. The framework adapters (adapters/hono, h3, elysia, nestjs) are deprecated and removed on 1 December 2026Recipe: subjectFromSupabase(ctx.jwtClaims); a toHono-style bridge for Hono, H3, Elysia and NestJS; withOAuthProtectedResource before the auth gate; withPostgresClient as the runtime twin of permdock rls verifySupabase provider, MCP adapter, RLS adapter
@supabase/ssrCookie-session Supabase client for Next.js, SvelteKit, Remix, React Router and Astro, 0.12.7Recipe: getClaims() feeding subjectFromSupabase inside the framework adapter's subjectSupabase provider
better-supabaseSupabase toolkit: token verification through @supabase/server, the kind-tagged AuthSession, typed clients, Storage and Realtime definitions (defineBucket, defineTopic), jobs, createMcp with authorize and visible hooks, checkSession and database hygiene lintsEntry: permdock/better-supabase fills its slots with authorizationProvider (the authorization config its SQL modules, entitlements, access policies and doctor read), bucketPolicy, topicPolicy, apiKeyVerifier, apiKeyClaimOptions and subjectFromBetterSupabase, with act.kind support and impersonation sessions as actors and anonymousSignIns: 'deny'; Hono, oRPC and createMcp recipes; PermDock owns the claims, the one token hook and the SQL helpers the provider's templates call; better-supabase imports nothing from PermDock; the bs.cached() snapshot recipe with snapshotTag(sub) and bs.invalidateSession; an optional peer of permdock/better-supabasebetter-supabase, Supabase token hook, RLS adapter, Next.js Cache Components guide
Clerk BillingPlans and features as pla and fea claimspla maps to principal.plans; fea maps to rolesClerk provider
Auth.js (NextAuth)Framework sessionSession resolverauthentication
WorkOS AuthKit and Connect, Auth0, Logto, Kinde, Neon Auth, Stack Auth, Firebase Auth, Amazon Cognito, Keycloak, OryJWKS-publishing providerssubjectFromJwtauthentication
Stytch Connected Apps, Descope, Scalekit, Auth0 Token Vault, Supabase OAuth 2.1 serverOAuth 2.1 authorization servers for MCP serverssubjectFromJwt, authInfoauthentication, MCP authorization
Okta (Cross App Access), Microsoft Entra ID (Agent ID)Enterprise IdPs with agent identity; sub is the human, the client is the agentsubjectFromJwt; EMA / ID-JAG transparentauthentication, delegation
Google Identity (Sign in with Google, Google Workspace)Consumer and workforce OIDC IdP; hd tenant, no groups in the tokensubjectFromJwt or the auth layer's session; groups from a directory lookupauthentication
Enterprise SSO layers (WorkOS AuthKit and Directory Sync, Clerk Enterprise SSO, Better Auth SSO plugin, Auth0 Organizations, Supabase SAML)SAML / OIDC termination and group-to-role mapping in front of the appSession or JWT consumed by subjectFrom*; Directory Sync rows read by context or a MembershipSource; or the IdP provisions straight into permdock/scimauthentication
Frontegg, PropelAuth, SuperTokens, HankoApplication-auth vendorssubjectFromJwtauthentication
ZitadelOpen-source IdP with project roles nested per organisation in urn:zitadel:iam:org:project:rolessubjectFromJwt with claims.memberships flattening role to { tenant, roles }JWT authorization claims, tenancy
Organisation, team and custom-role models (Clerk, Auth0 Organizations, WorkOS, Better Auth organization plugin, Kinde, Descope, Frontegg, PropelAuth, Logto)Where memberships and tenant-defined roles are storedprincipal.memberships from subjectFrom*; RoleSource and MembershipSource per provider; never a PermDock tabletenancy
SCIM 2.0 directories (Okta, Entra ID, Google Workspace; or via WorkOS Directory Sync)Group provisioning; group id as team identifierAdapter (permdock/scim: scimHandler writes a DirectoryStore you own, directoryMembershipSource yields memberships keyed on the SCIM id); the Cloud relay replays into the same handlerSCIM adapter, JWT authorization claims
Vercel Agent Auth (Better Auth)Delegated agent identities via RFC 8693; capability grantsactor and delegation mapper when published; capability grants are permission referenceslandscape, Cloud adapter
Web Bot Auth, SPIFFEWorkload and bot identityactor from signature or SVIDWeb Bot Auth, threat model
jose (panva)JOSE library: JWS / JWE / JWK / JWT, remote JWK Sets, typ and requiredClaims checksOptional peer of permdock/jwt and permdock/ssf; joseTokenVerifier and joseTokenSigner wrap it; other libraries plug in through TokenVerifier / TokenSignerJWT adapter, JOSE
OpenID Connect providers publishing DiscoverySource of issuer and jwks_uri for verificationsubjectFromJwt({ discovery }); RFC 8414 fallbackOpenID Connect, JWT adapter

Agent runtimes and frameworks

PermDock's agent adapters are thin translators from a Decision into a runtime's vocabulary. A framework earns an adapter only when it has a per-tool-call hook that can proceed, refuse or ask a human; a resume path on which the adapter can recompute Decision.token; and no existing route through MCP, the AI SDK, AuthZEN or a shipped adapter. Most frameworks fail the last test: MCP guards every tool a framework consumes from an MCP server, and the AI SDK adapter applies to everything built on it. A hook that cannot express "ask a human" must never map approval-required to denied, and the subject always comes from the host's verified material, never from agent state.

ToolWhat it isMechanismOwning page
Vercel AI SDK 7Model and tool layer; toolApproval returns approved, denied or user-approvalAdapter (permdock/ai-sdk)AI SDK adapter
Claude Agent SDKAnthropic agent runtime; canUseTool, PermissionRequest hookAdapter (permdock/claude-agent)Claude Agent adapter
EveVercel agent framework; approval and approval.response on defineToolAdapter (permdock/eve)Eve adapter
OpenAI Agents SDKneedsApproval, interruptions, serialisable RunState; tool guardrails as a second hook that cannot pauseAdapter (permdock/openai)OpenAI adapter
Model Context Protocol serversTool protocol runs the official SDK behind OAuth 2.1Adapter (permdock/mcp)MCP adapter
WebMCPBrowser tool registrationAdapter (permdock/webmcp)WebMCP adapter
A2AAgent-to-agent protocolAdapter (permdock/a2a)A2A adapter
@ai-sdk/reactAI SDK UI hooks (useChat, tool approval parts)Recipe (permdock/ai-sdk on the route, approval parts rendered by the app)AI SDK adapter
LangGraph.jsGraph runtime; interrupt() in a node, Command({ resume }) with a checkpointerRecipe (wrap each tool with decide, interrupt on approval-required, recompute token on resume); the one adapter candidate if the recipe proves too fiddlyapprovals
MastraTool execute; workflow suspend() and resume()AI SDK; recipe mapping approval-required to suspendapprovals
Cloudflare Agents SDKAI SDK tools on Durable ObjectsAI SDK; Durable Objects as the ApprovalStoreapprovals adapter
Vercel Workflow WorkflowAgentDurable needsApproval suspendAI SDK (needsApproval(permission))AI SDK adapter
Inngest AgentKitTool handlers, beforeTool-style middleware, step.waitForEventRecipe: middleware calls decide; approval as a wait step keyed by tokenapprovals
Google ADK for TypeScriptbeforeToolCallback, afterToolCallbackRecipe: refuse from decide; approvals need the app's own pauseapprovals
OpenAI Apps SDK (ChatGPT apps)Apps are MCP serversMCPMCP adapter
n8nAI Agent "Require approval" option and "Send and Wait for Response" nodeMCP on the tool side; no-code approval deliveryapprovals adapter
AWS Bedrock AgentCore Runtime and PolicyHosted runtime; Cedar at the gateway over tool name and parsed arguments, with no row and no pauseMCP; recipeOpenAPI adapter
Custom loops on raw provider SDKsWhatever the loop author writesdecide and assert directlyfor AI agents
AG-UIEvent stream between agent backend and UI, including human-in-the-loop eventsTracking; carries PermDock's approval request payload unchanged as a tool-call or custom eventwire formats
Agent Client ProtocolEditor-to-coding-agent protocol with permission requestsTracking; same shape as the coding-agent hooksterminal adapter

Coding-agent hooks

ToolWhat it isMechanismOwning page
Claude Code hooksPreToolUse allow, deny, askAdapter (permissionRequestHook)Claude Agent adapter
Cursor hooks, Gemini CLI hooks, Codex CLI, OpenCodePre-tool hooks (beforeShellExecution, beforeMCPExecution, BeforeTool, tool.execute.before); tool name and arguments in, allow, deny or ask outRecipe: one hook script over a permdock/terminal guard, subject from the developer's verified loginterminal adapter

Approval delivery and durable execution

ToolWhat it isMechanismOwning page
Vercel Chat SDK requestApprovalApproval cards on Slack, Teams, Discord with signature-verified respondersApprovalStore delivery recipe (reference)approvals adapter
Vercel Workflow SDKDurable stepsHolds the waitapprovals adapter
Trigger.dev waitpoints, Temporal, Restate, Inngest, Cloudflare WorkflowsDurable execution runtimesApprovalStore recipeapprovals adapter
Cloudflare Durable Objects, D1, Turso, SQLite, Redis, Upstash, Vercel KV, Postgres, Neon, SupabaseBacking storesApprovalStore recipeapprovals adapter
Knock, Novu, Courier, Resend, TwilioNotification channelsRecipe; link to approvalsHandlerapprovals adapter
Pushary, Rills, intrupt, Sesame, AxonFlowApproval-as-a-service APIs and SDKsPositioning; a self-hoster may back an ApprovalStore with any of themlandscape, approvals adapter
PermDock CloudHosted store, inbox, delivery at app.permdock.com; machine API at api.permdock.comcloud().approvalsCloud adapter
PermDock Cloud SCIM relayHosted SCIM endpoint per tenant replaying into your scimHandlerRFC 7523 JWT bearer verified by scimHandler({ verifier }); never a MembershipSourceSCIM adapter, Cloud adapter

Sinks, observability and compliance

ToolWhat it isMechanismOwning page
OpenTelemetry (@opentelemetry/api), GenAI semantic conventionsTracing API and the execute_tool spanAdapter (permdock/otel)OpenTelemetry adapter
Langfuse, LangSmith, Braintrust, Datadog LLM Observability, Sentry, PostHogLLM observabilityOpenTelemetry; no sink neededaudit
Splunk, Microsoft Sentinel, Datadog Cloud SIEM, AWS Security Lake, Google SecOps, Elastic SecuritySIEMs and security lakesDecisionSink with the OCSF projection; the Cloud posts the same projection to their ingest endpointsaudit, Cloud integrations
Axiom, Better Stack, a Postgres table, a queueLog and event destinationsDecisionSink recipe; CloudEvents envelopeaudit
Vanta, Drata, SecureframeCompliance automation collecting access-review evidencePull the signed batch (permdock-decisions+jwt) or CSV from the Cloud export endpoint, or query your own sinkaudit, Cloud integrations
Grafana Cloud, Honeycomb, New Relic, Datadog (OTLP intake), OpenTelemetry CollectorOTLP-native backends and receiverThe Cloud exports the evidence log as OTLP log records with permdock.* attributes; permdock/otel sends the app's spans to the same collector; a convenience copy, never the evidenceCloud integrations, OpenTelemetry adapter
Supabase Edge Functions, Supabase Postgres, Neon, your own Postgres (as evidence destinations)Tables and functions you ownScheduled signed-batch pull or a CloudEvents webhook; the Cloud never reads your tables or RLSCloud integrations
Slack, Microsoft Teams, Discord, email, PagerDuty, OpsgenieApproval delivery and paging surfacesChat SDK requestApproval run by the Cloud (Slack, Teams, Discord); email links land on the authenticated inbox; PagerDuty and Opsgenie receive a CloudEvents webhook and never resolveCloud integrations, approvals adapter
PermDock Cloud MCP server (mcp.permdock.com)The Cloud's read-only MCP server (evidence queries, pending approvals, catalog and drift)MCP over streamable HTTP with OAuth 2.1; approvals are never resolvable through itCloud integrations, MCP authorization
OCSF, CloudEventsSchemas for the events on the wireProjection and envelopewire formats
PermDock Cloud decision logHosted sinkcloud().sinkCloud adapter

Feature flags and entitlements

ToolWhat it isMechanismOwning page
OpenFeatureCNCF vendor-neutral flag APIsubject or context inputpolicies
@supabase-labs/middleware-openfeatureOpenFeature as a @supabase/middleware entry (withOpenFeature), 0.2.0Recipe: the evaluation context's targetingKey and tenant come from ctx.permdock; a flag never grants a permissionSupabase provider
Vercel Flags SDK, PostHog, LaunchDarkly, Statsig, Unleash, Flagsmith, GrowthBookFlag vendorsThrough OpenFeature or directly as context; never grantspolicies
Stripe Entitlements, Clerk Billing, Frontegg entitlements, Kinde feature_flagsBilling and plan entitlementsprincipal.plans and to: plan(...), fed by an EntitlementSource (fromStripeEntitlements reads stripe.entitlements.activeEntitlements.list through a structural client, no SDK import); Clerk fea stays on rolespolicies, Supabase token hook, Clerk provider
Stigg, SchematicEntitlement platforms (features per plan, overrides, usage limits)Plan features become roles through context or a RoleSource.assignable(tenant) subset; usage limits map to limit grants with a LimitStore; never grants on their owntenancy, policies
NilePostgres with a tenants table, per-tenant isolation and a tenant-aware connectionscopes.tenant.key on rows; memberOf compiles to the tenant column; a MembershipSource over users.tenant_userstenancy, RLS adapter

Databases and sync engines

ToolWhat it isMechanismOwning page
Drizzle, Prisma, KyselyTypeScript query builders and ORMsAdapter (toWhere)Drizzle, Prisma, Kysely
splinterSupabase's Postgres linter (CalVer 2026.09.1), run by supabase db advisors and the Supabase MCP server's get_advisorsRecipe (tests/integration asserts generated RLS raises no WARN or ERROR lint; permdock rls verify --advisors maps lints to doctor codes)Postgres RLS
supautilsSupabase's Postgres extension guarding reserved roles and superuser-only statements, 3.4.4Recipe (rls generate and doctor PD063 keep generated SQL and app migrations from altering, dropping or renaming a reserved role or granting a reserved membership)Postgres RLS
pg_jsonschemaJSON Schema validation for json and jsonb columns, 0.3.3 on SupabaseRecipe (rls.jsonSchema emits named check constraints on generated jsonb columns)Postgres RLS
Postgres, Supabase, Neon (RLS)Row-level security targetspermdock rls generateRLS adapter, Postgres RLS
@supabase/postgrest-typegenGenerates TypeScript types from a PostgREST schemaNone: the resource schema stays the Standard Schema a resource declares; better-supabase runs it for its typed clientsbetter-supabase
@supabase/postgres-metaSupabase's catalog API over pg_catalog (tables, policies, grants, functions)Not a dependency: permdock rls verify --introspect uses catalog queries modelled on its ownRLS CLI
@supabase-cache-helpers/*Query-cache bindings (SWR, TanStack Query) for PostgREST and StorageNone: they cache what RLS already filtered; invalidate on role change as for any cached readSupabase provider
@supabase/liteLightweight Supabase runtimeNot a parity target: no RLS parity with hosted Postgres is claimed; permdock rls verify runs against PostgresTesting
PGlite, @electric-sql/pglite-socketPostgres compiled to WASM and its wire-protocol socket serverTest and example database for toWhere (Drizzle through drizzle-orm/pglite, Prisma 7 through @prisma/adapter-pg); never a runtime dependencyDrizzle, Prisma, Testing
ConvexBackend platformAdapter (permdock/convex)Convex adapter
Zero (Rocicorp)Sync engine; ZQL permission expressions per table and operation with authData from a JWTwhere target candidate: a toZeroPermissions(policy) generator, the closest fitThis page, roadmap
ElectricSQLSync engine; shapes are a table plus a SQL-subset where chosen by your proxywhere target candidate for reads; writes stay on routes behind protectThis page, roadmap
PowerSyncSync engine; edition 3 Sync Streams with SQL subqueries over auth.user_id() and token parameterspermdock powersync generate compiles read grants to Sync Streams and streams the user's own membership and role rows; verify checks no stream syncs a denied row; powersyncSource builds the device snapshot from thempowersync
InstantDBSync engine; allow rule expressions per namespace and operationGenerator candidate after the SQL-like targetsThis page, roadmap
TinyBaseLocal-first store with no permission languageNothing to compile to; filter, the snapshot and protectThis page, roadmap
MongoDB, MongooseDocument database; Mongoose implements Standard Schema; no row-level policywhere target candidate: Prisma's MongoDB connector first, then a Mongoose or driver toFilterThis page, roadmap, RLS adapter
Payload CMSCMS with access-control functions returning WhereTrackinglandscape
Cloudflare D1, Turso, SQLiteSQLite-family stores without RLSDrizzle sqlite dialect; ApprovalStore recipeapprovals adapter, RLS adapter

Every sync-engine and MongoDB candidate is a compiler or generator in the permdock CLI, never a runtime dependency, and joins the parity suite in permdock/testing before it ships. The RLS portable subset is the contract: an operator that does not compile to RLS will not compile to a sync engine either. Engine filters take subject material only from verified token claims, and they cover reads only; every write still passes through a route or mutator guarded by protect, so approval-required and closures keep working.

Testing and CI

ToolWhat it isMechanismOwning page
Supabase capability matrix (supabase/sdk)Three-segment capability ids (auth.session.get_claims) shared by the Supabase client SDKs, capability-matrix-v1.12.0; a { feature, cases } conformance-vector schema is in review (PR #30)Tracking: the Supabase manifest names the capability ids the adapter needs; claim vectors follow the conformance shapeWatch list
PlaywrightBrowser and API e2e runnerRecipe (runs @next/playwright; no PermDock entry)Next.js Cache Components guide
@next/playwrightNext.js Playwright helper; instant() asserts a navigation completed from prefetched UIRecipe (the instant-navigation test, no wrapper in permdock/testing)Next.js Cache Components guide
testcontainersDocker-backed Postgres for RLS parity and the next-better-supabase exampleRecipe (pnpm test:integration, the example's serve)Testing adapter, RLS adapter
Bun, DenoJavaScript runtimes with a Web fetch serverWinterTC entries run unchanged; tests/runtimes smoke (kernel, Hono, AuthZEN, JWT; Elysia on Bun)Testing adapter, server kernel
workerd, MiniflareCloudflare Workers runtime and its local simulatorWinterTC entries without nodejs_compat; tests/runtimes smoke through MiniflareTesting adapter, server kernel
esbuildBundlerBuilds the platform: 'neutral' Worker bundle in tests/runtimes; never a dependency of permdockTesting adapter
@pgkit/migraThe schema diff engine supabase db diff runsRecipe (tests/integration diffs the generated schema files against the migrations with the CLI's options; never a dependency of permdock)rls

Distribution channels

ChannelWhat it isMechanismOwning page
npm (permdock)The packageInstall pathinstallation
Vercel MarketplaceNative integration listing for PermDock Cloud; eve-agent templateCloud provisioningCloud adapter, landscape
Supabase partner marketplace, Convex components directoryProvider ecosystemsDistributionlandscape
Cursor and Claude Code plugin marketplaces, skills.shSkills and a docs MCPDistributionagent docs standards
Slack App DirectoryListing for an approval botDistributionCloud integrations
GitHub (App for permdock-audit; Actions recipe for --check)CI and reviewRecipe; Cloud PR botCLI: openapi
MCP RegistryDiscovery of MCP serversRecipe (server.json, POST /mcp)agent docs standards
AWS MarketplaceChannel for the hosted ADS for teams enforcing from Go or Java on AWSNot yetlandscape

App frameworks (collect-only)

ToolWhat it isMechanismOwning page
NuxtVue meta-framework on Nitro and ViteLoader (getSnapshot in a server route, permdock/vue)server kernel, Vue
AstroContent-first framework with Vite and islandsRecipe (createPermDockUnplugin.vite, island UI adapter, permdock/server)unplugin
React Router 7Vite-based router / frameworkLoader (getSnapshot and snapshotHeaders in loader, permdock/react)unplugin, UI
TanStack StartFull-stack Vite frameworkLoader (getSnapshot in createServerFn, permdock/react)unplugin, UI
EffectTyped-effects runtime; Effect Schema and HttpApiRecipe (Standard Schema adapter; Overlay on HttpApi output; unplugin when the bundler is Vite)unplugin, Standard Schema, OpenAPI
SvelteKitSvelte meta-framework on ViteLoader (getSnapshot in +layout.server.ts, permdock/svelte stores)Svelte, unplugin
SolidStartSolid meta-framework on Vinxi and NitroRecipe (permdock/solid accessors, permdock/server in server functions)Solid, unplugin
NitroServer engine under Nuxt, SolidStart and TanStack StartRecipe (permdock/server over the Web Request)server kernel
Expo Router and expo-serverFile-based routing and API routes for React Native appsRecipe (permdock/react-native in screens, permdock/server in API routes)React Native
TurborepoMonorepo task runnerRecipe (shared definitions package, permdock collect with globbed srcPath)collect, Next.js plugin
tsdownLibrary bundler used for PermDock's packages and a shared definitions packageBuild tool; a bundled copy of the definitions resolves to the same grants by keycollect
unpluginUnified bundler plugin helperHook (createPermDockUnplugin)unplugin

Adopt / adapt / avoid

Adopt: standard fields, the Overlay, subjectFromJwt, the hosted-capability interfaces (ApprovalStore, DecisionSink, SnapshotSource), MCP and AuthZEN as the mechanisms through which every row is reached; MCP and the AI SDK as the two integration points that cover most agent frameworks.

Adapt: a recipe on the owning page whenever a tool needs more than a standard field; a consumer-side overlay when a tool wants a derived value in its own namespace; compilers and generators, not runtime adapters, for new data targets.

Avoid: a package entry for any row that is not already on the adapters matrix; one adapter per agent framework; naming a tool anywhere in the docs without a row here.

Last updated on

On this page