# Permit

Permit is an access control platform that provides fine-grained, real-time permission management using various models such as RBAC, ABAC, and ReBAC. It enables organizations to enforce dynamic policies across their applications, ensuring that only authorized users can access specific resources.

## Overview

This package provides two Langchain tools for JWT validation and permission checking using Permit:

* LangchainJWTValidationTool: Validates JWT tokens against a JWKS endpoint

* LangchainPermissionsCheckTool: Checks user permissions using Permit


## Setup

Set up the following environment variables:

```bash
PERMIT_API_KEY=your_permit_api_key
JWKS_URL=your_jwks_endpoint_url
PERMIT_PDP_URL=your_permit_pdp_url  # Usually http://localhost:7766 for local development or your real deployment
```

Make sure your PDP (Policy Decision Point) is running at PERMIT_PDP_URL.
See [Permit docs](https://docs.permit.io/concepts/pdp/overview/) for details on policy setup and how to launch the PDP container.

### Credentials

```bash
PERMIT_API_KEY=
JWKS_URL=your_jwks_endpoint_url # or your deployed url
PERMIT_PDP_URL=your_pdp_url # or your deployed url
TEST_JWT_TOKEN= # for quick test purposes
```

It's also helpful (but not needed) to set up [LangSmith](https://smith.langchain.com/) for best-in-class observability:

## Instantiation

### JWT Validation Tool
The JWT Validation tool verifies JWT tokens against a JWKS (JSON Web Key Set) endpoint.

#### Basic Usage

```python
from langchain_permit.tools import LangchainJWTValidationTool

# Initialize the tool
jwt_validator = LangchainJWTValidationTool(
    jwks_url=#your url endpoint
)

# Validate a token
async def validate_token():
    claims = await jwt_validator._arun(
        "eyJhbGciOiJSUzI1NiI..."  # Your JWT token
    )
    print("Validated Claims:", claims)
```

### Configuration Options
You can initialize the tool with either:

* A JWKS URL
* Direct JWKS JSON data
* Environment variable (JWKS_URL)

```python
# Using direct JWKS JSON
jwt_validator = LangchainJWTValidationTool(
    jwks_json={
        "keys": [
            {
                "kid": "key-id",
                "kty": "RSA",
                ...
            }
        ]
    }
)
```

## Invocation

### [Invoke directly with args](https://docs.permit.io/)

- TODO: Describe what the tool args are, fill them in, run cell

### [Invoke with ToolCall](https://docs.permit.io/)

We can also invoke the tool with a model-generated ToolCall, in which case a ToolMessage will be returned:

- TODO: Fill in tool args and run cell

## Chaining

- TODO: Add user question and run cells

We can use our tool in a chain by first binding it to a [tool-calling model](https://docs.permit.io/) and then calling it:

import ChatModelTabs from "@theme/ChatModelTabs";

<ChatModelTabs customVarName="llm" />


## API reference

For detailed documentation of all Permit features and configurations head to the API reference: https://docs.permit.io/