From af6814798bdac6c38bc4df2b19cafd73f793a5ad Mon Sep 17 00:00:00 2001 From: eli Date: Mon, 28 Sep 2026 14:50:45 -0500 Subject: [PATCH 1/5] PER-16379: remove the retired EU region from the docs The prod-EU region was torn down on 2026-09-28 and every EU host (api.eu.permit.io, *.eu-central-1.permit.io) is dead. Drop the EU base URL, SCIM host, Cloud PDP and PDP control-plane instructions, point the .NET quickstart apiUrl at https://api.permit.io, and leave a short note on the API page for anyone still configured with the EU URL. Co-Authored-By: Claude Opus 5.5 --- docs/api/api-reference.mdx | 3 +-- docs/api/api-with-cli.mdx | 27 +++---------------- .../_quickstart-parts/_quickstart_dotnet.mdx | 4 +-- docs/how-to/permit-cli/permit-cli-pdp.mdx | 2 +- docs/how-to/permit-cli/permit-cli.mdx | 2 +- docs/integrations/SCIM/EntraID.mdx | 2 +- docs/integrations/SCIM/OKTA.mdx | 2 +- docs/integrations/SCIM/SCIM_overview.mdx | 2 -- docs/modeling/google-drive.mdx | 2 +- 9 files changed, 11 insertions(+), 35 deletions(-) diff --git a/docs/api/api-reference.mdx b/docs/api/api-reference.mdx index 8d0f2ce4..3479cc2f 100644 --- a/docs/api/api-reference.mdx +++ b/docs/api/api-reference.mdx @@ -11,7 +11,6 @@ Use this page to find the Permit.io Cloud API reference and the facts every call | Item | Value | | --- | --- | | Base URL | `https://api.permit.io` (all paths start with `/v2`) | -| EU region base URL | `https://api.eu.permit.io`, for workspaces hosted in the EU region | | Authentication | `Authorization: Bearer ` header on every request | | Request and response format | JSON | @@ -44,6 +43,6 @@ Permit API objects nest in this order: a workspace (your organization) contains ## Related pages -- [Calling the API](/api/api-with-cli): API keys, rate limiting, regions, and curl and Postman examples +- [Calling the API](/api/api-with-cli): API keys, rate limiting, the API endpoint, and curl and Postman examples - [PDP API reference](/api/pdp-api-reference): the API of the policy decision point (PDP) - [Background APIs](/api/background-tasks): endpoints that run as background tasks diff --git a/docs/api/api-with-cli.mdx b/docs/api/api-with-cli.mdx index 7956e945..7a8e3721 100644 --- a/docs/api/api-with-cli.mdx +++ b/docs/api/api-with-cli.mdx @@ -2,7 +2,7 @@ sidebar_position: 3 title: Call the Permit API sidebar_label: Calling the API -description: "Get an API key and call the Permit.io REST API with curl, Postman, or an SDK, with the regional endpoints and how to handle a rate-limited request." +description: "Get an API key and call the Permit.io REST API with curl, Postman, or an SDK, with the API endpoint and how to handle a rate-limited request." --- Call the Permit.io REST API directly from curl, Postman, or any HTTP client. This page is for developers who automate Permit, for example to sync users or tenants from a script. Every action in the Permit dashboard calls the same API, so anything you do in the dashboard you can also do through the API. @@ -95,30 +95,9 @@ The tenants endpoint returns a plain JSON array of tenant objects. To get the pa To import every Permit endpoint into Postman at once, import the [OpenAPI spec](https://api.permit.io/v2/openapi.json). -## API endpoints and regions \{#api-endpoints-and-regions} +## API endpoint \{#api-endpoints-and-regions} -The examples in the Permit docs use the `api.permit.io` endpoint. If your workspace is hosted in the EU region, replace `api.permit.io` with `api.eu.permit.io` in every API call. Which regions you can choose depends on your plan; see [Permit pricing](https://www.permit.io/pricing). - -### Set the region in the Node.js SDK \{#permit-init-example-on-node-sdk} - -In the SDKs, set the API URL when you create the Permit client. In the Node.js SDK, set `apiUrl`: - -```js -const { Permit } = require("permitio"); - -const permit = new Permit({ - // the API key to the Permit environment you wish to connect to - token: "", - // the url in which the SDK can connect to the PDP container - pdp: "http://localhost:7766", - // use this to turn on sdk logs - log: { - level: "debug", - }, - // the region in which the Permit environment is located - apiUrl: "https://api.eu.permit.io", -}); -``` +All Permit workspaces use the `https://api.permit.io` endpoint, which is the one the examples in the Permit docs use. The EU region (`api.eu.permit.io`) was retired. If your code or SDK client sets `api.eu.permit.io` as the API URL, change it to `https://api.permit.io`. ## Handle an HTTP 429 response \{#rate-limiting} diff --git a/docs/getting-started/_quickstart-parts/_quickstart_dotnet.mdx b/docs/getting-started/_quickstart-parts/_quickstart_dotnet.mdx index abc05b0c..1300cb11 100644 --- a/docs/getting-started/_quickstart-parts/_quickstart_dotnet.mdx +++ b/docs/getting-started/_quickstart-parts/_quickstart_dotnet.mdx @@ -52,8 +52,8 @@ mkdir hello-permissions-dotnet && cd hello-permissions-dotnet && dotnet new cons label: "Permitio-sdk", // should log as JSON logAsJson: false, - // the URL of the API (relevant for EU customers) - apiUrl: "https://api.eu-central-1.permit.io", + // the URL of the Permit API + apiUrl: "https://api.permit.io", // should raise errors (instead of the default behavior of returning false for network errors in permit checks) raiseErrors: false, // Optional: manual set the environment_id and project_id for the SDK client (to avoid `scope` api call) diff --git a/docs/how-to/permit-cli/permit-cli-pdp.mdx b/docs/how-to/permit-cli/permit-cli-pdp.mdx index 49f39219..a0dcac11 100644 --- a/docs/how-to/permit-cli/permit-cli-pdp.mdx +++ b/docs/how-to/permit-cli/permit-cli-pdp.mdx @@ -14,7 +14,7 @@ The commands send requests to different PDPs when you don't pass a URL: | Command | Flag for the PDP URL | Default | |---|---|---| -| `permit pdp check` | `--pdpurl` | The Cloud PDP of your region: `https://cloudpdp.api.permit.io`, or `https://cloudpdp.api.eu-central-1.permit.io` for `eu` | +| `permit pdp check` | `--pdpurl` | The Cloud PDP: `https://cloudpdp.api.permit.io` | | `permit pdp check-url` | `--pdp-url` | `http://localhost:7766` | `permit pdp run` publishes the PDP on port `7766` of your machine. To check a permission against that container, pass `--pdpurl http://localhost:7766` to `permit pdp check`. diff --git a/docs/how-to/permit-cli/permit-cli.mdx b/docs/how-to/permit-cli/permit-cli.mdx index 1c8927fc..440d8ae9 100644 --- a/docs/how-to/permit-cli/permit-cli.mdx +++ b/docs/how-to/permit-cli/permit-cli.mdx @@ -37,7 +37,7 @@ Most commands call the Permit API, so they need your credentials. Run `permit lo |---|---|---| | `--api-key ` | `-k` | Sign in with a Permit API key instead of the browser. | | `--workspace ` | | The workspace key to use, which skips the workspace selection step. | -| `--region ` | `-r` | The Permit region: `us` or `eu`. Defaults to `us`. | +| `--region ` | `-r` | The Permit region. Defaults to `us`, the only active region; the EU region was retired. | ```bash $ permit login diff --git a/docs/integrations/SCIM/EntraID.mdx b/docs/integrations/SCIM/EntraID.mdx index 0955d489..0f3f21d7 100644 --- a/docs/integrations/SCIM/EntraID.mdx +++ b/docs/integrations/SCIM/EntraID.mdx @@ -44,7 +44,7 @@ Provision users from Microsoft Entra ID (formerly Azure Active Directory) into y | Field | Value | |---|---| - | **Tenant URL** | `https://scim.permit.io/scim/v2/{permit_project_id}/{permit_env_id}`. For EU users, `https://scim.eu-central-1.permit.io/scim/v2/{permit_project_id}/{permit_env_id}`. | + | **Tenant URL** | `https://scim.permit.io/scim/v2/{permit_project_id}/{permit_env_id}`. | | **Secret Token** | Your environment API key | Replace `{permit_project_id}` and `{permit_env_id}` with your Permit project ID or key and environment ID or key. The **Tenant URL** field is an Entra ID label. To assign roles in a specific Permit tenant, use the tenant-aware base URL described in [Permit SCIM base URLs](/integrations/SCIM/SCIM_overview#multi-tenant-scim). diff --git a/docs/integrations/SCIM/OKTA.mdx b/docs/integrations/SCIM/OKTA.mdx index da917e0d..33f35c1c 100644 --- a/docs/integrations/SCIM/OKTA.mdx +++ b/docs/integrations/SCIM/OKTA.mdx @@ -27,7 +27,7 @@ Provision users from Okta into your Permit.io environment with System for Cross- 4. **Connect Okta to the Permit SCIM API.** - Go to the **Provisioning** tab and click **Configure API Integration**. - Check **Enable API integration**. - - In **Base URL**, enter `https://scim.permit.io/scim/v2/{permit_project_id}/{permit_env_id}`. For EU users, enter `https://scim.eu-central-1.permit.io/scim/v2/{permit_project_id}/{permit_env_id}`. Replace `{permit_project_id}` and `{permit_env_id}` with your Permit project ID or key and environment ID or key. To assign roles in a specific Permit tenant, use the tenant-aware base URL described in [Permit SCIM base URLs](/integrations/SCIM/SCIM_overview#multi-tenant-scim). + - In **Base URL**, enter `https://scim.permit.io/scim/v2/{permit_project_id}/{permit_env_id}`. Replace `{permit_project_id}` and `{permit_env_id}` with your Permit project ID or key and environment ID or key. To assign roles in a specific Permit tenant, use the tenant-aware base URL described in [Permit SCIM base URLs](/integrations/SCIM/SCIM_overview#multi-tenant-scim). - In **API Token**, enter your environment API key. - Click **Test API Credentials**. Okta shows a success message when it can reach Permit with the API key. - Click **Save**. diff --git a/docs/integrations/SCIM/SCIM_overview.mdx b/docs/integrations/SCIM/SCIM_overview.mdx index 5e7008ef..850ee82a 100644 --- a/docs/integrations/SCIM/SCIM_overview.mdx +++ b/docs/integrations/SCIM/SCIM_overview.mdx @@ -61,8 +61,6 @@ Replace the placeholders as follows: | `{permit_env_id}` | Your Permit environment ID or key. See [Get the environment ID](/manage-your-account/projects-and-env#getting-the-environment-id). | | `{tenant_key}` | The key of the target Permit tenant. The SCIM server accepts `[A-Za-z0-9_-]{1,64}`: 1 to 64 alphanumerics, underscores, or hyphens. Another value returns HTTP `404` at the routing layer, before any handler runs. | -EU users replace the `scim.permit.io` host with `scim.eu-central-1.permit.io` in either shape, for example `https://scim.eu-central-1.permit.io/scim/v2/{permit_project_id}/{permit_env_id}/v2/{tenant_key}`. - :::note The second /v2/ segment is a routing prefix The second `/v2/` segment in the tenant-aware URL selects the multi-tenant SCIM API. It is not a SCIM protocol version. The SCIM 2.0 protocol version is the earlier `/scim/v2/` segment. ::: diff --git a/docs/modeling/google-drive.mdx b/docs/modeling/google-drive.mdx index a07b244a..db967d41 100644 --- a/docs/modeling/google-drive.mdx +++ b/docs/modeling/google-drive.mdx @@ -1838,7 +1838,7 @@ Check what John and Jane can do on `file:2023_report`. The PDP is a container that fetches the policy and data from the Permit control plane and answers permission checks locally. Run it with your environment API key. For other ways to run a PDP, see [Run the PDP](/overview/run-pdp). -The PDP connects to `https://api.permit.io` by default. If your workspace is hosted in the EU region, set `PDP_CONTROL_PLANE=https://api.eu.permit.io`. See [PDP configuration](/concepts/pdp/configuration). +The PDP connects to `https://api.permit.io` by default. See [PDP configuration](/concepts/pdp/configuration). ```bash docker run -it \ From e8a95a28dbde663abdbd4713be7bfe882e514a4a Mon Sep 17 00:00:00 2001 From: eli Date: Mon, 28 Sep 2026 14:51:27 -0500 Subject: [PATCH 2/5] PER-16379: drop Europe from the status page description The Europe components were removed from the public Instatus status page on 2026-09-28, so the page no longer reports a Europe region. Co-Authored-By: Claude Opus 5.5 --- docs/status.mdx | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/status.mdx b/docs/status.mdx index 6592b292..561ad330 100644 --- a/docs/status.mdx +++ b/docs/status.mdx @@ -1,7 +1,7 @@ --- sidebar_position: 21 title: Permit Uptime Status -description: "Check the live status, uptime, and incident notices of Permit.io services, including the backend, OPAL, frontend, and PDP data services, in the US East and Europe regions." +description: "Check the live status, uptime, and incident notices of Permit.io services, including the backend, OPAL, frontend, and PDP data services." sidebar_custom_props: { icon: planet-line} --- @@ -9,7 +9,7 @@ Check whether a Permit.io service is operational before you debug an outage in y ## Services on the status page -The status page lists these Permit services. Each service except Marketing Website reports the US East and Europe regions separately. The live status page is the authoritative list. +The status page lists these Permit services. The live status page is the authoritative list. - Permit.io Backend - Permit.io OPAL (Open Policy Administration Layer) From 11ee9973a21395b2562db71fdb5bae0acd4c7ded Mon Sep 17 00:00:00 2001 From: Zeev Manilovich Date: Mon, 28 Sep 2026 23:19:25 +0300 Subject: [PATCH 3/5] PER-16379: list every retired EU host on the API page The retirement note named only api.eu.permit.io, but the docs also published api.eu-central-1.permit.io (.NET quickstart), cloudpdp.api.eu-central-1.permit.io (CLI Cloud PDP default), scim.eu-central-1.permit.io (SCIM setup) and the EU PDP_CONTROL_PLANE. After this PR those hosts appear nowhere in the docs, so readers who configured them had no replacement. List each retired host with its US counterpart and where it is set, and scope "every workspace" to Permit's cloud, since a self-hosted Permit Platform uses its own URL. Co-Authored-By: Claude Opus 5.5 (1M context) --- docs/api/api-with-cli.mdx | 10 +++++++++- 1 file changed, 9 insertions(+), 1 deletion(-) diff --git a/docs/api/api-with-cli.mdx b/docs/api/api-with-cli.mdx index 7a8e3721..48224799 100644 --- a/docs/api/api-with-cli.mdx +++ b/docs/api/api-with-cli.mdx @@ -97,7 +97,15 @@ To import every Permit endpoint into Postman at once, import the [OpenAPI spec]( ## API endpoint \{#api-endpoints-and-regions} -All Permit workspaces use the `https://api.permit.io` endpoint, which is the one the examples in the Permit docs use. The EU region (`api.eu.permit.io`) was retired. If your code or SDK client sets `api.eu.permit.io` as the API URL, change it to `https://api.permit.io`. +Every workspace in Permit's cloud uses the `https://api.permit.io` endpoint, which is the one the examples in the Permit docs use. + +Permit retired its EU region in September 2026. The EU hosts no longer resolve, so a request from your code, SDK client, PDP, or identity provider to an EU host fails. Replace each EU host with its US counterpart: + +| Retired EU host | Replace with | Where it is set | +| ------------------------------------------------ | ------------------------ | -------------------------------------------------------------------------------------------------------------------- | +| `api.eu.permit.io`, `api.eu-central-1.permit.io` | `api.permit.io` | The API URL of the SDK client, for example `apiUrl` in the Node.js and .NET SDKs, and `PDP_CONTROL_PLANE` on the PDP | +| `cloudpdp.api.eu-central-1.permit.io` | `cloudpdp.api.permit.io` | The PDP URL of the SDK client (`pdp`) | +| `scim.eu-central-1.permit.io` | `scim.permit.io` | The SCIM base URL in your identity provider, such as Okta or Entra ID | ## Handle an HTTP 429 response \{#rate-limiting} From b93b094e047204fa7fbb100a0278ff260b707e3a Mon Sep 17 00:00:00 2001 From: Zeev Manilovich Date: Mon, 28 Sep 2026 23:19:35 +0300 Subject: [PATCH 4/5] PER-16379: drop SDK example claims from the API pages Removing the EU region section also removed the only SDK example on /api/api-with-cli (the Node.js apiUrl snippet), but the page description still promised calling the API "with ... an SDK" and the Cloud API reference still pointed there for "SDK examples". Both now name only the curl and Postman examples the page has. Co-Authored-By: Claude Opus 5.5 (1M context) --- docs/api/api-reference.mdx | 2 +- docs/api/api-with-cli.mdx | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/api/api-reference.mdx b/docs/api/api-reference.mdx index 3479cc2f..c9eff71d 100644 --- a/docs/api/api-reference.mdx +++ b/docs/api/api-reference.mdx @@ -14,7 +14,7 @@ Use this page to find the Permit.io Cloud API reference and the facts every call | Authentication | `Authorization: Bearer ` header on every request | | Request and response format | JSON | -Get an API key from the Permit dashboard. See [Get your API key](/overview/get-api-key). For curl, Postman, and SDK examples, see [Calling the API](/api/api-with-cli). +Get an API key from the Permit dashboard. See [Get your API key](/overview/get-api-key). For curl and Postman examples, see [Calling the API](/api/api-with-cli). ## Interactive API reference diff --git a/docs/api/api-with-cli.mdx b/docs/api/api-with-cli.mdx index 48224799..01cd7472 100644 --- a/docs/api/api-with-cli.mdx +++ b/docs/api/api-with-cli.mdx @@ -2,7 +2,7 @@ sidebar_position: 3 title: Call the Permit API sidebar_label: Calling the API -description: "Get an API key and call the Permit.io REST API with curl, Postman, or an SDK, with the API endpoint and how to handle a rate-limited request." +description: "Get an API key and call the Permit.io REST API with curl or Postman, with the API endpoint and how to handle a rate-limited request." --- Call the Permit.io REST API directly from curl, Postman, or any HTTP client. This page is for developers who automate Permit, for example to sync users or tenants from a script. Every action in the Permit dashboard calls the same API, so anything you do in the dashboard you can also do through the API. From 57f4ebd8fb6d066f15bf17a4c3368f67b85822ab Mon Sep 17 00:00:00 2001 From: Zeev Manilovich Date: Mon, 28 Sep 2026 23:24:02 +0300 Subject: [PATCH 5/5] PER-16379: state that us is the only --region value "Defaults to us, the only active region" read as if other values, such as eu, were still accepted but inactive. The CLI (permit-cli#149) accepts only us, so say that us is the only supported value. Co-Authored-By: Claude Opus 5.5 (1M context) --- docs/how-to/permit-cli/permit-cli.mdx | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/how-to/permit-cli/permit-cli.mdx b/docs/how-to/permit-cli/permit-cli.mdx index 440d8ae9..3ce10671 100644 --- a/docs/how-to/permit-cli/permit-cli.mdx +++ b/docs/how-to/permit-cli/permit-cli.mdx @@ -37,7 +37,7 @@ Most commands call the Permit API, so they need your credentials. Run `permit lo |---|---|---| | `--api-key ` | `-k` | Sign in with a Permit API key instead of the browser. | | `--workspace ` | | The workspace key to use, which skips the workspace selection step. | -| `--region ` | `-r` | The Permit region. Defaults to `us`, the only active region; the EU region was retired. | +| `--region ` | `-r` | The Permit region. The only supported value is `us`, which is also the default. The EU region (`eu`) was retired. | ```bash $ permit login