The PDP (Policy decision point) syncs with the authorization service and maintains up-to-date policy cache for open policy agent.
PDPs are connected to your Permit.io account using an API Key. Check out the Permit.io documentation to learn how to get an Environment API Key.
You can run a PDP in a docker container by running the following command:
docker run -it -p 7766:7000 -e PDP_API_KEY=<YOUR_API_KEY> -e PDP_DEBUG=True permitio/pdp-v2:latestYou can deploy the PDP to production in multiple designs. See the Permit.io documentation for more information.
- Clone the repository
- Install uv 0.12.19 or later
- Install the locked dependencies, including the dev group, into
.venv(uv fetches Python 3.13 if it is missing)
uv sync- Run the tests
uv run pytest horizon/tests/- Run the type check (ty, configured under
[tool.ty]inpyproject.toml). CI fails on any diagnostic, warnings included.
uv run ty check- Install the git hooks (ruff, rustfmt, clippy, the ty type check, the waiver and lock checks), or run them on demand
uvx prek install
uvx prek run --all-filesDependencies live in pyproject.toml and are locked in uv.lock, which the Docker image and CI
install as-is. After editing pyproject.toml, run uv lock and commit both files.
PDP_API_KEY=<YOUR_API_KEY> uv run uvicorn horizon.main:app --reload --port=7000
You can pass environment variables to control the behavior of the PDP image. For example, running a local PDP against the Permit API:
PDP_CONTROL_PLANE=https://api.permit.io PDP_API_KEY=<YOUR_API_KEY> uv run uvicorn horizon.main:app --reload --port=7000
For ARM architecture:
VERSION=<TAG> make build-arm64
For AMD64 architecture:
VERSION=<TAG> make build-amd64
VERSION=<TAG> API_KEY=<PDP_API_KEY> make run
