Run the PDP container (permitio/pdp-v2:latest with your environment API key as PDP_API_KEY) before making any permit.check calls, and set the SDK's pdp URL to wherever that container is reachable. Keep the PDP and PEP roles straight in your head: the PDP answers authorization queries, the PEP (your SDK call, middleware, or gateway plugin) enforces the answer.

Context: Official docs (Glossary): documents a gotcha that trips agents new to Permit. The SDK's permit.check is a Policy Enforcement Point: it queries a Policy Decision Point, which in Permit is a docker container you run yourself, usually as a sidecar next to your services. Agents that install the SDK, point it at the default YOUR_HOST (port 7766), and never start the container get connection refused on every check and blame the policy.