Skyvern MCP server and Dome
Let agents work your portals. Decide which ones.
Skyvern drives a browser through forms and logins from plain-language instructions. Connect its hosted MCP server to Dome once, and rules decide every navigation and login on its URL. Each person's Skyvern account stays in Dome, and every step lands in one audit trail.
How Dome helps
Dome provides a governed gateway for Skyvern
Logins decided on the URL
Rules read the URL of every navigation and login. A payer portal on the list opens, and a lookalike domain is refused.
Passwords never reach the agent
skyvern_login signs in with a credential stored in Skyvern. Dome holds each person's Skyvern token, so the agent sees neither.
Every step on the record
Navigations, logins, actions and extractions are each a tool call. The audit trail shows which person each one ran for.
Get started
Skyvern behind the Gateway in three steps
Add the hosted MCP server with OAuth, sync its tools into the Gateway's catalog, and apply the rules. Dome registers its own OAuth client with Skyvern.
01
Add the Skyvern MCP server
Each person connects their own Skyvern account on their first call. Dome holds the token.
$ dome tools add --name skyvern \--url https://api.skyvern.com/mcp/ \--auth-method oauth --credential-type per-user \--oauth-authorize-url https://api.skyvern.com/oauth/authorize \--oauth-token-url https://api.skyvern.com/oauth/token \--oauth-registration-url https://clerk.skyvern.com/oauth/register \--gateway ops-gateway02
Sync the catalog
Sync spends your own Skyvern credential, so sign in first. Until then it fails and agents get “tool not available in this gateway”.
$ dome tools catalog sync skyvern03
Apply the rules
Scope them to one agent while you try them. Simulate before you deploy.
$ dome rules apply skyvern-permit.cedar skyvern-portals.cedar \--agent claims-filer --name skyvern-portals
Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Skyvern itself, see Skyvern's documentation.
Rules
Log in to two portals, nothing else
The permit opens the browser tools to the agent. The forbid refuses any navigation or login whose URL isn't on one of two payer portals, and a login with no URL is refused too.
permit (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "skyvern" && ["skyvern_browser_session_create", "skyvern_browser_session_close", "skyvern_navigate", "skyvern_login", "skyvern_act", "skyvern_extract"].contains(resource.tool_name)}; forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "skyvern" && ["skyvern_navigate", "skyvern_login"].contains(resource.tool_name) && !(resource has arguments && resource.arguments has url && (resource.arguments.url like "https://portal.coastal-mutual.com/*" || resource.arguments.url like "https://claims.brightline-health.com/*"))};Try it
One call, two outcomes
Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.
Site
- Agentclaims-filer is registered and active
- Callerd.mensah verified through Microsoft Entra ID
- Ruleportal.coastal-mutual.com is on the list
Example agents
Three agents on Skyvern
Each one works a short list of portals, for the specialist it acts for. A bundle per agent keeps the lists apart.
claims-filer
File claims on payer portals
Logs in to two payer portals and fills each claim form from the case file. Any other site is refused.
- skyvern/skyvern_login
- skyvern/skyvern_navigate
- skyvern/skyvern_act
eligibility-checker
Check member eligibility
Looks up coverage for each new case and extracts the plan details. It reads and never submits.
- skyvern/skyvern_login
- skyvern/skyvern_navigate
- skyvern/skyvern_extract
remittance-collector
Collect remittance notices
Signs in to each payer weekly and extracts new remittance totals for finance.
- skyvern/skyvern_login
- skyvern/skyvern_navigate
- skyvern/skyvern_extract
Agent workflow
Bringing it together
Connecting Skyvern to registered agents, models, and identity in Dome completes a governed agent application.
Acting for
Control point
Gateway
- Rules
- Guards
- Quotas
Every call decided and audited
Tools
Agent service
Skyvern
This page
Models
FAQ
Common questions
Does Skyvern have a hosted MCP server?
Yes. Skyvern hosts one at api.skyvern.com/mcp/ with OAuth, and Dome adds it by URL and registers its own client.
Can I limit which portals a Skyvern agent logs in to?
Yes. Rules read the URL argument of skyvern_navigate and skyvern_login, so a listed portal opens and any other host is refused.
Does the agent ever see the portal password?
No. skyvern_login signs in with a credential stored in Skyvern, and Dome holds the Skyvern token for each person.
Whose Skyvern account does an agent use?
The account of the person it acts for. Dome holds a token for each person and picks it from their verified identity.
Explore
More of what Dome works with
Model
Claude Fable
Fable 5.1 from Anthropic and Amazon Bedrock in one failover pool, open to one group and capped by quota.
Read moreProvider
Anthropic
The Claude API behind the Model Broker: the key held in Dome, every call authorized, metered and audited.
Read moreMCP server
GitHub
The GitHub MCP server behind the Tool Gateway, with rules that decide each call on its owner and repository.
Read moreIdentity
Okta
Okta tokens verified on every agent call, so rules and audit name the person each agent acted for.
Read moreRuntime
OpenAI Agents SDK
OpenAI Agents SDK agents with their models on the Model Broker and their MCP tools on the Tool Gateway.
Read moreClient
Claude Code
Claude Code on a Dome Gateway with per-developer sign-in, rules on every tool call, and audit by name.
Read moreNext steps
Talk with our FDE team
Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.
No card required to start. Register your first agent in minutes.
Agent services: web, research, payments, voice and sandboxes
Web actions, research, payments, phone calls and code execution are where agents reach past your walls. Put each service behind the Gateway, and every call is authorized, metered and audited.
See them all