Dome Systems

MCP clients

Claude Code, Cursor and Codex for the enterprise

People connect Claude Code, Cursor or Codex to a Gateway and sign in with their own Dome account. Nobody holds a shared key, and every call is audited under the person who made it.

How it works

Sign-in instead of keys

Turn on interactive access for a Gateway and name who may use it. Each person authorizes once in a browser.

  1. 01

    Turn on interactive access

    Dome creates one managed agent for the Gateway. Allow-lists match exact emails or identity provider subjects.

    $ dome gateways interactive enable prod-gateway \
    --email alice@example.com
  2. 02

    Permit what it may call

    Write a rule for the managed agent, the same as any agent. Rules can scope by the signed-in person's email.

  3. 03

    Add the Gateway to the client

    Give the client the Gateway's MCP URL. The first call opens a browser to sign in.

Commands tested against a Dome workspace on October 1, 2026.

FAQ

Common questions

Do people need an agent key?

No. They sign in through a browser, and the client gets a token that expires within 10 minutes and renews.

Can different people reach different tools?

Yes. Rules read the signed-in person's email, so one Gateway can serve teams with different access.

Can I allow a whole group?

Not for interactive sign-in. Allow-lists match exact emails or identity provider subjects.

Next steps

Talk with our FDE team

Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.