Claude Code MCP and Dome
Every developer signs in. Every tool call is checked.
Commit one .mcp.json and every developer who clones the repository gets your Gateway. Each signs in with their own Dome account the first time they run /mcp, and rules decide what Claude Code may call for them.
How Dome helps
Dome provides governed MCP access for Claude Code
The config ships with the repository
Project scope writes the Gateway URL to .mcp.json and nothing else. Commit it, and a new hire's first /mcp opens the sign-in.
Same repository, different reach
Rules read who signed in. Everyone on the repository can have Claude Code open pull requests. Only alice can have it merge one.
One merge, one name
Audit records each tool call under the developer who signed in. A merge Claude Code made is a merge alice made.
Get started
Claude Code on a Gateway in three steps
Allow your developers, permit the tools, and commit the Gateway to the repository's .mcp.json.
01
Turn on interactive access
List the developers who may sign in from Claude Code, by exact email or identity provider subject. Dome creates the Gateway's managed agent.
$ dome gateways interactive enable eng-gateway \--email alice@example.com \--email bob@example.com02
Permit what it may call
The rule below goes on that managed agent. dome gateways get shows its name.
$ dome rules apply interactive-access.cedar \--agent gateway-interactive-<gateway-id> \--name interactive-access03
Add the Gateway to Claude Code
Project scope writes .mcp.json, which holds no secret and can be committed. Run /mcp in Claude Code to sign in.
$ claude mcp add --transport http --scope project dome \https://<gateway-host>/gateways/<gateway-id>/mcp
Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Claude Code itself, see Anthropic's documentation.
Rules
A rule for the managed agent
Every signed-in developer may list tools and call GitHub. The merge tool is refused unless alice is the one signed in.
permit ( principal is Dome::Agent, action == Dome::Action::"mcp:discover", resource); permit ( principal is Dome::Agent, action == Dome::Action::"mcp:call", resource is Dome::MCPTool) when { resource.connection_name == "github" }; forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "github" && resource.tool_name == "merge_pull_request"}unless { principal has act_as && principal.act_as.email == "alice@example.com"};Try it
One call, two outcomes
Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.
Signed in as
- Sign-inalice@example.com is on the allow-list
- TokenInteractive token for eng-gateway, still valid
- RuleMerges are open to alice
Agent workflow
Bringing it together
Connecting Claude Code to registered tools and models in Dome completes a governed agent application.
Acting for
Agent
Client
Claude Code
This page
Client
Cursor
See how
Control point
Gateway
- Rules
- Guards
- Quotas
Every call decided and audited
FAQ
Common questions
How do I secure Claude Code's MCP servers?
Put them behind a Dome Gateway and add the Gateway to Claude Code. Each developer signs in, and rules decide every tool call.
Does each developer need an API key?
No. /mcp opens a browser to sign in. Claude Code keeps a token that lasts at most 10 minutes and renews while the developer is still allowed.
Can my team share the Claude Code MCP config?
Yes. Add the Gateway with --scope project and commit .mcp.json, since it holds only the URL.
Can I allow a whole group to sign in?
No. Allow-lists match exact emails or identity provider subjects.
Explore
More of what Dome works with
Model
Claude Fable
Fable 5.1 from Anthropic and Amazon Bedrock in one failover pool, open to one group and capped by quota.
Read moreProvider
Anthropic
The Claude API behind the Model Broker: the key held in Dome, every call authorized, metered and audited.
Read moreMCP server
Atlassian
The Atlassian Rovo MCP server behind the Tool Gateway, with rules that decide each Jira and Confluence call on its tool and site.
Read moreIdentity
Okta
Okta tokens verified on every agent call, so rules and audit name the person each agent acted for.
Read moreRuntime
LangGraph
LangGraph agents with their model calls on the Model Broker and their MCP tools on the Tool Gateway.
Read moreAgent service
TinyFish
TinyFish's web agents behind the Tool Gateway, with rules that decide each run on the site it targets.
Read moreNext steps
Talk with our FDE team
Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.
No card required to start. Register your first agent in minutes.
Claude Code, Cursor and Codex: governed MCP access for your people
People connect Claude Code, Cursor or Codex to a Gateway and sign in with their own Dome account. Nobody holds a shared key, and every call is audited under the person who made it.
See them all