Dome Systems

Codex MCP and Dome

Codex gets your tools. You keep the rules.

Two commands put your Gateway in Codex. codex mcp add writes the URL to config.toml, and codex mcp login signs the developer in with their own Dome account. Turn interactive access off and every Codex session loses the Gateway within minutes.

Developers in CodexAgentsDomeTools & modelsCallersDevelopers in CodexAgentsgateway-interactive-1d85Agentstest-runnerAgentsrelease-botGatewayseng-gatewayGitHubMCP serverInternal toolsMCP serversgptModel poolRulesGuardsAuditsaudit-trail
gateway-interactive-1d85→github/create_pull_request· as priya@example.comAllowed

How Dome helps

Dome provides governed MCP access for Codex

Sign-in, not a key

Each developer runs codex mcp login and signs in with their own Dome account. No agent key lands in config.toml.

Merges for one person

Rules see which developer ran the login. Give priya merges and everyone else the rest of GitHub.

Short-lived by design

Interactive tokens expire within 10 minutes and reach one Gateway only. Dome rechecks the developer at every renewal.

Get started

Codex on a Gateway in three steps

Allow your developers, permit the tools, then two codex commands add the Gateway and sign in.

  1. 01

    Turn on interactive access

    The allow-list takes exact emails or identity provider subjects. Turning access on creates the managed agent Codex sessions run as.

    $ dome gateways interactive enable eng-gateway \
    --email priya@example.com \
    --email tom@example.com
  2. 02

    Permit what it may call

    Attach the rule below to that agent with --agent. dome gateways get prints the name.

    $ dome rules apply interactive-access.cedar \
    --agent gateway-interactive-<gateway-id> \
    --name interactive-access
  3. 03

    Add the Gateway to Codex

    This writes the server to ~/.codex/config.toml with no token. The login opens a browser to sign in.

    $ codex mcp add dome \
    --url https://<gateway-host>/gateways/<gateway-id>/mcp
    $ codex mcp login dome

Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Codex itself, see OpenAI's documentation.

Rules

A rule for the managed agent

Discovery and GitHub calls are open to every developer who logged in. A merge from Codex goes through only for priya.

permit (
principal is Dome::Agent,
action == Dome::Action::"mcp:discover",
resource
);
 
permit (
principal is Dome::Agent,
action == Dome::Action::"mcp:call",
resource is Dome::MCPTool
) when { resource.connection_name == "github" };
 
forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when {
resource.connection_name == "github" &&
resource.tool_name == "merge_pull_request"
}
unless {
principal has act_as &&
principal.act_as.email == "priya@example.com"
};

Try it

One call, two outcomes

Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.

Signed in as

agent gateway-interactive-1d85 · acting as priya@example.com
github/merge_pull_request(owner: "acme", repo: "api", pullNumber: 311)
  1. Sign-inpriya@example.com is on the allow-list
  2. TokenInteractive token for eng-gateway, still valid
  3. RuleMerges are open to priya
DecisionAllowed

Agent workflow

Bringing it together

Connecting Codex to registered tools and models in Dome completes a governed agent application.

Dome

Agent

Client

Codex

This page

Client

Claude Code

See how

Control point

Gateway

  • Rules
  • Guards
  • Quotas

Every call decided and audited

FAQ

Common questions

How do I add a remote MCP server to Codex?

Run codex mcp add with the server's --url, then codex mcp login if it uses OAuth. For a Dome Gateway, that login is your Dome account.

Does Codex need an API key for the Gateway?

No. codex mcp login opens a browser once. After that Codex holds a token that expires within 10 minutes and renews.

Can different developers reach different tools?

Yes. A rule can name developers by email. Two teams can share one Gateway and call different tools.

What happens when I turn interactive access off?

Tokens stop renewing and expire within minutes. The allow-list and managed agent stay for when you turn it back on.

Next steps

Talk with our FDE team

Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.