Codex MCP and Dome
Codex gets your tools. You keep the rules.
Two commands put your Gateway in Codex. codex mcp add writes the URL to config.toml, and codex mcp login signs the developer in with their own Dome account. Turn interactive access off and every Codex session loses the Gateway within minutes.
How Dome helps
Dome provides governed MCP access for Codex
Sign-in, not a key
Each developer runs codex mcp login and signs in with their own Dome account. No agent key lands in config.toml.
Merges for one person
Rules see which developer ran the login. Give priya merges and everyone else the rest of GitHub.
Short-lived by design
Interactive tokens expire within 10 minutes and reach one Gateway only. Dome rechecks the developer at every renewal.
Get started
Codex on a Gateway in three steps
Allow your developers, permit the tools, then two codex commands add the Gateway and sign in.
01
Turn on interactive access
The allow-list takes exact emails or identity provider subjects. Turning access on creates the managed agent Codex sessions run as.
$ dome gateways interactive enable eng-gateway \--email priya@example.com \--email tom@example.com02
Permit what it may call
Attach the rule below to that agent with --agent. dome gateways get prints the name.
$ dome rules apply interactive-access.cedar \--agent gateway-interactive-<gateway-id> \--name interactive-access03
Add the Gateway to Codex
This writes the server to ~/.codex/config.toml with no token. The login opens a browser to sign in.
$ codex mcp add dome \--url https://<gateway-host>/gateways/<gateway-id>/mcp$ codex mcp login dome
Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Codex itself, see OpenAI's documentation.
Rules
A rule for the managed agent
Discovery and GitHub calls are open to every developer who logged in. A merge from Codex goes through only for priya.
permit ( principal is Dome::Agent, action == Dome::Action::"mcp:discover", resource); permit ( principal is Dome::Agent, action == Dome::Action::"mcp:call", resource is Dome::MCPTool) when { resource.connection_name == "github" }; forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "github" && resource.tool_name == "merge_pull_request"}unless { principal has act_as && principal.act_as.email == "priya@example.com"};Try it
One call, two outcomes
Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.
Signed in as
- Sign-inpriya@example.com is on the allow-list
- TokenInteractive token for eng-gateway, still valid
- RuleMerges are open to priya
Agent workflow
Bringing it together
Connecting Codex to registered tools and models in Dome completes a governed agent application.
Acting for
Agent
Client
Codex
This page
Client
Claude Code
See how
Control point
Gateway
- Rules
- Guards
- Quotas
Every call decided and audited
Models
FAQ
Common questions
How do I add a remote MCP server to Codex?
Run codex mcp add with the server's --url, then codex mcp login if it uses OAuth. For a Dome Gateway, that login is your Dome account.
Does Codex need an API key for the Gateway?
No. codex mcp login opens a browser once. After that Codex holds a token that expires within 10 minutes and renews.
Can different developers reach different tools?
Yes. A rule can name developers by email. Two teams can share one Gateway and call different tools.
What happens when I turn interactive access off?
Tokens stop renewing and expire within minutes. The allow-list and managed agent stay for when you turn it back on.
Explore
More of what Dome works with
Model
Claude Fable
Fable 5.1 from Anthropic and Amazon Bedrock in one failover pool, open to one group and capped by quota.
Read moreProvider
Anthropic
The Claude API behind the Model Broker: the key held in Dome, every call authorized, metered and audited.
Read moreMCP server
Atlassian
The Atlassian Rovo MCP server behind the Tool Gateway, with rules that decide each Jira and Confluence call on its tool and site.
Read moreIdentity
Okta
Okta tokens verified on every agent call, so rules and audit name the person each agent acted for.
Read moreRuntime
LangGraph
LangGraph agents with their model calls on the Model Broker and their MCP tools on the Tool Gateway.
Read moreAgent service
TinyFish
TinyFish's web agents behind the Tool Gateway, with rules that decide each run on the site it targets.
Read moreNext steps
Talk with our FDE team
Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.
No card required to start. Register your first agent in minutes.
Claude Code, Cursor and Codex: governed MCP access for your people
People connect Claude Code, Cursor or Codex to a Gateway and sign in with their own Dome account. Nobody holds a shared key, and every call is audited under the person who made it.
See them all