Dome Systems

Identity providers

Identity providers for AI agents

Your identity provider already knows your people. Dome verifies that identity on every agent call, so rules and audit name the person an agent acted for.

How it works

Any OIDC issuer, two steps

Register the issuer with Dome, then have agents pass the user's token with each call. Dome needs no credentials for your identity provider.

  1. 01

    Register a verification provider

    Dome reads the issuer's signing keys from its discovery document.

    $ dome verification-providers create \
    --name corporate-idp --method oidc \
    --oidc-url https://<issuer> \
    --oidc-expected-audience <client-id>
  2. 02

    Pass the user's token

    The agent keeps its own Dome key and adds the person's token as a header.

    client = OpenAI(
    base_url=f"{GATEWAY_URL}/v1",
    api_key=DOME_AGENT_KEY,
    default_headers={"X-Dome-Act-As": user_token},
    )

Commands tested against a Dome workspace on September 30, 2026.

FAQ

Common questions

Which identity providers work?

Any OIDC issuer that signs tokens with RS, ES, PS or EdDSA keys. HMAC-signed tokens are refused.

What does Dome read from the token?

The sub, email, roles and groups claims, from the token's top level. Rules and audit see all four.

Is this the same as signing in to Dome?

No. Dashboard sign-in is Enterprise SSO. An agent acts for a person only when it sends that person's token.

Next steps

Talk with our FDE team

Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.