Identity providers
Identity providers for AI agents
Your identity provider already knows your people. Dome verifies that identity on every agent call, so rules and audit name the person an agent acted for.
Identity providers
Identity providers for AI agents
Any OIDC identity provider
Register its issuer once, and every agent call carries a verified person.
How it works
Any OIDC issuer, two steps
Register the issuer with Dome, then have agents pass the user's token with each call. Dome needs no credentials for your identity provider.
01
Register a verification provider
Dome reads the issuer's signing keys from its discovery document.
$ dome verification-providers create \--name corporate-idp --method oidc \--oidc-url https://<issuer> \--oidc-expected-audience <client-id>02
Pass the user's token
The agent keeps its own Dome key and adds the person's token as a header.
client = OpenAI(base_url=f"{GATEWAY_URL}/v1",api_key=DOME_AGENT_KEY,default_headers={"X-Dome-Act-As": user_token},)
Commands tested against a Dome workspace on September 30, 2026.
FAQ
Common questions
Which identity providers work?
Any OIDC issuer that signs tokens with RS, ES, PS or EdDSA keys. HMAC-signed tokens are refused.
What does Dome read from the token?
The sub, email, roles and groups claims, from the token's top level. Rules and audit see all four.
Is this the same as signing in to Dome?
No. Dashboard sign-in is Enterprise SSO. An agent acts for a person only when it sends that person's token.
Next steps
Talk with our FDE team
Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.
No card required to start. Register your first agent in minutes.
Access
How agents, people and the apps that call them are identified, and how that identity reaches every decision.
Read more