Dome Systems

Google sign-in and Dome

Signed in with Google. Checked on every call.

An agent sends the user's Google ID token with each call. Dome verifies it against Google, and rules decide on that person's email and Workspace domain. Audit records the agent and the person, every time.

People with Google accountsAgentsDomeTools & modelsCallersPeople with Google accountsAgentsresearch-agentAgentscode-reviewerAgentsops-assistantGatewaysprod-gatewayGitHubMCP serverWarehouseInternal MCP serverclaude-opus-5-5Model poolRulesGuardsAuditsaudit-trail
code-reviewer→github/search_code· as a.okafor@example.comAllowed

How Dome helps

Dome provides verified identity and access control with Google

Verified against Google

Dome checks the ID token's signature against Google's keys, its issuer and its expiry. Pin the audience to your OAuth client ID.

Rules read email and domain

The person's email reaches every rule. For Workspace accounts, so does the hd claim with their domain.

No groups in the token

Google ID tokens carry no groups. Scope rules by email, domain or subject instead.

Get started

Google in three steps

Register Google as a verification provider, have the agent pass the user's ID token, and scope rules by domain. Dome needs no Google credentials of its own.

  1. 01

    Register Google as a verification provider

    The issuer is the same for every Google account. Pin the audience to your app's OAuth client ID.

    $ dome verification-providers create \
    --name google \
    --method oidc \
    --oidc-url https://accounts.google.com \
    --oidc-expected-audience <client-id>.apps.googleusercontent.com
  2. 02

    Pass the user's ID token with each call

    Send the ID token from sign-in, with the email scope. Google access tokens aren't JWTs, so Dome can't verify them.

    from openai import OpenAI
     
    client = OpenAI(
    base_url=f"{GATEWAY_URL}/v1",
    api_key=DOME_AGENT_KEY,
    default_headers={"X-Dome-Act-As": google_id_token},
    )
  3. 03

    Scope by Workspace domain

    Google sets hd only for Workspace and Cloud organization accounts. It arrives under principal.act_as.claims.

    principal has act_as &&
    principal.act_as has claims &&
    principal.act_as.claims has hd &&
    principal.act_as.claims.hd == "example.com"

Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Google itself, see Google's documentation.

Rules

A rule on the person's email

Only people with an example.com address may use the agent's GitHub tools. A personal Gmail account is refused, even with a valid token.

forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when { resource.connection_name == "github" }
unless {
principal has act_as &&
principal.act_as has email &&
principal.act_as.email like "*@example.com"
};

Try it

One call, two outcomes

Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.

Acting for

agent code-reviewer · acting as a.okafor@example.com
github/search_code(query: "rate limit repo:acme/web")
  1. CallerID token verified against Google
  2. Emaila.okafor@example.com
  3. RuleGitHub tools are open to example.com
DecisionAllowed

Agent workflow

Bringing it together

Connecting Google to registered agents, tools, and models in Dome completes a governed agent application.

Dome

Acting for

Identity

Google

This page

Control point

Gateway

  • Rules
  • Guards
  • Quotas

Every call decided and audited

FAQ

Common questions

Do Google ID tokens include groups?

No. Rules can use the person's email, subject and, for Workspace accounts, the hd domain claim.

Can an agent send a Google access token?

No. Google access tokens aren't JWTs, so the agent sends the ID token instead.

Will any Google account get through?

Any account your OAuth app lets sign in gets a token that verifies. Rules on email or hd decide which accounts may call anything.

Next steps

Talk with our FDE team

Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.