Keycloak and Dome
Your realm, your groups. Checked on every agent call.
An agent sends the user's Keycloak token with each call. Dome verifies it against your realm, and rules decide on that person's groups. Audit records the agent and the person, every time.
How Dome helps
Dome provides verified identity and access control with Keycloak
Verified against your realm
Dome checks each token's signature against the realm's keys, its issuer and its expiry. A token from another realm fails the issuer check.
Rules read group paths
With a group membership mapper, the person's groups reach every rule. Full paths keep /engineering/platform apart from /sales/platform.
Self-hosted is fine
Dome fetches your realm's discovery document over HTTPS. The realm needs a public URL Dome can reach.
Get started
Keycloak in three steps
Register your realm with Dome, map groups into the token, and have the agent pass the token on. Dome needs no Keycloak credentials of its own.
01
Register your realm as a verification provider
The issuer is the realm URL. Keycloak releases before 17 serve it under /auth/realms instead.
$ dome verification-providers create \--name corporate-keycloak \--method oidc \--oidc-url https://<host>/realms/<realm> \--oidc-expected-audience <client-id>02
Map groups and roles into the token
Add a group membership mapper named groups to the client, on the access token. Realm roles sit under realm_access, which Dome doesn't read, so add a realm role mapper with the claim name roles if rules need them.
03
Pass the user's token with each call
The agent keeps its own Dome key and adds the person's Keycloak token as a header.
from openai import OpenAIclient = OpenAI(base_url=f"{GATEWAY_URL}/v1",api_key=DOME_AGENT_KEY,default_headers={"X-Dome-Act-As": user_keycloak_token},)
Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Keycloak itself, see Keycloak's documentation.
Rules
A rule on a Keycloak group
Only people in /engineering/platform may have an agent merge a pull request. The group path comes straight from their token.
forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "github" && resource.tool_name == "merge_pull_request"}unless { principal has act_as && principal.act_as.groups.contains("/engineering/platform")};Try it
One call, two outcomes
Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.
Acting for
- CallerToken verified against corporate-keycloak
- Groups/engineering/platform
- RuleMerges are open to /engineering/platform
Agent workflow
Bringing it together
Connecting Keycloak to registered agents, tools, and models in Dome completes a governed agent application.
Acting for
Identity
Keycloak
This page
Control point
Gateway
- Rules
- Guards
- Quotas
Every call decided and audited
Models
FAQ
Common questions
Why doesn't Dome see my Keycloak realm roles?
Keycloak nests them under realm_access, and Dome reads roles from the token's top level. Add a realm role mapper with the claim name roles.
Do group rules use names or full paths?
Whatever the mapper sends. With Full group path on, a rule matches /engineering/platform.
Does Dome accept HS256 tokens from Keycloak?
No. Dome refuses HMAC-signed tokens, so keep the realm on an RS, ES, PS or EdDSA algorithm.
Does Dome sync users from Keycloak?
No. Dome has no SCIM endpoint and reads identity from each verified token as the call arrives.
Explore
More of what Dome works with
Model
Claude Fable
Fable 5.1 from Anthropic and Amazon Bedrock in one failover pool, open to one group and capped by quota.
Read moreProvider
Anthropic
The Claude API behind the Model Broker: the key held in Dome, every call authorized, metered and audited.
Read moreMCP server
Atlassian
The Atlassian Rovo MCP server behind the Tool Gateway, with rules that decide each Jira and Confluence call on its tool and site.
Read moreRuntime
OpenAI Agents SDK
OpenAI Agents SDK agents with their models on the Model Broker and their MCP tools on the Tool Gateway.
Read moreClient
Claude Code
Claude Code on a Dome Gateway with per-developer sign-in, rules on every tool call, and audit by name.
Read moreAgent service
TinyFish
TinyFish's web agents behind the Tool Gateway, with rules that decide each run on the site it targets.
Read moreNext steps
Talk with our FDE team
Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.
No card required to start. Register your first agent in minutes.
Identity providers for AI agents: a verified person on every call
Your identity provider already knows your people. Dome verifies that identity on every agent call, so rules and audit name the person an agent acted for.
See them all