Dome Systems

Okta and Dome

Know who every agent is acting for.

An agent sends the user's Okta token with each call. Dome verifies it against Okta, and your rules decide on that person's groups. Audit records the agent and the person, every time.

People in OktaAgentsDomeTools & modelsCallersPeople in OktaAgentssupport-agentAgentsresearch-agentAgentssales-assistantGatewaysprod-gatewayGitHubMCP serverCRMInternal MCP serverclaude-opus-5-5Model poolRulesGuardsAuditsaudit-trail
sales-assistant→crm/get_account· as r.castilloAllowed

How Dome helps

Dome provides verified identity and access control with Okta

Verified on every call

Dome checks the token's signature against Okta's keys, its issuer and its expiry. A forged or stale token is refused.

Rules read their groups

The user's Okta groups, roles and email reach every rule. Give research the frontier models and support the rest.

Required where it matters

Require a verified user on a workspace or a single agent. Allow only certain groups, emails or subjects.

Get started

Okta in three steps

Register your Okta authorization server with Dome, put groups in the token, and have the agent pass the token on. Dome needs no Okta credentials of its own.

  1. 01

    Register Okta as a verification provider

    Dome reads Okta's signing keys from its discovery document. Pin the audience to your app's client id.

    $ dome verification-providers create \
    --name corporate-okta \
    --method oidc \
    --oidc-url https://<org>.okta.com/oauth2/default \
    --oidc-expected-audience <client-id>
  2. 02

    Add a groups claim in Okta

    Dome reads sub, email, roles and groups from the token's top level. Add a groups claim to the authorization server your app uses.

  3. 03

    Pass the user's token with each call

    The agent keeps its own Dome key and adds the person's Okta token as a header.

    from openai import OpenAI
     
    client = OpenAI(
    base_url=f"{GATEWAY_URL}/v1",
    api_key=DOME_AGENT_KEY,
    default_headers={"X-Dome-Act-As": user_okta_token},
    )

Commands and rules tested against a Dome workspace on September 30, 2026. For anything about Okta itself, see Okta's documentation.

Rules

A rule on Okta groups

Frontier models are refused unless the person the agent acts for is in ml-research. The group comes straight from their Okta token.

forbid (principal, action == Dome::Action::"llm:invoke", resource is Dome::LLMModel)
when { resource has tier && resource.tier == "frontier" }
unless {
principal has act_as &&
principal.act_as.groups.contains("ml-research")
};

Try it

One call, two outcomes

Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.

Acting for

agent research-agent · acting as a.okafor
llm:invoke(model: "claude-opus-5-5")
  1. CallerToken verified against corporate-okta
  2. Groupsml-research, engineering
  3. RuleFrontier models are open to ml-research
DecisionAllowed

Agent workflow

Bringing it together

Connecting Okta to registered agents, tools, and models in Dome completes a governed agent application.

Dome

Acting for

Identity

Okta

This page

Control point

Gateway

  • Rules
  • Guards
  • Quotas

Every call decided and audited

FAQ

Common questions

Does Dome have an Okta connector?

It doesn't need one. Dome verifies tokens from any OIDC issuer, and Okta's authorization servers are OIDC issuers.

Can agents use SAML?

No. Acting for a user needs an OIDC token. Signing in to the Dome dashboard supports Okta over SAML or OIDC through Enterprise SSO.

Does signing in to Dome with Okta make my agents act as me?

No. Dashboard sign-in and agent identity are separate. An agent acts for a person only when it sends that person's token.

Does Dome sync my Okta directory?

No. Dome reads identity from each verified token as the call arrives.

Next steps

Talk with our FDE team

Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.