Okta and Dome
Know who every agent is acting for.
An agent sends the user's Okta token with each call. Dome verifies it against Okta, and your rules decide on that person's groups. Audit records the agent and the person, every time.
How Dome helps
Dome provides verified identity and access control with Okta
Verified on every call
Dome checks the token's signature against Okta's keys, its issuer and its expiry. A forged or stale token is refused.
Rules read their groups
The user's Okta groups, roles and email reach every rule. Give research the frontier models and support the rest.
Required where it matters
Require a verified user on a workspace or a single agent. Allow only certain groups, emails or subjects.
Get started
Okta in three steps
Register your Okta authorization server with Dome, put groups in the token, and have the agent pass the token on. Dome needs no Okta credentials of its own.
01
Register Okta as a verification provider
Dome reads Okta's signing keys from its discovery document. Pin the audience to your app's client id.
$ dome verification-providers create \--name corporate-okta \--method oidc \--oidc-url https://<org>.okta.com/oauth2/default \--oidc-expected-audience <client-id>02
Add a groups claim in Okta
Dome reads sub, email, roles and groups from the token's top level. Add a groups claim to the authorization server your app uses.
03
Pass the user's token with each call
The agent keeps its own Dome key and adds the person's Okta token as a header.
from openai import OpenAIclient = OpenAI(base_url=f"{GATEWAY_URL}/v1",api_key=DOME_AGENT_KEY,default_headers={"X-Dome-Act-As": user_okta_token},)
Commands and rules tested against a Dome workspace on September 30, 2026. For anything about Okta itself, see Okta's documentation.
Rules
A rule on Okta groups
Frontier models are refused unless the person the agent acts for is in ml-research. The group comes straight from their Okta token.
forbid (principal, action == Dome::Action::"llm:invoke", resource is Dome::LLMModel)when { resource has tier && resource.tier == "frontier" }unless { principal has act_as && principal.act_as.groups.contains("ml-research")};Try it
One call, two outcomes
Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.
Acting for
- CallerToken verified against corporate-okta
- Groupsml-research, engineering
- RuleFrontier models are open to ml-research
Agent workflow
Bringing it together
Connecting Okta to registered agents, tools, and models in Dome completes a governed agent application.
Acting for
Identity
Okta
This page
Control point
Gateway
- Rules
- Guards
- Quotas
Every call decided and audited
Models
FAQ
Common questions
Does Dome have an Okta connector?
It doesn't need one. Dome verifies tokens from any OIDC issuer, and Okta's authorization servers are OIDC issuers.
Can agents use SAML?
No. Acting for a user needs an OIDC token. Signing in to the Dome dashboard supports Okta over SAML or OIDC through Enterprise SSO.
Does signing in to Dome with Okta make my agents act as me?
No. Dashboard sign-in and agent identity are separate. An agent acts for a person only when it sends that person's token.
Does Dome sync my Okta directory?
No. Dome reads identity from each verified token as the call arrives.
Explore
More of what Dome works with
Model
Claude Fable
Fable 5.1 from Anthropic and Amazon Bedrock in one failover pool, open to one group and capped by quota.
Read moreProvider
Anthropic
The Claude API behind the Model Broker: the key held in Dome, every call authorized, metered and audited.
Read moreMCP server
Atlassian
The Atlassian Rovo MCP server behind the Tool Gateway, with rules that decide each Jira and Confluence call on its tool and site.
Read moreRuntime
OpenAI Agents SDK
OpenAI Agents SDK agents with their models on the Model Broker and their MCP tools on the Tool Gateway.
Read moreClient
Claude Code
Claude Code on a Dome Gateway with per-developer sign-in, rules on every tool call, and audit by name.
Read moreAgent service
TinyFish
TinyFish's web agents behind the Tool Gateway, with rules that decide each run on the site it targets.
Read moreNext steps
Talk with our FDE team
Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.
No card required to start. Register your first agent in minutes.
Identity providers for AI agents: a verified person on every call
Your identity provider already knows your people. Dome verifies that identity on every agent call, so rules and audit name the person an agent acted for.
See them all