Dome Systems

Amazon Bedrock AgentCore and Dome

Run agents on AgentCore. Keep one set of rules.

AgentCore Gateway takes any remote MCP server as a target, and a Dome Gateway is one. Dome then decides every tool call AgentCore agents make, under the same rules as your agents anywhere else. Agents on AgentCore Runtime run your own code, so they can call Dome directly too.

EngineersAgentsDomeTools & modelsCallersEngineersAgentsagentcore-engAgentsagentcore-supportAgentsrelease-notesGatewaysprod-gatewayGitHubMCP serverInternal toolsMCP serversclaude-opus-5-5Model poolRulesGuardsAuditsaudit-trail
agentcore-eng→github/pull_request_read· scheduledAllowed

How Dome helps

Dome provides governance for every Amazon Bedrock AgentCore tool and model call

A target like any other

AgentCore Gateway adds the Dome Gateway by URL and syncs its tools. Its catalog holds only the tools the Dome agent is granted.

Rules that travel

The rule that refuses a merge on AgentCore refuses it on any other runtime. Audit puts every call in one trail.

Models from your own code

AgentCore Runtime hosts code you write, in any framework. Point its model client at the Broker and model calls are governed too.

Get started

AgentCore behind Dome in three steps

Register a Dome agent for the AgentCore gateway, store its key in AgentCore Identity, and add the Dome Gateway as an MCP server target. The Dome commands were run against a workspace; the AgentCore commands come from AWS's docs.

  1. 01

    Register an agent and issue its key

    One Dome agent stands for the AgentCore gateway, with the rule below applied to it.

    $ dome agents register --name agentcore-eng --gateway prod-gateway
    $ dome agents create-key agentcore-eng --name agentcore
    $ dome rules apply agentcore-eng.cedar --agent agentcore-eng --name github-read-only
  2. 02

    Store the key in AgentCore Identity

    An API key credential provider holds the Dome key for outbound calls.

    $ aws bedrock-agentcore-control create-api-key-credential-provider \
    --name dome-agentcore-eng \
    --api-key "$DOME_AGENT_KEY"
  3. 03

    Add the Dome Gateway as a target

    AgentCore sends the key as a Bearer token and lists the tools when the target is created.

    $ aws bedrock-agentcore-control create-gateway-target \
    --gateway-identifier "$AGENTCORE_GATEWAY_ID" \
    --name dome \
    --target-configuration '{"mcp": {"mcpServer": {
    "endpoint": "https://<gateway-host>/gateways/<gateway-id>/mcp"}}}' \
    --credential-provider-configurations '[{
    "credentialProviderType": "API_KEY",
    "credentialProvider": {"apiKeyCredentialProvider": {
    "providerArn": "<credential-provider-arn>",
    "credentialLocation": "HEADER",
    "credentialParameterName": "Authorization",
    "credentialPrefix": "Bearer"}}}]'

Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Amazon Bedrock AgentCore itself, see AWS's documentation.

Rules

Review code, never change it

The permit lets the agent discover tools and call GitHub. The forbid refuses merges and every tool that writes to a repository.

permit (principal, action == Dome::Action::"mcp:discover", resource);
 
permit (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when { resource.connection_name == "github" };
 
forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when {
resource.connection_name == "github" &&
["merge_pull_request", "push_files", "create_or_update_file"].contains(resource.tool_name)
};

Try it

One call, two outcomes

Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.

Call

agent agentcore-eng · scheduled
github/pull_request_read(owner: "acme", repo: "web", pullNumber: 482)
  1. Agentagentcore-eng is registered and active
  2. KeyBearer key from AgentCore Identity is valid
  3. RuleGitHub reads are allowed
DecisionAllowed

Agent workflow

Bringing it together

Connecting Amazon Bedrock AgentCore to registered agents, tools, and models in Dome completes a governed agent application.

Dome

Agent

Runtime

Amazon Bedrock AgentCore

This page

Runtime

LangGraph

See how

Control point

Gateway

  • Rules
  • Guards
  • Quotas

Every call decided and audited

FAQ

Common questions

Can AgentCore Gateway connect to an external MCP server?

Yes. An MCP server target takes any HTTPS endpoint, with OAuth, IAM or an API key for outbound authorization.

Why put Dome behind AgentCore Gateway?

To keep one set of rules and one audit trail for agents on AgentCore and on every other runtime. AgentCore keeps its own inbound authorization in front.

Does Dome see each AgentCore user?

No. Dome sees the agent whose key the target holds, so register one Dome agent for each AgentCore gateway you want to tell apart.

Can model calls from AgentCore go through Dome?

From AgentCore Runtime, yes: it runs your code, so point its OpenAI- or Anthropic-compatible client at the Gateway. The AgentCore Gateway target covers tool calls.

Next steps

Talk with our FDE team

Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.