Amazon Bedrock AgentCore and Dome
Run agents on AgentCore. Keep one set of rules.
AgentCore Gateway takes any remote MCP server as a target, and a Dome Gateway is one. Dome then decides every tool call AgentCore agents make, under the same rules as your agents anywhere else. Agents on AgentCore Runtime run your own code, so they can call Dome directly too.
How Dome helps
Dome provides governance for every Amazon Bedrock AgentCore tool and model call
A target like any other
AgentCore Gateway adds the Dome Gateway by URL and syncs its tools. Its catalog holds only the tools the Dome agent is granted.
Rules that travel
The rule that refuses a merge on AgentCore refuses it on any other runtime. Audit puts every call in one trail.
Models from your own code
AgentCore Runtime hosts code you write, in any framework. Point its model client at the Broker and model calls are governed too.
Get started
AgentCore behind Dome in three steps
Register a Dome agent for the AgentCore gateway, store its key in AgentCore Identity, and add the Dome Gateway as an MCP server target. The Dome commands were run against a workspace; the AgentCore commands come from AWS's docs.
01
Register an agent and issue its key
One Dome agent stands for the AgentCore gateway, with the rule below applied to it.
$ dome agents register --name agentcore-eng --gateway prod-gateway$ dome agents create-key agentcore-eng --name agentcore$ dome rules apply agentcore-eng.cedar --agent agentcore-eng --name github-read-only02
Store the key in AgentCore Identity
An API key credential provider holds the Dome key for outbound calls.
$ aws bedrock-agentcore-control create-api-key-credential-provider \--name dome-agentcore-eng \--api-key "$DOME_AGENT_KEY"03
Add the Dome Gateway as a target
AgentCore sends the key as a Bearer token and lists the tools when the target is created.
$ aws bedrock-agentcore-control create-gateway-target \--gateway-identifier "$AGENTCORE_GATEWAY_ID" \--name dome \--target-configuration '{"mcp": {"mcpServer": {"endpoint": "https://<gateway-host>/gateways/<gateway-id>/mcp"}}}' \--credential-provider-configurations '[{"credentialProviderType": "API_KEY","credentialProvider": {"apiKeyCredentialProvider": {"providerArn": "<credential-provider-arn>","credentialLocation": "HEADER","credentialParameterName": "Authorization","credentialPrefix": "Bearer"}}}]'
Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Amazon Bedrock AgentCore itself, see AWS's documentation.
Rules
Review code, never change it
The permit lets the agent discover tools and call GitHub. The forbid refuses merges and every tool that writes to a repository.
permit (principal, action == Dome::Action::"mcp:discover", resource); permit (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "github" }; forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "github" && ["merge_pull_request", "push_files", "create_or_update_file"].contains(resource.tool_name)};Try it
One call, two outcomes
Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.
Call
- Agentagentcore-eng is registered and active
- KeyBearer key from AgentCore Identity is valid
- RuleGitHub reads are allowed
Agent workflow
Bringing it together
Connecting Amazon Bedrock AgentCore to registered agents, tools, and models in Dome completes a governed agent application.
Acting for
Agent
Runtime
Amazon Bedrock AgentCore
This page
Runtime
LangGraph
See how
Control point
Gateway
- Rules
- Guards
- Quotas
Every call decided and audited
FAQ
Common questions
Can AgentCore Gateway connect to an external MCP server?
Yes. An MCP server target takes any HTTPS endpoint, with OAuth, IAM or an API key for outbound authorization.
Why put Dome behind AgentCore Gateway?
To keep one set of rules and one audit trail for agents on AgentCore and on every other runtime. AgentCore keeps its own inbound authorization in front.
Does Dome see each AgentCore user?
No. Dome sees the agent whose key the target holds, so register one Dome agent for each AgentCore gateway you want to tell apart.
Can model calls from AgentCore go through Dome?
From AgentCore Runtime, yes: it runs your code, so point its OpenAI- or Anthropic-compatible client at the Gateway. The AgentCore Gateway target covers tool calls.
Explore
More of what Dome works with
Model
Claude Fable
Fable 5.1 from Anthropic and Amazon Bedrock in one failover pool, open to one group and capped by quota.
Read moreProvider
Anthropic
The Claude API behind the Model Broker: the key held in Dome, every call authorized, metered and audited.
Read moreMCP server
Atlassian
The Atlassian Rovo MCP server behind the Tool Gateway, with rules that decide each Jira and Confluence call on its tool and site.
Read moreIdentity
Okta
Okta tokens verified on every agent call, so rules and audit name the person each agent acted for.
Read moreClient
Claude Code
Claude Code on a Dome Gateway with per-developer sign-in, rules on every tool call, and audit by name.
Read moreAgent service
TinyFish
TinyFish's web agents behind the Tool Gateway, with rules that decide each run on the site it targets.
Read moreNext steps
Talk with our FDE team
Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.
No card required to start. Register your first agent in minutes.
Agent frameworks and runtimes: govern agents without a rewrite
Build agents on the framework you already use. Dome governs their tool and model calls without a rewrite.
See them all