Dome Systems

Claude Agent SDK and Dome

The Claude Code loop, with every call governed.

Point a Claude Agent SDK agent at the Gateway for its model and its MCP tools. The agent loop is the one Claude Code runs. Every model call and tool call is checked against your rules and recorded against the agent.

PeopleAgentsDomeTools & modelsCallersPeopleAgentsreviewerAgentsresearcherAgentstriagerGatewaysprod-gatewayGitHubMCP serverJiraMCP serverclaude-opus-5-5Model poolRulesGuardsAuditsaudit-trail
reviewer→claude-opus-5-5· as s.lindqvistAllowed

How Dome helps

Dome provides governance for every Claude Agent SDK tool and model call

Only the tools you grant

Switch off the built-in tools and the agent works through the Gateway alone. It sees only the tools its agent is granted.

Claude through the Broker

The SDK's Claude Code CLI takes the Gateway as its Anthropic base URL. The model name is a pool, with failover across providers.

One key, one record

The agent's Dome key authenticates both the model and the tools. Every call lands in one audit trail against that agent.

Get started

Claude Agent SDK on Dome in two changes

Give the SDK the Gateway's address for models and add the Gateway as an HTTP MCP server. The agent loop is untouched.

  1. 01

    Install the SDK

    Anthropic's Agent SDK for Python. It bundles the Claude Code CLI it drives. Python 3.10 or later.

    $ pip install claude-agent-sdk
  2. 02

    Load tools from the Gateway

    The Gateway's MCP endpoint serves the tools this agent is granted. An empty tools list switches off the built-in file and shell tools.

    mcp_servers={"dome": {
    "type": "http",
    "url": f"{GATEWAY_URL}/mcp",
    "headers": {"Authorization": f"Bearer {DOME_AGENT_KEY}"},
    }},
    strict_mcp_config=True,
    tools=[],
    allowed_tools=["mcp__dome"],
  3. 03

    Call models through the Broker

    The CLI reads its Anthropic base URL and bearer token from the environment. The model name is a pool.

    model="claude-opus-5-5",
    env={"ANTHROPIC_BASE_URL": GATEWAY_URL, "ANTHROPIC_AUTH_TOKEN": DOME_AGENT_KEY},

Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Claude Agent SDK itself, see Anthropic's documentation.

Example agents

One agent, end to end

The Claude Code loop as a library: query() runs Opus through the Broker with the Gateway as its MCP server. Its Dome key is the only credential it holds.

researcher

Answer questions about the code

query() streams messages until the result arrives. The Gateway decides each tool call, and the Broker routes each model call to a provider that answers.

import asyncio
 
from claude_agent_sdk import ClaudeAgentOptions, ResultMessage, query
 
options = ClaudeAgentOptions(
# Model: a pool on the Broker, through its Anthropic-compatible endpoint
model="claude-opus-5-5",
env={"ANTHROPIC_BASE_URL": GATEWAY_URL, "ANTHROPIC_AUTH_TOKEN": DOME_AGENT_KEY},
# Tools: whatever this agent is granted on the Gateway, and nothing local
mcp_servers={"dome": {
"type": "http",
"url": f"{GATEWAY_URL}/mcp",
"headers": {"Authorization": f"Bearer {DOME_AGENT_KEY}"},
}},
strict_mcp_config=True,
tools=[],
allowed_tools=["mcp__dome"],
system_prompt="Answer questions about the code. Search before you answer.",
)
 
 
async def main():
async for message in query(prompt="Where is rate limiting handled?", options=options):
if isinstance(message, ResultMessage):
print(message.result)
 
 
asyncio.run(main())

Agent workflow

Bringing it together

Connecting Claude Agent SDK agents to tools, models, and identity in Dome completes a governed agent application.

Dome

Agent

Runtime

Claude Agent SDK

This page

Client

Claude Code

See how

Control point

Gateway

  • Rules
  • Guards
  • Quotas

Every call decided and audited

FAQ

Common questions

Can the Claude Agent SDK use a custom Anthropic base URL?

Yes. Set ANTHROPIC_BASE_URL to the Gateway and ANTHROPIC_AUTH_TOKEN to the agent's Dome key in the SDK's env option.

How do I connect the Claude Agent SDK to a remote MCP server?

Add it under mcp_servers with type http, the Gateway's /mcp URL, and the Dome key as a bearer token. Allow it with mcp__dome in allowed_tools.

Can the agent still run shell commands or edit files?

Not with tools set to an empty list. The agent then works only through the tools the Gateway grants it.

Where are rules enforced?

At the Gateway, on every model call and every tool call. A refused model call ends the run with the reason.

Next steps

Talk with our FDE team

Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.