CrewAI agents and Dome
Keep your crew. Govern every call it makes.
A crew is several agents, and Dome can tell them apart. Give each one an LLM pointed at the Broker, the Gateway as its MCP server, and its own Dome key. Roles, tasks and process stay as written, and rules decide each member's calls.
How Dome helps
Dome provides governance for every CrewAI tool and model call
Roles and tasks stay as they are
Agents, tasks and process are unchanged. Each agent's LLM and MCP server change.
A key per agent
Give each crew member its own Dome key and rules can tell them apart. The researcher can read what the writer cannot.
Who in the crew did it
Audit records each LLM and tool call against the crew member that made it, and the person it acted for.
Get started
CrewAI on Dome in two changes
Per agent: a crewai.LLM on the Broker and an MCPServerHTTP on the Gateway. The crew definition is untouched.
01
Install CrewAI
CrewAI includes its MCP client. Python 3.10 to 3.13.
$ pip install crewai02
Load tools from the Gateway
Each agent's mcps list takes the Gateway, and sees the tools that agent's key is granted.
from crewai.mcp import MCPServerHTTPdome = MCPServerHTTP(url=f"{GATEWAY_URL}/mcp",headers={"Authorization": f"Bearer {DOME_AGENT_KEY}"},)03
Call models through the Broker
An OpenAI-compatible LLM with the Gateway as its base URL. The model name is a pool.
from crewai import LLMllm = LLM(model="openai/claude-opus-5-5",base_url=f"{GATEWAY_URL}/v1",api_key=DOME_AGENT_KEY,)
Commands and rules tested against a Dome workspace on October 1, 2026. For anything about CrewAI itself, see CrewAI's documentation.
Example agents
One agent, end to end
A one-agent crew: the LLM points at the Broker and MCPServerHTTP points at the Gateway. Add crew members and each gets its own Dome key.
researcher
Answer questions about the code
The crew's one task is the question. kickoff() runs it through the GitHub tools, each call decided at the Gateway, each model call routed by the Broker.
from crewai import LLM, Agent, Crew, Taskfrom crewai.mcp import MCPServerHTTP # Model: a pool on the Broker, through the OpenAI-compatible endpointllm = LLM( model="openai/claude-opus-5-5", base_url=f"{GATEWAY_URL}/v1", api_key=DOME_AGENT_KEY,) # Tools: whatever this agent is granted on the Gatewaydome = MCPServerHTTP( url=f"{GATEWAY_URL}/mcp", headers={"Authorization": f"Bearer {DOME_AGENT_KEY}"},) researcher = Agent( role="researcher", goal="Answer questions about the code", backstory="Searches repositories before answering.", llm=llm, mcps=[dome],) task = Task( description="Where is rate limiting handled?", expected_output="The files and functions that handle rate limiting.", agent=researcher,) result = Crew(agents=[researcher], tasks=[task]).kickoff()print(result.raw)Agent workflow
Bringing it together
Connecting CrewAI crews to tools, models, and identity in Dome completes a governed agent application.
Acting for
Agent
Runtime
CrewAI
This page
Control point
Gateway
- Rules
- Guards
- Quotas
Every call decided and audited
FAQ
Common questions
How do I use a custom LLM base URL in CrewAI?
Pass base_url and api_key to crewai.LLM, with the model as openai/ plus the pool name. Dome's /v1 endpoint is OpenAI-compatible.
How do I connect CrewAI to a remote MCP server?
Give the agent an MCPServerHTTP in its mcps list, with the Gateway's /mcp URL and the Dome key as a bearer token.
Can each agent in a crew have different permissions?
Yes. Register each agent in Dome with its own key, and rules decide per agent.
Do rules run inside the crew?
No. They run at the Gateway, on every LLM and tool call. A refused call comes back as a 403 with the reason.
Explore
More of what Dome works with
Model
Claude Fable
Fable 5.1 from Anthropic and Amazon Bedrock in one failover pool, open to one group and capped by quota.
Read moreProvider
Anthropic
The Claude API behind the Model Broker: the key held in Dome, every call authorized, metered and audited.
Read moreMCP server
GitHub
The GitHub MCP server behind the Tool Gateway, with rules that decide each call on its owner and repository.
Read moreIdentity
Microsoft Entra ID
Entra access tokens verified on every agent call, so rules read app roles and audit names the person.
Read moreClient
Claude Code
Claude Code on a Dome Gateway with per-developer sign-in, rules on every tool call, and audit by name.
Read moreAgent service
TinyFish
TinyFish's web agents behind the Tool Gateway, with rules that decide each run on the site it targets.
Read moreNext steps
Talk with our FDE team
Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.
No card required to start. Register your first agent in minutes.
Agent frameworks and runtimes: govern agents without a rewrite
Build agents on the framework you already use. Dome governs their tool and model calls without a rewrite.
See them all