LangGraph agents and Dome
Keep your graph. Govern every call it makes.
Point a LangGraph agent's model and tools at Dome and its graph stays as it is. Every model call and every tool call is checked against your rules and recorded against the agent.
How Dome helps
Dome provides governance for every LangGraph tool and model call
No rewrite
Nodes, edges and state stay as they are. The model client and the tool list change.
Tools from the Gateway
The graph loads its tools from the Gateway's MCP endpoint. It sees only the tools its agent is granted.
Every call on the record
Model and tool calls land in one audit trail, against the agent and the person it acted for. Retries show as attempts of their own.
Get started
LangGraph on Dome in two changes
Swap the chat model for one that calls the Model Broker, and load tools from the Gateway over MCP. The graph itself is untouched.
01
Install the packages
Dome's LangChain adapter and LangChain's MCP adapters. Python 3.12 or later.
$ pip install dome-langchain langchain-mcp-adapters langgraph02
Load tools from the Gateway
The Gateway's MCP endpoint serves the tools this agent is granted, with their real schemas.
from langchain_mcp_adapters.client import MultiServerMCPClientmcp = MultiServerMCPClient({"dome": {"transport": "streamable_http","url": f"{GATEWAY_URL}/mcp","headers": {"Authorization": f"Bearer {DOME_AGENT_KEY}"},}})tools = await mcp.get_tools()03
Call models through the Broker
The model name is a pool, so failover across providers comes with it.
from dome_langchain import AgentIdentity, DomeChatOpenAIllm = DomeChatOpenAI.for_agent(AgentIdentity(token=DOME_AGENT_KEY, gateway_url=GATEWAY_URL),model="claude-opus-5-5",).bind_tools(tools)
Commands and rules tested against a Dome workspace on October 1, 2026. For anything about LangGraph itself, see LangChain's documentation.
Example agents
One agent, end to end
A two-node graph: a model node on Opus through the Broker and a ToolNode fed by the Gateway. Its Dome key is the only credential it holds.
researcher
Answer questions about the code
The graph loops between Opus and the GitHub tools until the question is answered. Each tool call is decided at the Gateway, each model call routed by the Broker.
from langchain_mcp_adapters.client import MultiServerMCPClientfrom langgraph.graph import START, MessagesState, StateGraphfrom langgraph.prebuilt import ToolNode, tools_conditionfrom dome_langchain import AgentIdentity, DomeChatOpenAI async def build_researcher(): # Tools: whatever this agent is granted on the Gateway mcp = MultiServerMCPClient({"dome": { "transport": "streamable_http", "url": f"{GATEWAY_URL}/mcp", "headers": {"Authorization": f"Bearer {DOME_AGENT_KEY}"}, }}) tools = await mcp.get_tools() # Model: a pool on the Broker, with failover across providers llm = DomeChatOpenAI.for_agent( AgentIdentity(token=DOME_AGENT_KEY, gateway_url=GATEWAY_URL), model="claude-opus-5-5", ).bind_tools(tools) async def think(state: MessagesState): return {"messages": [await llm.ainvoke(state["messages"])]} graph = StateGraph(MessagesState) graph.add_node("think", think) graph.add_node("tools", ToolNode(tools)) graph.add_edge(START, "think") graph.add_conditional_edges("think", tools_condition) graph.add_edge("tools", "think") return graph.compile() researcher = await build_researcher()await researcher.ainvoke({"messages": [("user", "Where is rate limiting handled?")]})Agent workflow
Bringing it together
Connecting LangGraph agents to tools, models, and identity in Dome completes a governed agent application.
Acting for
Agent
Runtime
LangGraph
This page
Control point
Gateway
- Rules
- Guards
- Quotas
Every call decided and audited
FAQ
Common questions
Do I have to change my LangGraph code?
Only the chat model and where tools come from. Nodes, edges and state are unchanged.
Where are rules enforced?
At the Gateway, on every call. The SDK can also pre-check in-process tools, but the Gateway decides.
Does it work with other LangChain chat models?
Yes. DomeChatOpenAI and DomeChatAnthropic are ready-made, and any OpenAI- or Anthropic-compatible client pointed at the Gateway works too.
Can a graph act for the person who started it?
Yes. Pass the person's identity token with each call and rules and audit name them alongside the agent.
Explore
More of what Dome works with
Model
Claude Fable
Fable 5.1 from Anthropic and Amazon Bedrock in one failover pool, open to one group and capped by quota.
Read moreProvider
OpenAI
The OpenAI API behind the Model Broker: the key held in Dome, every call authorized, metered and audited.
Read moreMCP server
Atlassian
The Atlassian Rovo MCP server behind the Tool Gateway, with rules that decide each Jira and Confluence call on its tool and site.
Read moreIdentity
Microsoft Entra ID
Entra access tokens verified on every agent call, so rules read app roles and audit names the person.
Read moreClient
Claude Code
Claude Code on a Dome Gateway with per-developer sign-in, rules on every tool call, and audit by name.
Read moreAgent service
TinyFish
TinyFish's web agents behind the Tool Gateway, with rules that decide each run on the site it targets.
Read moreNext steps
Talk with our FDE team
Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.
No card required to start. Register your first agent in minutes.
Agent frameworks and runtimes: govern agents without a rewrite
Build agents on the framework you already use. Dome governs their tool and model calls without a rewrite.
See them all