OpenAI Agents SDK and Dome
Keep your agents. Govern every call they make.
Swap the SDK's model client for one pointed at Dome and add the Gateway as an MCP server. Handoffs and the run loop keep working. Claude can sit behind the same client as GPT, and the record of every call stays in your workspace.
How Dome helps
Dome provides governance for every OpenAI Agents SDK tool and model call
Handoffs stay as they are
Agents, instructions and handoffs are unchanged. The model client and the MCP server change.
Any model behind one client
The SDK's chat completions model talks to the Broker's OpenAI-compatible endpoint. The model name is a pool, so Claude and GPT sit behind the same client.
Audit stays in your workspace
Turn off the SDK's tracing export and Dome keeps the record. Every model and tool call lands against the agent that made it.
Get started
OpenAI Agents SDK on Dome in two changes
An OpenAIChatCompletionsModel on the Broker and an MCPServerStreamableHttp on the Gateway. The agent definition is untouched.
01
Install the SDK
OpenAI's Agents SDK, with its MCP support built in. Python 3.10 or later.
$ pip install openai-agents02
Load tools from the Gateway
MCPServerStreamableHttp lists only the tools this agent is granted, with their real schemas.
from agents.mcp import MCPServerStreamableHttpdome = MCPServerStreamableHttp(name="dome",params={"url": f"{GATEWAY_URL}/mcp","headers": {"Authorization": f"Bearer {DOME_AGENT_KEY}"},},cache_tools_list=True,)03
Call models through the Broker
An OpenAI client with the Gateway as its base URL. The model name is a pool.
from openai import AsyncOpenAIfrom agents import OpenAIChatCompletionsModelbroker = AsyncOpenAI(base_url=f"{GATEWAY_URL}/v1", api_key=DOME_AGENT_KEY)model = OpenAIChatCompletionsModel(model="claude-opus-5-5", openai_client=broker)
Commands and rules tested against a Dome workspace on October 1, 2026. For anything about OpenAI Agents SDK itself, see OpenAI's documentation.
Example agents
One agent, end to end
An Agents SDK agent whose model client points at the Broker and whose MCP server is the Gateway. Tracing stays off; the record lives in Dome.
researcher
Answer questions about the code
Runner works the question through the GitHub tools. The Gateway decides each tool call, and Opus answers through the Broker.
import asyncio from openai import AsyncOpenAIfrom agents import Agent, OpenAIChatCompletionsModel, Runner, set_tracing_disabledfrom agents.mcp import MCPServerStreamableHttp set_tracing_disabled(True) # Dome keeps the audit trail async def main(): # Model: a pool on the Broker, through the OpenAI-compatible endpoint broker = AsyncOpenAI(base_url=f"{GATEWAY_URL}/v1", api_key=DOME_AGENT_KEY) model = OpenAIChatCompletionsModel(model="claude-opus-5-5", openai_client=broker) # Tools: whatever this agent is granted on the Gateway async with MCPServerStreamableHttp( name="dome", params={ "url": f"{GATEWAY_URL}/mcp", "headers": {"Authorization": f"Bearer {DOME_AGENT_KEY}"}, }, cache_tools_list=True, ) as dome: researcher = Agent( name="researcher", instructions="Answer questions about the code. Search before you answer.", model=model, mcp_servers=[dome], ) result = await Runner.run(researcher, "Where is rate limiting handled?") print(result.final_output) asyncio.run(main())Agent workflow
Bringing it together
Connecting OpenAI Agents SDK agents to tools, models, and identity in Dome completes a governed agent application.
Acting for
Agent
Runtime
OpenAI Agents SDK
This page
Control point
Gateway
- Rules
- Guards
- Quotas
Every call decided and audited
Models
FAQ
Common questions
Does the OpenAI Agents SDK work with non-OpenAI models through Dome?
Yes. Point OpenAIChatCompletionsModel at the Gateway's /v1 endpoint and name any pool the agent is allowed, Claude included.
How do I connect the OpenAI Agents SDK to a remote MCP server?
Use MCPServerStreamableHttp with the Gateway's /mcp URL and the agent's Dome key as a bearer token. The agent sees only the tools it is granted.
What happens when Dome refuses a call?
The Gateway returns a 403 with the reason, on model and tool calls alike. Nothing reaches the provider or the tool.
Do I still need OpenAI tracing?
No. Dome records every model and tool call against the agent, so the tracing export can stay off.
Explore
More of what Dome works with
Model
Claude Fable
Fable 5.1 from Anthropic and Amazon Bedrock in one failover pool, open to one group and capped by quota.
Read moreProvider
Anthropic
The Claude API behind the Model Broker: the key held in Dome, every call authorized, metered and audited.
Read moreMCP server
Atlassian
The Atlassian Rovo MCP server behind the Tool Gateway, with rules that decide each Jira and Confluence call on its tool and site.
Read moreIdentity
Microsoft Entra ID
Entra access tokens verified on every agent call, so rules read app roles and audit names the person.
Read moreClient
Claude Code
Claude Code on a Dome Gateway with per-developer sign-in, rules on every tool call, and audit by name.
Read moreAgent service
TinyFish
TinyFish's web agents behind the Tool Gateway, with rules that decide each run on the site it targets.
Read moreNext steps
Talk with our FDE team
Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.
No card required to start. Register your first agent in minutes.
Agent frameworks and runtimes: govern agents without a rewrite
Build agents on the framework you already use. Dome governs their tool and model calls without a rewrite.
See them all