Dome Systems

Vercel AI SDK agents and Dome

Keep your TypeScript agent. Govern every call it makes.

The AI SDK is TypeScript, and so is the change. Create its OpenAI provider with the Gateway as baseURL and load tools with its MCP client. generateText, streamText and your stop conditions stay as written. The server holds one Dome key and no provider keys.

PeopleAgentsDomeTools & modelsCallersPeopleAgentsassistantAgentsresearcherAgentsbillingGatewaysprod-gatewayNotionMCP serverStripeMCP serverclaude-opus-5-5Model poolRulesGuardsAuditsaudit-trail
assistant→claude-opus-5-5· as j.nakamuraAllowed

How Dome helps

Dome provides governance for every Vercel AI SDK tool and model call

Your loop stays as it is

generateText, streamText and stop conditions are unchanged. The provider and the tool set change.

Tools from the Gateway

The AI SDK's MCP client loads tools from the Gateway's endpoint. The agent sees only the tools it is granted.

Keys stay on the server

The app holds one Dome key and no provider credentials. Every call lands in the audit trail against the agent.

Get started

Vercel AI SDK on Dome in two changes

createOpenAI on the Gateway's /v1 endpoint and createMCPClient on its /mcp endpoint. The agent loop is untouched.

  1. 01

    Install the packages

    The AI SDK, its OpenAI provider and its MCP client.

    $ npm install ai @ai-sdk/openai @ai-sdk/mcp
  2. 02

    Load tools from the Gateway

    createMCPClient over HTTP returns the tools this agent is granted, ready to pass to generateText.

    import { createMCPClient } from "@ai-sdk/mcp";
     
    const mcp = await createMCPClient({
    transport: {
    type: "http",
    url: `${GATEWAY_URL}/mcp`,
    headers: { Authorization: `Bearer ${DOME_AGENT_KEY}` },
    },
    });
    const tools = await mcp.tools();
  3. 03

    Call models through the Broker

    The OpenAI provider with the Gateway as its base URL, on chat completions. The model name is a pool.

    import { createOpenAI } from "@ai-sdk/openai";
     
    const broker = createOpenAI({ baseURL: `${GATEWAY_URL}/v1`, apiKey: DOME_AGENT_KEY });
    const model = broker.chat("claude-opus-5-5");

Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Vercel AI SDK itself, see Vercel's documentation.

Example agents

One agent, end to end

A server-side generateText loop: the OpenAI provider points at the Broker, and createMCPClient loads the Gateway's tools. Keys never reach the browser.

researcher

Answer questions about the code

generateText steps through the GitHub tools until it has an answer. The Gateway decides each tool call, and the Broker routes each model call.

import { createOpenAI } from "@ai-sdk/openai";
import { createMCPClient } from "@ai-sdk/mcp";
import { generateText, isStepCount } from "ai";
 
// Model: a pool on the Broker, through the OpenAI-compatible endpoint
const broker = createOpenAI({ baseURL: `${GATEWAY_URL}/v1`, apiKey: DOME_AGENT_KEY });
 
// Tools: whatever this agent is granted on the Gateway
const mcp = await createMCPClient({
transport: {
type: "http",
url: `${GATEWAY_URL}/mcp`,
headers: { Authorization: `Bearer ${DOME_AGENT_KEY}` },
},
});
 
try {
const { text } = await generateText({
model: broker.chat("claude-opus-5-5"),
tools: await mcp.tools(),
stopWhen: isStepCount(10),
system: "Answer questions about the code. Search before you answer.",
prompt: "Where is rate limiting handled?",
});
console.log(text);
} finally {
await mcp.close();
}

Agent workflow

Bringing it together

Connecting Vercel AI SDK agents to tools, models, and identity in Dome completes a governed agent application.

Dome

Agent

Runtime

Vercel AI SDK

This page

Control point

Gateway

  • Rules
  • Guards
  • Quotas

Every call decided and audited

FAQ

Common questions

How do I use a custom base URL with the Vercel AI SDK?

Call createOpenAI with baseURL set to the Gateway's /v1 endpoint and the Dome key as apiKey. Use provider.chat with a pool name.

How do I connect the Vercel AI SDK to a remote MCP server?

Use createMCPClient from @ai-sdk/mcp with an http transport, the Gateway's /mcp URL, and the Dome key as a bearer token.

What does a refused call look like?

An APICallError with status 403. Dome decides at the Gateway, before any provider or tool sees the call.

Next steps

Talk with our FDE team

Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.