Vertex AI Agent Engine and Dome
Deploy on Google Cloud. Govern every call the agent makes.
Agent Engine, now Agent Runtime in Gemini Enterprise Agent Platform, hosts agent code you write. Give the agent a Dome key and point its tools and model at the Gateway. Dome decides every call and records it against the agent.
How Dome helps
Dome provides governance for every Vertex AI Agent Engine tool and model call
Your code, your endpoints
Agent Runtime runs the agent you deploy, in ADK, LangGraph or your own code. Its tools and model point at the Gateway.
The key in Secret Manager
The Dome key reaches the agent as an environment variable from Secret Manager. It is the only credential the agent holds.
Every call on the record
Tool and model calls land in one audit trail, against the agent. The same rules apply wherever else the agent runs.
Get started
Agent Engine on Dome in three steps
Register the agent in Dome, pass its key from Secret Manager, and point its tools and model at the Gateway. The Dome commands were run against a workspace; the Google Cloud side comes from Google's docs.
01
Register an agent and issue its key
Then store the key in Secret Manager.
$ dome agents register --name support-triager --gateway prod-gateway$ dome agents create-key support-triager --name agent-runtime$ dome rules apply support-triager.cedar --agent support-triager --name linear-support-only02
Pass the key at deploy
Agent Runtime's env_vars can reference a Secret Manager secret. The agent reads it from the environment.
env_vars = {"GATEWAY_URL": "https://<gateway-host>/gateways/<gateway-id>","DOME_AGENT_KEY": {"secret": "dome-support-triager", "version": "1"},}03
Point tools and model at the Gateway
In ADK, an MCP toolset for tools and LiteLLM for the model. The model name is a pool.
import osfrom google.adk.models.lite_llm import LiteLlmfrom google.adk.tools.mcp_tool import McpToolset, StreamableHTTPConnectionParamsGATEWAY_URL, DOME_AGENT_KEY = os.environ["GATEWAY_URL"], os.environ["DOME_AGENT_KEY"]tools = McpToolset(connection_params=StreamableHTTPConnectionParams(url=f"{GATEWAY_URL}/mcp",headers={"Authorization": f"Bearer {DOME_AGENT_KEY}"},))model = LiteLlm(model="openai/claude-opus-5-5", api_base=f"{GATEWAY_URL}/v1", api_key=DOME_AGENT_KEY)
Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Vertex AI Agent Engine itself, see Google Cloud's documentation.
Rules
File issues for Support only
The permit lets the agent discover tools and call Linear. The forbid refuses any save_issue that doesn't name the Support team.
permit (principal, action == Dome::Action::"mcp:discover", resource); permit (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "linear" }; forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "linear" && resource.tool_name == "save_issue" && !(resource has arguments && resource.arguments has team && resource.arguments.team == "Support")};Try it
One call, two outcomes
Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.
Team
- Agentsupport-triager is registered and active
- KeyBearer key from Secret Manager is valid
- RuleIssues for Support are allowed
Agent workflow
Bringing it together
Connecting agents on Vertex AI Agent Engine to registered tools, models, and identity in Dome completes a governed agent application.
Acting for
Agent
Runtime
Vertex AI Agent Engine
This page
Runtime
Google ADK
See how
Control point
Gateway
- Rules
- Guards
- Quotas
Every call decided and audited
Models
FAQ
Common questions
Is Vertex AI Agent Engine now Agent Runtime?
Yes. Google renamed it Agent Runtime in April 2026, as part of Gemini Enterprise Agent Platform.
Which frameworks work with Dome on Agent Runtime?
Any that can load MCP tools over HTTP with a header and call an OpenAI- or Anthropic-compatible endpoint. ADK, LangGraph and LangChain all can.
Where should the Dome key live?
In Secret Manager, passed to the agent through env_vars at deploy. Revoke it in Dome and the deployed agent's calls stop.
Can the agent still use Gemini?
Yes. Add Gemini to a pool and name the pool as the model, and Gemini calls go through the Broker.
Explore
More of what Dome works with
Model
Claude Fable
Fable 5.1 from Anthropic and Amazon Bedrock in one failover pool, open to one group and capped by quota.
Read moreProvider
Anthropic
The Claude API behind the Model Broker: the key held in Dome, every call authorized, metered and audited.
Read moreMCP server
GitHub
The GitHub MCP server behind the Tool Gateway, with rules that decide each call on its owner and repository.
Read moreIdentity
Okta
Okta tokens verified on every agent call, so rules and audit name the person each agent acted for.
Read moreClient
Claude Code
Claude Code on a Dome Gateway with per-developer sign-in, rules on every tool call, and audit by name.
Read moreAgent service
TinyFish
TinyFish's web agents behind the Tool Gateway, with rules that decide each run on the site it targets.
Read moreNext steps
Talk with our FDE team
Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.
No card required to start. Register your first agent in minutes.
Agent frameworks and runtimes: govern agents without a rewrite
Build agents on the framework you already use. Dome governs their tool and model calls without a rewrite.
See them all