Dome Systems

GitHub MCP server and Dome

Let agents open pull requests. Decide where they can merge.

Connect the GitHub MCP server to Dome once. Every call runs with the GitHub token of the person the agent acts for, and rules decide each call on its repository.

EngineersAgentsDomeGitHubCallersEngineersAgentspr-reviewerAgentsrelease-drafterAgentsdependency-botGatewayseng-gatewayacme/webRepositoryacme/paymentsProtectedModel poolAny providerRulesGuardsAuditsaudit-trail
pr-reviewer→github/pull_request_read· as d.oseiAllowed

How Dome helps

Dome provides a tool gateway and authorization for GitHub

Decided on the arguments

One tool, allowed on one repository and refused on another. Rules read the owner and repo of every call.

Their token, their permissions

Attach a GitHub token for each engineer. An agent acting for one reaches only what they can.

Outside repositories refused

Calls to an owner other than your organization are refused. A prompt can't point an agent at someone else's fork.

Get started

GitHub behind the Gateway in three steps

Add the server, sync its tools into the Gateway's catalog, and apply the rules. Agents reach GitHub through the Gateway's single MCP endpoint.

  1. 01

    Add the GitHub MCP server

    Credentials are per user. Dome holds each engineer's GitHub token and injects it on calls made for them.

    $ dome tools add --name github \
    --url https://api.githubcopilot.com/mcp/ \
    --auth-method api-key \
    --credential-type per-user \
    --gateway eng-gateway
  2. 02

    Sync the catalog

    Run it once a token is attached, and again when GitHub adds tools. Until then, agents get “tool not available in this gateway”.

    $ dome tools catalog sync github
  3. 03

    Apply the rules

    Scope them to one agent while you try them. Simulate before you deploy.

    $ dome rules apply github-permit.cedar github-args.cedar \
    --agent release-drafter --name github-per-argument

Commands and rules tested against a Dome workspace on September 30, 2026. For anything about GitHub itself, see GitHub's documentation.

Rules

Merge anywhere but payments

The permit opens GitHub to the agent. The first forbid refuses merges into acme/payments, and the second refuses any owner outside acme.

permit (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when { resource.connection_name == "github" };
 
forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when {
resource.connection_name == "github" &&
resource.tool_name == "merge_pull_request" &&
resource has arguments &&
resource.arguments has owner && resource.arguments has repo &&
resource.arguments.owner == "acme" && resource.arguments.repo == "payments"
};
 
forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when {
resource.connection_name == "github" &&
resource has arguments &&
resource.arguments has owner && resource.arguments.owner != "acme"
};

Try it

One call, two outcomes

Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.

Repository

agent dependency-bot · acting as d.osei
github/merge_pull_request(owner: "acme", repo: "web", pullNumber: 482)
  1. Agentdependency-bot is registered and active
  2. Callerd.osei verified through Okta
  3. RuleGitHub calls inside acme are allowed
DecisionAllowed

Example agents

Three agents on GitHub

From our template library. Each one reads broadly and writes narrowly.

pr-reviewer

Review pull requests

Reads the diff and the files around it, and leaves a first review. Approval stays with an engineer.

  • github/pull_request_read
  • github/get_file_contents
  • github/list_commits

release-drafter

Draft release notes

Reads the pull requests merged since the last release and drafts customer-facing notes.

  • github/list_pull_requests
  • github/get_latest_release
  • github/list_releases

dependency-bot

Merge dependency updates

Reviews dependency update pull requests and merges the ones that pass their checks. Protected repositories stay with an engineer.

  • github/pull_request_read
  • github/list_commits
  • github/merge_pull_request

Agent workflow

Bringing it together

Connecting GitHub to registered agents, models, and identity in Dome completes a governed agent application.

Dome

Control point

Gateway

  • Rules
  • Guards
  • Quotas

Every call decided and audited

Tools

MCP server

GitHub

This page

FAQ

Common questions

Does Dome work with GitHub's remote MCP server?

Yes. Add it by URL, attach a token per user, and sync its tools into the Gateway's catalog.

Can I allow a GitHub tool on some repositories and not others?

Yes. Rules read the arguments of every tool call, so the same tool can be allowed on one owner and repository and refused on another.

Whose GitHub permissions does an agent use?

With per-user credentials, the permissions of the person it acts for. Dome picks their token from their verified identity.

Why write rules against connection_name and not the tool's full name?

Dome rewrites connection names to ids when rules deploy. A pattern on the full tool name isn't rewritten, so a forbid written that way deploys and matches nothing.

Next steps

Talk with our FDE team

Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.