GitHub MCP server and Dome
Let agents open pull requests. Decide where they can merge.
Connect the GitHub MCP server to Dome once. Every call runs with the GitHub token of the person the agent acts for, and rules decide each call on its repository.
How Dome helps
Dome provides a tool gateway and authorization for GitHub
Decided on the arguments
One tool, allowed on one repository and refused on another. Rules read the owner and repo of every call.
Their token, their permissions
Attach a GitHub token for each engineer. An agent acting for one reaches only what they can.
Outside repositories refused
Calls to an owner other than your organization are refused. A prompt can't point an agent at someone else's fork.
Get started
GitHub behind the Gateway in three steps
Add the server, sync its tools into the Gateway's catalog, and apply the rules. Agents reach GitHub through the Gateway's single MCP endpoint.
01
Add the GitHub MCP server
Credentials are per user. Dome holds each engineer's GitHub token and injects it on calls made for them.
$ dome tools add --name github \--url https://api.githubcopilot.com/mcp/ \--auth-method api-key \--credential-type per-user \--gateway eng-gateway02
Sync the catalog
Run it once a token is attached, and again when GitHub adds tools. Until then, agents get “tool not available in this gateway”.
$ dome tools catalog sync github03
Apply the rules
Scope them to one agent while you try them. Simulate before you deploy.
$ dome rules apply github-permit.cedar github-args.cedar \--agent release-drafter --name github-per-argument
Commands and rules tested against a Dome workspace on September 30, 2026. For anything about GitHub itself, see GitHub's documentation.
Rules
Merge anywhere but payments
The permit opens GitHub to the agent. The first forbid refuses merges into acme/payments, and the second refuses any owner outside acme.
permit (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "github" }; forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "github" && resource.tool_name == "merge_pull_request" && resource has arguments && resource.arguments has owner && resource.arguments has repo && resource.arguments.owner == "acme" && resource.arguments.repo == "payments"}; forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "github" && resource has arguments && resource.arguments has owner && resource.arguments.owner != "acme"};Try it
One call, two outcomes
Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.
Repository
- Agentdependency-bot is registered and active
- Callerd.osei verified through Okta
- RuleGitHub calls inside acme are allowed
Example agents
Three agents on GitHub
From our template library. Each one reads broadly and writes narrowly.
pr-reviewer
Review pull requests
Reads the diff and the files around it, and leaves a first review. Approval stays with an engineer.
- github/pull_request_read
- github/get_file_contents
- github/list_commits
release-drafter
Draft release notes
Reads the pull requests merged since the last release and drafts customer-facing notes.
- github/list_pull_requests
- github/get_latest_release
- github/list_releases
dependency-bot
Merge dependency updates
Reviews dependency update pull requests and merges the ones that pass their checks. Protected repositories stay with an engineer.
- github/pull_request_read
- github/list_commits
- github/merge_pull_request
Agent workflow
Bringing it together
Connecting GitHub to registered agents, models, and identity in Dome completes a governed agent application.
Acting for
Control point
Gateway
- Rules
- Guards
- Quotas
Every call decided and audited
Tools
MCP server
GitHub
This page
Models
FAQ
Common questions
Does Dome work with GitHub's remote MCP server?
Yes. Add it by URL, attach a token per user, and sync its tools into the Gateway's catalog.
Can I allow a GitHub tool on some repositories and not others?
Yes. Rules read the arguments of every tool call, so the same tool can be allowed on one owner and repository and refused on another.
Whose GitHub permissions does an agent use?
With per-user credentials, the permissions of the person it acts for. Dome picks their token from their verified identity.
Why write rules against connection_name and not the tool's full name?
Dome rewrites connection names to ids when rules deploy. A pattern on the full tool name isn't rewritten, so a forbid written that way deploys and matches nothing.
Explore
More of what Dome works with
Model
Claude Fable
Fable 5.1 from Anthropic and Amazon Bedrock in one failover pool, open to one group and capped by quota.
Read moreProvider
Anthropic
The Claude API behind the Model Broker: the key held in Dome, every call authorized, metered and audited.
Read moreIdentity
Microsoft Entra ID
Entra access tokens verified on every agent call, so rules read app roles and audit names the person.
Read moreRuntime
OpenAI Agents SDK
OpenAI Agents SDK agents with their models on the Model Broker and their MCP tools on the Tool Gateway.
Read moreClient
Claude Code
Claude Code on a Dome Gateway with per-developer sign-in, rules on every tool call, and audit by name.
Read moreAgent service
TinyFish
TinyFish's web agents behind the Tool Gateway, with rules that decide each run on the site it targets.
Read moreNext steps
Talk with our FDE team
Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.
No card required to start. Register your first agent in minutes.
MCP servers for AI agents: per-argument rules on every call
Put any remote MCP server behind the Tool Gateway. Agents reach it through one governed endpoint, and rules decide each call on its arguments.
See them all