Skip to main content
This tutorial is coming soon.
Govern per end user teaches the pattern with HMAC: your backend holds the agent token, signs X-Dome-Act-As, and calls Dome. The frontend never sees either secret. Production usually should not mint identities with a shared HMAC secret. This tutorial will cover the two stronger verification methods: Until this tutorial ships, use the HMAC sandbox path and the delegated-agent reference below.

Next steps

Until this tutorial ships, use the HMAC path and the delegated-agent reference: