Apify MCP server and Dome
Put Apify's Actors to work. Decide which ones, on which sites.
Apify runs Actors, ready-made scrapers and crawlers that agents call as tools. Connect Apify's hosted MCP server to Dome once, and rules decide each fetch on its URL and each run on the Actor it names. Every run lands in one audit trail.
How Dome helps
Dome provides a governed gateway for Apify
Fetches decided on the URL
Rules read the URL of every Web Fetch call. A listed site is fetched, and a lookalike domain is refused.
Actors decided by name
call-actor can start any Actor in the Apify Store. A rule on its actor argument keeps an agent to the ones you name.
One token, held by Dome
Dome holds the Apify API token and injects it on each call. Agents authenticate to the Gateway with their own Dome key.
Get started
Apify behind the Gateway in three steps
Add the hosted MCP server with the tools you want, sync them into the Gateway's catalog, and apply the rules. The tools parameter on the URL picks which tools Apify serves.
01
Add the Apify MCP server
This URL loads Web Fetch and call-actor. Dome stores the Apify token and sends it as a Bearer token.
$ dome tools add --name apify \--url "https://mcp.apify.com?tools=apify/web-fetch,call-actor" \--auth-method api-key \--credential-type shared \--authorization "Bearer $APIFY_TOKEN" \--gateway research-gateway02
Sync the catalog
Sync needs a valid token, and Apify refuses the listing without one. Until it runs, agents get “tool not available in this gateway”.
$ dome tools catalog sync apify03
Apply the rules
Scope them to one agent while you try them. Simulate before you deploy.
$ dome rules apply apify-permit.cedar apify-limits.cedar \--agent filings-reader --name apify-limits
Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Apify itself, see Apify's documentation.
Rules
Fetch two sites, run one Actor
The permit opens Web Fetch, call-actor and the run results to the agent. The first forbid refuses any fetch off two sites, and the second refuses any Actor but Google Search Scraper.
permit (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "apify" && ["apify--web-fetch", "call-actor", "get-actor-run", "get-dataset-items"].contains(resource.tool_name)}; forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "apify" && resource.tool_name == "apify--web-fetch" && !(resource has arguments && resource.arguments has url && (resource.arguments.url like "https://www.sec.gov/*" || resource.arguments.url like "https://investors.northwind-supply.com/*"))}; forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "apify" && resource.tool_name == "call-actor" && !(resource has arguments && resource.arguments has actor && resource.arguments.actor == "apify/google-search-scraper")};Try it
One call, two outcomes
Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.
Site
- Agentfilings-reader is registered and active
- Rulewww.sec.gov is on the list
Example agents
Three agents on Apify
Each one gets its own sites and Actors. A bundle per agent keeps one agent's list from widening another's.
filings-reader
Read SEC filings
Fetches new filings for the companies under review each morning. Any other site is refused.
- apify/apify--web-fetch
- apify/call-actor
- apify/get-dataset-items
news-scanner
Scan search results for news
Runs Google Search Scraper for each vendor and hands the results to an analyst. Every other Actor is refused.
- apify/call-actor
- apify/get-actor-run
- apify/get-dataset-items
supplier-researcher
Read supplier investor pages
Fetches investor news from the suppliers on its list and flags changes for procurement.
- apify/apify--web-fetch
Agent workflow
Bringing it together
Connecting Apify to registered agents, models, and runtimes in Dome completes a governed agent application.
Acting for
Control point
Gateway
- Rules
- Guards
- Quotas
Every call decided and audited
Tools
Agent service
Apify
This page
Models
FAQ
Common questions
Does Apify have a hosted MCP server?
Yes. Apify hosts one at mcp.apify.com, and Dome adds it by URL with an Apify API token.
Can I limit which Apify Actors an agent runs?
Yes. Rules read the actor argument of call-actor, so a named Actor runs and any other is refused.
Can I limit which websites an agent fetches through Apify?
Yes. Rules read the URL argument of Web Fetch, so a listed site is fetched and any other host is refused.
How do I choose which Apify tools an agent sees?
Set the tools parameter on the server URL. Apify serves only those, and Dome syncs that list into the catalog.
Explore
More of what Dome works with
Model
Claude Fable
Fable 5.1 from Anthropic and Amazon Bedrock in one failover pool, open to one group and capped by quota.
Read moreProvider
Anthropic
The Claude API behind the Model Broker: the key held in Dome, every call authorized, metered and audited.
Read moreMCP server
GitHub
The GitHub MCP server behind the Tool Gateway, with rules that decide each call on its owner and repository.
Read moreIdentity
Okta
Okta tokens verified on every agent call, so rules and audit name the person each agent acted for.
Read moreRuntime
LangGraph
LangGraph agents with their model calls on the Model Broker and their MCP tools on the Tool Gateway.
Read moreClient
Codex
Codex on a Dome Gateway with per-developer sign-in, rules on every tool call, and audit by name.
Read moreNext steps
Talk with our FDE team
Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.
No card required to start. Register your first agent in minutes.
Agent services: web, research, payments, voice and sandboxes
Web actions, research, payments, phone calls and code execution are where agents reach past your walls. Put each service behind the Gateway, and every call is authorized, metered and audited.
See them all