Dome Systems

Apify MCP server and Dome

Put Apify's Actors to work. Decide which ones, on which sites.

Apify runs Actors, ready-made scrapers and crawlers that agents call as tools. Connect Apify's hosted MCP server to Dome once, and rules decide each fetch on its URL and each run on the Actor it names. Every run lands in one audit trail.

AnalystsAgentsDomeApifyCallersAnalystsAgentsfilings-readerAgentsnews-scannerAgentssupplier-researcherGatewaysresearch-gatewaywww.sec.govOn the listAny other siteRefusedModel poolAny providerRulesGuardsAuditsaudit-trail
filings-reader→apify/apify--web-fetch· scheduledAllowed

How Dome helps

Dome provides a governed gateway for Apify

Fetches decided on the URL

Rules read the URL of every Web Fetch call. A listed site is fetched, and a lookalike domain is refused.

Actors decided by name

call-actor can start any Actor in the Apify Store. A rule on its actor argument keeps an agent to the ones you name.

One token, held by Dome

Dome holds the Apify API token and injects it on each call. Agents authenticate to the Gateway with their own Dome key.

Get started

Apify behind the Gateway in three steps

Add the hosted MCP server with the tools you want, sync them into the Gateway's catalog, and apply the rules. The tools parameter on the URL picks which tools Apify serves.

  1. 01

    Add the Apify MCP server

    This URL loads Web Fetch and call-actor. Dome stores the Apify token and sends it as a Bearer token.

    $ dome tools add --name apify \
    --url "https://mcp.apify.com?tools=apify/web-fetch,call-actor" \
    --auth-method api-key \
    --credential-type shared \
    --authorization "Bearer $APIFY_TOKEN" \
    --gateway research-gateway
  2. 02

    Sync the catalog

    Sync needs a valid token, and Apify refuses the listing without one. Until it runs, agents get “tool not available in this gateway”.

    $ dome tools catalog sync apify
  3. 03

    Apply the rules

    Scope them to one agent while you try them. Simulate before you deploy.

    $ dome rules apply apify-permit.cedar apify-limits.cedar \
    --agent filings-reader --name apify-limits

Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Apify itself, see Apify's documentation.

Rules

Fetch two sites, run one Actor

The permit opens Web Fetch, call-actor and the run results to the agent. The first forbid refuses any fetch off two sites, and the second refuses any Actor but Google Search Scraper.

permit (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when {
resource.connection_name == "apify" &&
["apify--web-fetch", "call-actor", "get-actor-run", "get-dataset-items"].contains(resource.tool_name)
};
 
forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when {
resource.connection_name == "apify" &&
resource.tool_name == "apify--web-fetch" &&
!(resource has arguments &&
resource.arguments has url &&
(resource.arguments.url like "https://www.sec.gov/*" ||
resource.arguments.url like "https://investors.northwind-supply.com/*"))
};
 
forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when {
resource.connection_name == "apify" &&
resource.tool_name == "call-actor" &&
!(resource has arguments &&
resource.arguments has actor &&
resource.arguments.actor == "apify/google-search-scraper")
};

Try it

One call, two outcomes

Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.

Site

agent filings-reader · scheduled
apify/apify--web-fetch(url: "https://www.sec.gov/cgi-bin/browse-edgar?action=getcompany&CIK=0000320193")
  1. Agentfilings-reader is registered and active
  2. Rulewww.sec.gov is on the list
DecisionAllowed

Example agents

Three agents on Apify

Each one gets its own sites and Actors. A bundle per agent keeps one agent's list from widening another's.

filings-reader

Read SEC filings

Fetches new filings for the companies under review each morning. Any other site is refused.

  • apify/apify--web-fetch
  • apify/call-actor
  • apify/get-dataset-items

news-scanner

Scan search results for news

Runs Google Search Scraper for each vendor and hands the results to an analyst. Every other Actor is refused.

  • apify/call-actor
  • apify/get-actor-run
  • apify/get-dataset-items

supplier-researcher

Read supplier investor pages

Fetches investor news from the suppliers on its list and flags changes for procurement.

  • apify/apify--web-fetch

Agent workflow

Bringing it together

Connecting Apify to registered agents, models, and runtimes in Dome completes a governed agent application.

Dome

Control point

Gateway

  • Rules
  • Guards
  • Quotas

Every call decided and audited

Tools

Agent service

Apify

This page

FAQ

Common questions

Does Apify have a hosted MCP server?

Yes. Apify hosts one at mcp.apify.com, and Dome adds it by URL with an Apify API token.

Can I limit which Apify Actors an agent runs?

Yes. Rules read the actor argument of call-actor, so a named Actor runs and any other is refused.

Can I limit which websites an agent fetches through Apify?

Yes. Rules read the URL argument of Web Fetch, so a listed site is fetched and any other host is refused.

How do I choose which Apify tools an agent sees?

Set the tools parameter on the server URL. Apify serves only those, and Dome syncs that list into the catalog.

Next steps

Talk with our FDE team

Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.