Dome Systems

Apollo.io MCP server and Dome

Let agents research prospects. Keep them out of your sequences.

Apollo's MCP server gives agents people and company search, enrichment, contacts and sequences. A research agent needs the first two and none of the rest. Put Apollo behind Dome, and rules keep each agent to the lookups it needs while every call lands in one audit trail.

RepsAgentsDomeApolloCallersRepsAgentsaccount-researcherAgentslead-enricherAgentsmeeting-prepGatewayssales-gatewaySearch and enrichmentAllowedContacts and sequencesRefusedModel poolAny providerRulesGuardsAuditsaudit-trail
account-researcher→apollo/apollo_mixed_people_api_search· as j.okaforAllowed

How Dome helps

Dome provides a governed gateway for Apollo

Lookups open, writes closed

Rules allow people search, company search and enrichment. Creating contacts and loading sequences stay refused for every research agent.

Each rep's own Apollo account

Each rep signs in to Apollo once through OAuth. Their agent calls Apollo with that rep's account, not a shared master key.

Personal emails decided per call

Rules read the arguments of every enrichment. A match that asks to reveal personal emails is refused.

Get started

Apollo behind the Gateway in four steps

Add Apollo's MCP server with per-user OAuth, sync its tools, apply the rules and cap the calls. Agents reach Apollo through the Gateway's single MCP endpoint.

  1. 01

    Add the Apollo MCP server

    Dome registers itself with Apollo's OAuth server. Each rep signs in to Apollo once, and Dome stores their token.

    $ dome tools add --name apollo \
    --url https://mcp.apollo.io/mcp \
    --auth-method oauth \
    --credential-type per-user \
    --oauth-client-origin dcr \
    --oauth-authorize-url https://mcp.apollo.io/mcp/oauth_metadata/redirect_to_authorize \
    --oauth-token-url https://mcp.apollo.io/api/v1/oauth/token \
    --oauth-revoke-url https://mcp.apollo.io/api/v1/oauth/revoke \
    --oauth-registration-url https://mcp.apollo.io/api/v1/oauth/applications/register_oauth_client \
    --gateway prod-gateway
  2. 02

    Sync the catalog

    Sync runs with your own Apollo sign-in, so connect your account first. Until it runs, agents get “tool not available in this gateway”.

    $ dome tools catalog sync apollo
  3. 03

    Apply the rules

    Scope them to one agent while you try them. Simulate before you deploy.

    $ dome rules apply apollo-lookups.cedar --agent lead-enricher --name apollo-lookups
  4. 04

    Cap the calls

    The quota counts every tool call the agent makes. Past the limit, calls are refused until the window resets.

    $ dome quotas set --subject agent --agent lead-enricher \
    --dimension tool --unit calls --limit 200 --window daily

Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Apollo itself, see Apollo.io's documentation.

Rules

Search and enrich, never write

The permit opens four lookup tools. One forbid closes every other Apollo tool, contacts and sequences included. The other refuses a people match that asks for personal emails.

permit (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when {
resource.connection_name == "apollo" &&
["apollo_mixed_people_api_search", "apollo_mixed_companies_search",
"apollo_organizations_enrich", "apollo_people_match"].contains(resource.tool_name)
};
 
forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when {
resource.connection_name == "apollo" &&
!["apollo_mixed_people_api_search", "apollo_mixed_companies_search",
"apollo_organizations_enrich", "apollo_people_match"].contains(resource.tool_name)
};
 
forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when {
resource.connection_name == "apollo" &&
resource.tool_name == "apollo_people_match" &&
resource has arguments &&
resource.arguments has reveal_personal_emails &&
resource.arguments.reveal_personal_emails == true
};

Try it

One call, two outcomes

Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.

Request

agent lead-enricher · acting as j.okafor
apollo/apollo_people_match(first_name: "Dana", last_name: "Reyes", domain: "northwind-supply.com")
  1. Agentlead-enricher is registered and active
  2. Callerj.okafor verified through Okta
  3. RulePeople match without personal emails is allowed
DecisionAllowed

Example agents

Three agents on Apollo

Each one looks people and companies up. None of them creates a contact or loads a sequence.

account-researcher

Map the buying group

Finds the decision makers at a target account by title and seniority, and writes a short map for the rep.

  • apollo/apollo_mixed_people_api_search
  • apollo/apollo_organizations_enrich

lead-enricher

Enrich inbound leads

Matches each inbound lead to a person and a company. A request for personal emails is refused.

  • apollo/apollo_people_match
  • apollo/apollo_organizations_enrich

meeting-prep

Prepare for a first call

Looks up the company and the people on the invite before a first meeting, and drafts a one-page brief.

  • apollo/apollo_mixed_companies_search
  • apollo/apollo_people_match

Agent workflow

Bringing it together

Connecting Apollo to registered agents, CRM tools, and identity in Dome completes a governed agent application.

Dome

Control point

Gateway

  • Rules
  • Guards
  • Quotas

Every call decided and audited

Tools

Agent service

Apollo

This page

MCP server

HubSpot

See how

FAQ

Common questions

Does Apollo.io have an MCP server?

Yes. Apollo hosts one at mcp.apollo.io/mcp, and Dome adds it with per-user OAuth so each rep signs in with their own account.

Can I stop an AI agent writing to Apollo?

Yes. A forbid on every tool outside an allowed list refuses contact creation and sequence changes, and the agent keeps search and enrichment.

Can I limit how many Apollo lookups an agent makes?

Yes. A quota on the agent with --dimension tool --unit calls caps its tool calls each day or month.

Next steps

Talk with our FDE team

Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.