Devin MCP and Dome
Devin works in your systems. You decide what it touches.
Devin writes code on its own and reaches your tools through custom MCP servers. Point it at a Dome Gateway and it works there as a registered agent: pull requests in your organization, no merges, and every call on the record.
How Dome helps
Dome provides a governed gateway for Devin
Devin signs in as Devin
Devin carries an agent key of its own, not an engineer's token. Revoke it and Devin's tool access ends.
Tools scoped by rule
Rules name the tools Devin may call and read their arguments. Pull requests open in one organization, and merges stay with people.
One trail with your agents
Devin's calls sit in the same audit trail as your own agents', allowed and refused alike.
Get started
Devin on a Gateway in four steps
Register Devin, give it a key, apply the rules, and add the Gateway to Devin as a custom MCP server. Your tools stay behind the Gateway the whole time.
01
Register Devin
Give it the GitHub tools it may call and the Gateway in front of them.
$ dome agents register --name devin \--tool github/search_code \--tool github/get_file_contents \--tool github/create_pull_request \--gateway eng-gateway02
Create its key
The response holds the key and the MCP URL. Paste both into Devin and keep no other copy.
$ dome agents create-key devin --name devin-mcp --gateway eng-gateway03
Apply the rules
Scope them to the devin agent. Simulate a merge to see it refused, then deploy.
$ dome rules apply devin-github.cedar \--agent devin --name devin-github04
Add the Gateway to Devin
In Devin, open Customize, then MCPs, and add a custom MCP. Choose HTTP, paste the MCP URL, and set the Authorization header to Bearer and the key.
Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Devin itself, see Cognition's documentation.
Rules
Read code, open pull requests in one org
The permit opens three GitHub tools to Devin. The first forbid refuses every other GitHub tool, merges included, and the second refuses a pull request outside the acme organization.
permit (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "github" && ["search_code", "get_file_contents", "create_pull_request"].contains(resource.tool_name)}; forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "github" && !["search_code", "get_file_contents", "create_pull_request"].contains(resource.tool_name)}; forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "github" && resource.tool_name == "create_pull_request" && !(resource has arguments && resource.arguments has owner && resource.arguments.owner == "acme")};Try it
One call, two outcomes
Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.
Organization
- Agentdevin is registered and its key is active
- Gatewaydevin may reach eng-gateway
- RulePull requests are open in acme
Agent workflow
Bringing it together
Connecting Devin to registered tools, models, and identity in Dome completes a governed agent application.
Acting for
Control point
Gateway
- Rules
- Guards
- Quotas
Every call decided and audited
Tools
Agent service
Devin
This page
MCP server
GitHub
See how
Models
FAQ
Common questions
Can Devin connect to a custom MCP server?
Yes. Devin adds custom MCP servers over HTTP with an auth header or OAuth, so it can connect to a Dome Gateway with its own agent key.
How do I limit what Devin can do in GitHub?
Put GitHub behind a Dome Gateway and apply rules to the devin agent. Rules name the tools it may call and read arguments such as the repository owner.
How do I cut off Devin's access?
Revoke the devin agent's key in Dome. Within seconds Devin's calls are refused, and your other agents are untouched.
Can I see what Devin did in my systems?
Yes. Audit records every tool call Devin makes through the Gateway, allowed or refused, under the devin agent.
Explore
More of what Dome works with
Model
Claude Fable
Fable 5.1 from Anthropic and Amazon Bedrock in one failover pool, open to one group and capped by quota.
Read moreProvider
Anthropic
The Claude API behind the Model Broker: the key held in Dome, every call authorized, metered and audited.
Read moreMCP server
Atlassian
The Atlassian Rovo MCP server behind the Tool Gateway, with rules that decide each Jira and Confluence call on its tool and site.
Read moreIdentity
Microsoft Entra ID
Entra access tokens verified on every agent call, so rules read app roles and audit names the person.
Read moreRuntime
LangGraph
LangGraph agents with their model calls on the Model Broker and their MCP tools on the Tool Gateway.
Read moreClient
Codex
Codex on a Dome Gateway with per-developer sign-in, rules on every tool call, and audit by name.
Read moreNext steps
Talk with our FDE team
Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.
No card required to start. Register your first agent in minutes.
Agent services: web, research, payments, voice and sandboxes
Web actions, research, payments, phone calls and code execution are where agents reach past your walls. Put each service behind the Gateway, and every call is authorized, metered and audited.
See them all