ElevenLabs MCP and Dome
Voice agents talk to your customers. You decide what they look up.
ElevenLabs Agents reach outside tools through custom MCP servers, added by URL and secret token. Point one at a Dome Gateway, and the voice agent reaches your tools as a registered agent with its own key. Rules decide each call it makes mid-conversation, and audit records every one.
How Dome helps
Dome provides a governed gateway for ElevenLabs Agents
A key per voice agent
Each ElevenLabs agent connects with its own Dome key as the secret token. Revoke one key and only that agent loses access.
Reads open, writes closed
Rules decide every tool call the voice agent makes mid-conversation. It looks up a caller's record and can't change it.
Every lookup audited
Each tool call lands in audit under the voice agent's name. You see what it read during every call.
Get started
ElevenLabs Agents on a Gateway in four steps
Register the voice agent, give it a key, apply the rules, and add the Gateway to ElevenLabs as a custom MCP server. Your tools stay behind the Gateway the whole time.
01
Register the voice agent
Name the tools it may call and the Gateway it reaches.
$ dome agents register --name support-voice \--tool hubspot/search_crm_objects \--tool hubspot/get_crm_objects \--tool hubspot/search_owners \--gateway support-gateway02
Create its key
The response carries the key and the Gateway's MCP URL. Store the key in ElevenLabs and nowhere else.
$ dome agents create-key support-voice --name elevenlabs --gateway support-gateway03
Apply the rules
The Gateway grant opens every tool on the Gateway, so the forbid narrows it to three. Simulate before you deploy.
$ dome rules apply support-voice.cedar \--agent support-voice --name support-voice04
Add the Gateway to ElevenLabs
In ElevenLabs, open the MCP server integrations and add a custom MCP server. Paste the MCP URL, set the secret token to Bearer and the key, then attach the server to your agent.
Commands and rules tested against a Dome workspace on October 1, 2026. For anything about ElevenLabs Agents itself, see ElevenLabs's documentation.
Rules
Three HubSpot reads, nothing else
The permit opens HubSpot to the voice agent. The forbid refuses every tool call that isn't one of three reads, so writes and every other tool on the Gateway stay closed.
permit (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "hubspot" }; forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)unless { resource.connection_name == "hubspot" && ["search_crm_objects", "get_crm_objects", "search_owners"].contains(resource.tool_name)};Try it
One call, two outcomes
Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.
Call
- Agentsupport-voice is registered and active
- KeyThe ElevenLabs key belongs to support-voice
- Rulesearch_crm_objects is one of three reads
Example agents
Three agents around ElevenLabs
Two ElevenLabs voice agents, each with its own key and rules. One of your own agents works from what they recorded.
support-voice
Answer support calls
Looks up the caller's contact record and its owner while it talks. It reads HubSpot and changes nothing.
- hubspot/search_crm_objects
- hubspot/get_crm_objects
- hubspot/search_owners
billing-voice
Answer billing questions
Reads a caller's invoices in a Stripe sandbox while it talks. Its own key and rules keep it out of HubSpot.
- stripe/stripe_api_read
call-summarizer
Log what each call covered
Reads the day's support records and drafts follow-ups for the team lead. It never speaks to a caller.
- hubspot/search_crm_objects
- hubspot/get_crm_objects
Agent workflow
Bringing it together
Connecting ElevenLabs Agents to registered tools, models, and identity in Dome completes a governed agent application.
Acting for
Control point
Gateway
- Rules
- Guards
- Quotas
Every call decided and audited
Tools
Models
FAQ
Common questions
Can ElevenLabs Agents connect to a remote MCP server?
Yes. ElevenLabs adds custom MCP servers by URL, with an optional secret token sent as the Authorization header.
How do I limit which tools an ElevenLabs voice agent can call?
Register it in Dome and point it at a Gateway. Rules decide each tool call, so it reaches only the tools you list.
Does each ElevenLabs agent need its own Dome key?
It should. Each key belongs to one registered agent, so rules and audit tell your voice agents apart.
Does Dome place ElevenLabs phone calls?
No. ElevenLabs places the call, and Dome decides the tool calls its agent makes during it.
Explore
More of what Dome works with
Model
Claude Fable
Fable 5.1 from Anthropic and Amazon Bedrock in one failover pool, open to one group and capped by quota.
Read moreProvider
Anthropic
The Claude API behind the Model Broker: the key held in Dome, every call authorized, metered and audited.
Read moreMCP server
GitHub
The GitHub MCP server behind the Tool Gateway, with rules that decide each call on its owner and repository.
Read moreIdentity
Microsoft Entra ID
Entra access tokens verified on every agent call, so rules read app roles and audit names the person.
Read moreRuntime
LangGraph
LangGraph agents with their model calls on the Model Broker and their MCP tools on the Tool Gateway.
Read moreClient
Claude Code
Claude Code on a Dome Gateway with per-developer sign-in, rules on every tool call, and audit by name.
Read moreNext steps
Talk with our FDE team
Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.
No card required to start. Register your first agent in minutes.
Agent services: web, research, payments, voice and sandboxes
Web actions, research, payments, phone calls and code execution are where agents reach past your walls. Put each service behind the Gateway, and every call is authorized, metered and audited.
See them all