Dome Systems

Exa and Dome

Your agents' searches say what you're working on. Check them before they leave.

Exa's hosted MCP server gives agents search, page fetches and an agent_run tool besides. Research agents search a lot, and every query carries context. Put Exa behind Dome, and each agent gets two tools, a daily call budget and a rule on what it may search for.

AnalystsAgentsDomeExaCallersAnalystsAgentsmarket-researcherAgentsregulatory-trackerAgentsdeal-scoutGatewaysresearch-gatewaySearch and fetchQueries checkedagent_runClosedModel poolAny providerRulesGuardsAuditsaudit-trail
regulatory-tracker→exa/web_search_exa· scheduledAllowed

How Dome helps

Dome provides a governed gateway for Exa

Every spelling of the codename

Cedar's like is case-sensitive. List Halcyon and HALCYON, and a query or objective with either is refused before Exa sees it.

Two tools, not three

Search and fetch stay open. A forbid closes agent_run and every other Exa tool.

A budget per agent

A quota counts each Exa call an agent makes. Past the daily limit, the next one is refused.

Get started

Exa behind the Gateway in five steps

Add Exa's server, sync it, guard outbound arguments, deploy the rules and set each agent's budget.

  1. 01

    Add the Exa MCP server

    Exa reads its API key from the x-api-key header. Dome stores the key and sends it on every call.

    $ dome tools add --name exa \
    --url https://mcp.exa.ai/mcp \
    --auth-method api-key \
    --credential-type shared \
    --authorization "Bearer $EXA_API_KEY" \
    --secret-value EXA_API_KEY=$EXA_API_KEY \
    --header-secret x-api-key=EXA_API_KEY \
    --gateway prod-gateway
  2. 02

    Sync the catalog

    Sync lists web_search_exa, web_fetch_exa and agent_run. Agents see none of them until it runs.

    $ dome tools catalog sync exa
  3. 03

    Block personal data in arguments

    A JSON filter on the request direction scans every argument. A match blocks the call before it reaches Exa.

    $ cat > query-leak.json <<'EOF'
    $ {"json":{"components":[{"fieldActions":[{
    "matcher":{"contentMatchers":[{"ssn":{}},{"creditCard":{"requireLuhn":true}},{"email":{}}]},
    "action":"FILTER_ACTION_BLOCK"}]}]}}
    $ EOF
    $ dome guards filters create query-leak --config-from query-leak.json
    $ dome tools guards filters set exa --direction request --filters query-leak
  4. 04

    Apply the rules

    The rule is scoped to deal-scout. Simulate a query with each spelling of the codename, then deploy.

    $ dome rules apply exa-queries.cedar --agent deal-scout --name exa-queries
  5. 05

    Cap the calls

    The quota counts every tool call the agent makes. Past the limit, calls are refused until the window resets.

    $ dome quotas set --subject agent --agent deal-scout \
    --dimension tool --unit calls --limit 500 --window daily

Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Exa itself, see Exa's documentation.

Rules

Search and fetch, never the codename

The permit opens search and fetch. One forbid closes every other Exa tool, and the other refuses any query or objective that names Project Halcyon. Cedar's like is case-sensitive, so list each spelling you need.

permit (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when {
resource.connection_name == "exa" &&
["web_search_exa", "web_fetch_exa"].contains(resource.tool_name)
};
 
forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when {
resource.connection_name == "exa" &&
!["web_search_exa", "web_fetch_exa"].contains(resource.tool_name)
};
 
forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when {
resource.connection_name == "exa" &&
resource has arguments &&
((resource.arguments has query && resource.arguments.query like "*Halcyon*") ||
(resource.arguments has objective && resource.arguments.objective like "*Halcyon*"))
};

Try it

One call, two outcomes

Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.

Query

agent deal-scout · acting as m.chen
exa/web_search_exa(query: "industrial sensor startups Series B 2026", objective: "Map the market")
  1. Agentdeal-scout is registered and active
  2. Callerm.chen verified through Okta
  3. RuleThe query names no internal project
DecisionAllowed

Example agents

Three agents on Exa

Each one searches the open web. None of them sends an internal name or a customer's details to do it.

market-researcher

Map a market

Searches for companies in a category and reads their sites. A daily quota caps its calls.

  • exa/web_search_exa
  • exa/web_fetch_exa

regulatory-tracker

Track new rules

Searches regulators' sites each morning and fetches anything new for the compliance team.

  • exa/web_search_exa
  • exa/web_fetch_exa

deal-scout

Scout acquisition targets

Runs targeted searches against a deal thesis. Any listed spelling of the deal's codename is refused.

  • exa/web_search_exa

Agent workflow

Bringing it together

Connecting Exa to registered agents, models, and identity in Dome completes a governed agent application.

Dome

Control point

Gateway

  • Rules
  • Guards
  • Quotas

Every call decided and audited

Tools

Agent service

Exa

This page

FAQ

Common questions

Does Exa have an MCP server?

Yes. Exa hosts one at mcp.exa.ai/mcp, and Dome adds it by URL with the API key in the x-api-key header.

Does a codename rule catch every spelling?

Only the spellings you list. Cedar's like is case-sensitive, so the rule names each one, and a query or objective with any of them is refused.

Can Dome keep customer details out of Exa?

Yes. A guard on the request direction blocks a call whose arguments carry an email address, a card number or a Social Security number.

Can I limit how many Exa searches an agent runs?

Yes. A quota on the agent with --dimension tool --unit calls caps its tool calls each day or month.

Next steps

Talk with our FDE team

Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.