Dome Systems

Firecrawl and Dome

Scrape the pages you meant to. Refuse the rest.

Firecrawl turns any URL into clean content for an agent, and searches, maps and crawls sites over a hosted MCP server. It also opens browser sessions and runs its own agent, more reach than most jobs need. Behind Dome, three tools stay open and scrapes stay on the sites you list.

EngineersAgentsDomeFirecrawlCallersEngineersAgentsdocs-indexerAgentsfilings-readerAgentsdeal-scoutGatewaysresearch-gatewayListed sitesScrape and mapAny other siteSearch onlyModel poolAny providerRulesGuardsAuditsaudit-trail
docs-indexer→firecrawl/firecrawl_map· scheduledAllowed

How Dome helps

Dome provides a governed gateway for Firecrawl

Scrapes on listed sites

A rule reads the url of every scrape and map. Your supplier's docs and sec.gov are scraped. Any other site is refused.

Three tools open, the rest closed

Search, scrape and map stay open. Crawls, browser sessions, monitors and Firecrawl's own agent are closed until you open them.

No personal data in the request

A guard reads search queries and URLs alike. A card number, a Social Security number or an email address in either blocks the call.

Get started

Firecrawl behind the Gateway in three steps

Add Firecrawl's server, guard its arguments and deploy the rules. There's no catalog sync: the tools list as soon as the server is added.

  1. 01

    Add the Firecrawl MCP server

    One Firecrawl API key serves every agent. Dome sends it as a Bearer token, and the Gateway lists Firecrawl's tools once the server is added.

    $ dome tools add --name firecrawl \
    --url https://mcp.firecrawl.dev/v2/mcp \
    --auth-method api-key \
    --credential-type shared \
    --authorization "Bearer $FIRECRAWL_API_KEY" \
    --gateway prod-gateway
  2. 02

    Block personal data in arguments

    The filter runs on requests. A match stops the call before Firecrawl fetches anything.

    $ cat > query-leak.json <<'EOF'
    $ {"json":{"components":[{"fieldActions":[{
    "matcher":{"contentMatchers":[{"ssn":{}},{"creditCard":{"requireLuhn":true}},{"email":{}}]},
    "action":"FILTER_ACTION_BLOCK"}]}]}}
    $ EOF
    $ dome guards filters create query-leak --config-from query-leak.json
    $ dome tools guards filters set firecrawl --direction request --filters query-leak
  3. 03

    Apply the rules

    The site list is scoped to filings-reader. Simulate a scrape on and off the list, then deploy.

    $ dome rules apply firecrawl-sites.cedar --agent filings-reader --name firecrawl-sites

Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Firecrawl itself, see Firecrawl's documentation.

Rules

Scrape two sites, search the rest

The permit opens search, scrape and map. Forbids close every other Firecrawl tool, refuse any search that names Project Halcyon and refuse a scrape or map outside two sites.

permit (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when {
resource.connection_name == "firecrawl" &&
["firecrawl_search", "firecrawl_scrape", "firecrawl_map"].contains(resource.tool_name)
};
 
forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when {
resource.connection_name == "firecrawl" &&
!["firecrawl_search", "firecrawl_scrape", "firecrawl_map"].contains(resource.tool_name)
};
 
forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when {
resource.connection_name == "firecrawl" &&
resource.tool_name == "firecrawl_search" &&
resource has arguments &&
resource.arguments has query &&
resource.arguments.query like "*Halcyon*"
};
 
forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when {
resource.connection_name == "firecrawl" &&
["firecrawl_scrape", "firecrawl_map"].contains(resource.tool_name) &&
!(resource has arguments &&
resource.arguments has url &&
(resource.arguments.url like "https://docs.northwind-supply.com/*" ||
resource.arguments.url like "https://www.sec.gov/*"))
};

Try it

One call, two outcomes

Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.

Site

agent filings-reader · acting as s.patel
firecrawl/firecrawl_scrape(url: "https://www.sec.gov/Archives/edgar/data/320193/000032019325000079/aapl-20250927.htm", formats: ["markdown"])
  1. Agentfilings-reader is registered and active
  2. Callers.patel verified through Okta
  3. RuleScrapes on www.sec.gov are allowed
DecisionAllowed

Example agents

Three agents on Firecrawl

Each one reads the web as clean text. Two scrape, and only the sites they're given.

docs-indexer

Index a supplier's docs

Maps a supplier's documentation site each night and scrapes changed pages into the search index.

  • firecrawl/firecrawl_map
  • firecrawl/firecrawl_scrape

filings-reader

Read public filings

Scrapes annual reports on sec.gov and pulls the sections an analyst asks for. Any other site is refused.

  • firecrawl/firecrawl_scrape

deal-scout

Scout acquisition targets

Searches for companies that fit a thesis and reads the results as clean text. A query naming the deal is refused.

  • firecrawl/firecrawl_search

Agent workflow

Bringing it together

Connecting Firecrawl to registered agents, models, and identity in Dome completes a governed agent application.

Dome

Control point

Gateway

  • Rules
  • Guards
  • Quotas

Every call decided and audited

Tools

Agent service

Firecrawl

This page

FAQ

Common questions

Does Firecrawl have a hosted MCP server?

Yes, at mcp.firecrawl.dev/v2/mcp. Dome connects by URL and sends your Firecrawl API key as a Bearer token.

Can I limit which websites an agent scrapes with Firecrawl?

Yes. The rule reads the url of firecrawl_scrape and firecrawl_map. Pages on the two listed sites come back, and every other site is refused.

Can I turn off Firecrawl's crawl and browser tools?

Yes. A forbid on every tool outside an allowed list closes them, including firecrawl_crawl, firecrawl_interact and firecrawl_agent.

Next steps

Talk with our FDE team

Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.