Lindy and Dome
Lindy acts in your tools. Rules decide which actions.
Lindy switches on every tool an MCP integration lists. Behind a Dome Gateway, that stops mattering: Lindy calls in as a registered agent with its own key, and rules decide which of those tools it may use.
How Dome helps
Dome provides a governed gateway for Lindy
A key that's only Lindy's
Lindy authenticates with an agent key minted for it. Revoke that key and Lindy is cut off. Your own agents run on.
Comment, don't change
Lindy may read Linear issues and comment on them. Creating, editing and closing stay with your team.
Lindy's calls, labeled
Audit files each call under the lindy agent. Filter by it and you see Lindy's work alone.
Get started
Lindy on a Gateway in four steps
Register Lindy, mint its key, deploy the rules, then add the Gateway in Lindy as an MCP integration. The rules do the scoping.
01
Register Lindy
Register it with the Linear tools it may reach and the Gateway they sit behind.
$ dome agents register --name lindy \--tool linear/list_issues \--tool linear/get_issue \--tool linear/save_comment \--gateway ops-gateway02
Create its key
You get back the key and the Gateway's MCP URL. Both go into Lindy, and only there.
$ dome agents create-key lindy --name lindy-mcp --gateway ops-gateway03
Apply the rules
Scope them to the lindy agent. Simulate a create_issue to see it refused, then deploy.
$ dome rules apply lindy-linear.cedar \--agent lindy --name lindy-linear04
Add the Gateway to Lindy
In Lindy, open Integrations, choose Add, then MCP, and paste the MCP URL. Under Advanced, send the key as an Authorization bearer token.
Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Lindy itself, see Lindy's documentation.
Rules
Read issues and comment
The permit opens three Linear tools to Lindy. The forbid refuses every other Linear tool, so Lindy can't create, edit or close an issue.
permit (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "linear" && ["list_issues", "get_issue", "save_comment"].contains(resource.tool_name)}; forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "linear" && !["list_issues", "get_issue", "save_comment"].contains(resource.tool_name)};Try it
One call, two outcomes
Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.
Action
- Agentlindy is registered and its key is active
- Gatewaylindy may reach ops-gateway
- RuleComments are open to lindy
Agent workflow
Bringing it together
Connecting Lindy to registered tools, models, and identity in Dome completes a governed agent application.
Acting for
Control point
Gateway
- Rules
- Guards
- Quotas
Every call decided and audited
Tools
Models
FAQ
Common questions
Can Lindy connect to a custom MCP server?
Yes. Lindy adds hosted MCP servers over HTTPS with a bearer token, so a Dome Gateway is one more integration.
How do I limit which tools Lindy can use?
Write rules for the lindy agent in Dome. Whatever Lindy switches on, a tool the rules refuse is refused at the Gateway.
What if Lindy's key leaks?
Revoke it in Dome and mint another. Within seconds the Gateway refuses the old key.
Explore
More of what Dome works with
Model
Claude Fable
Fable 5.1 from Anthropic and Amazon Bedrock in one failover pool, open to one group and capped by quota.
Read moreProvider
Anthropic
The Claude API behind the Model Broker: the key held in Dome, every call authorized, metered and audited.
Read moreMCP server
GitHub
The GitHub MCP server behind the Tool Gateway, with rules that decide each call on its owner and repository.
Read moreIdentity
Microsoft Entra ID
Entra access tokens verified on every agent call, so rules read app roles and audit names the person.
Read moreRuntime
LangGraph
LangGraph agents with their model calls on the Model Broker and their MCP tools on the Tool Gateway.
Read moreClient
Claude Code
Claude Code on a Dome Gateway with per-developer sign-in, rules on every tool call, and audit by name.
Read moreNext steps
Talk with our FDE team
Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.
No card required to start. Register your first agent in minutes.
Agent services: web, research, payments, voice and sandboxes
Web actions, research, payments, phone calls and code execution are where agents reach past your walls. Put each service behind the Gateway, and every call is authorized, metered and audited.
See them all