Dome Systems

Linkup MCP server and Dome

Give agents the web. Keep your project names off it.

Linkup's remote MCP server searches the web, fetches pages and runs long research jobs. A fetch is where an agent picks its own sources. Put Linkup behind Dome, and a rule holds every fetch to the sources you trust, such as sec.gov and eur-lex.

AnalystsAgentsDomeLinkupCallersAnalystsAgentspolicy-analystAgentsnews-brieferAgentsdeal-scoutGatewaysresearch-gatewaysec.gov and eur-lexFetch allowedAny other siteSearch onlyModel poolAny providerRulesGuardsAuditsaudit-trail
news-briefer→linkup/linkup-search· scheduledAllowed

How Dome helps

Dome provides a governed gateway for Linkup

Sources you trust, and no others

A rule reads the url of linkup-fetch. A regulation on eur-lex comes back. A paste site is refused.

Research jobs off by default

linkup-research and linkup-get-research stay closed. Open them for the one agent that needs a long-running job.

Search without the codename

A forbid refuses any search that names Project Halcyon, so Linkup never receives it. A guard catches personal data in any argument.

Get started

Linkup behind the Gateway in four steps

Add Linkup's server, sync its four tools, guard outbound arguments, then deploy the source list.

  1. 01

    Add the Linkup MCP server

    Every agent shares one Linkup API key, held by Dome and sent as a Bearer token.

    $ dome tools add --name linkup \
    --url https://mcp.linkup.so/mcp \
    --auth-method api-key \
    --credential-type shared \
    --authorization "Bearer $LINKUP_API_KEY" \
    --gateway prod-gateway
  2. 02

    Sync the catalog

    Sync lists linkup-search, linkup-fetch, linkup-research and linkup-get-research. Calls fail until the catalog has them.

    $ dome tools catalog sync linkup
  3. 03

    Block personal data in arguments

    Request filters see each argument before Linkup does. A match ends the call there.

    $ cat > query-leak.json <<'EOF'
    $ {"json":{"components":[{"fieldActions":[{
    "matcher":{"contentMatchers":[{"ssn":{}},{"creditCard":{"requireLuhn":true}},{"email":{}}]},
    "action":"FILTER_ACTION_BLOCK"}]}]}}
    $ EOF
    $ dome guards filters create query-leak --config-from query-leak.json
    $ dome tools guards filters set linkup --direction request --filters query-leak
  4. 04

    Apply the rules

    The source list is scoped to policy-analyst. Simulate a fetch from each source, then deploy.

    $ dome rules apply linkup-sources.cedar --agent policy-analyst --name linkup-sources

Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Linkup itself, see Linkup's documentation.

Rules

Search anything, fetch from two sources

The permit opens search and fetch. Forbids close the research tools, refuse any search that names Project Halcyon and refuse a fetch outside sec.gov and eur-lex.

permit (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when {
resource.connection_name == "linkup" &&
["linkup-search", "linkup-fetch"].contains(resource.tool_name)
};
 
forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when {
resource.connection_name == "linkup" &&
!["linkup-search", "linkup-fetch"].contains(resource.tool_name)
};
 
forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when {
resource.connection_name == "linkup" &&
resource.tool_name == "linkup-search" &&
resource has arguments &&
resource.arguments has query &&
resource.arguments.query like "*Halcyon*"
};
 
forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when {
resource.connection_name == "linkup" &&
resource.tool_name == "linkup-fetch" &&
!(resource has arguments &&
resource.arguments has url &&
(resource.arguments.url like "https://www.sec.gov/*" ||
resource.arguments.url like "https://eur-lex.europa.eu/*"))
};

Try it

One call, two outcomes

Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.

Source

agent policy-analyst · acting as a.novak
linkup/linkup-fetch(url: "https://eur-lex.europa.eu/eli/reg/2024/1689/oj")
  1. Agentpolicy-analyst is registered and active
  2. Callera.novak verified through Okta
  3. RuleFetches from eur-lex.europa.eu are allowed
DecisionAllowed

Example agents

Three agents on Linkup

Each one searches the open web. Only one fetches pages, and only from the sources it's given.

policy-analyst

Read the regulation

Fetches the text of EU and SEC rules and drafts summaries for counsel. Any other source is refused.

  • linkup/linkup-search
  • linkup/linkup-fetch

news-briefer

Brief the team each morning

Searches the news for named accounts and writes a short brief before the day starts.

  • linkup/linkup-search

deal-scout

Scout acquisition targets

Looks for companies that fit a thesis by sector, size and region. A search that names the deal is refused at the Gateway.

  • linkup/linkup-search

Agent workflow

Bringing it together

Connecting Linkup to registered agents, models, and identity in Dome completes a governed agent application.

Dome

Control point

Gateway

  • Rules
  • Guards
  • Quotas

Every call decided and audited

Tools

Agent service

Linkup

This page

FAQ

Common questions

Does Linkup have a remote MCP server?

Yes. It runs at mcp.linkup.so/mcp, and Dome adds it with your Linkup API key.

Can I keep a Linkup agent to approved sources?

Yes. The rule reads the url of every linkup-fetch. Pages on sec.gov and eur-lex come back, and anything else is refused.

Can I keep internal project names out of Linkup searches?

Yes. A forbid on the query argument refuses a search that names the project. Linkup never receives the query.

Next steps

Talk with our FDE team

Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.