Dome Systems

Retell AI MCP server and Dome

Agents that place phone calls, on numbers you allow.

Retell's MCP server gives an agent the whole Retell API through one tool. Connect it to Dome once, and rules decide each call on the endpoint it names and the number it dials. Every request lands in one audit trail.

PatientsAgentsDomeRetell AICallersPatientsAgentsappointment-confirmerAgentscall-analystAgentsintake-builderGatewaysvoice-gatewayOutbound calls+1 numbers, one agentCalls and agentsRead onlyModel poolAny providerRulesGuardsAuditsaudit-trail
appointment-confirmer→retell/invoke_api_endpoint· scheduledAllowed

How Dome helps

Dome provides a governed gateway for Retell AI

Endpoints on a list

Retell's MCP server reaches every endpoint through invoke_api_endpoint. Rules read the endpoint name, so batch calls and agent edits stay closed.

+1 numbers only

Every createPhoneCall carries a to_number. The rule refuses any that isn't a +1 number.

One voice agent, no overrides

Rules pin the Retell agent that speaks on each call. A call that rewrites the agent's configuration is refused.

Get started

Retell behind the Gateway in four steps

Add Retell's server, sync its three tools, deploy the endpoint list and cap each agent's calls.

  1. 01

    Add the Retell MCP server

    Dome holds the Retell API key and sends it as a Bearer token. Agents never see it.

    $ dome tools add --name retell \
    --url https://mcp.retellai.com \
    --auth-method api-key \
    --credential-type shared \
    --authorization "Bearer $RETELL_API_KEY" \
    --gateway voice-gateway
  2. 02

    Sync the catalog

    Sync lists Retell's three tools: list_api_endpoints, get_api_endpoint_schema, and invoke_api_endpoint.

    $ dome tools catalog sync retell
  3. 03

    Apply the rules

    The endpoint list is scoped to appointment-confirmer. Simulate a batch call to see it refused, then deploy.

    $ dome rules apply retell-calls.cedar \
    --agent appointment-confirmer --name retell-calls
  4. 04

    Cap the agent's calls

    A hundred calls a day for appointment-confirmer. Every tool call counts, reads included.

    $ dome quotas set --subject agent --agent appointment-confirmer \
    --dimension tool --unit calls --limit 100 --window daily

Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Retell AI itself, see Retell AI's documentation.

Rules

Read calls, place them on +1 numbers

The permit opens Retell to the agent. The forbid refuses any endpoint but four reads and createPhoneCall, and refuses a call unless it dials a +1 number through one Retell agent with no override.

permit (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when { resource.connection_name == "retell" };
 
forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when {
resource.connection_name == "retell" &&
resource.tool_name == "invoke_api_endpoint"
}
unless {
resource has arguments &&
resource.arguments has endpoint &&
(["listCalls", "getCall", "listAgents", "getAgent"].contains(resource.arguments.endpoint) ||
(resource.arguments.endpoint == "createPhoneCall" &&
resource.arguments has arguments &&
resource.arguments.arguments has requestBody &&
resource.arguments.arguments.requestBody has to_number &&
resource.arguments.arguments.requestBody has override_agent_id &&
resource.arguments.arguments.requestBody.to_number like "+1*" &&
resource.arguments.arguments.requestBody.override_agent_id == "agent_appointment_confirm" &&
!(resource.arguments.arguments.requestBody has agent_override)))
};

Try it

One call, two outcomes

Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.

Number

agent appointment-confirmer · scheduled
retell/invoke_api_endpoint(endpoint: "createPhoneCall", to_number: "+14155550123", override_agent_id: "agent_appointment_confirm")
  1. Agentappointment-confirmer is registered and active
  2. EndpointcreatePhoneCall is on the list
  3. Rule+1 numbers through agent_appointment_confirm
DecisionAllowed

Example agents

Three agents on Retell

One places calls, one reads them, and one builds. Each gets its own rules on the same three tools.

appointment-confirmer

Call patients about tomorrow

Calls each patient booked for the next day through one Retell agent. Any number outside +1 is refused.

  • retell/invoke_api_endpoint
  • retell/get_api_endpoint_schema

call-analyst

Summarize the week's calls

Lists and reads calls, then reports outcomes to the clinic manager. It reaches read endpoints only.

  • retell/invoke_api_endpoint
  • retell/list_api_endpoints

intake-builder

Draft new voice agents

Creates draft Retell agents for an engineer to test. It can't publish a version or place a call.

  • retell/invoke_api_endpoint
  • retell/get_api_endpoint_schema

Agent workflow

Bringing it together

Connecting Retell AI to registered agents, tools, and models in Dome completes a governed agent application.

Dome

Control point

Gateway

  • Rules
  • Guards
  • Quotas

Every call decided and audited

Tools

Agent service

Retell AI

This page

MCP server

Salesforce

See how

FAQ

Common questions

Does Retell AI have an MCP server?

Yes, at mcp.retellai.com. Dome connects by URL with your Retell API key.

How do rules work when one tool reaches the whole Retell API?

Rules read the endpoint argument of invoke_api_endpoint. Allow the endpoints an agent needs and the rest are refused.

Can a Retell agent dial international numbers?

Not under this rule. It reads to_number on each createPhoneCall and refuses anything outside +1.

Can an agent change what the Retell agent says on a call?

Not with this rule. It pins override_agent_id and refuses any call that carries an agent_override.

Next steps

Talk with our FDE team

Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.