Dome Systems

Skyfire and Dome

Let agents pay for services. Decide who they pay, and how much.

Skyfire's MCP server issues the tokens an agent uses to identify itself to a seller and pay it. Connect it to Dome once, and rules decide each pay token on its seller and its amount. Every token an agent asks for lands in one audit trail.

AnalystsAgentsDomeSkyfireCallersAnalystsAgentsnews-brieferAgentsdata-buyerAgentsseller-scoutGatewaysdata-gatewayListed sellersAt set amountsAny other sellerRefusedModel poolAny providerRulesGuardsAuditsaudit-trail
seller-scout→skyfire/find-sellers· scheduledAllowed

How Dome helps

Dome provides a governed gateway for Skyfire

Sellers on a list

Rules read the seller service on every pay token. A seller you haven't listed is refused at the Gateway.

Amounts you set

Each listed seller gets the amounts you allow. A token for any other amount is refused before Skyfire issues it.

Calls capped per day

A quota caps the tool calls an agent makes in a day, pay tokens included. Quotas count calls, not dollars.

Get started

Skyfire behind the Gateway in four steps

Add the hosted MCP server, sync its tools, apply the rules, and set a quota. Agents reach Skyfire through the Gateway's single MCP endpoint.

  1. 01

    Add the Skyfire MCP server

    Skyfire reads its key from a skyfire-api-key header. Dome stores the key once and sends it in that header on every call.

    $ dome tools add --name skyfire \
    --url https://mcp.skyfire.xyz/mcp \
    --auth-method api-key \
    --credential-type shared \
    --authorization "$SKYFIRE_API_KEY" \
    --header-secret skyfire-api-key=Authorization \
    --gateway data-gateway
  2. 02

    Sync the catalog

    Sync needs a valid key. Until it runs, agents get “tool not available in this gateway”.

    $ dome tools catalog sync skyfire
  3. 03

    Apply the rules

    Scope them to one agent while you try them. Simulate before you deploy.

    $ dome rules apply skyfire-payments.cedar \
    --agent data-buyer --name skyfire-payments
  4. 04

    Cap the agent's calls

    Fifty tool calls a day, across every tool the agent reaches.

    $ dome quotas set --subject agent --agent data-buyer \
    --dimension tool --unit calls --limit 50 --window daily

Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Skyfire itself, see Skyfire's documentation.

Rules

Two sellers, at set amounts

The permit opens Skyfire to the agent. The forbid refuses any pay token, with or without identity, unless it names a listed seller at one of that seller's amounts.

permit (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when { resource.connection_name == "skyfire" };
 
forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when {
resource.connection_name == "skyfire" &&
["create-pay-token", "create-kya-payment-token"].contains(resource.tool_name)
}
unless {
resource has arguments &&
resource.arguments has sellerServiceId &&
resource.arguments has amount &&
// Dappier Search
((resource.arguments.sellerServiceId == "81085b79-68d8-4a46-9f8c-63c11a969828" &&
["0.50", "1.00"].contains(resource.arguments.amount)) ||
// Your Apify seller service
(resource.arguments.sellerServiceId == "<apify-service-id>" &&
resource.arguments.amount == "5.00"))
};

Try it

One call, two outcomes

Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.

Amount

agent data-buyer · acting as m.osei
skyfire/create-pay-token(sellerServiceId: "81085b79-68d8-4a46-9f8c-63c11a969828", amount: "1.00")
  1. Agentdata-buyer is registered and active
  2. SellerDappier Search is on the list
  3. Rule1.00 is an allowed amount for this seller
DecisionAllowed

Example agents

Three agents on Skyfire

Each one pays narrowly or not at all. Finding sellers is open, and paying them is not.

news-briefer

Buy the morning's news

Pays Dappier for real-time search each morning and writes a briefing for the desk. Only the two listed amounts go through.

  • skyfire/create-pay-token
  • skyfire/find-sellers

data-buyer

Pay for scraping runs

Buys a pay token for an Apify run when a research task needs fresh data. Any other seller is refused.

  • skyfire/create-pay-token
  • skyfire/create-kya-token

seller-scout

Find new data sources

Searches Skyfire's sellers and drafts a shortlist for an analyst to review. It never pays.

  • skyfire/find-sellers

Agent workflow

Bringing it together

Connecting Skyfire to registered agents, tools, and models in Dome completes a governed agent application.

Dome

Control point

Gateway

  • Rules
  • Guards
  • Quotas

Every call decided and audited

Tools

Agent service

Skyfire

This page

Agent service

Apify

See how

FAQ

Common questions

Does Skyfire have an MCP server?

Yes. Skyfire hosts one at mcp.skyfire.xyz/mcp, and Dome adds it by URL and sends your key in the skyfire-api-key header.

Can I limit how much an AI agent pays through Skyfire?

Yes. Rules read the seller and the amount of every pay token, so only the amounts you list for each seller go through.

Can Dome cap an agent's total Skyfire spend?

Not in dollars. A quota caps the agent's tool calls per day, and with set amounts per seller that bounds what it can spend.

Can an agent find sellers without paying them?

Yes. find-sellers and create-kya-token stay open while the pay tools are ruled on.

Next steps

Talk with our FDE team

Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.