Dome Systems

Tavily MCP server and Dome

Search the web without telling it what you're working on.

Tavily's remote MCP server searches, extracts, maps and crawls. The crawl is the one to watch: one call, and an agent walks a whole site. Put Tavily behind Dome, and a rule decides where each crawl may start while guards read every query on its way out.

AnalystsAgentsDomeTavilyCallersAnalystsAgentsfilings-readerAgentscompetitor-monitorAgentsdeal-scoutGatewaysresearch-gatewaywww.sec.govCrawl allowedAny other siteSearch onlyModel poolAny providerRulesGuardsAuditsaudit-trail
competitor-monitor→tavily/tavily_search· scheduledAllowed

How Dome helps

Dome provides a governed gateway for Tavily

Crawls start where you say

A rule reads the url of tavily_crawl. A crawl that starts on sec.gov runs, and one that starts anywhere else never reaches Tavily.

Map and research stay shut

tavily_map and tavily_research are closed until you open them. Search, extract and one crawl cover the daily work.

Codenames kept out of queries

A forbid refuses any search that names Project Halcyon. A guard reads every argument, each URL in a list included, for personal data.

Get started

Tavily behind the Gateway in four steps

Add Tavily's server, sync its five tools, guard outbound arguments, then deploy the crawl rule.

  1. 01

    Add the Tavily MCP server

    Dome keeps the Tavily API key and presents it as a Bearer token. No agent holds a copy.

    $ dome tools add --name tavily \
    --url https://mcp.tavily.com/mcp/ \
    --auth-method api-key \
    --credential-type shared \
    --authorization "Bearer $TAVILY_API_KEY" \
    --gateway prod-gateway
  2. 02

    Sync the catalog

    Sync lists tavily_search, tavily_extract, tavily_crawl, tavily_map and tavily_research. Agents can call none of them before it runs.

    $ dome tools catalog sync tavily
  3. 03

    Block personal data in arguments

    The filter runs on requests and reads inside lists of URLs. A match stops the call at the Gateway.

    $ cat > query-leak.json <<'EOF'
    $ {"json":{"components":[{"fieldActions":[{
    "matcher":{"contentMatchers":[{"ssn":{}},{"creditCard":{"requireLuhn":true}},{"email":{}}]},
    "action":"FILTER_ACTION_BLOCK"}]}]}}
    $ EOF
    $ dome guards filters create query-leak --config-from query-leak.json
    $ dome tools guards filters set tavily --direction request --filters query-leak
  4. 04

    Apply the rules

    The crawl rule is scoped to filings-reader. Simulate a crawl on and off sec.gov, then deploy.

    $ dome rules apply tavily-research.cedar --agent filings-reader --name tavily-research

Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Tavily itself, see Tavily's documentation.

Rules

Search anywhere, crawl one site

The permit opens search, extract and crawl. Forbids close map and research, refuse any search that names Project Halcyon and refuse a crawl that starts anywhere but sec.gov.

permit (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when {
resource.connection_name == "tavily" &&
["tavily_search", "tavily_extract", "tavily_crawl"].contains(resource.tool_name)
};
 
forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when {
resource.connection_name == "tavily" &&
!["tavily_search", "tavily_extract", "tavily_crawl"].contains(resource.tool_name)
};
 
forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when {
resource.connection_name == "tavily" &&
resource.tool_name == "tavily_search" &&
resource has arguments &&
resource.arguments has query &&
resource.arguments.query like "*Halcyon*"
};
 
forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when {
resource.connection_name == "tavily" &&
resource.tool_name == "tavily_crawl" &&
!(resource has arguments &&
resource.arguments has url &&
resource.arguments.url like "https://www.sec.gov/*")
};

Try it

One call, two outcomes

Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.

Site

agent filings-reader · acting as s.patel
tavily/tavily_crawl(url: "https://www.sec.gov/cgi-bin/browse-edgar?action=getcompany&CIK=0000320193", max_depth: 1)
  1. Agentfilings-reader is registered and active
  2. Callers.patel verified through Okta
  3. RuleCrawls on www.sec.gov are allowed
DecisionAllowed

Example agents

Three agents on Tavily

Each one searches broadly. Only one crawls, and only the site it's given.

filings-reader

Read public filings

Crawls a company's filings on sec.gov and extracts the sections an analyst asks for. Any other crawl is refused.

  • tavily/tavily_crawl
  • tavily/tavily_extract

competitor-monitor

Watch competitors

Searches for competitor news and pricing changes each morning and reads the pages it finds.

  • tavily/tavily_search
  • tavily/tavily_extract

deal-scout

Scout acquisition targets

Searches for companies that match a thesis by sector and size. The deal's codename never makes it into a query.

  • tavily/tavily_search

Agent workflow

Bringing it together

Connecting Tavily to registered agents, models, and identity in Dome completes a governed agent application.

Dome

Control point

Gateway

  • Rules
  • Guards
  • Quotas

Every call decided and audited

Tools

Agent service

Tavily

This page

FAQ

Common questions

Does Tavily have a remote MCP server?

Yes, at mcp.tavily.com/mcp. Dome connects to it by URL and authenticates with your Tavily API key.

Can I limit which sites an agent crawls with Tavily?

Yes. The rule reads the url argument of tavily_crawl. List the sites a crawl may start on, and every other start is refused.

Can I turn off Tavily's map and research tools?

Yes. The rule above forbids tavily_map and tavily_research. An agent that calls either is refused at the Gateway.

Next steps

Talk with our FDE team

Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.