Tavily MCP server and Dome
Search the web without telling it what you're working on.
Tavily's remote MCP server searches, extracts, maps and crawls. The crawl is the one to watch: one call, and an agent walks a whole site. Put Tavily behind Dome, and a rule decides where each crawl may start while guards read every query on its way out.
How Dome helps
Dome provides a governed gateway for Tavily
Crawls start where you say
A rule reads the url of tavily_crawl. A crawl that starts on sec.gov runs, and one that starts anywhere else never reaches Tavily.
Map and research stay shut
tavily_map and tavily_research are closed until you open them. Search, extract and one crawl cover the daily work.
Codenames kept out of queries
A forbid refuses any search that names Project Halcyon. A guard reads every argument, each URL in a list included, for personal data.
Get started
Tavily behind the Gateway in four steps
Add Tavily's server, sync its five tools, guard outbound arguments, then deploy the crawl rule.
01
Add the Tavily MCP server
Dome keeps the Tavily API key and presents it as a Bearer token. No agent holds a copy.
$ dome tools add --name tavily \--url https://mcp.tavily.com/mcp/ \--auth-method api-key \--credential-type shared \--authorization "Bearer $TAVILY_API_KEY" \--gateway prod-gateway02
Sync the catalog
Sync lists tavily_search, tavily_extract, tavily_crawl, tavily_map and tavily_research. Agents can call none of them before it runs.
$ dome tools catalog sync tavily03
Block personal data in arguments
The filter runs on requests and reads inside lists of URLs. A match stops the call at the Gateway.
$ cat > query-leak.json <<'EOF'$ {"json":{"components":[{"fieldActions":[{"matcher":{"contentMatchers":[{"ssn":{}},{"creditCard":{"requireLuhn":true}},{"email":{}}]},"action":"FILTER_ACTION_BLOCK"}]}]}}$ EOF$ dome guards filters create query-leak --config-from query-leak.json$ dome tools guards filters set tavily --direction request --filters query-leak04
Apply the rules
The crawl rule is scoped to filings-reader. Simulate a crawl on and off sec.gov, then deploy.
$ dome rules apply tavily-research.cedar --agent filings-reader --name tavily-research
Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Tavily itself, see Tavily's documentation.
Rules
Search anywhere, crawl one site
The permit opens search, extract and crawl. Forbids close map and research, refuse any search that names Project Halcyon and refuse a crawl that starts anywhere but sec.gov.
permit (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "tavily" && ["tavily_search", "tavily_extract", "tavily_crawl"].contains(resource.tool_name)}; forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "tavily" && !["tavily_search", "tavily_extract", "tavily_crawl"].contains(resource.tool_name)}; forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "tavily" && resource.tool_name == "tavily_search" && resource has arguments && resource.arguments has query && resource.arguments.query like "*Halcyon*"}; forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "tavily" && resource.tool_name == "tavily_crawl" && !(resource has arguments && resource.arguments has url && resource.arguments.url like "https://www.sec.gov/*")};Try it
One call, two outcomes
Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.
Site
- Agentfilings-reader is registered and active
- Callers.patel verified through Okta
- RuleCrawls on www.sec.gov are allowed
Example agents
Three agents on Tavily
Each one searches broadly. Only one crawls, and only the site it's given.
filings-reader
Read public filings
Crawls a company's filings on sec.gov and extracts the sections an analyst asks for. Any other crawl is refused.
- tavily/tavily_crawl
- tavily/tavily_extract
competitor-monitor
Watch competitors
Searches for competitor news and pricing changes each morning and reads the pages it finds.
- tavily/tavily_search
- tavily/tavily_extract
deal-scout
Scout acquisition targets
Searches for companies that match a thesis by sector and size. The deal's codename never makes it into a query.
- tavily/tavily_search
Agent workflow
Bringing it together
Connecting Tavily to registered agents, models, and identity in Dome completes a governed agent application.
Acting for
Control point
Gateway
- Rules
- Guards
- Quotas
Every call decided and audited
Tools
Agent service
Tavily
This page
FAQ
Common questions
Does Tavily have a remote MCP server?
Yes, at mcp.tavily.com/mcp. Dome connects to it by URL and authenticates with your Tavily API key.
Can I limit which sites an agent crawls with Tavily?
Yes. The rule reads the url argument of tavily_crawl. List the sites a crawl may start on, and every other start is refused.
Can I turn off Tavily's map and research tools?
Yes. The rule above forbids tavily_map and tavily_research. An agent that calls either is refused at the Gateway.
Explore
More of what Dome works with
Model
Claude Fable
Fable 5.1 from Anthropic and Amazon Bedrock in one failover pool, open to one group and capped by quota.
Read moreProvider
Anthropic
The Claude API behind the Model Broker: the key held in Dome, every call authorized, metered and audited.
Read moreMCP server
GitHub
The GitHub MCP server behind the Tool Gateway, with rules that decide each call on its owner and repository.
Read moreIdentity
Microsoft Entra ID
Entra access tokens verified on every agent call, so rules read app roles and audit names the person.
Read moreRuntime
OpenAI Agents SDK
OpenAI Agents SDK agents with their models on the Model Broker and their MCP tools on the Tool Gateway.
Read moreClient
Claude Code
Claude Code on a Dome Gateway with per-developer sign-in, rules on every tool call, and audit by name.
Read moreNext steps
Talk with our FDE team
Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.
No card required to start. Register your first agent in minutes.
Agent services: web, research, payments, voice and sandboxes
Web actions, research, payments, phone calls and code execution are where agents reach past your walls. Put each service behind the Gateway, and every call is authorized, metered and audited.
See them all