TinyFish MCP server and Dome
Send agents to the open web. Decide which sites they work on.
TinyFish runs web automations from a URL and a goal in plain language. Connect its MCP server to Dome once, and rules decide each run on the site it targets. Every search, fetch and run lands in one audit trail.
How Dome helps
Dome provides a governed gateway for TinyFish
Sites decided per run
Rules read the URL of every automation run. A portal on your list runs, and any other site is refused.
Reading apart from acting
Search and fetch read pages. Automation runs click, log in and fill forms, so grant them only to the agents that need them.
Runs on the record
Every run_web_automation call is audited under the agent that made it, allowed or refused.
Get started
TinyFish behind the Gateway in three steps
Add TinyFish's server, sync it, then keep automation runs to the portals you list.
01
Add the TinyFish MCP server
Dome holds the TinyFish API key and sends it as a Bearer token on every call.
$ dome tools add --name tinyfish \--url https://agent.tinyfish.ai/mcp \--auth-method api-key \--credential-type shared \--authorization "Bearer $TINYFISH_API_KEY" \--gateway prod-gateway02
Sync the catalog
Sync needs a valid key. TinyFish won't list its tools without one.
$ dome tools catalog sync tinyfish03
Apply the rules
The portal list is scoped to supplier-portal-reader. Simulate a run on an unlisted site, then deploy.
$ dome rules apply tinyfish-permit.cedar tinyfish-sites.cedar \--agent supplier-portal-reader --name tinyfish-sites
Commands and rules tested against a Dome workspace on October 1, 2026. For anything about TinyFish itself, see TinyFish's documentation.
Rules
Automate two portals, read anything
The permit opens search, fetch and automation runs to the agent. The forbid refuses any run whose URL isn't on one of two supplier portals.
permit (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "tinyfish" && ["search", "fetch_content", "run_web_automation", "get_run"].contains(resource.tool_name)}; forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "tinyfish" && resource.tool_name == "run_web_automation" && !(resource has arguments && resource.arguments has url && (resource.arguments.url like "https://portal.northwind-supply.com/*" || resource.arguments.url like "https://b2b.harbor-parts.com/*"))};Try it
One call, two outcomes
Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.
Site
- Agentsupplier-portal-reader is registered and active
- Callerr.alvarez verified through Okta
- RuleRuns on portal.northwind-supply.com are allowed
Example agents
Three agents on TinyFish
Each one reads broadly and acts narrowly. Only one may run an automation, and only on the portals it's given.
price-monitor
Track competitor prices
Fetches competitor pricing pages each morning and flags changes for the pricing team. It reads pages and never clicks.
- tinyfish/search
- tinyfish/fetch_content
supplier-portal-reader
Read supplier portals
Logs in to two supplier portals and reads open orders and ship dates. Any other site is refused.
- tinyfish/run_web_automation
- tinyfish/get_run
- tinyfish/fetch_content
compliance-checker
Check vendors against the news
Searches recent news for each vendor under review and reads the sources it finds. Findings go to a compliance analyst.
- tinyfish/search
- tinyfish/fetch_content
Agent workflow
Bringing it together
Connecting TinyFish to registered agents, models, and identity in Dome completes a governed agent application.
Acting for
Control point
Gateway
- Rules
- Guards
- Quotas
Every call decided and audited
Tools
Agent service
TinyFish
This page
Models
FAQ
Common questions
Does TinyFish have an MCP server?
Yes. It runs at agent.tinyfish.ai/mcp, and Dome connects with your TinyFish API key.
Can I limit which websites an agent automates with TinyFish?
Yes. Rules read the URL argument of every automation run, so a run on a listed site is allowed and a run anywhere else is refused.
Can an agent read the web without automating it?
Yes. Allow search and fetch_content and leave run_web_automation out, and the agent reads pages without clicking or logging in.
Can a goal in plain language get around the rule?
No. The rule decides on the URL, not the goal. A run on an unlisted site is refused whatever it asks for.
Explore
More of what Dome works with
Model
Claude Fable
Fable 5.1 from Anthropic and Amazon Bedrock in one failover pool, open to one group and capped by quota.
Read moreProvider
Anthropic
The Claude API behind the Model Broker: the key held in Dome, every call authorized, metered and audited.
Read moreMCP server
GitHub
The GitHub MCP server behind the Tool Gateway, with rules that decide each call on its owner and repository.
Read moreIdentity
Microsoft Entra ID
Entra access tokens verified on every agent call, so rules read app roles and audit names the person.
Read moreRuntime
OpenAI Agents SDK
OpenAI Agents SDK agents with their models on the Model Broker and their MCP tools on the Tool Gateway.
Read moreClient
Claude Code
Claude Code on a Dome Gateway with per-developer sign-in, rules on every tool call, and audit by name.
Read moreNext steps
Talk with our FDE team
Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.
No card required to start. Register your first agent in minutes.
Agent services: web, research, payments, voice and sandboxes
Web actions, research, payments, phone calls and code execution are where agents reach past your walls. Put each service behind the Gateway, and every call is authorized, metered and audited.
See them all