Vapi MCP server and Dome
Your agents place real phone calls. Decide who they reach.
Vapi's MCP server lets an agent place outbound calls through a Vapi assistant. Connect it to Dome once, and rules decide each call on the number it dials and the assistant that speaks. Every call an agent places lands in one audit trail.
How Dome helps
Dome provides a governed gateway for Vapi
US and Canadian numbers
Rules read customer.number on each create_call. Anything outside +1 is refused at the Gateway.
Assistants on a list
Rules read the assistant on every call, so only the assistants you've approved speak. Agents can't create or edit an assistant's script.
A ceiling on calls
Two hundred tool calls a day per agent. The one after that is refused.
Get started
Vapi behind the Gateway in four steps
Add Vapi's server, sync it, deploy the assistant and number rules, then set each agent's ceiling.
01
Add the Vapi MCP server
Every agent shares one Vapi API key. Dome holds it and sends it as a Bearer token.
$ dome tools add --name vapi \--url https://mcp.vapi.ai/mcp \--auth-method api-key \--credential-type shared \--authorization "Bearer $VAPI_API_KEY" \--gateway voice-gateway02
Sync the catalog
Vapi won't list its tools for a bad key, so sync with the real one.
$ dome tools catalog sync vapi03
Apply the rules
The rules are scoped to renewal-caller. Simulate a call to a number outside +1, then deploy.
$ dome rules apply vapi-calls.cedar \--agent renewal-caller --name vapi-calls04
Cap the agent's calls
Two hundred a day for renewal-caller, counting every Vapi tool it calls.
$ dome quotas set --subject agent --agent renewal-caller \--dimension tool --unit calls --limit 200 --window daily
Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Vapi itself, see Vapi's documentation.
Rules
Two assistants, North American numbers
The permit opens Vapi to the agent. The first forbid closes the tools that write assistants. The second refuses any call unless a listed assistant dials a +1 number.
permit (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "vapi" }; forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "vapi" && ["create_assistant", "update_assistant", "create_tool", "update_tool"].contains(resource.tool_name)}; forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "vapi" && resource.tool_name == "create_call"}unless { resource has arguments && resource.arguments has assistantId && resource.arguments has customer && resource.arguments.customer has number && ["asst-renewal-reminder", "asst-appointment-confirm"].contains(resource.arguments.assistantId) && resource.arguments.customer.number like "+1*"};Try it
One call, two outcomes
Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.
Number
- Agentrenewal-caller is registered and active
- Assistantasst-renewal-reminder is on the list
- Rule+1 numbers are allowed
Example agents
Three agents on Vapi
Two place calls, each through its own assistant. One only reads what happened.
renewal-caller
Remind customers to renew
Calls customers in the US and Canada before a contract lapses, through the renewal assistant. Any other number is refused.
- vapi/create_call
- vapi/get_call
appointment-confirmer
Confirm appointments by phone
Calls each patient booked for the next day through the confirmation assistant and records the answer.
- vapi/create_call
- vapi/list_calls
call-reviewer
Review yesterday's calls
Reads call records and flags any that ended early for a team lead. It places no calls.
- vapi/list_calls
- vapi/get_call
- vapi/list_assistants
Agent workflow
Bringing it together
Connecting Vapi to registered agents, tools, and models in Dome completes a governed agent application.
Acting for
Control point
Gateway
- Rules
- Guards
- Quotas
Every call decided and audited
Tools
Agent service
Vapi
This page
MCP server
HubSpot
See how
Models
FAQ
Common questions
Does Vapi have a remote MCP server?
Yes, at mcp.vapi.ai/mcp. Dome adds it by URL and authenticates with your Vapi API key.
Can I restrict which phone numbers an AI agent calls?
Yes. The rule reads customer.number on every create_call and refuses any number outside +1.
Can an agent change what a Vapi assistant says?
Not if you forbid create_assistant and update_assistant. The agent then calls only through assistants you've approved.
Can I cap how many calls an agent places?
Yes. A quota on the agent counts its Vapi tool calls each day. Past two hundred, calls are refused until the window resets.
Explore
More of what Dome works with
Model
Claude Fable
Fable 5.1 from Anthropic and Amazon Bedrock in one failover pool, open to one group and capped by quota.
Read moreProvider
Anthropic
The Claude API behind the Model Broker: the key held in Dome, every call authorized, metered and audited.
Read moreMCP server
GitHub
The GitHub MCP server behind the Tool Gateway, with rules that decide each call on its owner and repository.
Read moreIdentity
Okta
Okta tokens verified on every agent call, so rules and audit name the person each agent acted for.
Read moreRuntime
OpenAI Agents SDK
OpenAI Agents SDK agents with their models on the Model Broker and their MCP tools on the Tool Gateway.
Read moreClient
Claude Code
Claude Code on a Dome Gateway with per-developer sign-in, rules on every tool call, and audit by name.
Read moreNext steps
Talk with our FDE team
Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.
No card required to start. Register your first agent in minutes.
Agent services: web, research, payments, voice and sandboxes
Web actions, research, payments, phone calls and code execution are where agents reach past your walls. Put each service behind the Gateway, and every call is authorized, metered and audited.
See them all