MCP servers
MCP servers for AI agents
Put any remote MCP server behind the Tool Gateway. Agents reach it through one governed endpoint, and rules decide each call on its arguments.
MCP servers
MCP servers for AI agents
Any remote MCP server
Add it by URL, and rules decide each call on its arguments.
How it works
Any remote MCP server in three steps
Add the server by URL, sync its tools into the Gateway's catalog, and apply rules. GitHub is the example here.
01
Add the server
Its credential stays in Dome, shared or per user.
$ dome tools add --name github \--url https://api.githubcopilot.com/mcp/ \--auth-method api-key --credential-type per-user \--gateway eng-gateway02
Sync the catalog
Agents get “tool not available in this gateway” until the catalog is synced.
$ dome tools catalog sync github03
Decide on arguments
Rules read the tool's name and its arguments.
forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when {resource.connection_name == "github" &&resource.tool_name == "merge_pull_request" &&resource has arguments && resource.arguments has repo &&resource.arguments.repo == "payments"};
Commands tested against a Dome workspace on September 30, 2026.
FAQ
Common questions
Which MCP servers work with Dome?
Any remote MCP server. Add it by URL, attach its credential, and sync its tools.
Can a rule look at a tool call's arguments?
Yes. The same tool can be allowed with one argument and refused with another.
Do agents need a credential for each server?
No. Each agent holds one Dome key. Dome holds each server's credential and injects it on the call.
Next steps
Talk with our FDE team
Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.
No card required to start. Register your first agent in minutes.
MCP gateway guide
What an MCP gateway does, and what to ask of one before your agents depend on it.
Read the guide