Dome Systems

Linear MCP server and Dome

Let agents file issues. Decide which teams they land in.

Linear is where agents file the work they find. Connect its MCP server to Dome once, and every issue an agent saves is checked against the team it names, with the Linear login of the person it acts for.

EngineersAgentsDomeLinearCallersEngineersAgentssupport-triagerAgentsbug-deduperAgentschangelog-writerGatewayseng-gatewaySupportTeamPlatformRead onlyModel poolAny providerRulesGuardsAuditsaudit-trail
bug-deduper→linear/list_issues· as r.haddadAllowed

How Dome helps

Dome provides a tool gateway and authorization for Linear

Decided on the team

One tool, allowed in one team and refused in another. Rules read the team of every issue an agent saves.

Their login, their workspace

An engineer authorizes Linear the first time an agent calls it for them. From then on the agent sees the teams that engineer sees.

Comments added, never deleted

Rules name the tool. An agent can comment on any issue while delete_comment is refused.

Get started

Linear behind the Gateway in three steps

Add Linear's server by URL, sync its tools once you've signed in, then scope the team rules to one agent. Dome brings its own OAuth client.

  1. 01

    Add the Linear MCP server

    Credentials are per user, through OAuth. Each engineer consents on their first call.

    $ dome tools add --name linear \
    --url https://mcp.linear.app/mcp \
    --auth-method oauth --credential-type per-user \
    --oauth-authorize-url https://mcp.linear.app/authorize \
    --oauth-token-url https://mcp.linear.app/token \
    --oauth-registration-url https://mcp.linear.app/register \
    --oauth-default-scope read --oauth-default-scope write \
    --gateway eng-gateway
  2. 02

    Sync the catalog

    The sync calls Linear as you, so finish your own sign-in first. Skip it and agents get “tool not available in this gateway”.

    $ dome tools catalog sync linear
  3. 03

    Apply the rules

    Try the Support rule on one agent with --agent, and simulate a save_issue for another team before you deploy.

    $ dome rules apply linear-args.cedar \
    --agent support-triager --name linear-per-team

Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Linear itself, see Linear's documentation.

Rules

Support team only

The permit gives the agent Linear. One forbid refuses a save_issue for any team but Support, and refuses a team given by ID. The other refuses delete_comment.

permit (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when { resource.connection_name == "linear" };
 
forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when {
resource.connection_name == "linear" &&
resource.tool_name == "save_issue" &&
resource has arguments && resource.arguments has team &&
resource.arguments.team != "Support"
};
 
forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when {
resource.connection_name == "linear" &&
resource.tool_name == "delete_comment"
};

Try it

One call, two outcomes

Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.

Team

agent support-triager · acting as r.haddad
linear/save_issue(team: "Support", title: "SSO login loops for Okta users")
  1. Agentsupport-triager is registered and active
  2. Callerr.haddad verified through Okta
  3. RuleIssues in Support are allowed
DecisionAllowed

Example agents

Three agents on Linear

From our template library. Each one reads broadly and writes narrowly.

support-triager

File support issues

Turns support conversations into Support team issues, with priority and labels set. Moving one to another team is refused.

  • linear/list_issues
  • linear/get_issue
  • linear/save_issue

bug-deduper

Flag duplicate bugs

Searches every team for duplicates of each new bug and comments with the likely match. Closing stays with an engineer.

  • linear/list_issues
  • linear/get_issue
  • linear/save_comment

changelog-writer

Draft the changelog

Reads the issues completed this cycle and drafts the changelog as a Linear document.

  • linear/list_cycles
  • linear/list_issues
  • linear/save_document

Agent workflow

Bringing it together

Connecting Linear to registered agents, models, and clients in Dome completes a governed agent application.

Dome

Control point

Gateway

  • Rules
  • Guards
  • Quotas

Every call decided and audited

Tools

MCP server

Linear

This page

MCP server

GitHub

See how

FAQ

Common questions

Does Dome work with Linear's remote MCP server?

Yes. Add mcp.linear.app by URL with OAuth. Dome registers its own client, and each engineer authorizes on their first call.

Can I limit which Linear teams an agent files issues in?

Yes. Rules read the team argument of save_issue, so the same tool is allowed in one team and refused in another.

Can an agent comment on issues without deleting comments?

Yes. Rules name the tool, so save_comment is allowed while delete_comment is refused.

Whose Linear permissions does an agent use?

Those of the person it acts for. Each engineer's Linear token is held in Dome and chosen by their verified identity, so an agent never reaches a team they can't.

Next steps

Talk with our FDE team

Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.