Linear MCP server and Dome
Let agents file issues. Decide which teams they land in.
Linear is where agents file the work they find. Connect its MCP server to Dome once, and every issue an agent saves is checked against the team it names, with the Linear login of the person it acts for.
How Dome helps
Dome provides a tool gateway and authorization for Linear
Decided on the team
One tool, allowed in one team and refused in another. Rules read the team of every issue an agent saves.
Their login, their workspace
An engineer authorizes Linear the first time an agent calls it for them. From then on the agent sees the teams that engineer sees.
Comments added, never deleted
Rules name the tool. An agent can comment on any issue while delete_comment is refused.
Get started
Linear behind the Gateway in three steps
Add Linear's server by URL, sync its tools once you've signed in, then scope the team rules to one agent. Dome brings its own OAuth client.
01
Add the Linear MCP server
Credentials are per user, through OAuth. Each engineer consents on their first call.
$ dome tools add --name linear \--url https://mcp.linear.app/mcp \--auth-method oauth --credential-type per-user \--oauth-authorize-url https://mcp.linear.app/authorize \--oauth-token-url https://mcp.linear.app/token \--oauth-registration-url https://mcp.linear.app/register \--oauth-default-scope read --oauth-default-scope write \--gateway eng-gateway02
Sync the catalog
The sync calls Linear as you, so finish your own sign-in first. Skip it and agents get “tool not available in this gateway”.
$ dome tools catalog sync linear03
Apply the rules
Try the Support rule on one agent with --agent, and simulate a save_issue for another team before you deploy.
$ dome rules apply linear-args.cedar \--agent support-triager --name linear-per-team
Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Linear itself, see Linear's documentation.
Rules
Support team only
The permit gives the agent Linear. One forbid refuses a save_issue for any team but Support, and refuses a team given by ID. The other refuses delete_comment.
permit (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "linear" }; forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "linear" && resource.tool_name == "save_issue" && resource has arguments && resource.arguments has team && resource.arguments.team != "Support"}; forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "linear" && resource.tool_name == "delete_comment"};Try it
One call, two outcomes
Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.
Team
- Agentsupport-triager is registered and active
- Callerr.haddad verified through Okta
- RuleIssues in Support are allowed
Example agents
Three agents on Linear
From our template library. Each one reads broadly and writes narrowly.
support-triager
File support issues
Turns support conversations into Support team issues, with priority and labels set. Moving one to another team is refused.
- linear/list_issues
- linear/get_issue
- linear/save_issue
bug-deduper
Flag duplicate bugs
Searches every team for duplicates of each new bug and comments with the likely match. Closing stays with an engineer.
- linear/list_issues
- linear/get_issue
- linear/save_comment
changelog-writer
Draft the changelog
Reads the issues completed this cycle and drafts the changelog as a Linear document.
- linear/list_cycles
- linear/list_issues
- linear/save_document
Agent workflow
Bringing it together
Connecting Linear to registered agents, models, and clients in Dome completes a governed agent application.
Acting for
Control point
Gateway
- Rules
- Guards
- Quotas
Every call decided and audited
Tools
MCP server
Linear
This page
MCP server
GitHub
See how
Models
FAQ
Common questions
Does Dome work with Linear's remote MCP server?
Yes. Add mcp.linear.app by URL with OAuth. Dome registers its own client, and each engineer authorizes on their first call.
Can I limit which Linear teams an agent files issues in?
Yes. Rules read the team argument of save_issue, so the same tool is allowed in one team and refused in another.
Can an agent comment on issues without deleting comments?
Yes. Rules name the tool, so save_comment is allowed while delete_comment is refused.
Whose Linear permissions does an agent use?
Those of the person it acts for. Each engineer's Linear token is held in Dome and chosen by their verified identity, so an agent never reaches a team they can't.
Explore
More of what Dome works with
Model
Claude Fable
Fable 5.1 from Anthropic and Amazon Bedrock in one failover pool, open to one group and capped by quota.
Read moreProvider
Anthropic
The Claude API behind the Model Broker: the key held in Dome, every call authorized, metered and audited.
Read moreIdentity
Okta
Okta tokens verified on every agent call, so rules and audit name the person each agent acted for.
Read moreRuntime
LangGraph
LangGraph agents with their model calls on the Model Broker and their MCP tools on the Tool Gateway.
Read moreClient
Codex
Codex on a Dome Gateway with per-developer sign-in, rules on every tool call, and audit by name.
Read moreAgent service
TinyFish
TinyFish's web agents behind the Tool Gateway, with rules that decide each run on the site it targets.
Read moreNext steps
Talk with our FDE team
Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.
No card required to start. Register your first agent in minutes.
MCP servers for AI agents: per-argument rules on every call
Put any remote MCP server behind the Tool Gateway. Agents reach it through one governed endpoint, and rules decide each call on its arguments.
See them all