Notion MCP server and Dome
Let agents edit the wiki. Decide what they can overwrite.
One bad rewrite can wreck a wiki page. Connect Notion's hosted MCP server to Dome once, and each edit is checked on its page and its command, with the Notion access of the person the agent acts for.
How Dome helps
Dome provides a tool gateway and authorization for Notion
Edits, not rewrites
One tool, allowed for a targeted edit and refused for a full-page replace. Rules read the command of every update.
Their login, their pages
A teammate connects Notion the first time an agent works for them. The agent reaches the pages that teammate can, no further.
Protected pages
Rules read the page_id of every update. The handbook stays read-only to agents.
Get started
Notion behind the Gateway in three steps
Add Notion's server, sync its tools while signed in, then protect the pages that matter. Dome handles the OAuth client registration.
01
Add the Notion MCP server
Credentials are per user, through OAuth. Each teammate consents on their first call.
$ dome tools add --name notion \--url https://mcp.notion.com/mcp \--auth-method oauth --credential-type per-user \--oauth-authorize-url https://mcp.notion.com/authorize \--oauth-token-url https://mcp.notion.com/token \--oauth-registration-url https://mcp.notion.com/register \--gateway ops-gateway02
Sync the catalog
Notion's tool list is fetched with your login, so connect Notion yourself before you sync. Otherwise agents hit “tool not available in this gateway”.
$ dome tools catalog sync notion03
Apply the rules
Put the handbook's page_id in the rule, scope it to one agent, and simulate an update before you deploy.
$ dome rules apply notion-args.cedar \--agent wiki-gardener --name notion-per-page
Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Notion itself, see Notion's documentation.
Rules
Targeted edits, handbook untouched
With the permit in place, one forbid turns away replace_content on every page and the other turns away any update to the handbook.
permit (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "notion" }; forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "notion" && resource.tool_name == "notion-update-page" && resource has arguments && resource.arguments has command && resource.arguments.command == "replace_content"}; forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "notion" && resource.tool_name == "notion-update-page" && resource has arguments && resource.arguments has page_id && resource.arguments.page_id == "1c9e5d2a7b3f4e8a9d0c6b1a2e3f4d5c"};Try it
One call, two outcomes
Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.
Command
- Agentwiki-gardener is registered and active
- Callerp.novak verified through Google
- RuleTargeted edits to the wiki are allowed
Example agents
Three agents on Notion
From our template library. Each one reads broadly and writes narrowly.
meeting-notes-filer
File meeting decisions
Reads each meeting's notes and files the decisions as a page in the team wiki.
- notion/notion-query-meeting-notes
- notion/notion-fetch
- notion/notion-create-pages
wiki-gardener
Tend the wiki
Finds stale wiki pages and fixes them with targeted edits. Full-page rewrites and the handbook are refused.
- notion/notion-search
- notion/notion-fetch
- notion/notion-update-page
onboarding-guide
Answer new hires
Answers new hires from the handbook and comments where a page is out of date.
- notion/notion-search
- notion/notion-fetch
- notion/notion-create-comment
Agent workflow
Bringing it together
Connecting Notion to registered agents, models, and identity in Dome completes a governed agent application.
Acting for
Agent
Control point
Gateway
- Rules
- Guards
- Quotas
Every call decided and audited
Tools
MCP server
Notion
This page
Models
FAQ
Common questions
Does Dome work with Notion's hosted MCP server?
Yes. It's added by URL with OAuth. Dome registers a client of its own, and each teammate connects Notion on their first call.
Can an agent edit a Notion page without rewriting it?
Yes. Rules read the command argument of notion-update-page, so targeted edits pass and replace_content is refused.
Can I keep some Notion pages read-only to agents?
Yes. Rules read the page_id of every update, so a protected page refuses edits from any agent.
Whose Notion access does an agent use?
Their access, never more. Dome stores a Notion token per person and selects it by the caller's verified identity.
Explore
More of what Dome works with
Model
Claude Fable
Fable 5.1 from Anthropic and Amazon Bedrock in one failover pool, open to one group and capped by quota.
Read moreProvider
Anthropic
The Claude API behind the Model Broker: the key held in Dome, every call authorized, metered and audited.
Read moreIdentity
Okta
Okta tokens verified on every agent call, so rules and audit name the person each agent acted for.
Read moreRuntime
LangGraph
LangGraph agents with their model calls on the Model Broker and their MCP tools on the Tool Gateway.
Read moreClient
Claude Code
Claude Code on a Dome Gateway with per-developer sign-in, rules on every tool call, and audit by name.
Read moreAgent service
TinyFish
TinyFish's web agents behind the Tool Gateway, with rules that decide each run on the site it targets.
Read moreNext steps
Talk with our FDE team
Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.
No card required to start. Register your first agent in minutes.
MCP servers for AI agents: per-argument rules on every call
Put any remote MCP server behind the Tool Gateway. Agents reach it through one governed endpoint, and rules decide each call on its arguments.
See them all