How to set approved domains in Parallel source_policy with include_domains
This skill shows how to restrict Parallel.ai web search to an approved domain list using the source_policy feature (include_domains). It covers the Search API (advanced_settings.source_policy), the Search MCP connection overrides (URL query parameters or config header), and the Task API, plus the rules that exclude_domains is ignored when include_domains is set, apex domains cover subdomains, and domain/path prefixes need fast, basic, or advanced mode (not turbo).
TL;DR
Restrict Parallel web search to an approved domain list by setting source_policy.include_domains to your allowlist. Only matching sources are returned. On the Search API, nest it under advanced_settings.source_policy; on the Search MCP, pin it as a connection-level override (URL query parameter or config header). Leave exclude_domains out of the same request: it is silently ignored whenever include_domains is non-empty.
Search: parallel search source policy approved domainsSearch API
curl https://api.parallel.ai/v1/search \
-H "Content-Type: application/json" \
-H "x-api-key value $PARALLEL_API_KEY" \
-d '{
"objective": "What did the Parallel changelog announce this month?",
"search_queries": ["Parallel changelog October"],
"advanced_settings": {
"source_policy": {
"include_domains": ["parallel.ai", "docs.parallel.ai"]
}
}
}'Expected output: every returned result's URL lives on parallel.ai or docs.parallel.ai (an apex entry like parallel.ai automatically covers its subdomains).
Task API
Put source_policy at the top level of the task request:
curl -X POST "https://api.parallel.ai/v1/tasks/runs" \
-H "x-api-key value $PARALLEL_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"input": "Summarize the Parallel changelog this month",
"processor": "core",
"source_policy": {
"include_domains": ["parallel.ai"]
}
}'Search MCP (connection override)
Authenticated MCP connections can pin the same policy so it applies to every web_search on the connection. Append list fields to the server URL, comma-separated or repeated:
https://search.parallel.ai/mcp?advanced_settings.source_policy.include_domains=parallel.ai,docs.parallel.aiOr send a config header (useful for larger nested configs) matching the Search API request shape:
{
"advanced_settings": {
"source_policy": {
"include_domains": ["parallel.ai", "docs.parallel.ai"]
}
}
}Expected output: the MCP handshake succeeds (a 400 at connect time means a bad field, bad mode, or malformed header JSON), and every web_search call returns only the allowed domains.
Steps
- List your approved domains in apex form, one per entry:
parallel.aicoverswww.parallel.ai,docs.parallel.ai, and deeper subdomains. Never add schemes, ports, query strings, or fragments. - On the Search API, set
advanced_settings.source_policy.include_domains. On the Task API, set top-levelsource_policy.include_domains. - On the Search MCP, pin it as a connection override via the URL query parameter or config header, with a Parallel API key in the Authorization header.
- Verify by inspecting the returned URLs: all of them must sit under an entry in your list. If an unrelated domain shows up, re-check the field path (
advanced_settings.source_policy, not a top-level field on the Search API) and your spelling.
When to use
- You want Parallel web search or a research task to draw only from an approved list of domains.
- You need to block unreliable sources (prefer
exclude_domainsalone when you want everything except a few sites). - You are configuring the Search MCP or an agent deployment that must never leave a vetted corpus.
When NOT to use
- You want a soft preference ("prefer official docs over blogs"): put that in the objective instead; a hard allowlist excludes everything else.
- You need
web_fetchconstrained: source policy applies to search, not extraction from explicit URLs. - Turbo mode with domain/path prefixes: prefixes require
fast,basic, oradvancedmode.
Compatibility
Parallel Search API /v1/search, Task API /v1/tasks/runs, Monitor API, Responses API (via the OpenAI web_search tool: filters.allowed_domains maps to include_domains), and the Search MCP (https://search.parallel.ai/mcp). Documented at docs.parallel.ai/resources/source-policy.
Variant: allowlisting domains in Parallel search
"Parallel search allowlist domains" and "Parallel sourcepolicy approved domains" are the same feature: the `includedomains allowlist. include_domains` is a hard filter, nothing outside it is searched.
Variant: domain denylist in Parallel search
To block sites instead of allowlisting, use exclude_domains alone: it is only honored when include_domains is empty, and a request containing both applies the allowlist only.
Variant: subdomain and path scoping
Scope to one section with a domain/path prefix such as docs.example.com/api. Paths are case-sensitive and match at segment boundaries, so example.com/blog matches /blog/post but not /blogroll. A leading-dot extension like .org matches that extension; *.org wildcard syntax is not supported.
Why it behaves this way
Source policy is a hard pre-search filter, not a ranking hint: the docs state only matching sources are returned for include_domains, which is why quality drops sharply if relevant pages live outside the list. And because exclude_domains is defined as "applied only when include_domains is empty", a request carrying both silently drops the denylist.
Edge cases
include_domainsandexclude_domainstogether: the allowlist wins, the denylist is ignored with no error. Pick one per request.- Entry format: apex domains, subdomain prefixes (
docs.example.com), domain/path prefixes, or leading-dot extensions. No schemes, ports, query strings, or fragments; a leadingwww.is normalized away. - Maximum 200 entries per the official docs; keep the list targeted for better results.
- Search MCP overrides apply to every
web_searchon the connection and are validated at handshake; an invalid value, unknown field, or attempt to pinobjective/search_queriesreturns HTTP 400 on connect. - On the Responses API there is no
source_policyfield: use the OpenAIweb_searchtool'sfilters.allowed_domains/filters.blocked_domainsinstead.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.