## TL;DR

Restrict Parallel web search to an approved domain list by setting `source_policy.include_domains` to your allowlist. Only matching sources are returned. On the Search API, nest it under `advanced_settings.source_policy`; on the Search MCP, pin it as a connection-level override (URL query parameter or config header). Leave `exclude_domains` out of the same request: it is silently ignored whenever `include_domains` is non-empty.

```text
Search: parallel search source policy approved domains
```

## Search API

```bash
curl https://api.parallel.ai/v1/search \
  -H "Content-Type: application/json" \
  -H "x-api-key value $PARALLEL_API_KEY" \
  -d '{
    "objective": "What did the Parallel changelog announce this month?",
    "search_queries": ["Parallel changelog October"],
    "advanced_settings": {
      "source_policy": {
        "include_domains": ["parallel.ai", "docs.parallel.ai"]
      }
    }
  }'
```

Expected output: every returned result's URL lives on `parallel.ai` or `docs.parallel.ai` (an apex entry like `parallel.ai` automatically covers its subdomains).

## Task API

Put `source_policy` at the top level of the task request:

```bash
curl -X POST "https://api.parallel.ai/v1/tasks/runs" \
  -H "x-api-key value $PARALLEL_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "input": "Summarize the Parallel changelog this month",
    "processor": "core",
    "source_policy": {
      "include_domains": ["parallel.ai"]
    }
  }'
```

## Search MCP (connection override)

Authenticated MCP connections can pin the same policy so it applies to every `web_search` on the connection. Append list fields to the server URL, comma-separated or repeated:

```
https://search.parallel.ai/mcp?advanced_settings.source_policy.include_domains=parallel.ai,docs.parallel.ai
```

Or send a config header (useful for larger nested configs) matching the Search API request shape:

```json
{
  "advanced_settings": {
    "source_policy": {
      "include_domains": ["parallel.ai", "docs.parallel.ai"]
    }
  }
}
```

Expected output: the MCP handshake succeeds (a 400 at connect time means a bad field, bad mode, or malformed header JSON), and every `web_search` call returns only the allowed domains.

## Steps

1. List your approved domains in apex form, one per entry: `parallel.ai` covers `www.parallel.ai`, `docs.parallel.ai`, and deeper subdomains. Never add schemes, ports, query strings, or fragments.
2. On the Search API, set `advanced_settings.source_policy.include_domains`. On the Task API, set top-level `source_policy.include_domains`.
3. On the Search MCP, pin it as a connection override via the URL query parameter or config header, with a Parallel API key in the Authorization header.
4. Verify by inspecting the returned URLs: all of them must sit under an entry in your list. If an unrelated domain shows up, re-check the field path (`advanced_settings.source_policy`, not a top-level field on the Search API) and your spelling.

## When to use

- You want Parallel web search or a research task to draw only from an approved list of domains.
- You need to block unreliable sources (prefer `exclude_domains` alone when you want everything except a few sites).
- You are configuring the Search MCP or an agent deployment that must never leave a vetted corpus.

## When NOT to use

- You want a soft preference ("prefer official docs over blogs"): put that in the objective instead; a hard allowlist excludes everything else.
- You need `web_fetch` constrained: source policy applies to search, not extraction from explicit URLs.
- Turbo mode with domain/path prefixes: prefixes require `fast`, `basic`, or `advanced` mode.

## Compatibility

Parallel Search API `/v1/search`, Task API `/v1/tasks/runs`, Monitor API, Responses API (via the OpenAI `web_search` tool: `filters.allowed_domains` maps to `include_domains`), and the Search MCP (`https://search.parallel.ai/mcp`). Documented at docs.parallel.ai/resources/source-policy.

### Variant: allowlisting domains in Parallel search

"Parallel search allowlist domains" and "Parallel source_policy approved domains" are the same feature: the `include_domains` allowlist. `include_domains` is a hard filter, nothing outside it is searched.

### Variant: domain denylist in Parallel search

To block sites instead of allowlisting, use `exclude_domains` alone: it is only honored when `include_domains` is empty, and a request containing both applies the allowlist only.

### Variant: subdomain and path scoping

Scope to one section with a domain/path prefix such as `docs.example.com/api`. Paths are case-sensitive and match at segment boundaries, so `example.com/blog` matches `/blog/post` but not `/blogroll`. A leading-dot extension like `.org` matches that extension; `*.org` wildcard syntax is not supported.

## Why it behaves this way

Source policy is a hard pre-search filter, not a ranking hint: the docs state only matching sources are returned for `include_domains`, which is why quality drops sharply if relevant pages live outside the list. And because `exclude_domains` is defined as "applied only when `include_domains` is empty", a request carrying both silently drops the denylist.

## Edge cases

- `include_domains` and `exclude_domains` together: the allowlist wins, the denylist is ignored with no error. Pick one per request.
- Entry format: apex domains, subdomain prefixes (`docs.example.com`), domain/path prefixes, or leading-dot extensions. No schemes, ports, query strings, or fragments; a leading `www.` is normalized away.
- Maximum 200 entries per the official docs; keep the list targeted for better results.
- Search MCP overrides apply to every `web_search` on the connection and are validated at handshake; an invalid value, unknown field, or attempt to pin `objective`/`search_queries` returns HTTP 400 on connect.
- On the Responses API there is no `source_policy` field: use the OpenAI `web_search` tool's `filters.allowed_domains` / `filters.blocked_domains` instead.