Claude Opus and Dome
Run Claude Opus 5.5 with failover, rules and a spend ceiling.
Opus is the Claude you ration. It goes to the research agent working a hard problem, not the support bot answering a refund question. Dome pools it across Anthropic and AWS Bedrock, opens it to one group, and caps the bill.
How Dome helps
Dome provides model brokering and routing for Claude Opus
One name, two providers
Agents send claude-opus-5-5, the pool's name. An Anthropic error moves that call to Bedrock, and the agent's request doesn't change.
Opus for the teams that need it
Tag a connection as frontier and a rule refuses it outside one group. The group comes from your identity provider.
A ceiling on spend
$500 of provider spend a month on the pool, and 2M tokens a day for each caller. Both are enforced on the call.
Get started
Opus with failover in five steps
Two Opus connections, one pool, a group rule and a monthly cap.
01
Connect Anthropic
Tag the connection tier: frontier. The rule below reads that tag, and the Anthropic key stays in Dome's vault.
$ dome models add opus-55-anthropic \--provider anthropic \--model claude-opus-5-5 \--api-key "$ANTHROPIC_API_KEY" \--attributes '{"tier":"frontier"}' \--gateway prod-gateway02
Connect AWS Bedrock
Add a Bedrock connection in the dashboard with your AWS keys and region. Static AWS keys can only be set there.
03
Pool them for failover
Anthropic at priority 0, Bedrock at 1. Agents address the pool, so swapping a member later touches no agent code.
$ dome models pool create claude-opus-5-5 \--failover-max all --gateway prod-gateway$ dome models pool member add claude-opus-5-5 opus-55-anthropic --priority 0$ dome models pool member add claude-opus-5-5 opus-55-bedrock --priority 104
Point your agent at the Gateway
The research agent's client keeps its shape. Only the base URL and the key change, and the key is the agent's own.
from openai import OpenAIclient = OpenAI(base_url=f"{GATEWAY_URL}/v1", api_key=DOME_AGENT_KEY)client.chat.completions.create(model="claude-opus-5-5",messages=[{"role": "user", "content": "Summarize this incident."}],)05
Cap the spend
Quotas bind to the pool, a single connection, or each caller.
$ dome quotas set --subject pool --pool claude-opus-5-5 \--unit provider_usd --limit 500 --window monthly$ dome quotas set --subject model --model opus-55-anthropic \--per-caller --unit tokens --limit 2000000 --window daily
Commands and rules tested against a Dome workspace on September 30, 2026. For anything about Claude Opus itself, see Anthropic's documentation.
Rules
Opus for research, refused for everyone else
Any connection tagged frontier is refused unless the person the agent acts for is in ml-research. The group arrives in their identity token.
forbid (principal, action == Dome::Action::"llm:invoke", resource is Dome::LLMModel)when { resource has tier && resource.tier == "frontier" }unless { principal has act_as && principal.act_as.groups.contains("ml-research")};Try it
One call, two outcomes
Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.
Acting for
- Agentresearch-agent is registered and active
- Callera.okafor verified, groups: ml-research
- RuleFrontier models are open to ml-research
- Quota$212 of $500 this month
Agent workflow
Bringing it together
Serving Claude Opus to registered agents, alongside their tools and identity, completes a governed agent application in Dome.
Acting for
Control point
Gateway
- Rules
- Guards
- Quotas
Every call decided and audited
Models
Model
Claude Opus
This page
Provider
Anthropic
See how
FAQ
Common questions
Which providers serve Claude Opus through Dome?
Two: Anthropic's API and AWS Bedrock, pooled here at priorities 0 and 1. Vertex AI can't serve Claude through Dome.
What happens when a new Opus version ships?
Add a connection for the new version and swap it into the pool. Agents keep sending the pool's name.
Can I limit what Opus costs?
Yes. Quotas cap provider spend, tokens or calls per pool, per connection or per caller, over a daily or monthly window.
Do Anthropic beta features pass through Dome?
Only context management. Dome drops the other beta headers, including those that let Anthropic call tools itself, so every tool call goes through the Gateway.
Explore
More of what Dome works with
Provider
OpenAI
The OpenAI API behind the Model Broker: the key held in Dome, every call authorized, metered and audited.
Read moreMCP server
GitHub
The GitHub MCP server behind the Tool Gateway, with rules that decide each call on its owner and repository.
Read moreIdentity
Microsoft Entra ID
Entra access tokens verified on every agent call, so rules read app roles and audit names the person.
Read moreRuntime
OpenAI Agents SDK
OpenAI Agents SDK agents with their models on the Model Broker and their MCP tools on the Tool Gateway.
Read moreClient
Claude Code
Claude Code on a Dome Gateway with per-developer sign-in, rules on every tool call, and audit by name.
Read moreAgent service
TinyFish
TinyFish's web agents behind the Tool Gateway, with rules that decide each run on the site it targets.
Read moreNext steps
Talk with our FDE team
Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.
No card required to start. Register your first agent in minutes.
AI models for enterprise agents: failover, rules and quotas
Every model your agents call goes through the Model Broker. Pool providers for failover, decide who may call each model, and cap what it costs.
See them all