Dome Systems

DeepSeek and Dome

Run DeepSeek V4 Pro, and decide where it runs.

With DeepSeek, the question is where it runs. The same weights are on DeepSeek's own API and on US hosts like Together AI and DeepInfra. Tag each connection with its jurisdiction, and a rule keeps regulated work on the ones tagged us.

PeopleAgentsDomePool: deepseek-v4-proCallersPeopleAgentsclaims-agentAgentsresearch-agentAgentsreport-builderGatewaysprod-gatewayTogether AIPriority 0, jurisdiction: usDeepInfraPriority 1, jurisdiction: usDeepSeekDirect, jurisdiction: cnRulesGuardsAuditsaudit-trail
claims-agent→deepseek-v4-pro· as k.oseiAllowed

How Dome helps

Dome provides model brokering and routing for DeepSeek

One name, two hosts

Together AI and DeepInfra both serve deepseek-ai/DeepSeek-V4-Pro-0813. Pool them as deepseek-v4-pro, and a failed call moves to the next.

Regulated work stays put

Tag every connection with a jurisdiction. A rule on the claims agent refuses any connection not tagged us.

A ceiling on spend

The US pool gets $250 of provider spend a month. The direct DeepSeek connection sits outside it.

Get started

DeepSeek with failover in five steps

Tag every connection with a jurisdiction, pool the US ones, and scope the claims agent to them.

  1. 01

    Connect Together AI and DeepInfra

    Both use the same model id. The jurisdiction attribute is your label, and rules read it.

    $ dome models add deepseek-together \
    --provider together \
    --model deepseek-ai/DeepSeek-V4-Pro-0813 \
    --api-key "$TOGETHER_API_KEY" \
    --attributes '{"family":"deepseek","jurisdiction":"us"}' \
    --gateway prod-gateway
     
    $ dome models add deepseek-deepinfra \
    --provider deepinfra \
    --model deepseek-ai/DeepSeek-V4-Pro-0813 \
    --api-key "$DEEPINFRA_API_KEY" \
    --attributes '{"family":"deepseek","jurisdiction":"us"}' \
    --gateway prod-gateway
  2. 02

    Connect DeepSeek directly

    For agents with no residency limit. DeepSeek's own id for the model is deepseek-v4-pro.

    $ dome models add deepseek-direct \
    --provider deepseek \
    --model deepseek-v4-pro \
    --api-key "$DEEPSEEK_API_KEY" \
    --attributes '{"family":"deepseek","jurisdiction":"cn"}' \
    --gateway prod-gateway
  3. 03

    Pool the US connections

    Only the us connections join deepseek-v4-pro. Together leads, and DeepInfra takes over when it fails.

    $ dome models pool create deepseek-v4-pro \
    --failover-max all --gateway prod-gateway
     
    $ dome models pool member add deepseek-v4-pro deepseek-together --priority 0
    $ dome models pool member add deepseek-v4-pro deepseek-deepinfra --priority 1
  4. 04

    Point your agent at the Gateway

    The claims agent sends deepseek-v4-pro through the OpenAI SDK, with a Dome key and the Gateway URL.

    from openai import OpenAI
     
    client = OpenAI(base_url=f"{GATEWAY_URL}/v1", api_key=DOME_AGENT_KEY)
    client.chat.completions.create(
    model="deepseek-v4-pro",
    messages=[{"role": "user", "content": "Check this claim against the policy terms."}],
    )
  5. 05

    Cap the spend

    The quota counts Together and DeepInfra together, as one US budget.

    $ dome quotas set --subject pool --pool deepseek-v4-pro \
    --unit provider_usd --limit 250 --window monthly

Commands and rules tested against a Dome workspace on October 1, 2026. For anything about DeepSeek itself, see DeepSeek's documentation.

Rules

Regulated work stays on connections tagged us

Applied to an agent with --agent, this refuses any connection not tagged jurisdiction: us. The claims agent can use the pool, never DeepSeek's own API.

forbid (principal, action == Dome::Action::"llm:invoke", resource is Dome::LLMModel)
unless { resource has jurisdiction && resource.jurisdiction == "us" };

Try it

One call, two outcomes

Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.

Model

agent claims-agent · acting as k.osei
llm:invoke(model: "deepseek-v4-pro")
  1. Agentclaims-agent is registered and active
  2. Callerk.osei verified
  3. RuleConnection is tagged jurisdiction: us
DecisionAllowed

Agent workflow

Bringing it together

Connecting DeepSeek to registered agents, tools, and identity in Dome completes a governed agent application.

Dome

Control point

Gateway

  • Rules
  • Guards
  • Quotas

Every call decided and audited

FAQ

Common questions

Which providers serve DeepSeek through Dome?

DeepSeek's own API, Together AI, DeepInfra and Fireworks AI serve DeepSeek V4. Amazon Bedrock and SambaNova serve DeepSeek V3 models.

Does the jurisdiction tag change where DeepSeek runs?

No. It is a label you set on the connection, and rules enforce against it.

How does Dome connect to DeepSeek's own API?

The provider id is deepseek, and Dome calls https://api.deepseek.com/v1 with your key as a bearer token. The key stays in Dome's vault.

What happens when a new DeepSeek ships?

Connect it on each host with the same jurisdiction tags. The rule keeps reading the tag, whatever the version.

Next steps

Talk with our FDE team

Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.