GPT and Dome
Run GPT-6 from OpenAI and Azure under one name.
Serve GPT from OpenAI directly and from your Azure OpenAI deployment behind one pool. Agents ask for gpt-6-sol, and the Broker tries Azure when OpenAI fails. Rules send legal work to the zero-retention deployment.
How Dome helps
Dome provides model brokering and routing for GPT
OpenAI first, Azure next
Pool the OpenAI connection and your Azure deployment under gpt-6-sol. When OpenAI fails, the call goes to Azure.
Sensitive work on the right deployment
Tag the Azure connection with its retention terms. A rule keeps legal work off any connection without them.
Spend by agent
Cap each agent's monthly provider spend. The sales assistant can't eat the support team's budget.
Get started
GPT with failover in five steps
Connect OpenAI and Azure, pool the connections in priority order, and point your agents at the Gateway. Provider keys stay in Dome.
01
Connect OpenAI
The key goes into Dome's vault and is sent as a bearer token at call time. Agents never hold it.
$ dome models add gpt-openai \--provider openai \--model gpt-6-sol \--api-key "$OPENAI_API_KEY" \--gateway prod-gateway02
Connect Azure OpenAI
Azure needs your resource endpoint, the deployment name and an API version. The key is sent as the api-key header.
$ dome models add gpt-azure \--provider azure_openai \--model gpt-6-sol \--provider-config '{"endpoint":"https://contoso-eu.openai.azure.com","deployment":"gpt-6-sol","api_version":"2024-10-21"}' \--api-key "$AZURE_OPENAI_API_KEY" \--attributes '{"retention":"zero"}' \--gateway prod-gateway03
Pool them for failover
Members are tried in priority order. Name the pool for the model and agents need no other change.
$ dome models pool create gpt-6-sol \--failover-max all --gateway prod-gateway$ dome models pool member add gpt-6-sol gpt-openai --priority 0$ dome models pool member add gpt-6-sol gpt-azure --priority 104
Point your agent at the Gateway
The OpenAI SDK takes the Gateway URL as its base. The agent's Dome key replaces the provider key.
from openai import OpenAIclient = OpenAI(base_url=f"{GATEWAY_URL}/v1", api_key=DOME_AGENT_KEY)client.chat.completions.create(model="gpt-6-sol",messages=[{"role": "user", "content": "Summarize this call transcript."}],)05
Cap spend per agent
An agent quota counts every model call that agent makes, through any pool.
$ dome quotas set --subject agent --agent sales-assistant \--dimension llm --unit provider_usd --limit 200 --window monthly
Commands and rules tested against a Dome workspace on October 1, 2026. For anything about GPT itself, see OpenAI's documentation.
Rules
Legal work stays on zero-retention connections
When the person an agent acts for is in legal, only connections tagged retention: zero are allowed. Everyone else can use either provider.
forbid (principal, action == Dome::Action::"llm:invoke", resource is Dome::LLMModel)when { principal has act_as && principal.act_as.groups.contains("legal")}unless { resource has retention && resource.retention == "zero" };Try it
One call, two outcomes
Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.
Connection
- Agentcontract-reviewer is registered and active
- Callere.walsh verified, groups: legal
- RuleConnection is tagged retention: zero
Agent workflow
Bringing it together
Connecting GPT to registered agents, tools, and identity in Dome completes a governed agent application.
Acting for
Control point
Gateway
- Rules
- Guards
- Quotas
Every call decided and audited
Models
FAQ
Common questions
Which providers serve GPT through Dome?
OpenAI directly, and Azure OpenAI through your own deployment. Both can sit in one pool.
Do agents need different code for Azure and OpenAI?
No. Agents send the pool's name to the Gateway, and Dome builds each provider's request.
What happens when a new GPT model ships?
Add a connection for the new model id, and a new Azure deployment if you use one. Swap them into the pool.
Does the Responses API work through Dome?
Yes, on OpenAI connections. Azure OpenAI connections serve chat completions and embeddings.
Explore
More of what Dome works with
Provider
Anthropic
The Claude API behind the Model Broker: the key held in Dome, every call authorized, metered and audited.
Read moreMCP server
GitHub
The GitHub MCP server behind the Tool Gateway, with rules that decide each call on its owner and repository.
Read moreIdentity
Okta
Okta tokens verified on every agent call, so rules and audit name the person each agent acted for.
Read moreRuntime
LangGraph
LangGraph agents with their model calls on the Model Broker and their MCP tools on the Tool Gateway.
Read moreClient
Claude Code
Claude Code on a Dome Gateway with per-developer sign-in, rules on every tool call, and audit by name.
Read moreAgent service
TinyFish
TinyFish's web agents behind the Tool Gateway, with rules that decide each run on the site it targets.
Read moreNext steps
Talk with our FDE team
Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.
No card required to start. Register your first agent in minutes.
AI models for enterprise agents: failover, rules and quotas
Every model your agents call goes through the Model Broker. Pool providers for failover, decide who may call each model, and cap what it costs.
See them all