Dome Systems

gpt-oss and Dome

Run gpt-oss-120b from three providers under one name.

gpt-oss is OpenAI's open-weight model, and that makes it the natural home for unattended work: nightly jobs, backfills, agents nobody is watching. Dome serves it from Groq, Cerebras and Together AI under one name, and keeps any call with no person behind it on open weights.

PeopleAgentsDomePool: gpt-oss-120bCallersPeopleAgentsnightly-batchAgentslog-summarizerAgentssupport-agentGatewaysprod-gatewayGroqPriority 0, weights: openCerebrasPriority 1, weights: openOpenAIgpt-6-sol, no weights tagRulesGuardsAuditsaudit-trail
nightly-batch→gpt-oss-120b· scheduledAllowed

How Dome helps

Dome provides model brokering and routing for gpt-oss

Three hosts, one name

Groq calls it openai/gpt-oss-120b and Cerebras calls it gpt-oss-120b. The pool gives agents one name to send.

Unattended jobs on open weights

Tag open-weight connections. When no verified person is behind a call, a rule refuses everything else.

Calls per caller

Give each agent and each person 2,000 calls a day on the Groq connection. One busy caller can't drain it for the rest.

Get started

gpt-oss with failover in five steps

Three hosts tagged weights: open, one pool, a rule for unattended calls, then a per-caller limit.

  1. 01

    Connect Groq

    On Groq the model is openai/gpt-oss-120b. Tag the connection weights: open; the key never leaves Dome.

    $ dome models add gpt-oss-groq \
    --provider groq \
    --model openai/gpt-oss-120b \
    --api-key "$GROQ_API_KEY" \
    --attributes '{"weights":"open"}' \
    --gateway prod-gateway
  2. 02

    Connect Cerebras and Together AI

    Same weights, each host's own id. Tag them the same way.

    $ dome models add gpt-oss-cerebras \
    --provider cerebras \
    --model gpt-oss-120b \
    --api-key "$CEREBRAS_API_KEY" \
    --attributes '{"weights":"open"}' \
    --gateway prod-gateway
     
    $ dome models add gpt-oss-together \
    --provider together \
    --model openai/gpt-oss-120b \
    --api-key "$TOGETHER_API_KEY" \
    --attributes '{"weights":"open"}' \
    --gateway prod-gateway
  3. 03

    Pool them for failover

    Groq leads. A nightly job that loses Groq mid-run carries on through Cerebras, then Together.

    $ dome models pool create gpt-oss-120b \
    --failover-max all --gateway prod-gateway
     
    $ dome models pool member add gpt-oss-120b gpt-oss-groq --priority 0
    $ dome models pool member add gpt-oss-120b gpt-oss-cerebras --priority 1
    $ dome models pool member add gpt-oss-120b gpt-oss-together --priority 2
  4. 04

    Point your agent at the Gateway

    The nightly job uses the OpenAI SDK with the Gateway as its base URL and its own Dome key.

    from openai import OpenAI
     
    client = OpenAI(base_url=f"{GATEWAY_URL}/v1", api_key=DOME_AGENT_KEY)
    client.chat.completions.create(
    model="gpt-oss-120b",
    messages=[{"role": "user", "content": "Summarize last night's error logs."}],
    )
  5. 05

    Cap calls per caller

    With --per-caller, a model quota applies to each agent and each verified person separately.

    $ dome quotas set --subject model --model gpt-oss-groq --per-caller \
    --unit calls --limit 2000 --window daily

Commands and rules tested against a Dome workspace on October 1, 2026. For anything about gpt-oss itself, see OpenAI's documentation.

Rules

Unattended jobs stay on open weights

Applied to an agent with --agent, this refuses any connection not tagged weights: open when the call carries no acting-as identity. Calls made for a verified person are unaffected.

forbid (principal, action == Dome::Action::"llm:invoke", resource is Dome::LLMModel)
when { !(principal has act_as) }
unless { resource has weights && resource.weights == "open" };

Try it

One call, two outcomes

Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.

Model

agent nightly-batch · scheduled
llm:invoke(model: "gpt-oss-120b")
  1. Agentnightly-batch is registered and active
  2. CallerNo acting-as identity
  3. RuleConnection is tagged weights: open
DecisionAllowed

Agent workflow

Bringing it together

Connecting gpt-oss to registered agents, tools, and identity in Dome completes a governed agent application.

Dome

Control point

Gateway

  • Rules
  • Guards
  • Quotas

Every call decided and audited

FAQ

Common questions

Which providers serve gpt-oss through Dome?

Groq, Cerebras, Together AI, Fireworks AI, SambaNova and Amazon Bedrock all serve gpt-oss-120b. Groq, Fireworks AI and Bedrock serve gpt-oss-20b too.

Do agents need different code for each host?

No. Agents send the pool's name to the Gateway, and Dome sends each host its own model id.

What does a per-caller quota do?

It applies the limit to each agent and each verified person separately. It is available on model quotas.

Next steps

Talk with our FDE team

Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.