Grok and Dome
Run Grok 4.7 from xAI, with a fallback, under one name.
Grok often starts as one team's request, well before it's anyone's standard. Dome lets research have it without opening it to the company: xAI serves it, OpenRouter backs it up, a rule checks the person behind each call, and a monthly cap bounds the trial.
How Dome helps
Dome provides model brokering and routing for Grok
xAI first, OpenRouter next
OpenRouter serves Grok as x-ai/grok-4.7. Pool it behind xAI and a failed call moves to it.
Grok for research
Tag Grok connections with a family attribute. A rule refuses them unless the person the agent acts for is in research.
A ceiling on spend
$200 of provider spend a month covers the trial. Calls over the line are refused, whichever provider would have served them.
Get started
Grok with failover in five steps
xAI, then OpenRouter, in one pool, opened to research and capped at $200.
01
Connect xAI
The provider id is xai. Dome holds the xAI key, and the research agent calls with its own.
$ dome models add grok-xai \--provider xai \--model grok-4.7 \--api-key "$XAI_API_KEY" \--attributes '{"family":"grok"}' \--gateway prod-gateway02
Connect OpenRouter
OpenRouter names the model with an x-ai/ prefix.
$ dome models add grok-openrouter \--provider openrouter \--model x-ai/grok-4.7 \--api-key "$OPENROUTER_API_KEY" \--attributes '{"family":"grok"}' \--gateway prod-gateway03
Pool them for failover
xAI at priority 0, OpenRouter at 1. The research agent sends grok-4.7 either way.
$ dome models pool create grok-4.7 \--failover-max all --gateway prod-gateway$ dome models pool member add grok-4.7 grok-xai --priority 0$ dome models pool member add grok-4.7 grok-openrouter --priority 104
Point your agent at the Gateway
xAI's API is OpenAI-compatible, so the OpenAI SDK needs only the Gateway URL and a Dome key.
from openai import OpenAIclient = OpenAI(base_url=f"{GATEWAY_URL}/v1", api_key=DOME_AGENT_KEY)client.chat.completions.create(model="grok-4.7",messages=[{"role": "user", "content": "Summarize this week's chip export news."}],)05
Cap the spend
One quota on the pool covers xAI and OpenRouter together.
$ dome quotas set --subject pool --pool grok-4.7 \--unit provider_usd --limit 200 --window monthly
Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Grok itself, see xAI's documentation.
Rules
Grok for the research team
On an agent with --agent, Grok is refused unless the person behind the call is in research. The agent's other models keep working.
forbid (principal, action == Dome::Action::"llm:invoke", resource is Dome::LLMModel)when { resource has family && resource.family == "grok" }unless { principal has act_as && principal.act_as.groups.contains("research") };Try it
One call, two outcomes
Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.
Acting for
- Agentresearch-agent is registered and active
- Callera.park verified, groups: research
- RuleGrok is open to the research group
- Quota$74 of $200 this month
Agent workflow
Bringing it together
Connecting Grok to registered agents, tools, and identity in Dome completes a governed agent application.
Acting for
Control point
Gateway
- Rules
- Guards
- Quotas
Every call decided and audited
Models
FAQ
Common questions
Which providers serve Grok through Dome?
xAI directly, OpenRouter, and Amazon Bedrock, which serves Grok 4.7 as us.xai.grok-4.7. Static AWS keys for Bedrock are set in the dashboard.
Which Grok models can I use?
Any model id xAI accepts, such as grok-4.7 or grok-4.6. Dome passes the id through unchanged.
What happens when a new Grok ships?
Connect the new id on xAI and OpenRouter, then swap both into the pool. The research agent's code stays as it is.
Explore
More of what Dome works with
Provider
Anthropic
The Claude API behind the Model Broker: the key held in Dome, every call authorized, metered and audited.
Read moreMCP server
GitHub
The GitHub MCP server behind the Tool Gateway, with rules that decide each call on its owner and repository.
Read moreIdentity
Microsoft Entra ID
Entra access tokens verified on every agent call, so rules read app roles and audit names the person.
Read moreRuntime
LangGraph
LangGraph agents with their model calls on the Model Broker and their MCP tools on the Tool Gateway.
Read moreClient
Claude Code
Claude Code on a Dome Gateway with per-developer sign-in, rules on every tool call, and audit by name.
Read moreAgent service
TinyFish
TinyFish's web agents behind the Tool Gateway, with rules that decide each run on the site it targets.
Read moreNext steps
Talk with our FDE team
Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.
No card required to start. Register your first agent in minutes.
AI models for enterprise agents: failover, rules and quotas
Every model your agents call goes through the Model Broker. Pool providers for failover, decide who may call each model, and cap what it costs.
See them all