Kimi and Dome
Run Kimi K3 from three providers under one name.
Kimi is an open-weight model built for coding. Three places serve it: Moonshot AI, which makes it, plus Together AI and Fireworks AI. Dome puts all three under kimi-k3, gives it to people with the engineer role, and caps the month.
How Dome helps
Dome provides model brokering and routing for Kimi
Moonshot first, then two hosts
Pool Moonshot's own API with Together AI and Fireworks AI under kimi-k3. When Moonshot fails, the call moves down the list.
Kimi for engineers
Tag Kimi connections with a family attribute. A rule refuses them unless the person the agent acts for holds the engineer role.
A ceiling on spend
A $400 monthly quota on the pool counts all three hosts. Kimi stops there; the agent's other models don't.
Get started
Kimi with failover in five steps
Moonshot plus two hosts, one kimi-k3 pool, a role rule and a monthly cap.
01
Connect Moonshot AI
Moonshot's API is OpenAI-compatible at api.moonshot.ai. Dome keeps its key and sends it as a bearer token.
$ dome models add kimi-moonshot \--provider moonshot \--model kimi-k3 \--api-key "$MOONSHOT_API_KEY" \--attributes '{"family":"kimi"}' \--gateway prod-gateway02
Connect Together AI and Fireworks AI
Same model, each host's own id. Tag them the same way.
$ dome models add kimi-together \--provider together \--model moonshotai/Kimi-K3 \--api-key "$TOGETHER_API_KEY" \--attributes '{"family":"kimi"}' \--gateway prod-gateway$ dome models add kimi-fireworks \--provider fireworks \--model accounts/fireworks/models/kimi-k3 \--api-key "$FIREWORKS_API_KEY" \--attributes '{"family":"kimi"}' \--gateway prod-gateway03
Pool them for failover
Moonshot first, then Together AI, then Fireworks AI. A coding agent asks for kimi-k3 and gets whichever answers.
$ dome models pool create kimi-k3 \--failover-max all --gateway prod-gateway$ dome models pool member add kimi-k3 kimi-moonshot --priority 0$ dome models pool member add kimi-k3 kimi-together --priority 1$ dome models pool member add kimi-k3 kimi-fireworks --priority 204
Point your agent at the Gateway
Swap the base URL for the Gateway and the key for the agent's Dome key. Nothing else in the client changes.
from openai import OpenAIclient = OpenAI(base_url=f"{GATEWAY_URL}/v1", api_key=DOME_AGENT_KEY)client.chat.completions.create(model="kimi-k3",messages=[{"role": "user", "content": "Refactor this module to remove the global state."}],)05
Cap the spend
The cap is on the pool, so moving between hosts doesn't reset it.
$ dome quotas set --subject pool --pool kimi-k3 \--unit provider_usd --limit 400 --window monthly
Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Kimi itself, see Moonshot AI's documentation.
Rules
Kimi for engineers
Scoped to one agent, this checks the role in the caller's identity token. Engineers reach Kimi through it. Anyone else is refused, and only on Kimi.
forbid (principal, action == Dome::Action::"llm:invoke", resource is Dome::LLMModel)when { resource has family && resource.family == "kimi" }unless { principal has act_as && principal.act_as.roles.contains("engineer") };Try it
One call, two outcomes
Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.
Acting for
- Agentcoding-agent is registered and active
- Callerd.chen verified, roles: engineer
- RuleKimi is open to engineers
- Quota$142 of $400 this month
Agent workflow
Bringing it together
Connecting Kimi to registered agents, tools, and identity in Dome completes a governed agent application.
Acting for
Control point
Gateway
- Rules
- Guards
- Quotas
Every call decided and audited
Models
FAQ
Common questions
Which providers serve Kimi through Dome?
Moonshot AI directly, plus Together AI, Fireworks AI, DeepInfra and Amazon Bedrock. Each uses its own model id, such as kimi-k3 on Moonshot and moonshotai/Kimi-K3 on Together AI.
Which Kimi models does Dome list?
The Moonshot AI picker lists Kimi K3, Kimi K2.7 Code and Kimi K2.6. Any other model id Moonshot accepts works too.
What happens when a new Kimi ships?
Add the new id on each host that serves it and swap it into the pool. Agents never change the name they send.
Explore
More of what Dome works with
Provider
Anthropic
The Claude API behind the Model Broker: the key held in Dome, every call authorized, metered and audited.
Read moreMCP server
GitHub
The GitHub MCP server behind the Tool Gateway, with rules that decide each call on its owner and repository.
Read moreIdentity
Okta
Okta tokens verified on every agent call, so rules and audit name the person each agent acted for.
Read moreRuntime
LangGraph
LangGraph agents with their model calls on the Model Broker and their MCP tools on the Tool Gateway.
Read moreClient
Claude Code
Claude Code on a Dome Gateway with per-developer sign-in, rules on every tool call, and audit by name.
Read moreAgent service
TinyFish
TinyFish's web agents behind the Tool Gateway, with rules that decide each run on the site it targets.
Read moreNext steps
Talk with our FDE team
Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.
No card required to start. Register your first agent in minutes.
AI models for enterprise agents: failover, rules and quotas
Every model your agents call goes through the Model Broker. Pool providers for failover, decide who may call each model, and cap what it costs.
See them all