Qwen and Dome
Run Qwen 3.8 from two providers under one name.
Teams pick Qwen for coding agents that run all day on open weights. The governance question is scope: a coding agent pinned to Qwen shouldn't wander onto a frontier model on a bad prompt. Dome pins it, backs Together AI with DeepInfra, and budgets each agent.
How Dome helps
Dome provides model brokering and routing for Qwen
Together first, DeepInfra next
Both serve Qwen/Qwen3.8-2.4T-A95B. Pool them as qwen3.8, and a failed call moves to the next provider.
A coding agent that stays on Qwen
Tag Qwen connections with a family attribute. A rule on the agent refuses every model outside it.
Spend by agent
Cap each agent's monthly provider spend. The migration agent can't spend the test writer's budget.
Get started
Qwen with failover in five steps
Together and DeepInfra under qwen3.8, a pin on the coding agent, and a budget per agent.
01
Connect Together AI
Tag it family: qwen. The Together key is Dome's to hold; the coding agent gets a Dome key.
$ dome models add qwen-together \--provider together \--model Qwen/Qwen3.8-2.4T-A95B \--api-key "$TOGETHER_API_KEY" \--attributes '{"family":"qwen"}' \--gateway prod-gateway02
Connect DeepInfra
DeepInfra serves the same weights under the same id.
$ dome models add qwen-deepinfra \--provider deepinfra \--model Qwen/Qwen3.8-2.4T-A95B \--api-key "$DEEPINFRA_API_KEY" \--attributes '{"family":"qwen"}' \--gateway prod-gateway03
Pool them for failover
Same id on both hosts, so the pool is a straight priority list: Together, then DeepInfra.
$ dome models pool create qwen3.8 \--failover-max all --gateway prod-gateway$ dome models pool member add qwen3.8 qwen-together --priority 0$ dome models pool member add qwen3.8 qwen-deepinfra --priority 104
Point your agent at the Gateway
The code assistant's OpenAI client sends qwen3.8 to the Gateway with its own key.
from openai import OpenAIclient = OpenAI(base_url=f"{GATEWAY_URL}/v1", api_key=DOME_AGENT_KEY)client.chat.completions.create(model="qwen3.8",messages=[{"role": "user", "content": "Write unit tests for parse_invoice()."}],)05
Cap spend per agent
Each agent's budget follows it across pools, so a second model doesn't open a second budget.
$ dome quotas set --subject agent --agent migration-agent \--dimension llm --unit provider_usd --limit 150 --window monthly
Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Qwen itself, see Alibaba's documentation.
Rules
Keep an agent on Qwen
Applied to one agent with --agent, this refuses any connection not tagged as Qwen. The code assistant can't reach Opus, whatever model name it sends.
forbid (principal, action == Dome::Action::"llm:invoke", resource is Dome::LLMModel)unless { resource has family && resource.family == "qwen" };Try it
One call, two outcomes
Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.
Model
- Agentcode-assistant is registered and active
- Callerd.chen verified
- RuleConnection is tagged family: qwen
Agent workflow
Bringing it together
Connecting Qwen to registered agents, tools, and identity in Dome completes a governed agent application.
Acting for
Control point
Gateway
- Rules
- Guards
- Quotas
Every call decided and audited
Models
FAQ
Common questions
Which providers serve Qwen through Dome?
Together AI and DeepInfra serve Qwen 3.8 as Qwen/Qwen3.8-2.4T-A95B. Fireworks AI, Cerebras and Groq serve other Qwen models under their own ids.
Can the agent get around the rule by asking for another model?
No. The rule reads the tag on the connection that would serve the call, not the name the agent sends.
What happens when a new Qwen ships?
Connect the new Qwen on Together and DeepInfra with the same family tag. The pin still holds, and the pool decides which version agents get.
Explore
More of what Dome works with
Provider
Anthropic
The Claude API behind the Model Broker: the key held in Dome, every call authorized, metered and audited.
Read moreMCP server
GitHub
The GitHub MCP server behind the Tool Gateway, with rules that decide each call on its owner and repository.
Read moreIdentity
Okta
Okta tokens verified on every agent call, so rules and audit name the person each agent acted for.
Read moreRuntime
OpenAI Agents SDK
OpenAI Agents SDK agents with their models on the Model Broker and their MCP tools on the Tool Gateway.
Read moreClient
Claude Code
Claude Code on a Dome Gateway with per-developer sign-in, rules on every tool call, and audit by name.
Read moreAgent service
TinyFish
TinyFish's web agents behind the Tool Gateway, with rules that decide each run on the site it targets.
Read moreNext steps
Talk with our FDE team
Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.
No card required to start. Register your first agent in minutes.
AI models for enterprise agents: failover, rules and quotas
Every model your agents call goes through the Model Broker. Pool providers for failover, decide who may call each model, and cap what it costs.
See them all