Dome Systems

Claude API and Dome

One Anthropic key. Every agent call governed.

Connect the Claude API to Dome once. Agents reach Claude with Dome keys of their own, Anthropic's key stays in Dome's vault, and rules decide each call before Anthropic sees it.

PeopleAgentsDomeAnthropic modelsCallersPeopleAgentssupport-agentAgentsresearch-agentAgentsbatch-classifierGatewaysprod-gatewayClaude Fable 5.1claude-fable-5-1Claude Opus 5.5claude-opus-5-5Claude Haiku 4.5claude-haiku-4-5RulesGuardsAuditsaudit-trail
support-agent→claude-fable-5-1· as j.lindqvistAllowed

How Dome helps

Dome provides model brokering and routing for Anthropic

Anthropic's key, out of reach

Dome injects the x-api-key header at call time. Every read of the key is audited, and no agent ever holds it.

Agents authenticate as themselves

Each agent calls with its own Dome key. Revoke the agent and its calls stop, with the Anthropic key untouched.

A ceiling on every loop

Calls are metered to the agent and the person it acted for. A quota halts a runaway Claude loop at the limit you set.

Get started

Connect Anthropic in two steps

Add the connection, then change your agent's base URL. Existing Anthropic and OpenAI SDK code keeps working.

  1. 01

    Add the connection

    Any Claude model id works. Add one connection per model you want agents to reach.

    $ dome models add claude-fable \
    --provider anthropic \
    --model claude-fable-5-1 \
    --api-key "$ANTHROPIC_API_KEY" \
    --gateway prod-gateway
  2. 02

    Point your agent at the Gateway

    The Anthropic SDK takes the Gateway URL as its base. OpenAI-compatible clients use the same URL with /v1.

    import anthropic
     
    client = anthropic.Anthropic(base_url=GATEWAY_URL, api_key=DOME_AGENT_KEY)
    client.messages.create(
    model="claude-fable",
    max_tokens=1024,
    messages=[{"role": "user", "content": "Draft a reply to this ticket."}],
    )

Commands and rules tested against a Dome workspace on September 30, 2026. For anything about Anthropic itself, see Anthropic's documentation.

Rules

Frontier models by group

Tag a connection with an attribute and write a rule against it. This one keeps frontier connections to one team, whichever agent is calling.

forbid (principal, action == Dome::Action::"llm:invoke", resource is Dome::LLMModel)
when { resource has tier && resource.tier == "frontier" }
unless {
principal has act_as &&
principal.act_as.groups.contains("ml-research")
};

Agent workflow

Bringing it together

Connecting Anthropic to registered agents, tools, and identity in Dome completes a governed agent application.

Dome

Control point

Gateway

  • Rules
  • Guards
  • Quotas

Every call decided and audited

Models

Provider

Anthropic

This page

Model

Claude Opus

See how

FAQ

Common questions

How does Dome authenticate to Anthropic?

With your Anthropic API key, stored in Dome's vault and sent as the x-api-key header on each call. Agents never see it.

Which Claude models can I use?

Any model id Anthropic accepts. The dashboard suggests current ones, from Claude Fable 5.1 to Claude Haiku 4.5.

Do I need to change my agent code?

Two settings: the base URL and the key. The Anthropic SDK and OpenAI-compatible clients both work.

Can Anthropic's server-side tools run through Dome?

No. Dome blocks Anthropic's MCP connector and code execution betas, so every tool call goes through the Gateway and its rules.

Next steps

Talk with our FDE team

Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.