Azure OpenAI and Dome
Your Azure OpenAI deployments, governed per call.
Connect each Azure OpenAI deployment to Dome with its endpoint, deployment name and API version. The key stays in Dome's vault, and agents call the Gateway with their own keys. Rules decide which people's work runs on which deployment.
How Dome helps
Dome provides model brokering and routing for Azure OpenAI
Azure's api-key, kept by Dome
Dome sets the api-key header from its vault on every call. Agents authenticate with their own Dome keys.
EU work on EU deployments
Tag each deployment with its region. A rule keeps EU staff's calls on EU deployments.
Azure behind OpenAI, or the reverse
Pool a deployment with OpenAI's API for the same model, in either order. The second member covers the first.
Get started
Connect Azure OpenAI in three steps
Add each deployment, pool it with OpenAI if you want cover, and let agents call the Gateway.
01
Add the deployment
The provider id is azure_openai. Endpoint, deployment and api_version are all required: Azure picks the model from the deployment.
$ dome models add gpt-azure-eu \--provider azure_openai \--model gpt-6-sol \--provider-config '{"endpoint":"https://contoso-eu.openai.azure.com","deployment":"gpt-6-sol","api_version":"2024-10-21"}' \--api-key "$AZURE_OPENAI_API_KEY" \--attributes '{"region":"eu"}' \--gateway prod-gateway02
Pool it with OpenAI
The EU deployment goes first and OpenAI second. Agents address gpt-6-sol, the pool.
$ dome models pool create gpt-6-sol \--failover-max all --gateway prod-gateway$ dome models pool member add gpt-6-sol gpt-azure-eu --priority 0$ dome models pool member add gpt-6-sol gpt-openai --priority 103
Point your agent at the Gateway
Use the standard OpenAI SDK, not the Azure client. The agent's Dome key replaces the Azure key.
from openai import OpenAIclient = OpenAI(base_url=f"{GATEWAY_URL}/v1", api_key=DOME_AGENT_KEY)client.chat.completions.create(model="gpt-6-sol",messages=[{"role": "user", "content": "Summarize this policy for a new hire."}],)
Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Azure OpenAI itself, see Microsoft's documentation.
Rules
EU staff stay on EU deployments
Calls made for anyone in eu-staff are allowed only on deployments tagged region: eu. Dome reads the group from that person's identity token.
forbid (principal, action == Dome::Action::"llm:invoke", resource is Dome::LLMModel)when { principal has act_as && principal.act_as.groups.contains("eu-staff")}unless { resource has region && resource.region == "eu" };Agent workflow
Bringing it together
Connecting Azure OpenAI to registered agents, tools, and identity in Dome completes a governed agent application.
Acting for
Control point
Gateway
- Rules
- Guards
- Quotas
Every call decided and audited
Models
FAQ
Common questions
What does Dome need to call Azure OpenAI?
Your resource endpoint, the deployment name, an API version and a key. Dome builds the deployment URL from them.
Which header carries the Azure key?
The api-key header, not Authorization. Dome sets it from the key in its vault.
Which Azure OpenAI operations work through Dome?
Chat completions and embeddings. The Responses API is not served on Azure connections.
Explore
More of what Dome works with
Model
Claude Fable
Fable 5.1 from Anthropic and Amazon Bedrock in one failover pool, open to one group and capped by quota.
Read moreMCP server
GitHub
The GitHub MCP server behind the Tool Gateway, with rules that decide each call on its owner and repository.
Read moreIdentity
Okta
Okta tokens verified on every agent call, so rules and audit name the person each agent acted for.
Read moreRuntime
LangGraph
LangGraph agents with their model calls on the Model Broker and their MCP tools on the Tool Gateway.
Read moreClient
Claude Code
Claude Code on a Dome Gateway with per-developer sign-in, rules on every tool call, and audit by name.
Read moreAgent service
TinyFish
TinyFish's web agents behind the Tool Gateway, with rules that decide each run on the site it targets.
Read moreNext steps
Talk with our FDE team
Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.
No card required to start. Register your first agent in minutes.
LLM providers for AI agents: one governed path to every model
Connect a provider once. Its key stays in Dome, and every agent call to it is authorized, metered and audited.
See them all