Databricks Model Serving and Dome
Your Databricks endpoints, with every agent call governed.
Databricks Model Serving gives each workspace its own endpoints. Connect those endpoints to Dome and a rule keeps production agents on production workspaces. Anthropic's API stands behind Claude Opus 5.5 if Databricks fails.
How Dome helps
Dome provides model brokering and routing for Databricks
The token never leaves Dome
Dome stores the Databricks token and presents it per call. Agents never get a workspace credential.
Databricks first, the vendor behind it
Pool the Databricks endpoint for Claude Opus 5.5 with Anthropic's API. When Databricks fails, the call goes to Anthropic.
Production agents on production workspaces
Tag each connection with its workspace's environment. A rule keeps a production agent off dev endpoints.
Get started
Connect Databricks in three steps
Add each serving endpoint, pool it with the vendor's API, and change one base URL in each agent.
01
Add the connection
The provider id is databricks. Databricks endpoints are per workspace, so set --endpoint to your workspace URL plus /serving-endpoints; the model is the serving endpoint's name.
$ dome models add opus-databricks \--provider databricks \--endpoint https://<workspace>.cloud.databricks.com/serving-endpoints \--model databricks-claude-opus-5-5 \--api-key "$DATABRICKS_TOKEN" \--attributes '{"env":"prod"}' \--gateway prod-gateway02
Pool it with Anthropic
Add an Anthropic connection for claude-opus-5-5, tagged env: prod too, and pool the two. Agents send the pool's name.
$ dome models pool create claude-opus-5-5 \--failover-max all --gateway prod-gateway$ dome models pool member add claude-opus-5-5 opus-databricks --priority 0$ dome models pool member add claude-opus-5-5 opus-anthropic --priority 103
Point your agent at the Gateway
Point the OpenAI SDK at the Gateway with the agent's Dome key, and call the pool by name.
from openai import OpenAIclient = OpenAI(base_url=f"{GATEWAY_URL}/v1", api_key=DOME_AGENT_KEY)client.chat.completions.create(model="claude-opus-5-5",messages=[{"role": "user", "content": "Explain why this pipeline run failed."}],)
Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Databricks itself, see Databricks's documentation.
Rules
Production agents use production endpoints
Applied to a production agent with --agent, this refuses any connection not tagged env: prod. A dev workspace's endpoint is out of reach.
forbid (principal, action == Dome::Action::"llm:invoke", resource is Dome::LLMModel)unless { resource has env && resource.env == "prod" };Agent workflow
Bringing it together
Connecting Databricks to registered agents, tools, and identity in Dome completes a governed agent application.
Acting for
Control point
Gateway
- Rules
- Guards
- Quotas
Every call decided and audited
Models
FAQ
Common questions
How does Dome connect to Databricks Model Serving?
Through your workspace's OpenAI-compatible serving endpoints at https://<workspace>/serving-endpoints, with a Databricks token sent as a bearer token. The token stays in Dome's vault.
Which models can I use through Databricks?
Any serving endpoint in your workspace that answers chat completions, such as databricks-claude-opus-5-5 or databricks-gpt-oss-120b. The model id is the endpoint's name.
Why does a Databricks connection need --endpoint?
Every Databricks workspace has its own URL, so Dome has no default to fill in. Without one, calls on the connection fail.
Explore
More of what Dome works with
Model
Claude Fable
Fable 5.1 from Anthropic and Amazon Bedrock in one failover pool, open to one group and capped by quota.
Read moreMCP server
GitHub
The GitHub MCP server behind the Tool Gateway, with rules that decide each call on its owner and repository.
Read moreIdentity
Okta
Okta tokens verified on every agent call, so rules and audit name the person each agent acted for.
Read moreRuntime
OpenAI Agents SDK
OpenAI Agents SDK agents with their models on the Model Broker and their MCP tools on the Tool Gateway.
Read moreClient
Claude Code
Claude Code on a Dome Gateway with per-developer sign-in, rules on every tool call, and audit by name.
Read moreAgent service
TinyFish
TinyFish's web agents behind the Tool Gateway, with rules that decide each run on the site it targets.
Read moreNext steps
Talk with our FDE team
Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.
No card required to start. Register your first agent in minutes.
LLM providers for AI agents: one governed path to every model
Connect a provider once. Its key stays in Dome, and every agent call to it is authorized, metered and audited.
See them all