Dome Systems

DeepInfra API and Dome

Open models on DeepInfra, with every call governed.

DeepInfra hosts open models like DeepSeek and Gemma under one key. Connect it to Dome, tag connections with the region you approved, and an agent is refused on anything untagged. Together AI serves the same DeepSeek V4 Flash as a fallback.

PeopleAgentsDomeDeepInfra modelsCallersPeopleAgentsclaims-agentAgentssummarizerAgentsintent-routerGatewaysprod-gatewayDeepSeek V4 Flashdeepseek-ai/DeepSeek-V4-Flash-0731Gemma 4 31Bgoogle/gemma-4-31B-itTogether AIDeepSeek failover, priority 1RulesGuardsAuditsaudit-trail
claims-agent→deepseek-v4-flash· as l.moreauAllowed

How Dome helps

Dome provides model brokering and routing for DeepInfra

The key stays put

Dome keeps DeepInfra's key and adds it to each outbound request. Agents hold Dome keys only, so a leaked agent key never exposes DeepInfra's.

Two hosts, one release

Together AI serves the same DeepSeek V4 Flash release. Put both in a pool and DeepInfra's failures land on Together.

Your tags, your rules

Tag each connection with the region you approved. A rule refuses anything without the tag.

Get started

Connect DeepInfra in three steps

Add DeepSeek V4 Flash on DeepInfra, pair it with Together AI, then hand agents the Gateway address.

  1. 01

    Add the connection

    The provider id is deepinfra. Dome uses https://api.deepinfra.com/v1/openai and DeepInfra's own model ids.

    $ dome models add deepseek-deepinfra \
    --provider deepinfra \
    --model deepseek-ai/DeepSeek-V4-Flash-0731 \
    --api-key "$DEEPINFRA_API_KEY" \
    --attributes '{"region":"us"}' \
    --gateway prod-gateway
  2. 02

    Pool it with Together AI

    Add the same DeepSeek id on Together as a second connection. DeepInfra goes first.

    $ dome models pool create deepseek-v4-flash \
    --failover-max all --gateway prod-gateway
     
    $ dome models pool member add deepseek-v4-flash deepseek-deepinfra --priority 0
    $ dome models pool member add deepseek-v4-flash deepseek-together --priority 1
  3. 03

    Point your agent at the Gateway

    Keep your OpenAI-compatible code. Point it at the Gateway and hand it the agent's Dome key.

    from openai import OpenAI
     
    client = OpenAI(base_url=f"{GATEWAY_URL}/v1", api_key=DOME_AGENT_KEY)
    client.chat.completions.create(
    model="deepseek-v4-flash",
    messages=[{"role": "user", "content": "Summarize this claim file."}],
    )

Commands and rules tested against a Dome workspace on October 1, 2026. For anything about DeepInfra itself, see DeepInfra's documentation.

Rules

Approved regions only

Applied to an agent, this refuses any connection not tagged region: us. A new connection stays out of reach until someone tags it.

forbid (principal, action == Dome::Action::"llm:invoke", resource is Dome::LLMModel)
unless { resource has region && resource.region == "us" };

Agent workflow

Bringing it together

Connecting DeepInfra to registered agents, tools, and identity in Dome completes a governed agent application.

Dome

Control point

Gateway

  • Rules
  • Guards
  • Quotas

Every call decided and audited

FAQ

Common questions

How does Dome connect to DeepInfra?

Through DeepInfra's OpenAI-compatible endpoint, https://api.deepinfra.com/v1/openai. Your key goes out as a bearer header from Dome, never from the agent.

Which model ids does DeepInfra use?

Repo-style ids with the publisher first, such as deepseek-ai/DeepSeek-V4-Flash-0731 or google/gemma-4-31B-it.

Does Dome know where a model runs?

Only what you tag. Connection attributes are your own vocabulary, and rules read them on every call.

Next steps

Talk with our FDE team

Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.