DeepSeek API and Dome
DeepSeek for the work that can use it. Rules for the work that can't.
Connect DeepSeek to Dome and tag each connection with where it runs. People handling regulated data are held to connections tagged residency: us, and everyone else can call DeepSeek directly. Together AI hosts the same V4 Pro.
How Dome helps
Dome provides model brokering and routing for DeepSeek
No DeepSeek key on the client
Dome keeps DeepSeek's key and adds it to each request. Agents carry Dome keys, and only Dome talks to DeepSeek.
Residency by rule
Tag each connection with where it runs. A rule keeps people who handle regulated data on the connections you approved.
The same model, another host
Together AI hosts DeepSeek V4 Pro too. Pool them and Together answers whatever DeepSeek can't.
Get started
Connect DeepSeek in three steps
Add DeepSeek and Together's copy of V4 Pro, pool them, and route agents through the Gateway.
01
Add the connections
The provider id is deepseek. Dome uses https://api.deepseek.com/v1 and DeepSeek's own model ids; Together uses its own.
$ dome models add deepseek-direct \--provider deepseek \--model deepseek-v4-pro \--api-key "$DEEPSEEK_API_KEY" \--gateway prod-gateway$ dome models add deepseek-together \--provider together \--model deepseek-ai/DeepSeek-V4-Pro-0813 \--api-key "$TOGETHER_API_KEY" \--attributes '{"residency":"us"}' \--gateway prod-gateway02
Pool them
DeepSeek goes first and Together second. Agents call deepseek-v4-pro, the pool.
$ dome models pool create deepseek-v4-pro \--failover-max all --gateway prod-gateway$ dome models pool member add deepseek-v4-pro deepseek-direct --priority 0$ dome models pool member add deepseek-v4-pro deepseek-together --priority 103
Point your agent at the Gateway
Swap the base URL for the Gateway and DeepSeek's key for the agent's. OpenAI-compatible code runs as before.
from openai import OpenAIclient = OpenAI(base_url=f"{GATEWAY_URL}/v1", api_key=DOME_AGENT_KEY)client.chat.completions.create(model="deepseek-v4-pro",messages=[{"role": "user", "content": "Refactor this function and explain the change."}],)
Commands and rules tested against a Dome workspace on October 1, 2026. For anything about DeepSeek itself, see DeepSeek's documentation.
Rules
Regulated data stays on approved connections
When the person an agent acts for is in regulated-data, only connections tagged residency: us are allowed. Everyone else can use DeepSeek directly.
forbid (principal, action == Dome::Action::"llm:invoke", resource is Dome::LLMModel)when { principal has act_as && principal.act_as.groups.contains("regulated-data")}unless { resource has residency && resource.residency == "us" };Try it
One call, two outcomes
Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.
Connection
- Agentclaims-assistant is registered and active
- Callerm.ortiz verified, groups: regulated-data
- RuleConnection is tagged residency: us
Agent workflow
Bringing it together
Connecting DeepSeek to registered agents, tools, and identity in Dome completes a governed agent application.
Acting for
Control point
Gateway
- Rules
- Guards
- Quotas
Every call decided and audited
Models
FAQ
Common questions
How does Dome connect to DeepSeek?
Through DeepSeek's OpenAI-compatible API at https://api.deepseek.com/v1. Only Dome sends the DeepSeek key, as a bearer header.
Which DeepSeek models can I use?
Any id DeepSeek's API accepts, such as deepseek-v4-pro or deepseek-flash.
Does the residency tag change where DeepSeek processes data?
No. The tag is your label, read by rules. DeepSeek's terms decide where it processes data.
Can I run DeepSeek models without calling DeepSeek's API?
Yes. Together and DeepInfra serve DeepSeek V4 Pro under their own model ids, and a pool can put them behind DeepSeek or in its place.
Explore
More of what Dome works with
Model
Claude Fable
Fable 5.1 from Anthropic and Amazon Bedrock in one failover pool, open to one group and capped by quota.
Read moreMCP server
GitHub
The GitHub MCP server behind the Tool Gateway, with rules that decide each call on its owner and repository.
Read moreIdentity
Microsoft Entra ID
Entra access tokens verified on every agent call, so rules read app roles and audit names the person.
Read moreRuntime
LangGraph
LangGraph agents with their model calls on the Model Broker and their MCP tools on the Tool Gateway.
Read moreClient
Claude Code
Claude Code on a Dome Gateway with per-developer sign-in, rules on every tool call, and audit by name.
Read moreAgent service
TinyFish
TinyFish's web agents behind the Tool Gateway, with rules that decide each run on the site it targets.
Read moreNext steps
Talk with our FDE team
Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.
No card required to start. Register your first agent in minutes.
LLM providers for AI agents: one governed path to every model
Connect a provider once. Its key stays in Dome, and every agent call to it is authorized, metered and audited.
See them all