Dome Systems

DeepSeek API and Dome

DeepSeek for the work that can use it. Rules for the work that can't.

Connect DeepSeek to Dome and tag each connection with where it runs. People handling regulated data are held to connections tagged residency: us, and everyone else can call DeepSeek directly. Together AI hosts the same V4 Pro.

PeopleAgentsDomePool: deepseek-v4-proCallersPeopleAgentscoding-agentAgentsclaims-assistantAgentsdoc-summarizerGatewaysprod-gatewayDeepSeekPriority 0Together AIPriority 1, residency: usTogether AIDeepSeek V4 Pro, residency: usRulesGuardsAuditsaudit-trail
coding-agent→deepseek-v4-pro· as d.chenAllowed

How Dome helps

Dome provides model brokering and routing for DeepSeek

No DeepSeek key on the client

Dome keeps DeepSeek's key and adds it to each request. Agents carry Dome keys, and only Dome talks to DeepSeek.

Residency by rule

Tag each connection with where it runs. A rule keeps people who handle regulated data on the connections you approved.

The same model, another host

Together AI hosts DeepSeek V4 Pro too. Pool them and Together answers whatever DeepSeek can't.

Get started

Connect DeepSeek in three steps

Add DeepSeek and Together's copy of V4 Pro, pool them, and route agents through the Gateway.

  1. 01

    Add the connections

    The provider id is deepseek. Dome uses https://api.deepseek.com/v1 and DeepSeek's own model ids; Together uses its own.

    $ dome models add deepseek-direct \
    --provider deepseek \
    --model deepseek-v4-pro \
    --api-key "$DEEPSEEK_API_KEY" \
    --gateway prod-gateway
     
    $ dome models add deepseek-together \
    --provider together \
    --model deepseek-ai/DeepSeek-V4-Pro-0813 \
    --api-key "$TOGETHER_API_KEY" \
    --attributes '{"residency":"us"}' \
    --gateway prod-gateway
  2. 02

    Pool them

    DeepSeek goes first and Together second. Agents call deepseek-v4-pro, the pool.

    $ dome models pool create deepseek-v4-pro \
    --failover-max all --gateway prod-gateway
     
    $ dome models pool member add deepseek-v4-pro deepseek-direct --priority 0
    $ dome models pool member add deepseek-v4-pro deepseek-together --priority 1
  3. 03

    Point your agent at the Gateway

    Swap the base URL for the Gateway and DeepSeek's key for the agent's. OpenAI-compatible code runs as before.

    from openai import OpenAI
     
    client = OpenAI(base_url=f"{GATEWAY_URL}/v1", api_key=DOME_AGENT_KEY)
    client.chat.completions.create(
    model="deepseek-v4-pro",
    messages=[{"role": "user", "content": "Refactor this function and explain the change."}],
    )

Commands and rules tested against a Dome workspace on October 1, 2026. For anything about DeepSeek itself, see DeepSeek's documentation.

Rules

Regulated data stays on approved connections

When the person an agent acts for is in regulated-data, only connections tagged residency: us are allowed. Everyone else can use DeepSeek directly.

forbid (principal, action == Dome::Action::"llm:invoke", resource is Dome::LLMModel)
when {
principal has act_as &&
principal.act_as.groups.contains("regulated-data")
}
unless { resource has residency && resource.residency == "us" };

Try it

One call, two outcomes

Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.

Connection

agent claims-assistant · acting as m.ortiz
llm:invoke(model: "deepseek-together")
  1. Agentclaims-assistant is registered and active
  2. Callerm.ortiz verified, groups: regulated-data
  3. RuleConnection is tagged residency: us
DecisionAllowed

Agent workflow

Bringing it together

Connecting DeepSeek to registered agents, tools, and identity in Dome completes a governed agent application.

Dome

Control point

Gateway

  • Rules
  • Guards
  • Quotas

Every call decided and audited

FAQ

Common questions

How does Dome connect to DeepSeek?

Through DeepSeek's OpenAI-compatible API at https://api.deepseek.com/v1. Only Dome sends the DeepSeek key, as a bearer header.

Which DeepSeek models can I use?

Any id DeepSeek's API accepts, such as deepseek-v4-pro or deepseek-flash.

Does the residency tag change where DeepSeek processes data?

No. The tag is your label, read by rules. DeepSeek's terms decide where it processes data.

Can I run DeepSeek models without calling DeepSeek's API?

Yes. Together and DeepInfra serve DeepSeek V4 Pro under their own model ids, and a pool can put them behind DeepSeek or in its place.

Next steps

Talk with our FDE team

Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.