Dome Systems

Fireworks AI API and Dome

Open models on Fireworks AI, with every call governed.

Fireworks AI serves Kimi, DeepSeek and gpt-oss under its own full model ids. Connect it to Dome and rules read who each agent is acting for, so a coding model stays with engineers. Together AI picks up Kimi K3 when Fireworks fails.

PeopleAgentsDomeFireworks AI modelsCallersPeopleAgentsdev-agentAgentscode-reviewerAgentssales-assistantGatewaysprod-gatewayKimi K3accounts/fireworks/models/kimi-k3DeepSeek V3.1accounts/fireworks/models/deepseek-v3p1Together AIKimi failover, priority 1RulesGuardsAuditsaudit-trail
dev-agent→kimi-k3· as r.chenAllowed

How Dome helps

Dome provides model brokering and routing for Fireworks AI

No Fireworks key in agent code

Dome keeps the Fireworks key and adds it on the way out. Your agents carry Dome keys, one per agent.

Kimi K3 on two hosts

Together AI serves Kimi K3 too. With both in a pool, a Fireworks failure becomes a Together answer.

Models by team

Rules read the verified user an agent acts for. Keep a coding model for engineers, even when another agent asks for it.

Get started

Connect Fireworks AI in three steps

Add Kimi K3 on Fireworks, pool it with Together AI, and send agents to the Gateway.

  1. 01

    Add the connection

    The provider id is fireworks. Dome uses https://api.fireworks.ai/inference/v1 and Fireworks' full model ids.

    $ dome models add kimi-fireworks \
    --provider fireworks \
    --model accounts/fireworks/models/kimi-k3 \
    --api-key "$FIREWORKS_API_KEY" \
    --attributes '{"family":"kimi"}' \
    --gateway prod-gateway
  2. 02

    Pool it with Together AI

    Add moonshotai/Kimi-K3 on Together as a second connection, ranked behind Fireworks.

    $ dome models pool create kimi-k3 \
    --failover-max all --gateway prod-gateway
     
    $ dome models pool member add kimi-k3 kimi-fireworks --priority 0
    $ dome models pool member add kimi-k3 kimi-together --priority 1
  3. 03

    Point your agent at the Gateway

    The OpenAI SDK works as is. Give it the Gateway URL and the agent's Dome key.

    from openai import OpenAI
     
    client = OpenAI(base_url=f"{GATEWAY_URL}/v1", api_key=DOME_AGENT_KEY)
    client.chat.completions.create(
    model="kimi-k3",
    messages=[{"role": "user", "content": "Review this diff for bugs."}],
    )

Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Fireworks AI itself, see Fireworks AI's documentation.

Rules

Kimi for engineering only

Applied to an agent, this refuses connections tagged family: kimi unless the verified user is in the engineering group. Other models are untouched.

forbid (principal, action == Dome::Action::"llm:invoke", resource is Dome::LLMModel)
when { resource has family && resource.family == "kimi" }
unless { principal has act_as && principal.act_as.groups.contains("engineering") };

Agent workflow

Bringing it together

Connecting Fireworks AI to registered agents, tools, and identity in Dome completes a governed agent application.

Dome

Control point

Gateway

  • Rules
  • Guards
  • Quotas

Every call decided and audited

FAQ

Common questions

How does Dome connect to Fireworks AI?

Through Fireworks' OpenAI-compatible inference API at https://api.fireworks.ai/inference/v1. Dome adds the Fireworks key as a bearer header.

Which model ids do I use for Fireworks AI?

Fireworks' full ids, such as accounts/fireworks/models/kimi-k3 or accounts/fireworks/models/gpt-oss-120b. Use them as written.

Can rules depend on who the agent is acting for?

Yes. A rule can read the verified user's groups and refuse a model to everyone outside one team.

Next steps

Talk with our FDE team

Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.