Dome Systems

Gemini on Vertex AI and Dome

Gemini on Vertex AI, with the service account kept in Dome.

Dome reaches Gemini through Vertex AI in your Google Cloud project. The service account key lives in Dome's vault, and Dome trades it for short-lived Google tokens on each call. Agents authenticate as themselves, and rules decide who gets which model.

PeopleAgentsDomeVertex AI: acme-agentsCallersPeopleAgentssupport-agentAgentsresearch-agentAgentsdoc-extractorGatewaysprod-gatewayGemini 3.8 Flashgemini-3.8-flashGemini 3.1 Progemini-3.1-proGemini 3.5 Flash-Litegemini-3.5-flash-liteRulesGuardsAuditsaudit-trail
support-agent→gemini-flash· as r.alvarezAllowed

How Dome helps

Dome provides model brokering and routing for Google Gemini

The service account stays in Dome

The JSON key sits in Dome's vault. Dome exchanges it for short-lived Google tokens, and agents never see either.

Models by team

Tag each Vertex connection with its tier. A rule keeps the support team on Flash.

One project, many agents

Every call is metered against the agent and the person it acted for. Spend is attributed per agent, not per project.

Get started

Connect Vertex AI in two steps

Add a connection per Gemini model with your project and location, then point agents at the Gateway.

  1. 01

    Add the connection

    The provider id is google. Pass the service account's JSON key as the credential; location defaults to us-central1.

    $ dome models add gemini-flash \
    --provider google \
    --model gemini-3.8-flash \
    --provider-config '{"project":"acme-agents","location":"us-central1"}' \
    --api-key "$(cat vertex-sa.json)" \
    --attributes '{"tier":"flash"}' \
    --gateway prod-gateway
  2. 02

    Point your agent at the Gateway

    Any OpenAI-compatible client works. Dome translates each request to Gemini's format and back.

    from openai import OpenAI
     
    client = OpenAI(base_url=f"{GATEWAY_URL}/v1", api_key=DOME_AGENT_KEY)
    client.chat.completions.create(
    model="gemini-flash",
    messages=[{"role": "user", "content": "Summarize this support thread."}],
    )

Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Google Gemini itself, see Google Cloud's documentation.

Rules

Support stays on Flash

Refuses connections tagged pro when the person the agent acts for is in support. Other teams can use either.

forbid (principal, action == Dome::Action::"llm:invoke", resource is Dome::LLMModel)
when {
resource has tier && resource.tier == "pro" &&
principal has act_as &&
principal.act_as.groups.contains("support")
};

Agent workflow

Bringing it together

Connecting Google Gemini to registered agents, tools, and identity in Dome completes a governed agent application.

Dome

Control point

Gateway

  • Rules
  • Guards
  • Quotas

Every call decided and audited

Models

Provider

Google Gemini

This page

Model

Gemini

See how

FAQ

Common questions

Does Dome use the Gemini API or Vertex AI?

Vertex AI. Gemini API keys from Google AI Studio are not supported.

How does Dome authenticate to Google?

With a service account JSON key in Dome's vault, exchanged for an OAuth access token on each call.

What does a connection need?

The model id, your Google Cloud project and a location. Dome builds the regional Vertex endpoint from them.

Do Gemini embeddings work through Dome?

Yes. Dome calls Vertex AI's predict endpoint for embeddings.

Next steps

Talk with our FDE team

Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.