Groq API and Dome
Fast open-weight models on Groq, with every call governed.
Groq runs open-weight models like gpt-oss-120b and Llama. Connect it to Dome and a rule can hold an agent to open weights, whatever model name it asks for. OpenRouter answers for gpt-oss-120b when Groq can't.
How Dome helps
Dome provides model brokering and routing for Groq
Groq's key, Dome's custody
The Groq key is stored in Dome and attached per request. An agent only ever has its Dome key.
Groq first, OpenRouter second
Both serve gpt-oss-120b. In one pool, OpenRouter answers whatever Groq drops.
Open weights by rule
Tag connections that serve open-weight models. A rule keeps an agent on them, whatever model name it sends.
Get started
Connect Groq in three steps
Add gpt-oss-120b on Groq, put OpenRouter behind it, and aim agents at the Gateway.
01
Add the connection
The provider id is groq. Dome uses https://api.groq.com/openai/v1 and Groq's own model ids.
$ dome models add gpt-oss-groq \--provider groq \--model openai/gpt-oss-120b \--api-key "$GROQ_API_KEY" \--attributes '{"weights":"open"}' \--gateway prod-gateway02
Pool it with OpenRouter
Groq is priority 0. Agents ask for gpt-oss-120b, the pool's name.
$ dome models pool create gpt-oss-120b \--failover-max all --gateway prod-gateway$ dome models pool member add gpt-oss-120b gpt-oss-groq --priority 0$ dome models pool member add gpt-oss-120b gpt-oss-openrouter --priority 103
Point your agent at the Gateway
Any client that speaks the OpenAI API works. Swap in the Gateway URL and a Dome agent key.
from openai import OpenAIclient = OpenAI(base_url=f"{GATEWAY_URL}/v1", api_key=DOME_AGENT_KEY)client.chat.completions.create(model="gpt-oss-120b",messages=[{"role": "user", "content": "Route this message: sales, support or billing."}],)
Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Groq itself, see Groq's documentation.
Rules
This agent uses open-weight models only
Applied to one agent with --agent, this refuses any connection not tagged weights: open. The intent router can't reach a frontier model by asking for one.
forbid (principal, action == Dome::Action::"llm:invoke", resource is Dome::LLMModel)unless { resource has weights && resource.weights == "open" };Agent workflow
Bringing it together
Connecting Groq to registered agents, tools, and identity in Dome completes a governed agent application.
Acting for
Agent
Control point
Gateway
- Rules
- Guards
- Quotas
Every call decided and audited
Models
Provider
Groq
This page
Provider
OpenRouter
See how
FAQ
Common questions
How does Dome connect to Groq?
Through Groq's OpenAI-compatible API at https://api.groq.com/openai/v1, with the Groq key added by Dome as a bearer header.
Which Groq models can I use?
Use Groq's own ids, such as openai/gpt-oss-120b or llama-3.3-70b-versatile.
Does the Responses API work on Groq connections?
No. Groq connections carry chat completions.
Explore
More of what Dome works with
Model
Claude Fable
Fable 5.1 from Anthropic and Amazon Bedrock in one failover pool, open to one group and capped by quota.
Read moreMCP server
GitHub
The GitHub MCP server behind the Tool Gateway, with rules that decide each call on its owner and repository.
Read moreIdentity
Okta
Okta tokens verified on every agent call, so rules and audit name the person each agent acted for.
Read moreRuntime
LangGraph
LangGraph agents with their model calls on the Model Broker and their MCP tools on the Tool Gateway.
Read moreClient
Claude Code
Claude Code on a Dome Gateway with per-developer sign-in, rules on every tool call, and audit by name.
Read moreAgent service
TinyFish
TinyFish's web agents behind the Tool Gateway, with rules that decide each run on the site it targets.
Read moreNext steps
Talk with our FDE team
Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.
No card required to start. Register your first agent in minutes.
LLM providers for AI agents: one governed path to every model
Connect a provider once. Its key stays in Dome, and every agent call to it is authorized, metered and audited.
See them all