Mistral API and Dome
Mistral behind one Gateway, with every call governed.
Put Mistral behind Dome and tag its connections region: eu. A rule then holds work done for EU staff to those connections, and Mistral Medium stands behind Large in one pool.
How Dome helps
Dome provides model brokering and routing for Mistral
One Mistral key for every team
Dome stores the Mistral key and attaches it to each request. Agents present their own Dome keys, so revoking one leaves the rest running.
EU work on EU connections
Tag Mistral connections region: eu. A rule refuses any untagged connection for EU staff.
A smaller model as fallback
Pool Mistral Large with Mistral Medium behind it. When Large fails, the call goes to Medium.
Get started
Connect Mistral in three steps
Add Large and Medium, pool them, and give your agents the Gateway URL.
01
Add the connections
The provider id is mistral. Dome uses https://api.mistral.ai/v1 and Mistral's own model ids.
$ dome models add mistral-large-eu \--provider mistral \--model mistral-large-latest \--api-key "$MISTRAL_API_KEY" \--attributes '{"region":"eu"}' \--gateway prod-gateway$ dome models add mistral-medium-eu \--provider mistral \--model mistral-medium-latest \--api-key "$MISTRAL_API_KEY" \--attributes '{"region":"eu"}' \--gateway prod-gateway02
Pool them
Large is priority 0 and Medium priority 1. Agents ask for mistral-large, the pool.
$ dome models pool create mistral-large \--failover-max all --gateway prod-gateway$ dome models pool member add mistral-large mistral-large-eu --priority 0$ dome models pool member add mistral-large mistral-medium-eu --priority 103
Point your agent at the Gateway
Swap Mistral's base URL for the Gateway's, and the Mistral key for the agent's Dome key.
from openai import OpenAIclient = OpenAI(base_url=f"{GATEWAY_URL}/v1", api_key=DOME_AGENT_KEY)client.chat.completions.create(model="mistral-large",messages=[{"role": "user", "content": "Draft a reply to this employee question."}],)
Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Mistral itself, see Mistral AI's documentation.
Rules
EU staff stay on EU connections
When the person an agent acts for is in eu-staff, only connections tagged region: eu are allowed. Dome reads the group from that person's verified token.
forbid (principal, action == Dome::Action::"llm:invoke", resource is Dome::LLMModel)when { principal has act_as && principal.act_as.groups.contains("eu-staff")}unless { resource has region && resource.region == "eu" };Agent workflow
Bringing it together
Connecting Mistral to registered agents, tools, and identity in Dome completes a governed agent application.
Acting for
Control point
Gateway
- Rules
- Guards
- Quotas
Every call decided and audited
Models
Provider
Mistral
This page
Provider
OpenRouter
See how
FAQ
Common questions
How does Dome connect to Mistral?
Through Mistral's OpenAI-compatible API at https://api.mistral.ai/v1. Dome adds your key as a bearer header on the way out.
Can I use mistral-large-latest or a pinned version?
Either. A connection carries whatever id Mistral accepts, and agents ask for the pool.
Does the region tag change where Mistral runs the model?
No. The tag is something you assert for rules to read. Your Mistral account settings decide where it processes data.
Explore
More of what Dome works with
Model
Claude Fable
Fable 5.1 from Anthropic and Amazon Bedrock in one failover pool, open to one group and capped by quota.
Read moreMCP server
GitHub
The GitHub MCP server behind the Tool Gateway, with rules that decide each call on its owner and repository.
Read moreIdentity
Okta
Okta tokens verified on every agent call, so rules and audit name the person each agent acted for.
Read moreRuntime
OpenAI Agents SDK
OpenAI Agents SDK agents with their models on the Model Broker and their MCP tools on the Tool Gateway.
Read moreClient
Claude Code
Claude Code on a Dome Gateway with per-developer sign-in, rules on every tool call, and audit by name.
Read moreAgent service
TinyFish
TinyFish's web agents behind the Tool Gateway, with rules that decide each run on the site it targets.
Read moreNext steps
Talk with our FDE team
Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.
No card required to start. Register your first agent in minutes.
LLM providers for AI agents: one governed path to every model
Connect a provider once. Its key stays in Dome, and every agent call to it is authorized, metered and audited.
See them all