Dome Systems

Mistral API and Dome

Mistral behind one Gateway, with every call governed.

Put Mistral behind Dome and tag its connections region: eu. A rule then holds work done for EU staff to those connections, and Mistral Medium stands behind Large in one pool.

PeopleAgentsDomePool: mistral-largeCallersPeopleAgentshr-assistantAgentssupport-agentAgentscontract-reviewerGatewaysprod-gatewayMistral LargePriority 0Mistral MediumPriority 1OpenAIgpt-6-sol, no region tagRulesGuardsAuditsaudit-trail
hr-assistant→mistral-large· as l.moreauAllowed

How Dome helps

Dome provides model brokering and routing for Mistral

One Mistral key for every team

Dome stores the Mistral key and attaches it to each request. Agents present their own Dome keys, so revoking one leaves the rest running.

EU work on EU connections

Tag Mistral connections region: eu. A rule refuses any untagged connection for EU staff.

A smaller model as fallback

Pool Mistral Large with Mistral Medium behind it. When Large fails, the call goes to Medium.

Get started

Connect Mistral in three steps

Add Large and Medium, pool them, and give your agents the Gateway URL.

  1. 01

    Add the connections

    The provider id is mistral. Dome uses https://api.mistral.ai/v1 and Mistral's own model ids.

    $ dome models add mistral-large-eu \
    --provider mistral \
    --model mistral-large-latest \
    --api-key "$MISTRAL_API_KEY" \
    --attributes '{"region":"eu"}' \
    --gateway prod-gateway
     
    $ dome models add mistral-medium-eu \
    --provider mistral \
    --model mistral-medium-latest \
    --api-key "$MISTRAL_API_KEY" \
    --attributes '{"region":"eu"}' \
    --gateway prod-gateway
  2. 02

    Pool them

    Large is priority 0 and Medium priority 1. Agents ask for mistral-large, the pool.

    $ dome models pool create mistral-large \
    --failover-max all --gateway prod-gateway
     
    $ dome models pool member add mistral-large mistral-large-eu --priority 0
    $ dome models pool member add mistral-large mistral-medium-eu --priority 1
  3. 03

    Point your agent at the Gateway

    Swap Mistral's base URL for the Gateway's, and the Mistral key for the agent's Dome key.

    from openai import OpenAI
     
    client = OpenAI(base_url=f"{GATEWAY_URL}/v1", api_key=DOME_AGENT_KEY)
    client.chat.completions.create(
    model="mistral-large",
    messages=[{"role": "user", "content": "Draft a reply to this employee question."}],
    )

Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Mistral itself, see Mistral AI's documentation.

Rules

EU staff stay on EU connections

When the person an agent acts for is in eu-staff, only connections tagged region: eu are allowed. Dome reads the group from that person's verified token.

forbid (principal, action == Dome::Action::"llm:invoke", resource is Dome::LLMModel)
when {
principal has act_as &&
principal.act_as.groups.contains("eu-staff")
}
unless { resource has region && resource.region == "eu" };

Agent workflow

Bringing it together

Connecting Mistral to registered agents, tools, and identity in Dome completes a governed agent application.

Dome

Control point

Gateway

  • Rules
  • Guards
  • Quotas

Every call decided and audited

Models

Provider

Mistral

This page

Provider

OpenRouter

See how

FAQ

Common questions

How does Dome connect to Mistral?

Through Mistral's OpenAI-compatible API at https://api.mistral.ai/v1. Dome adds your key as a bearer header on the way out.

Can I use mistral-large-latest or a pinned version?

Either. A connection carries whatever id Mistral accepts, and agents ask for the pool.

Does the region tag change where Mistral runs the model?

No. The tag is something you assert for rules to read. Your Mistral account settings decide where it processes data.

Next steps

Talk with our FDE team

Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.