Moonshot AI and Dome
Trial Kimi with one team. Every call governed.
Kimi K3 is the default when you pick Moonshot AI in Dome's model picker. Connect it, tag the connection stage: trial, and only the team running the evaluation gets through. Everyone else's call is refused and audited.
How Dome helps
Dome provides model brokering and routing for Moonshot AI
Trial access, not key access
The team trying Kimi uses Dome keys. Moonshot's key stays in Dome, so ending the trial never means rotating it.
Kimi models in the picker
Kimi K3, Kimi K2.7 Code and Kimi K2.6 are listed in Dome's model picker. Any other model id Moonshot accepts works too.
A trial for one team
Tag the connection stage: trial. A rule lets only the team running the evaluation use it.
Get started
Connect Moonshot AI in three steps
Add Kimi K3 from Moonshot, pool it with Fireworks AI's copy, and move agents onto the Gateway.
01
Add the connections
The provider id is moonshot. Dome uses https://api.moonshot.ai/v1 and Moonshot's own model ids; Fireworks uses its own.
$ dome models add kimi-moonshot \--provider moonshot \--model kimi-k3 \--api-key "$MOONSHOT_API_KEY" \--attributes '{"stage":"trial"}' \--gateway prod-gateway$ dome models add kimi-fireworks \--provider fireworks \--model accounts/fireworks/models/kimi-k3 \--api-key "$FIREWORKS_API_KEY" \--attributes '{"stage":"trial"}' \--gateway prod-gateway02
Pool them
Moonshot answers first and Fireworks second. The evaluation agents call kimi-k3, the pool.
$ dome models pool create kimi-k3 \--failover-max all --gateway prod-gateway$ dome models pool member add kimi-k3 kimi-moonshot --priority 0$ dome models pool member add kimi-k3 kimi-fireworks --priority 103
Point your agent at the Gateway
Code written for Moonshot's API runs against the Gateway once it carries the agent's Dome key.
from openai import OpenAIclient = OpenAI(base_url=f"{GATEWAY_URL}/v1", api_key=DOME_AGENT_KEY)client.chat.completions.create(model="kimi-k3",messages=[{"role": "user", "content": "Write tests for this module."}],)
Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Moonshot AI itself, see Moonshot AI's documentation.
Rules
Trial models for the evaluation team only
Connections tagged stage: trial refuse every call unless the person the agent acts for is in model-evals. Drop the tag when the trial ends.
forbid (principal, action == Dome::Action::"llm:invoke", resource is Dome::LLMModel)when { resource has stage && resource.stage == "trial" }unless { principal has act_as && principal.act_as.groups.contains("model-evals")};Try it
One call, two outcomes
Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.
Acting for
- Agenteval-runner is registered and active
- Callera.novak verified, groups: model-evals
- RuleTrial connections are open to model-evals
Agent workflow
Bringing it together
Connecting Moonshot AI to registered agents, tools, and identity in Dome completes a governed agent application.
Acting for
Control point
Gateway
- Rules
- Guards
- Quotas
Every call decided and audited
Models
FAQ
Common questions
How does Dome connect to Moonshot AI?
Through Moonshot's OpenAI-compatible API at https://api.moonshot.ai/v1. Dome attaches the Moonshot key to each request as a bearer header.
Which Kimi models can I use?
Any model id Moonshot accepts. Dome's model picker lists Kimi K3, Kimi K2.7 Code and Kimi K2.6.
Can I use Kimi K3 from another provider?
Yes. Fireworks serves it as accounts/fireworks/models/kimi-k3 and Together as moonshotai/Kimi-K3, and a pool can put either behind Moonshot.
Explore
More of what Dome works with
Model
Claude Fable
Fable 5.1 from Anthropic and Amazon Bedrock in one failover pool, open to one group and capped by quota.
Read moreMCP server
GitHub
The GitHub MCP server behind the Tool Gateway, with rules that decide each call on its owner and repository.
Read moreIdentity
Okta
Okta tokens verified on every agent call, so rules and audit name the person each agent acted for.
Read moreRuntime
LangGraph
LangGraph agents with their model calls on the Model Broker and their MCP tools on the Tool Gateway.
Read moreClient
Codex
Codex on a Dome Gateway with per-developer sign-in, rules on every tool call, and audit by name.
Read moreAgent service
TinyFish
TinyFish's web agents behind the Tool Gateway, with rules that decide each run on the site it targets.
Read moreNext steps
Talk with our FDE team
Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.
No card required to start. Register your first agent in minutes.
LLM providers for AI agents: one governed path to every model
Connect a provider once. Its key stays in Dome, and every agent call to it is authorized, metered and audited.
See them all