OpenAI API and Dome
One OpenAI key. Every agent call tied to a person.
Connect the OpenAI API to Dome once. Each call then names the agent that made it and the verified person it was for, and OpenAI's key never leaves Dome's vault.
How Dome helps
Dome provides model brokering and routing for OpenAI
OpenAI's key stays in the vault
Dome adds it as a Bearer header when a call goes out. Each read is audited.
Every call made for someone
A rule can refuse any call without a verified person behind it. Audit then names who each call was for.
Spend by agent, not by key
One OpenAI key carries every agent's usage. Dome splits it by agent and person, and a quota stops a loop at its ceiling.
Get started
Connect OpenAI in three steps
Add a connection per model, pool it with Azure for failover, and swap the base URL in your OpenAI SDK code.
01
Add the connection
The provider id is openai. Dome fills in https://api.openai.com and adds the Bearer prefix to your key.
$ dome models add gpt-openai \--provider openai \--model gpt-6-sol \--api-key "$OPENAI_API_KEY" \--gateway prod-gateway02
Pool it with Azure for failover
Add an Azure OpenAI connection for the same model and pool the two. Agents send the pool's name.
$ dome models pool create gpt-6-sol \--failover-max all --gateway prod-gateway$ dome models pool member add gpt-6-sol gpt-openai --priority 0$ dome models pool member add gpt-6-sol gpt-azure --priority 103
Point your agent at the Gateway
The OpenAI SDK takes the Gateway URL with /v1 as its base. The agent's Dome key replaces the OpenAI key.
from openai import OpenAIclient = OpenAI(base_url=f"{GATEWAY_URL}/v1", api_key=DOME_AGENT_KEY)client.responses.create(model="gpt-6-sol",input="Draft a reply to this ticket.",)
Commands and rules tested against a Dome workspace on October 1, 2026. For anything about OpenAI itself, see OpenAI's documentation.
Rules
No call without a person behind it
Applied to an agent, this refuses any OpenAI call that doesn't carry a verified acting-as identity. Unattended runs need their own agent.
forbid (principal, action == Dome::Action::"llm:invoke", resource is Dome::LLMModel)unless { principal has act_as };Agent workflow
Bringing it together
Connecting OpenAI to registered agents, tools, and identity in Dome completes a governed agent application.
Acting for
Control point
Gateway
- Rules
- Guards
- Quotas
Every call decided and audited
Models
Provider
OpenAI
This page
Model
GPT
See how
FAQ
Common questions
How does Dome authenticate to OpenAI?
With your OpenAI API key, stored in Dome's vault and sent as an Authorization: Bearer header. Agents never see it.
Which OpenAI models can I use?
Any model id OpenAI accepts. The dashboard suggests current ones, from GPT-6 Astra to GPT-4o mini.
Do the Responses API and embeddings work through Dome?
Yes. OpenAI connections serve chat completions, Responses, embeddings and moderation.
Do I need to change my agent code?
The base URL becomes the Gateway's /v1 path and the key becomes the agent's Dome key. Nothing else.
Explore
More of what Dome works with
Model
Claude Fable
Fable 5.1 from Anthropic and Amazon Bedrock in one failover pool, open to one group and capped by quota.
Read moreMCP server
GitHub
The GitHub MCP server behind the Tool Gateway, with rules that decide each call on its owner and repository.
Read moreIdentity
Okta
Okta tokens verified on every agent call, so rules and audit name the person each agent acted for.
Read moreRuntime
LangGraph
LangGraph agents with their model calls on the Model Broker and their MCP tools on the Tool Gateway.
Read moreClient
Claude Code
Claude Code on a Dome Gateway with per-developer sign-in, rules on every tool call, and audit by name.
Read moreAgent service
TinyFish
TinyFish's web agents behind the Tool Gateway, with rules that decide each run on the site it targets.
Read moreNext steps
Talk with our FDE team
Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.
No card required to start. Register your first agent in minutes.
LLM providers for AI agents: one governed path to every model
Connect a provider once. Its key stays in Dome, and every agent call to it is authorized, metered and audited.
See them all