Dome Systems

OpenAI API and Dome

One OpenAI key. Every agent call tied to a person.

Connect the OpenAI API to Dome once. Each call then names the agent that made it and the verified person it was for, and OpenAI's key never leaves Dome's vault.

PeopleAgentsDomeOpenAI modelsCallersPeopleAgentssupport-agentAgentscoding-agentAgentsnightly-reportGatewaysprod-gatewayGPT-6 Astragpt-6-astraGPT-6 Solgpt-6-solGPT-6 Lunagpt-6-lunaRulesGuardsAuditsaudit-trail
coding-agent→gpt-6-astra· as d.chenAllowed

How Dome helps

Dome provides model brokering and routing for OpenAI

OpenAI's key stays in the vault

Dome adds it as a Bearer header when a call goes out. Each read is audited.

Every call made for someone

A rule can refuse any call without a verified person behind it. Audit then names who each call was for.

Spend by agent, not by key

One OpenAI key carries every agent's usage. Dome splits it by agent and person, and a quota stops a loop at its ceiling.

Get started

Connect OpenAI in three steps

Add a connection per model, pool it with Azure for failover, and swap the base URL in your OpenAI SDK code.

  1. 01

    Add the connection

    The provider id is openai. Dome fills in https://api.openai.com and adds the Bearer prefix to your key.

    $ dome models add gpt-openai \
    --provider openai \
    --model gpt-6-sol \
    --api-key "$OPENAI_API_KEY" \
    --gateway prod-gateway
  2. 02

    Pool it with Azure for failover

    Add an Azure OpenAI connection for the same model and pool the two. Agents send the pool's name.

    $ dome models pool create gpt-6-sol \
    --failover-max all --gateway prod-gateway
     
    $ dome models pool member add gpt-6-sol gpt-openai --priority 0
    $ dome models pool member add gpt-6-sol gpt-azure --priority 1
  3. 03

    Point your agent at the Gateway

    The OpenAI SDK takes the Gateway URL with /v1 as its base. The agent's Dome key replaces the OpenAI key.

    from openai import OpenAI
     
    client = OpenAI(base_url=f"{GATEWAY_URL}/v1", api_key=DOME_AGENT_KEY)
    client.responses.create(
    model="gpt-6-sol",
    input="Draft a reply to this ticket.",
    )

Commands and rules tested against a Dome workspace on October 1, 2026. For anything about OpenAI itself, see OpenAI's documentation.

Rules

No call without a person behind it

Applied to an agent, this refuses any OpenAI call that doesn't carry a verified acting-as identity. Unattended runs need their own agent.

forbid (principal, action == Dome::Action::"llm:invoke", resource is Dome::LLMModel)
unless { principal has act_as };

Agent workflow

Bringing it together

Connecting OpenAI to registered agents, tools, and identity in Dome completes a governed agent application.

Dome

Control point

Gateway

  • Rules
  • Guards
  • Quotas

Every call decided and audited

Models

Provider

OpenAI

This page

Model

GPT

See how

FAQ

Common questions

How does Dome authenticate to OpenAI?

With your OpenAI API key, stored in Dome's vault and sent as an Authorization: Bearer header. Agents never see it.

Which OpenAI models can I use?

Any model id OpenAI accepts. The dashboard suggests current ones, from GPT-6 Astra to GPT-4o mini.

Do the Responses API and embeddings work through Dome?

Yes. OpenAI connections serve chat completions, Responses, embeddings and moderation.

Do I need to change my agent code?

The base URL becomes the Gateway's /v1 path and the key becomes the agent's Dome key. Nothing else.

Next steps

Talk with our FDE team

Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.