Dome Systems

OpenRouter and Dome

Hundreds of models through OpenRouter. Only the approved ones reach your agents.

One OpenRouter key reaches hundreds of models. Dome holds the key and exposes only the models you add as connections. A rule refuses anything not marked approved, and every call is metered against an agent.

PeopleAgentsDomePool: gpt-oss-120bCallersPeopleAgentseval-runnerAgentsresearch-agentAgentssummarizerGatewaysprod-gatewayGroqPriority 0OpenRouterPriority 1RulesGuardsAuditsaudit-trail
summarizer→gpt-oss-120b· scheduledAllowed

How Dome helps

Dome provides model brokering and routing for OpenRouter

One key, held in Dome

OpenRouter's key opens hundreds of models, so it stays with Dome. Agents hold their own Dome keys and never see it.

Approved models only

Each model is its own connection, tagged when it's vetted. A rule refuses every connection without the tag.

A fallback for any provider

Put OpenRouter behind a direct provider in a pool. When the first fails, the same model answers through OpenRouter.

Get started

Connect OpenRouter in three steps

Add each vetted model as a connection, put OpenRouter behind Groq, and connect agents to the Gateway.

  1. 01

    Add the connection

    The provider id is openrouter. Dome uses https://openrouter.ai/api/v1 and OpenRouter's own model ids.

    $ dome models add gpt-oss-openrouter \
    --provider openrouter \
    --model openai/gpt-oss-120b \
    --api-key "$OPENROUTER_API_KEY" \
    --attributes '{"approved":true}' \
    --gateway prod-gateway
  2. 02

    Pool it behind Groq

    Groq serves the same open-weight model and goes first. OpenRouter answers when it can't.

    $ dome models pool create gpt-oss-120b \
    --failover-max all --gateway prod-gateway
     
    $ dome models pool member add gpt-oss-120b gpt-oss-groq --priority 0
    $ dome models pool member add gpt-oss-120b gpt-oss-openrouter --priority 1
  3. 03

    Point your agent at the Gateway

    Code written for OpenRouter's API keeps working. Change the base URL to the Gateway and the key to the agent's.

    from openai import OpenAI
     
    client = OpenAI(base_url=f"{GATEWAY_URL}/v1", api_key=DOME_AGENT_KEY)
    client.chat.completions.create(
    model="gpt-oss-120b",
    messages=[{"role": "user", "content": "Summarize these release notes."}],
    )

Commands and rules tested against a Dome workspace on October 1, 2026. For anything about OpenRouter itself, see OpenRouter's documentation.

Rules

Only approved models

Applied to an agent, this refuses any connection not tagged approved. Adding a model to OpenRouter's catalog changes nothing until you vet it.

forbid (principal, action == Dome::Action::"llm:invoke", resource is Dome::LLMModel)
unless { resource has approved && resource.approved == true };

Agent workflow

Bringing it together

Connecting OpenRouter to registered agents, tools, and identity in Dome completes a governed agent application.

Dome

Control point

Gateway

  • Rules
  • Guards
  • Quotas

Every call decided and audited

Models

Provider

OpenRouter

This page

Provider

Groq

See how

FAQ

Common questions

How does Dome connect to OpenRouter?

Through OpenRouter's OpenAI-compatible API at https://openrouter.ai/api/v1. Dome adds the OpenRouter key as a bearer header; agents never hold it.

Can agents reach any model on OpenRouter?

No. Agents reach only the models you add as connections, and rules can narrow that further.

Which model ids do I use?

OpenRouter's own, such as openai/gpt-oss-120b, with the vendor prefix.

Next steps

Talk with our FDE team

Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.