OpenRouter and Dome
Hundreds of models through OpenRouter. Only the approved ones reach your agents.
One OpenRouter key reaches hundreds of models. Dome holds the key and exposes only the models you add as connections. A rule refuses anything not marked approved, and every call is metered against an agent.
How Dome helps
Dome provides model brokering and routing for OpenRouter
One key, held in Dome
OpenRouter's key opens hundreds of models, so it stays with Dome. Agents hold their own Dome keys and never see it.
Approved models only
Each model is its own connection, tagged when it's vetted. A rule refuses every connection without the tag.
A fallback for any provider
Put OpenRouter behind a direct provider in a pool. When the first fails, the same model answers through OpenRouter.
Get started
Connect OpenRouter in three steps
Add each vetted model as a connection, put OpenRouter behind Groq, and connect agents to the Gateway.
01
Add the connection
The provider id is openrouter. Dome uses https://openrouter.ai/api/v1 and OpenRouter's own model ids.
$ dome models add gpt-oss-openrouter \--provider openrouter \--model openai/gpt-oss-120b \--api-key "$OPENROUTER_API_KEY" \--attributes '{"approved":true}' \--gateway prod-gateway02
Pool it behind Groq
Groq serves the same open-weight model and goes first. OpenRouter answers when it can't.
$ dome models pool create gpt-oss-120b \--failover-max all --gateway prod-gateway$ dome models pool member add gpt-oss-120b gpt-oss-groq --priority 0$ dome models pool member add gpt-oss-120b gpt-oss-openrouter --priority 103
Point your agent at the Gateway
Code written for OpenRouter's API keeps working. Change the base URL to the Gateway and the key to the agent's.
from openai import OpenAIclient = OpenAI(base_url=f"{GATEWAY_URL}/v1", api_key=DOME_AGENT_KEY)client.chat.completions.create(model="gpt-oss-120b",messages=[{"role": "user", "content": "Summarize these release notes."}],)
Commands and rules tested against a Dome workspace on October 1, 2026. For anything about OpenRouter itself, see OpenRouter's documentation.
Rules
Only approved models
Applied to an agent, this refuses any connection not tagged approved. Adding a model to OpenRouter's catalog changes nothing until you vet it.
forbid (principal, action == Dome::Action::"llm:invoke", resource is Dome::LLMModel)unless { resource has approved && resource.approved == true };Agent workflow
Bringing it together
Connecting OpenRouter to registered agents, tools, and identity in Dome completes a governed agent application.
Acting for
Control point
Gateway
- Rules
- Guards
- Quotas
Every call decided and audited
Models
Provider
OpenRouter
This page
Provider
Groq
See how
FAQ
Common questions
How does Dome connect to OpenRouter?
Through OpenRouter's OpenAI-compatible API at https://openrouter.ai/api/v1. Dome adds the OpenRouter key as a bearer header; agents never hold it.
Can agents reach any model on OpenRouter?
No. Agents reach only the models you add as connections, and rules can narrow that further.
Which model ids do I use?
OpenRouter's own, such as openai/gpt-oss-120b, with the vendor prefix.
Explore
More of what Dome works with
Model
Claude Fable
Fable 5.1 from Anthropic and Amazon Bedrock in one failover pool, open to one group and capped by quota.
Read moreMCP server
GitHub
The GitHub MCP server behind the Tool Gateway, with rules that decide each call on its owner and repository.
Read moreIdentity
Okta
Okta tokens verified on every agent call, so rules and audit name the person each agent acted for.
Read moreRuntime
LangGraph
LangGraph agents with their model calls on the Model Broker and their MCP tools on the Tool Gateway.
Read moreClient
Claude Code
Claude Code on a Dome Gateway with per-developer sign-in, rules on every tool call, and audit by name.
Read moreAgent service
TinyFish
TinyFish's web agents behind the Tool Gateway, with rules that decide each run on the site it targets.
Read moreNext steps
Talk with our FDE team
Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.
No card required to start. Register your first agent in minutes.
LLM providers for AI agents: one governed path to every model
Connect a provider once. Its key stays in Dome, and every agent call to it is authorized, metered and audited.
See them all