Dome Systems

xAI API and Dome

Grok behind one Gateway, with every call governed.

Some models belong with your own people, not in front of customers. Connect xAI to Dome, tag the Grok connections use: internal, and customer-facing agents are refused before a call leaves. Grok 4.6 stands in when 4.7 fails.

PeopleAgentsDomePool: grok-4.7CallersPeopleAgentsresearch-agentAgentscoding-agentAgentssupport-agentGatewaysprod-gatewayGrok 4.7Priority 0, use: internalGrok 4.6Priority 1, use: internalAnthropicclaude-sonnet-5, no use tagRulesGuardsAuditsaudit-trail
research-agent→grok-4.7· as k.oseiAllowed

How Dome helps

Dome provides model brokering and routing for xAI

Grok access without the key

Agents reach Grok through the Gateway with Dome keys. The xAI key stays with Dome, attached only as the call goes out.

An older Grok as fallback

Pool Grok 4.7 with Grok 4.6 behind it. When 4.7 fails, the call goes to 4.6.

Internal models stay internal

Tag Grok connections use: internal. A rule on each customer-facing agent refuses them.

Get started

Connect xAI in three steps

Add Grok 4.7 and 4.6, put them in one pool, and switch agents to the Gateway.

  1. 01

    Add the connections

    The provider id is xai. Dome uses https://api.x.ai/v1 and xAI's own model ids.

    $ dome models add grok-4-7-xai \
    --provider xai \
    --model grok-4.7 \
    --api-key "$XAI_API_KEY" \
    --attributes '{"use":"internal"}' \
    --gateway prod-gateway
     
    $ dome models add grok-4-6-xai \
    --provider xai \
    --model grok-4.6 \
    --api-key "$XAI_API_KEY" \
    --attributes '{"use":"internal"}' \
    --gateway prod-gateway
  2. 02

    Pool them

    4.7 is tried first and 4.6 next. Agents name the pool, grok-4.7.

    $ dome models pool create grok-4.7 \
    --failover-max all --gateway prod-gateway
     
    $ dome models pool member add grok-4.7 grok-4-7-xai --priority 0
    $ dome models pool member add grok-4.7 grok-4-6-xai --priority 1
  3. 03

    Point your agent at the Gateway

    Use any client that speaks Chat Completions. It sends the agent's Dome key where the xAI key used to go.

    from openai import OpenAI
     
    client = OpenAI(base_url=f"{GATEWAY_URL}/v1", api_key=DOME_AGENT_KEY)
    client.chat.completions.create(
    model="grok-4.7",
    messages=[{"role": "user", "content": "Summarize this incident report."}],
    )

Commands and rules tested against a Dome workspace on October 1, 2026. For anything about xAI itself, see xAI's documentation.

Rules

Customer-facing agents stay off internal models

Applied to the support agent with --agent, this refuses any connection tagged use: internal. Other agents keep their Grok access.

forbid (principal, action == Dome::Action::"llm:invoke", resource is Dome::LLMModel)
when { resource has use && resource.use == "internal" };

Agent workflow

Bringing it together

Connecting xAI to registered agents, tools, and identity in Dome completes a governed agent application.

Dome

Control point

Gateway

  • Rules
  • Guards
  • Quotas

Every call decided and audited

FAQ

Common questions

How does Dome connect to xAI?

Through xAI's Chat Completions API at https://api.x.ai/v1. Dome holds the xAI key and adds it as a bearer header per call.

Can customer-facing agents reach Grok?

Not with the rule above. Each agent it's applied to is refused on any connection tagged use: internal, and audit records the refusal.

Does the Responses API work on xAI connections?

No. xAI connections serve chat completions only.

Next steps

Talk with our FDE team

Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.