xAI API and Dome
Grok behind one Gateway, with every call governed.
Some models belong with your own people, not in front of customers. Connect xAI to Dome, tag the Grok connections use: internal, and customer-facing agents are refused before a call leaves. Grok 4.6 stands in when 4.7 fails.
How Dome helps
Dome provides model brokering and routing for xAI
Grok access without the key
Agents reach Grok through the Gateway with Dome keys. The xAI key stays with Dome, attached only as the call goes out.
An older Grok as fallback
Pool Grok 4.7 with Grok 4.6 behind it. When 4.7 fails, the call goes to 4.6.
Internal models stay internal
Tag Grok connections use: internal. A rule on each customer-facing agent refuses them.
Get started
Connect xAI in three steps
Add Grok 4.7 and 4.6, put them in one pool, and switch agents to the Gateway.
01
Add the connections
The provider id is xai. Dome uses https://api.x.ai/v1 and xAI's own model ids.
$ dome models add grok-4-7-xai \--provider xai \--model grok-4.7 \--api-key "$XAI_API_KEY" \--attributes '{"use":"internal"}' \--gateway prod-gateway$ dome models add grok-4-6-xai \--provider xai \--model grok-4.6 \--api-key "$XAI_API_KEY" \--attributes '{"use":"internal"}' \--gateway prod-gateway02
Pool them
4.7 is tried first and 4.6 next. Agents name the pool, grok-4.7.
$ dome models pool create grok-4.7 \--failover-max all --gateway prod-gateway$ dome models pool member add grok-4.7 grok-4-7-xai --priority 0$ dome models pool member add grok-4.7 grok-4-6-xai --priority 103
Point your agent at the Gateway
Use any client that speaks Chat Completions. It sends the agent's Dome key where the xAI key used to go.
from openai import OpenAIclient = OpenAI(base_url=f"{GATEWAY_URL}/v1", api_key=DOME_AGENT_KEY)client.chat.completions.create(model="grok-4.7",messages=[{"role": "user", "content": "Summarize this incident report."}],)
Commands and rules tested against a Dome workspace on October 1, 2026. For anything about xAI itself, see xAI's documentation.
Rules
Customer-facing agents stay off internal models
Applied to the support agent with --agent, this refuses any connection tagged use: internal. Other agents keep their Grok access.
forbid (principal, action == Dome::Action::"llm:invoke", resource is Dome::LLMModel)when { resource has use && resource.use == "internal" };Agent workflow
Bringing it together
Connecting xAI to registered agents, tools, and identity in Dome completes a governed agent application.
Acting for
Control point
Gateway
- Rules
- Guards
- Quotas
Every call decided and audited
Models
FAQ
Common questions
How does Dome connect to xAI?
Through xAI's Chat Completions API at https://api.x.ai/v1. Dome holds the xAI key and adds it as a bearer header per call.
Can customer-facing agents reach Grok?
Not with the rule above. Each agent it's applied to is refused on any connection tagged use: internal, and audit records the refusal.
Does the Responses API work on xAI connections?
No. xAI connections serve chat completions only.
Explore
More of what Dome works with
Model
Claude Fable
Fable 5.1 from Anthropic and Amazon Bedrock in one failover pool, open to one group and capped by quota.
Read moreMCP server
GitHub
The GitHub MCP server behind the Tool Gateway, with rules that decide each call on its owner and repository.
Read moreIdentity
Okta
Okta tokens verified on every agent call, so rules and audit name the person each agent acted for.
Read moreRuntime
OpenAI Agents SDK
OpenAI Agents SDK agents with their models on the Model Broker and their MCP tools on the Tool Gateway.
Read moreClient
Claude Code
Claude Code on a Dome Gateway with per-developer sign-in, rules on every tool call, and audit by name.
Read moreAgent service
TinyFish
TinyFish's web agents behind the Tool Gateway, with rules that decide each run on the site it targets.
Read moreNext steps
Talk with our FDE team
Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.
No card required to start. Register your first agent in minutes.
LLM providers for AI agents: one governed path to every model
Connect a provider once. Its key stays in Dome, and every agent call to it is authorized, metered and audited.
See them all