Dome Systems

dome quotas

Cap spend, tokens, or calls for workspace, agent, act-as, pool, model, Gateway, and tool subjects

dome quotas is the single command group for every usage cap in the active workspace. Model, tool, and Gateway quotas used to live on separate groups; they now share this surface.

Command
List quotasdome quotas list
Set quotadome quotas set --subject <kind> --limit <amount>
Update quotadome quotas update <quota-id>
Remove quotadome quotas rm <quota-id>

Each quota has a subject (what it covers) and a dimension (which traffic it meters). Dimension is usually implied by --subject:

SubjectImplied dimensionTypical units
workspace, agentall (model + tool)dome_usd
model, pool, gateway, act-asllmdome_usd, provider_usd, tokens, calls
tooltooldome_usd, calls

Pass --dimension only when a subject is valid on more than one dimension. Create is insert-only for each subject identity, dimension, and window pair. Subject and unit cannot change after create.

List quotas

dome quotas list
dome quotas list --dimension llm
dome quotas list --gateway prod-tools

List quotas in the active workspace with subject, dimension, unit, limit, window, usage, and enforcement state. Alias: ls.

FlagTypeDefaultDescription
--dimensionstring—Only list one dimension: all, llm, or tool
--gatewaystring—Only list caps on one Gateway (name or id)
Requires gateways.view.

Set quota

dome quotas set --subject <kind> --limit <amount>

Create a spend, token, or call cap. The Gateway either spills routing for an exhausted model budget or rejects traffic when a total cap is reached.

FlagTypeRequiredDefaultDescription
--subjectstringYes—workspace, agent, act-as, pool, model, gateway, or tool
--dimensionstringNoimpliedall, llm, or tool — usually implied by --subject
--unitstringNodome_usddome_usd (what you spend with Dome), provider_usd (an estimate of the upstream model bill), tokens, or calls. The two dollar units are different money.
--limitstringYes—US dollars for a dollar unit (e.g. 500 or 12.50); a whole count for tokens or calls
--windowstringNomonthlydaily or monthly
--namestringNo—Human-readable label
--modelstringConditional—Model connection name (--subject model)
--poolstringConditional—Pool name (--subject pool, or to scope a model quota to one pool)
--agentstringConditional—Agent name or id (--subject agent)
--act-asstringConditional—Verified end-user OIDC subject (--subject act-as)
--gatewaystringConditional—Gateway name or id (--subject gateway)
--toolstringConditional—One MCP tool as <connection>/<tool>, e.g. github/create_issue (--subject tool)
--per-callerboolNofalseApply the limit independently to each agent and verified end user (--subject model only)
--disabledboolNofalseCreate without enforcing until enabled
Requires gateways.manage.
Workspace monthly cap (model + tool)
dome quotas set --subject workspace --limit 5
Agent daily cap
dome quotas set --subject agent --agent bot --limit 1 --window daily
Model spend cap
dome quotas set --subject model --model gpt-4o --limit 500 --dimension llm
Pool spill-over budget for one model
# Caps claude-sonnet spend inside the production pool at $1000/month.
# When exhausted, the pool spills to the next member.
dome quotas set \
  --subject model --model claude-sonnet --pool production \
  --limit 1000 --window monthly
Gateway LLM cap
dome quotas set --subject gateway --gateway prod-tools --limit 500 --window monthly --name prod-monthly
Tool call cap
dome quotas set --subject tool --tool github/create_issue --unit calls --limit 100

The Gateway picks up a new quota on its next configuration sync.

Update quota

dome quotas update <quota-id> --limit 750
dome quotas update <quota-id> --enabled=false

Update a quota's name, limit, window, or enforcement state. Its subject and unit cannot change. --window has no default: an unset flag leaves the window unchanged.

FlagTypeDescription
--namestringNew label
--limitstringNew limit, interpreted in the quota's existing unit
--windowstringdaily or monthly
--enabledboolEnable or disable enforcement

Pass at least one flag.

Requires gateways.manage.

Remove quota

dome quotas rm <quota-id>

Remove a quota by id (from dome quotas list). Aliases: remove, delete.

Requires gateways.manage.

On this page

Was this page helpful?