hermes 
- Description
- Emacs frontend for Hermes Agent
- Latest
- hermes-0.3.2.tar (.sig), 2026-Aug-17, 2.30 MiB
- Maintainer
- Thanos Apollo <public@thanosapollo.org>
- Website
- https://git.thanosapollo.org/emacs-hermes
- Browse ELPA's repository
- CGit or Gitweb
- All Dependencies
- keymap-popup (.tar), websocket (.tar), markdown-mode (.tar)
- Badge
To install this package from Emacs, use package-install or list-packages.
Full description
An Emacs front-end for Hermes Agent, driven over the dashboard/TUI gateway.
M-x hermesdashboard withkeymap-popupactions- ERC/emacs-jabber-style chat buffer with streaming replies
- Slash commands, approvals, clarify/sudo/secret prompts, interrupts, and steering
- Markdown-rendered replies; diffs open as
[View Diff]indiff-mode - Kanban, sessions, profiles, MCP, cron, inventory, and rollback browsers
- Configurable desktop notifications with click-to-open actions
- Provider onboarding (API keys and provider accounts) from Emacs
- Optional local eval endpoint (
hermes-exec) for the Hermes Emacs MCP bridge
1. Installation
Hermes Agent with dashboard/TUI gateway support is required.
- See the Hermes Agent quickstart for installation and initial setup.
1.1. NonGNU ELPA
hermes is available via NonGNU ELPA.
Install it with M-x package-install RET hermes.
1.2. package-vc (Emacs 30+)
(use-package hermes :vc (:url "https://git.thanosapollo.org/emacs-hermes" :lisp-dir "lisp") :custom (hermes-dashboard-transport-url "http://127.0.0.1:9119"))
2. Usage
M-x hermes opens the dashboard. M-x hermes-project-chat switches to a
live chat for the current project or creates one at its root; with C-u it
always creates another. M-x hermes-chat always opens a new chat buffer:
RETto send./for slash commands.C-c C-ofor the actions menu.- Chats propose the launching buffer's
default-directorywhen creating a session; the gateway returns the authoritative workspace. Use “Set directory” to browse the owning instance and change an idle chat's gateway workspace and buffer-localdefault-directorytogether. M-x hermes-closecloses local connections and Hermes buffers for restart.
Point hermes-dashboard-transport-url at your running dashboard:
hermes dashboard --no-open --tui --host 127.0.0.1 --port 9119
To use more than one dashboard, configure named instances:
(setq hermes-instances
'(("local" . "http://127.0.0.1:9119")
("remote" . "https://dashboard.example.org")))
Commands prompt for an instance only when the current buffer does not already own one. Chat buffers remain attached to their original instance, so chats against different dashboards can stay open at the same time. Browser views retain their chosen instance until explicitly reopened for another one. With zero or one named instance, existing single-dashboard behavior is unchanged.
3. Dashboard authentication
hermes-dashboard-transport-remote-auth-method defaults to auto:
- Loopback dashboards (
127.0.0.1/localhost) can spawn or attach without extra credentials when the dashboard is not gated. - Remote or gated dashboards probe
/api/statusand choose one of the supported attach paths below.
Supported gated attach paths:
- Native PKCE OAuth — when
/api/statusadvertisesnative_pkce, Emacs opens the system browser, completes the official/auth/native/*loopback flow, stores access/refresh tokens in auth-source under login/porthermes-dashboard-native, authenticates REST withAuthorization: Bearer, and mints a short-lived WebSocket ticket. Failed or cancelled login does not overwrite prior stored tokens. - Basic/password — auth-source entry with port
hermes-dashboard-basic, loginusername, and password secret. Emacs posts password-login cookies and mints a WebSocket ticket. - Legacy session token — auth-source entry with login/port
hermes-dashboard-tokenand the token as secret, or environment variableHERMES_DASHBOARD_SESSION_TOKEN. Used for ungated dashboards and forcedtokenmode.
Force a path with:
(setq hermes-dashboard-transport-remote-auth-method 'native) ; or 'basic / 'token / 'auto
Generic auth-source examples (replace host/port/values; never commit real secrets):
machine https://dashboard.example.org:9119 login hermes-dashboard-native password {"access_token":"…","refresh_token":"…","expires_at":0,"provider":"oauth","user_id":""}
machine https://dashboard.example.org:9119 login admin password s3cret port hermes-dashboard-basic
machine https://dashboard.example.org:9119 login hermes-dashboard-token password SESSIONTOKEN port hermes-dashboard-token
If a gated dashboard advertises neither native_pkce nor a basic provider, Emacs refuses attach with an actionable error. Cookie-only browser OAuth without native_pkce remains unsupported.
4. Optional Emacs bridges
The dashboard/TUI connection above drives chat and management. Two separate, optional paths let Hermes call into Emacs:
hermes-capabilitiesis the native dashboard capability-provider path.hermes-execis the HTTP eval endpoint used by the external stdio MCP bridge, hermes-emacs-plugin.
To use the stdio MCP bridge, install it from Git, enable the endpoint, then copy its registration command:
pipx install git+https://git.thanosapollo.org/hermes-emacs-plugin
(require 'hermes-exec)
(setq hermes-exec-enabled t
hermes-exec-host "127.0.0.1"
hermes-exec-require-approval t)
(hermes-exec-start)
;; M-x hermes-exec-show-bridge-command
The generated command registers the packaged hermes-emacs-mcp entry point.
For a non-loopback private address, also set the same EMACS_EXEC_TOKEN for
Emacs and the bridge. Do not expose the eval endpoint on a public interface.
Desktop notifications default to completed chat replies, terminal chat errors,
input requests, background-task results, and Kanban states that need attention.
Cron failures use the same policy when cron failure monitoring is enabled.
They are suppressed when the target buffer is already visible on the focused
frame. Customize the event set, or set it to nil to disable notifications:
(setq hermes-notifications-events
'(chat-reply chat-error prompt background
kanban-attention cron-failure kanban-done))
Old versions
| hermes-0.3.1.tar.lz | 2026-Aug-15 | 318 KiB |
| hermes-0.3.0.tar.lz | 2026-Aug-14 | 307 KiB |
| hermes-0.2.1.tar.lz | 2026-Aug-13 | 297 KiB |
| hermes-0.2.0.tar.lz | 2026-Aug-13 | 250 KiB |
News
1. Version 0.3.2 (2026-08-16)
- Added
hermes-project-chatto reuse or create a chat at the current project root; a prefix argument always opens another. - Grouped the dashboard by Hermes instance, rebalanced chat action popup groups, and reused one status line for compression warnings.
- Isolated prompt, steer, background-submit, and session-panel ownership so stale callbacks cannot mutate a successor chat or restore a rejected draft into the wrong buffer.
- Kept instance-scoped browsers, Kanban tails, cron edits, MCP toggles, rollback restores, provider-key saves, capability connects, and subagent interrupts from leaking across instance switches or list refreshes.
2. Version 0.3.1 (2026-08-15)
- Added shell-style completion and direct session switching for
/modelwhile preserving the interactive model picker. - Serialized session handoffs and command mutations so stale callbacks, disconnects, and overdue handoffs cannot race or permanently block chats.
- Improved queued and background turn ordering, session working-directory updates, credential-prompt expiry, and pending-reply rendering.
- Hardened provider authentication, OAuth token rollback, reconnect readiness, and bounded embedded-image parsing.
3. Version 0.3.0 (2026-08-14)
- Added named Hermes instances with per-instance dashboard endpoints and instance selection across chats and management browsers.
- Kept asynchronous reads, mutations, and singleton browsers scoped to their owning instance; stale callbacks no longer leak state or report actions after a buffer changes ownership.
- Preserved the single-instance workflow as the default configuration.
4. Version 0.2.1 (2026-08-13)
- Added a backend-driven provider-account browser for OAuth and external account flows. Dashboard-provided shell commands are copied, never run.
- Kept provider-account list, OAuth, and disconnect operations scoped to the Hermes profile that opened them.
- Kept OAuth-only providers out of API-key onboarding.
- Reported backend account errors while suppressing stale asynchronous errors; failed OAuth operations no longer trigger success effects.
5. Version 0.2.0 (2026-08-13)
- Published on NonGNU ELPA.