hermes 
- Description
- Emacs frontend for Hermes Agent
- Latest
- hermes-0.6.0.0.20260909.0.tar (.sig), 2026-Sep-09, 3.64 MiB
- Maintainer
- Thanos Apollo <public@thanosapollo.org>
- Other versions:
- release version
- Website
- https://git.thanosapollo.org/emacs-hermes
- ELPA's Repository
- CGit or Gitweb
- All Dependencies
- keymap-popup (.tar)
- websocket (.tar)
- markdown-mode (.tar)
- Badge
To install this package from Emacs, use package-install or list-packages.
Full description
An Emacs front-end for Hermes Agent, driven over the dashboard/TUI gateway.
M-x hermesdashboard withkeymap-popupactions- ERC/emacs-jabber-style chat buffer with streaming replies
- Slash commands, approvals, clarify/sudo/secret prompts, interrupts, and steering
- Markdown-rendered replies; diffs open as
[View Diff]indiff-mode - Kanban, sessions, profiles, MCP, cron, inventory, and rollback browsers
- Configurable desktop notifications with click-to-open actions
- Provider onboarding (API keys and provider accounts) from Emacs
- Optional local eval endpoint (
hermes-exec) for the Hermes Emacs MCP bridge
1. Installation
Hermes Agent with dashboard/TUI gateway support is required.
- See the Hermes Agent quickstart for installation and initial setup.
1.1. NonGNU ELPA
hermes is available via NonGNU ELPA.
Install it with M-x package-install RET hermes.
1.2. package-vc (Emacs 30+)
(use-package hermes :vc (:url "https://git.thanosapollo.org/emacs-hermes" :lisp-dir "lisp") :custom (hermes-dashboard-transport-url "http://127.0.0.1:9119"))
2. Usage
M-x hermes opens the dashboard. M-x hermes-project-chat switches to a
live chat for the current project or creates one at its root; with C-u it
always creates another. Project-chat names stay anchored to that launching
project while the header reports the gateway working directory. Customize
hermes-chat-buffer-name-function to replace the default complete naming
convention. A direct or resumed remote chat uses the editor directory in its
initial buffer name while its gateway cwd is unknown. Its header stays
detached, and the editor path is not sent to the gateway. M-x hermes-chat
always opens a new chat buffer:
RETto send./for slash commands.C-c C-ofor the actions menu.- Each chat pins its resolved spawned or remote transport mode. A spawned
chat starts from the editor's
default-directory; a remote chat does not. - Passive gateway cwd updates change the header and a direct chat's buffer
name, but leave
default-directoryalone. - “Set directory” browses or accepts a path in the gateway's namespace. On
success, the backend-returned path becomes both the gateway cwd and the
buffer's
default-directory; a project chat keeps its launch-root name. M-x hermes-closecloses local connections and Hermes buffers for restart.
Point hermes-dashboard-transport-url at your running dashboard:
hermes dashboard --no-open --tui --host 127.0.0.1 --port 9119
To use more than one dashboard, configure named instances:
(setq hermes-instances
'(("local" . "http://127.0.0.1:9119")
("remote" . "https://dashboard.example.org")))
Commands prompt for an instance only when the current buffer does not already own one. Chat buffers retain their original instance and resolved transport mode, so later configuration changes cannot reroute them. Chats against different dashboards can stay open at the same time. Browser views retain their chosen instance until explicitly reopened for another one.
3. Dashboard authentication
hermes-dashboard-transport-remote-auth-method defaults to auto:
- Loopback dashboards (
127.0.0.1/localhost) can spawn or attach without extra credentials when the dashboard is not gated. - Remote or gated dashboards probe
/api/status. Auto mode uses valid stored basic credentials first, otherwise native PKCE when advertised, and finally reports missing basic credentials for a basic-only dashboard.
Supported gated attach paths:
- Basic/password — auth-source entry with port
hermes-dashboard-basic, loginusername, and password secret. Emacs posts password-login cookies and mints a WebSocket ticket. - Native PKCE OAuth — when
/api/statusadvertisesnative_pkce, Emacs opens the system browser, completes the official/auth/native/*loopback flow, stores access/refresh tokens in auth-source under login/porthermes-dashboard-native, authenticates REST withAuthorization: Bearer, and mints a short-lived WebSocket ticket. Failed or cancelled login does not overwrite prior stored tokens. - Legacy session token — auth-source entry with login/port
hermes-dashboard-tokenand the token as secret, or environment variableHERMES_DASHBOARD_SESSION_TOKEN. Used for ungated dashboards and forcedtokenmode.
Force native, basic, or token to bypass auto selection:
(setq hermes-dashboard-transport-remote-auth-method 'native) ; or 'basic / 'token / 'auto
Generic auth-source examples (replace host/port/values; never commit real secrets):
machine https://dashboard.example.org:9119 login hermes-dashboard-native password {"access_token":"…","refresh_token":"…","expires_at":0,"provider":"oauth","user_id":""}
machine https://dashboard.example.org:9119 login admin password s3cret port hermes-dashboard-basic
machine https://dashboard.example.org:9119 login hermes-dashboard-token password SESSIONTOKEN port hermes-dashboard-token
If a gated dashboard advertises neither native_pkce nor a basic provider, Emacs refuses attach with an actionable error. Cookie-only browser OAuth without native_pkce remains unsupported.
4. Optional Emacs bridges
The dashboard/TUI connection above drives chat and management. Two separate, optional paths let Hermes call into Emacs:
hermes-capabilitiesis the native dashboard capability-provider path.hermes-execis the HTTP eval endpoint used by the external stdio MCP bridge, hermes-emacs-plugin.
To use the stdio MCP bridge, install it from Git, enable the endpoint, then copy its registration command:
pipx install git+https://git.thanosapollo.org/hermes-emacs-plugin
(require 'hermes-exec)
(setq hermes-exec-enabled t
hermes-exec-host "127.0.0.1"
hermes-exec-require-approval t)
(hermes-exec-start)
;; M-x hermes-exec-show-bridge-command
The generated command registers the packaged hermes-emacs-mcp entry point.
For a non-loopback private address, also set the same EMACS_EXEC_TOKEN for
Emacs and the bridge. Do not expose the eval endpoint on a public interface.
Desktop notifications default to completed chat replies, terminal chat errors,
input requests, background-task results, and Kanban states that need attention.
Cron failures use the same policy when cron failure monitoring is enabled.
They are suppressed when the target buffer is already visible on the focused
frame. Customize the event set, or set it to nil to disable notifications:
(setq hermes-notifications-events
'(chat-reply chat-error prompt background
kanban-attention cron-failure kanban-done))
Old versions
| hermes-0.5.0.0.20260908.13.tar.lz | 2026-Sep-08 | 498 KiB |
| hermes-0.5.0.0.20260907.10.tar.lz | 2026-Sep-07 | 472 KiB |
| hermes-0.5.0.0.20260906.3.tar.lz | 2026-Sep-06 | 429 KiB |
| hermes-0.5.0.0.20260905.0.tar.lz | 2026-Sep-05 | 420 KiB |
| hermes-0.4.3.0.20260901.0.tar.lz | 2026-Sep-01 | 369 KiB |
| hermes-0.4.2.0.20260831.5.tar.lz | 2026-Sep-01 | 369 KiB |
| hermes-0.4.0.0.20260828.0.tar.lz | 2026-Aug-29 | 360 KiB |
| hermes-0.3.3.0.20260824.6.tar.lz | 2026-Aug-26 | 357 KiB |
| hermes-0.3.0.0.20260814.2.tar.lz | 2026-Aug-14 | 310 KiB |
| hermes-0.2.1.0.20260813.1.tar.lz | 2026-Aug-13 | 299 KiB |
News
1. Version 0.6.0 (2026-09-09)
- Added local image drafts from files and PNG clipboard data. Images can be previewed or removed before submission; selecting them does not upload them. Failed or uncertain submissions retain bytes in an in-memory recovery view for explicit inspection and manual recovery. Image staging is shared by a backend session, so do not use another client to send into that session.
- Rendered Markdown tables inline with wrapped cells and a copy-source action. Tables reflow to the narrowest displaying window, account for line-number gutters, and preserve the transcript, draft, and undo history during resize.
- Added
hermes-chat-quote-regionto append selected transcript text as a Markdown quote to the draft. It preserves existing input and never sends or queues the quote, including while a turn is running. - Added
M-x hermes-filesto browse backend-managed files and open inert text or image previews without file-local variables or evaluation. The viewer can save validated bytes to a new local file, never overwrite an existing destination. Reads are capped at 4 MiB and listings at 2000 entries. - Added native pairing and webhook management, tool-provider setup, and agent plugin installation, enablement, update, removal, and context-engine choice. Commands retain their owning instance and reject stale confirmations or unprovable mutation targets.
- Expanded MCP management with server creation and removal, reviewed catalog installation, backend-owned OAuth, and progress monitoring. Cancelling monitoring does not imply cancellation of a remote installation.
- Added system-log source, level, component, and line-count filters, optional auto-refresh, and popup controls. Worker views can open logs when the backend publishes an exact transcript or child-session identity.
- Added optional chat-header and process icons, with text fallbacks. Settings menus show reported values and distinguish pending create-time choices from active settings.
- Preserved browser position and instance ownership across refreshes, kept asynchronous completion from displacing later window choices, and settled failed initial client acquisition so views can be retried.
- Added
M-x hermes-dashboard-restartin chat buffers. After confirming its shared impact, it restarts the Emacs-owned dashboard and eagerly reattaches live chats to their durable sessions without replacing buffers or drafts. Queued and uncertain input is copied to editable recovery buffers for manual sending. The backend may recover interrupted turns under its own policy; Emacs never resends input. Remote dashboards are not restarted: usehermes-dashboard-reconnectfor an idle socket reconnect. - Rechecked eval enablement immediately before execution, kept non-loopback connections authenticated when token configuration changes, and closed accepted connections when stopping or replacing a dead listener. IPv6 loopback listeners now use the correct address family.
- Retired capability sockets before reconnect backoff so late callbacks cannot dispatch requests or affect a replacement connection.
- Preserved HTTPS and URL path prefixes when explicitly attaching to a loopback dashboard in remote mode.
- Kept rollback checkpoints tied to the session attachment that listed them; switching chats, reconnecting, or changing the owner retires old selections.
- Rechecked management mutation ownership after authentication waits, and released busy state when client acquisition fails or is cancelled.
- Refused model and reasoning changes on detached durable sessions instead of silently losing them during resume. Fresh chats and owned failed-create retries still support pending settings.
- Cleared old status and log content when reopening a view, before assigning the next response to its new instance.
2. Version 0.5.0 (2026-09-05)
- Added
C-c C-w(hermes-chat-work) to inspect a chat's observed delegates
… …