How it works
How it works
.env file on that machine.By the end of this guide, that file will hold placeholders instead of real API keys. Every request the gateway makes goes through an Agent Vault proxy on a second machine, which attaches the real credential before forwarding the request to the API.Prerequisites
- An Infisical organization where you’re an Agent Vault admin
- Two machines on the same private network, one for the Agent Vault proxy and one for Hermes (physical machines, virtual machines, or containers)
- Hermes Agent installed on the Hermes machine, with the gateway set up and working with your real API keys
- The Infisical CLI 0.43.133 or later installed on the Agent Vault machine (earlier versions don’t apply substitutions)
curlandjqinstalled on the Hermes machine
Step 1: List the API keys Hermes uses
Hermes reads its API keys from.env in its home directory, which is ~/.hermes by default.
~/.hermes throughout. If you’ve set HERMES_HOME, replace ~/.hermes with its value in every command and path in this guide.~/.hermes/.env without printing their values, run this on the Hermes machine:
How do I know which keys to use?
How do I know which keys to use?
~/.hermes/.env contains any keys that hold non-sensitive information, those keys don’t need services in Agent Vault. This includes settings like allowed user IDs and channel IDs.Step 2: Set up Agent Vault
Create an access bundle
First, create an access bundle that holds a service for each API from Step 1.hermes-gateway, then select Create Access Bundle.~/.hermes/.env.- The API expects the key outside a header, such as in the URL path. For example, Telegram’s bot token goes in the URL of every request:
https://api.telegram.org/bot<token>/getUpdates - The API uses more than one key, such as Slack’s bot token and app token (one service can hold a substitution for each key, and an access bundle can’t have two services for the same host)
~/.hermes/.env in Step 3.Enroll a proxy
Next, enroll a proxy on the Agent Vault machine. Every request Hermes makes will go through this proxy first. The proxy gets the real credential from the access bundle you just created. It attaches the credential to the request, then forwards the request to the API.- systemd
- Docker
/etc/systemd/system/agent-vault-proxy.service, then enable and start the proxy:enable starts the proxy every time the machine boots, and --now also starts it right away.17323. Make sure the Hermes machine can reach that port on the Agent Vault machine’s private address.
Create a session
Finally, create a session for the gateway. This will generate a token that Hermes can use to make authenticated requests via the proxy you enrolled.--session-token. The token appears once and can’t be retrieved again.Step 3: Point the Hermes gateway at the proxy
Run the commands in this step on the Hermes machine. In each command, replace<proxy-host> with the Agent Vault machine’s private address.
Trust the proxy’s certificate
To attach the real credentials, the proxy decrypts the HTTPS requests Hermes sends, so Hermes has to trust the proxy’s certificate authority. Download the certificate from the proxy:<proxy-host> is the Agent Vault machine’s address, then download the certificate again.
Replace the API keys with placeholders
Open~/.hermes/.env and replace the value of each API key you added a service for in Step 2:
- For a service that attaches the credential to a header: use any value Hermes accepts as a key (the proxy replaces the header with the real credential)
- For a service with a substitution: use the exact placeholder you entered in Replace
Add the proxy settings
Add these lines to~/.hermes/.env:
<session-token> with the token from Step 2, and <path-to-ca.pem> with the absolute path of the certificate you downloaded, such as /home/hermes/.hermes/agent-vault/ca.pem.
Restart the gateway
Restart the gateway so it loads the new settings:hermes gateway install instead.
Step 4: Verify it works
On the Agent Vault machine, follow the proxy’s logs:- systemd
- Docker
Check the model provider
Send Hermes a message through your messaging platform. If Hermes replies, both the messaging platform and the model provider received the real credentials, and the proxy logs those requests asbrokered.
Check API calls
To check the credential for another API in your access bundle, ask Hermes to call that API. For example, if your access bundle has a GitHub service:
Run curl -sS https://api.github.com/user and show me the output.
GitHub returns your account. If you run the same request on the Hermes machine without the proxy settings, GitHub responds with a 401.
Revoke or replace the session
To stop Hermes from using the real credentials, open Agent Vault in Infisical and go to Sessions. Open the session’s menu and select Revoke Session. The proxy stops attaching credentials within one poll interval, and Hermes stops replying because its requests to the model provider fail. To give the gateway a new session, create a session in Infisical. Then, on the Hermes machine, replace the token in bothHTTPS_PROXY and HTTP_PROXY in ~/.hermes/.env and run hermes gateway restart.
Troubleshooting
Hermes writes the gateway’s logs to~/.hermes/logs/gateway.log. On Linux, you can also read them with journalctl --user -u hermes-gateway, or journalctl -u hermes-gateway for a gateway installed with --system.
Setting up the proxy
The proxy's systemd service fails to start
The proxy's systemd service fails to start
sudo systemctl status agent-vault-proxy shows status=203/EXEC, systemd couldn’t find the Infisical CLI. The unit from the enrollment dialog starts the proxy with /usr/local/bin/infisical, but your CLI may be installed somewhere else.Run which infisical to find your CLI’s path. In /etc/systemd/system/agent-vault-proxy.service, replace /usr/local/bin/infisical at the start of the ExecStart= line with that path, then reload and restart the proxy:Requests that skip the proxy
The proxy logs no requests from Hermes
The proxy logs no requests from Hermes
--log-level debug added to its command.If the proxy still logs nothing from Hermes, the gateway didn’t load the proxy settings. Confirm you edited the .env file in the Hermes home the gateway uses ($HERMES_HOME if you’ve set it), then run hermes gateway restart and check hermes gateway status.The messaging platform's requests skip the proxy
The messaging platform's requests skip the proxy
TELEGRAM_PROXY, DISCORD_PROXY, MATRIX_PROXY, and MATTERMOST_PROXY in ~/.hermes/.env, or telegram.proxy_url in ~/.hermes/config.yaml. If one of these is set, that platform’s requests use it instead of HTTPS_PROXY.Remove the proxy setting for your platform, then run hermes gateway restart.Shell commands that Hermes runs aren't getting credentials
Shell commands that Hermes runs aren't getting credentials
terminal.backend to docker, ssh, or another backend other than local, Hermes runs its commands in an environment that doesn’t have the proxy settings.To route those commands through the proxy, switch back by running hermes config set terminal.backend local.Errors from the proxy
407 from the proxy
407 from the proxy
HTTPS_PROXY and HTTP_PROXY include the token as the password, like http://x-agent-vault:<session-token>@<proxy-host>:17323.403 from the proxy
403 from the proxy
- The session was revoked or has expired (check the Sessions page in Infisical, and replace the session if needed)
- Under the proxy’s strict traffic policy, no service in the bundle covers the host Hermes called (add a service that does, or use a pass-through service)
- The service covers the host, but doesn’t allow the request’s method or path (check the service’s methods and paths)
Requests to Telegram fail with a 502
Requests to Telegram fail with a 502
api.telegram.org). Hermes’s Telegram adapter can connect to Telegram by IP address instead, and for those requests the proxy can’t verify Telegram’s certificate, so it returns a 502. The proxy logs these requests with decision=error and an IP address as the host.To keep Hermes on api.telegram.org, add this line to ~/.hermes/.env, then run hermes gateway restart:Errors in Hermes
The gateway logs certificate verification errors
The gateway logs certificate verification errors
ca.pem isn’t empty.Hermes reports an API key as missing
Hermes reports an API key as missing
Authentication error from an upstream API
Authentication error from an upstream API
~/.hermes/.env matches Replace exactly.Hermes keeps getting authentication errors after you fix the credential
Hermes keeps getting authentication errors after you fix the credential
hermes auth list to find the provider’s name, then reset the key and restart the gateway:The gateway stopped after a messaging platform rejected its token
The gateway stopped after a messaging platform rejected its token
hermes gateway start.