Authsome
agentrhq/authsome
Credential gateway that logs in once via OAuth2 or API key and keeps AI agents authenticated
Authsome is an open-source credential gateway that sits between AI agents and the services they call, injecting credentials through an HTTP proxy so the agents never see them. A user logs in once with OAuth2 or an API key, and agents including Hermes Agent can then run headlessly.
What Authsome does
Authsome addresses agents that run outside interactive sessions, in CI, over SSH, in cron jobs and in background workers, yet still need API access. Instead of hardcoded environment tokens or auth code rebuilt in every project, a person authenticates once with a command such as authsome login github, using browser PKCE, device code or a browser bridge for entering API keys. Credentials are encrypted at rest and refreshed before they expire.
Agents then put authsome run -- in front of a command. The command runs behind an auth proxy that injects headers at request time, matched automatically by the provider's API URL, so secrets never appear in the child process environment. Bundled OAuth2 and API key providers work without configuration, and several accounts per provider are supported. A self-hosted daemon can run in Docker with Postgres, and an authsome skill added with npx skills add lets agents such as Claude Code, Codex, Cursor and Hermes use it.
Key features
- One-time login through OAuth2, browser PKCE, device code or API key entry
- HTTP auth proxy that injects credentials at request time
- Encrypted storage with automatic refresh before expiry
- Bundled OAuth2 and API key providers
- Multiple accounts per provider
- Docker-based self-hosted daemon with Postgres
When to use it
- Giving a Hermes agent access to GitHub or another API without putting tokens in its environment
- Running agents in CI, cron jobs or SSH sessions that need valid tokens without a browser
- Managing and rotating credentials for several agents from one place
Who it is for: Developers who run agents headlessly and want credentials kept out of the agent process.
How it fits with Hermes Agent
Supports Hermes Agent among several agents: the README names Hermes in the list of agents that can load the authsome skill.
How to install Authsome
These commands are copied from the project's README. Check the repository for the latest steps before you run them.
uv tool install authsome
authsome onboard
npx skills add agentrhq/authsomeRequirements: Python 3.13+ (the Docker-based self-hosted daemon needs no Python on the host)
FAQ
What is Authsome?
Authsome is an open-source credential gateway for AI agents. You log in once via OAuth2 or an API key, and it injects fresh credentials through an HTTP proxy when an agent runs a command, so the agent never handles the secrets.
Does Authsome work with Hermes Agent?
Yes. The README lists Hermes among the agents that can use the authsome skill, which is added with npx skills add agentrhq/authsome.
How do I install Authsome?
Run uv tool install authsome, which requires Python 3.13 or newer, then run authsome onboard for first-time setup. To give an agent access, add the skill with npx skills add agentrhq/authsome.
Similar security for Hermes Agent
All securityOpen-source agent safety platform that monitors and guards OpenClaw, Hermes and Nanobot sessions
Strategic-Automation ViolinSupervised Hermes pentest profile with guarded execution and evidence-backed reporting
x-glacier kali-pentestKali Linux pentest skill that plans, runs and adapts attacks with approval gates
mturac PromptGuardOffline prompt auditor with a pre-write guard for Hermes, Claude Code, Codex, OpenCode and OpenClaw
TheAiSingularity HermesClawRun Hermes Agent inside NVIDIA OpenShell with enforced network, filesystem and syscall limits
claudlos Hermes KatanaSecurity layer for Hermes Agent with taint tracking, a policy engine and outbound secret scrubbing
Related guides: How to run Hermes Agent securely