hermes-ldap-auth
angel12/hermes-ldap-auth
LDAP and Active Directory password login for the Hermes Agent web dashboard, as a Hermes plugin
hermes-ldap-auth is a Hermes Agent plugin that adds LDAP and Active Directory password login to the web dashboard by checking each login with an LDAP bind.
What hermes-ldap-auth does
The plugin registers a DashboardAuthProvider named ldap that verifies each login with an LDAP bind, so Hermes never stores or hashes passwords. It works with OpenLDAP, Active Directory, FreeIPA, 389-ds and other LDAPv3 directories. After sign-in, the shared Hermes dashboard-auth framework handles the login form, session cookies, refresh, WebSocket tickets, logout, audit logging and the login rate limit. Two bind modes exist: direct bind with a user_dn_template, and search-then-bind with a service account, which Active Directory sAMAccountName logins require. An optional require_group limits access to group members.
Security choices include required TLS (ldaps:// or StartTLS, with cleartext refused unless allow_insecure is set), rejection of empty passwords before any bind, escaping of usernames against LDAP injection, identical responses for unknown users and wrong passwords, no referral chasing, and rejection of filters that match more than one entry. Settings live under dashboard.ldap_auth in config.yaml with HERMES_DASHBOARD_LDAP environment overrides. Sessions are stateless signed tokens, 12 hours by default. The ldap3 dependency needs your approval when you enable the plugin.
Key features
- LDAP bind verification, so Hermes stores no passwords
- Direct bind and search-then-bind modes
- Optional group requirement through require_group
- TLS required by default, with StartTLS support and CA bundle option
- Environment variable overrides for every connection setting
When to use it
- Letting staff sign in to the Hermes dashboard with their Active Directory accounts
- Restricting dashboard access to members of one directory group
- Using an existing OpenLDAP or FreeIPA directory instead of a separate dashboard password
Who it is for: Hermes Agent administrators in organizations with an LDAP or Active Directory directory who want directory-backed dashboard sign-in.
How it fits with Hermes Agent
Built for Hermes Agent as a dashboard auth plugin that plugs into the shared Hermes dashboard-auth framework. It requires Hermes 0.21 or newer.
How to install hermes-ldap-auth
These commands are copied from the project's README. Check the repository for the latest steps before you run them.
hermes plugins install https://github.com/angel12/hermes-ldap-auth --enableRequirements: Hermes 0.21 or newer and an LDAPv3 directory; the ldap3 package is installed after you approve it when enabling the plugin
FAQ
What is hermes-ldap-auth?
hermes-ldap-auth is a Hermes Agent plugin that lets users sign in to the web dashboard with LDAP or Active Directory credentials. Each login is verified by an LDAP bind.
How do I install hermes-ldap-auth?
Run hermes plugins install https://github.com/angel12/hermes-ldap-auth --enable from an interactive terminal and approve the ldap3 dependency. A non-interactive install leaves it disabled until you run hermes plugins enable dashboard-auth-ldap.
Does hermes-ldap-auth work with Active Directory?
Yes. Use search-then-bind mode with a service account and a filter such as (sAMAccountName={username}). The README says Active Directory sAMAccountName logins need that mode.
Similar security for Hermes Agent
All securityProof-carrying defensive security reviews for AI-assisted code with deterministic policy and portable evidence
nordicnode Model SherpaHermes Agent plugin that repairs bad tool calls, breaks tool loops and redacts secrets from logs
dafka007 Hermes Security AuditApproval-gated Hermes plugin that runs Gitleaks, OSV-Scanner and Semgrep CE on a workspace
chchchadzilla GitHub Safe PushHermes skill that keeps secrets out of git and checks a project is properly packaged before shipping
xielevi Hermes Dashboard Auth for FeishuFeishu and Lark OAuth sign-in for the Hermes Agent web dashboard, limited to an allow-list of users
cybertecla Hermes Telemetry DashboardDashboard tab that shows what telemetry Hermes Agent would send to Nous before any sending is enabled
Related guides: How to run Hermes Agent securely