Hermes Atlas
Security & sandboxing

Hermes Vault

asimons81/hermes-vault

Local-first credential broker, secret scanner and encrypted vault for Hermes agents

In short

Hermes Vault is a local-first credential broker and encrypted vault that scans for risky plaintext secrets, stores credentials locally and gives agents access through policy-gated, lease-aware workflows. It is built for Hermes agents.

What Hermes Vault does

Hermes Vault keeps credentials in an encrypted local store and verifies them before an agent claims it needs to re-authenticate. A scanner looks for risky plaintext secrets. Agent access goes through a broker that applies policy and issues leases, with lease ownership and expiry enforced. An MCP server exposes vault:// resources, and hermes-vault run injects secrets into a child process environment through the same policy-gated path.

The release described in the README is v0.26.0, which it calls the Trustworthy Under Failure line. Changes include restore preflights that prove a backup decrypts before anything is modified, a non-destructive audit-checkpoint repair, a hermes-vault doctor command for install and recovery health with JSON output, and aesgcm-v2 envelopes as the default for new writes, with an opt-in migrate-crypto command. Existing v1 credential rows stay readable.

Key features

  • Scans for risky plaintext secrets
  • Encrypted local credential storage with aesgcm-v2 as the default for new writes
  • Policy-gated broker with lease ownership and expiry enforcement
  • MCP server that exposes vault:// resources
  • hermes-vault run injects secrets into a child process
  • hermes-vault doctor checks install and recovery health

When to use it

  • Moving API keys out of plaintext files that an agent can read
  • Giving an agent time-limited access to a credential
  • Restoring a vault from backup with a preflight check that the backup decrypts

Who it is for: Hermes Agent users who want their agents to get credentials through a local, policy-controlled broker instead of plaintext files.

How it fits with Hermes Agent

Built for Hermes agents, which request credentials through its broker or MCP server, and its CLI entrypoint scrubs hermes-agent PYTHONPATH leakage.

FAQ

What is Hermes Vault?

Hermes Vault is a local-first credential broker and encrypted vault for Hermes agents. It scans for plaintext secrets, stores credentials locally and controls agent access with policies and leases.

Does Hermes Vault work with Hermes Agent?

Yes, it is described as Hermes-native and built for Hermes agents. Agents reach it through the broker CLI or its MCP server.

Is Hermes Vault free and open source?

Yes, the repository is licensed under MIT.

Similar security for Hermes Agent

All security

Related guides: How to run Hermes Agent securely