Hermes Dashboard Auth for Feishu
xielevi/hermes-dashboard-auth-feishu
Feishu and Lark OAuth sign-in for the Hermes Agent web dashboard, limited to an allow-list of users
Hermes Dashboard Auth for Feishu is a Hermes Agent plugin that puts Feishu or Lark OAuth sign-in in front of the web dashboard so only listed people can get in.
What Hermes Dashboard Auth for Feishu does
The plugin lets you expose the Hermes dashboard on a public hostname and admit only the people you list by open_id. It registers a dashboard auth provider through ctx.register_dashboard_auth_provider(). Cookies, auth routes, WebSocket tickets and the login page stay in Hermes core, and the plugin only answers who the user is and whether they are allowed. Sign-in checks both the tenant_key and the open_id against your settings, and inside the Feishu app it can also serve as a one-tap workbench entry.
Feishu is contacted once per sign-in. After that the dashboard runs on locally signed session tokens, with 12-hour access and rotating refresh, and no Feishu token is kept. Non-secret settings go under plugins.entries.dashboard-auth-feishu.settings, while the app secret and a session key go in ~/.hermes/.env. The gate turns on once dashboard.public_url is a non-loopback address. The README warns that everyone on the allow-list gets full dashboard access, including config, keys, sessions and terminal. It is MIT licensed with English and Chinese docs.
Key features
- Feishu or Lark OAuth sign-in for the Hermes web dashboard
- Allow-list by tenant_key and open_id
- One-tap workbench entry inside the Feishu app
- Secrets kept in ~/.hermes/.env rather than config.yaml
- Local signed session tokens, with no Feishu token stored
When to use it
- Putting the Hermes dashboard on a public hostname behind company sign-in
- Letting a small admin group open the dashboard from inside Feishu
- Replacing a shared dashboard password with named-user access
Who it is for: Hermes Agent operators in organizations that use Feishu or Lark and want to expose the dashboard to a few trusted admins.
How it fits with Hermes Agent
Built for Hermes Agent as a dashboard auth provider plugin, with Hermes core still handling cookies, routes and the login page.
How to install Hermes Dashboard Auth for Feishu
These commands are copied from the project's README. Check the repository for the latest steps before you run them.
hermes plugins install xielevi/hermes-dashboard-auth-feishu --no-enable
hermes plugins enable dashboard-auth-feishuRequirements: Hermes Agent 0.21.5 or later, a Feishu or Lark custom app in your tenant, and HTTPS in front of the dashboard that keeps the public Host header and passes WebSockets
FAQ
What is Hermes Dashboard Auth for Feishu?
Hermes Dashboard Auth for Feishu is a Hermes Agent plugin that requires Feishu or Lark sign-in before anyone can use the web dashboard. Only people on your open_id allow-list are admitted.
Who can sign in with Hermes Dashboard Auth for Feishu?
Only people from the configured tenant whose open_id is in your owner_open_ids setting. The README warns that each of them gets full dashboard access, including config, keys, sessions and terminal.
How do I install Hermes Dashboard Auth for Feishu?
Run hermes plugins install xielevi/hermes-dashboard-auth-feishu --no-enable, then hermes plugins enable dashboard-auth-feishu. After that you configure the Feishu app, the plugin settings and dashboard.public_url.
Similar security for Hermes Agent
All securityProof-carrying defensive security reviews for AI-assisted code with deterministic policy and portable evidence
nordicnode Model SherpaHermes Agent plugin that repairs bad tool calls, breaks tool loops and redacts secrets from logs
dafka007 Hermes Security AuditApproval-gated Hermes plugin that runs Gitleaks, OSV-Scanner and Semgrep CE on a workspace
chchchadzilla GitHub Safe PushHermes skill that keeps secrets out of git and checks a project is properly packaged before shipping
cybertecla Hermes Telemetry DashboardDashboard tab that shows what telemetry Hermes Agent would send to Nous before any sending is enabled
angel12 hermes-ldap-authLDAP and Active Directory password login for the Hermes Agent web dashboard, as a Hermes plugin
Related guides: How to run Hermes Agent securely