Skip to content
Mimir

Hermes Capture

Hermes AgentHermes

Mimir captures Hermes through its OpenRouter proxy and a companion plugin for direct providers. Proxy traffic produces full redacted exchanges; direct traffic produces bounded turn summaries.

Terminal window
mimir install --harness hermes

Restart Hermes after installation so it reloads the managed environment. Run mimir doctor --json and confirm that the route, plugin, and credentials are active.

  • OpenRouter: Mimir redirects Hermes’ built-in provider through the Worker.
  • Direct providers: the plugin reports completed turns, heartbeats, and session ends without intercepting provider traffic.
  • Mixed sessions: the proxy owns proxied turns while the plugin reports only direct-provider activity, preventing duplicate capture.
  1. Run mimir doctor; it checks the managed route and metadata endpoints without invoking a model.
  2. Restart Hermes because it does not hot-reload its environment.
  3. Start a fresh session on an OpenRouter model and switch to another OpenRouter model mid-session.
  4. Check the durable session receipt. Transport activity alone is not proof of persistence.

If capture is missing, follow Hermes capture is missing.

Managed route and credentials

Mimir maintains this block at the end of the active Hermes .env:

# >>> mimir managed openrouter route
OPENROUTER_BASE_URL="https://<worker>.workers.dev/v1/hermes/<installation-id>"
# <<< mimir managed openrouter route

Hermes keeps its existing OPENROUTER_API_KEY. Mimir registers only its SHA-256 digest for the installation; the raw key is not stored in D1. The ordinary OpenRouter model picker continues to work without a custom provider or model migration.

Plugin lifecycle

The plugin classifies direct traffic from pre_api_request, reports completed turns through post_llm_call, and ends active direct sessions through on_session_finalize. The first direct turn activates heartbeats. Proxy-only sessions emit no plugin lifecycle events.

Delivery is best-effort and never blocks Hermes. If an end event is missed, the server-side silence timer finalizes the session.

Supported boundary

The proxy captures OpenRouter traffic, including mid-session model switches. Nous, Anthropic OAuth, Codex, Gemini, and other direct transports bypass the proxy; the plugin retains bounded completed-turn summaries instead. Their raw request and response bodies are not archived.

Auxiliary tools that hard-code OpenRouter’s URL remain direct and uncaptured. Desktop and TUI share the hermes harness because they use the same profile. Session boundaries use inactivity fallback because Hermes does not send an exact Mimir session ID.

Worker compatibility endpoints
  • POST /v1/hermes/<installation-id>/chat/completions
  • GET /v1/hermes/<installation-id>/models
  • GET /v1/hermes/<installation-id>/key
  • GET /v1/hermes/<installation-id>/credits

These routes accept a Mimir machine token or the OpenRouter credential registered to that installation. OpenRouter authentication on this surface cannot read sessions, logs, or configuration.

File ownership and profile changes

The installer manages ~/.hermes/plugins/mimir/ or the active Windows Hermes home. Update and uninstall touch only unchanged receipt-owned files; conflicting, modified, and symlinked targets are preserved or rejected.

Run mimir update after switching Hermes profiles so the new profile’s route and credential are registered. Manual copying from plugins/hermes/ is recovery-only.