hermes-mcp-bridge
Integrates with a local Hermes Gateway API, enabling AI agents to delegate tasks to a Hermes AI agent with support for session continuity and profile selection.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@hermes-mcp-bridgeSearch for MCP protocol documentation"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
hermes-mcp-bridge
A zero-friction stdio MCP bridge connecting Cursor Desktop to a local Hermes Agent — no OAuth, no tunnels, no Dynamic Client Registration.
1. Architecture
Cursor Desktop hermes-mcp-bridge Hermes Gateway
┌──────────────┐ stdio ┌─────────────────────┐ HTTP ┌──────────────┐
│ mcp.json │ ─────────→ │ FastMCP │ ───────→ │ 127.0.0.1 │
│ command: │ │ ├ hermes_ask() │ Bearer │ :8642 │
│ /home/... │ ←───────── │ ├ hermes_check() │ ←─────── │ /v1/chat/ │
└──────────────┘ stdio │ ├ hermes_cancel() │ JSON │ completions │
│ └ hermes_reset() │ └──────────────┘
└─────────────────────┘
X-Hermes-Session-Id → REPL context1.1 Comparison with mlennie/hermes-mcp
|
| |
Transport | Streamable HTTP | stdio |
Auth | OAuth 2.1 + DCR | Bearer header |
External deps | cloudflared / ngrok | none |
Process model | Standalone daemon | Cursor subprocess |
Deployment files | 5 configs + systemd unit | 2 files |
Related MCP server: cursor-mcp-server
2. Profile Awareness
The bridge connects to the same Hermes profile your gateway is serving. It inherits everything that profile has loaded — skills, memory, tools, sessions.
You can pick which profile to use in two ways:
Method | What you do | When to use |
Set a default | Edit | You mostly use one profile |
Mention it in chat | Say "Use Hermes with the default profile to…" in the Cursor chat input | You switch profiles often |
Neither requires touching mcp.json or restarting Cursor.
2.1 Default profile (config.toml)
# ~/.config/hermes-mcp-bridge/config.toml
model = "general_researcher" # ← used when no profile arg is passed2.2 Switching profiles from Cursor
The hermes_ask tool exposes an optional profile parameter. Just mention
which profile you want — Cursor's LLM reads the tool signature and passes it.
┌─────────────────────────────────────────────────────────┐
│ You say in Cursor │
├─────────────────────────────────────────────────────────┤
│ "Use Hermes with the default profile to send an email" │
│ → hermes_ask(prompt="send an email", │
│ profile="default") │
│ │
│ "Ask Hermes to search arXiv for MCP papers" │
│ → hermes_ask(prompt="search arXiv...") │
│ # no profile → uses config.toml default │
└─────────────────────────────────────────────────────────┘No mcp.json changes, no config edits, no restart. Just say the profile name.
2.3 Discover available profiles
curl -s http://127.0.0.1:8642/v1/models \
-H "Authorization: Bearer change...-dev"
# → {"data": [{"id": "general_researcher", ...}, {"id": "default", ...}]}If your gateway only runs one profile, only one
idappears. Start additional gateway instances on different ports to serve multiple profiles simultaneously.
3. Why This Exists
mlennie/hermes-mcp v0.4.0 hits three real-world blockers:
OAuth 2.1 demands an HTTPS tunnel — even when Cursor and Hermes run on the same machine.
No Dynamic Client Registration support —
mcp-remotecrashes withIncompatible auth server.Cursor's localhost OAuth callback is broken — its built-in MCP HTTP client returns
ERR_EMPTY_RESPONSEonlocalhost.
This bridge drops the HTTP transport layer entirely, runs as a stdio subprocess, and sidesteps all three.
4. Quick Start
4.1 Install
git clone https://github.com/<your-org>/hermes-mcp-bridge.git
cd hermes-mcp-bridge
uv tool install --editable .4.2 Configure
mkdir -p ~/.config/hermes-mcp-bridge
cat > ~/.config/hermes-mcp-bridge/config.toml << 'EOF'
api_url = "http://127.0.0.1:8642"
api_key = "change-me-local-dev" # must match API_SERVER_KEY in ~/.hermes/.env
model = "general_researcher"
timeout_seconds = 300
EOF
chmod 600 ~/.config/hermes-mcp-bridge/config.toml4.3 Register with Cursor
Add to ~/.cursor/mcp.json:
{
"mcpServers": {
"hermes": {
"command": "/home/nirvana/.local/bin/hermes-mcp-bridge"
}
}
}4.4 Restart Cursor
Settings → MCP → hermes should show connected.
5. Tools
Tool | Signature | Purpose |
|
| Delegate a task to Hermes Agent |
|
| Poll async job status (stub) |
|
| Cancel an async job (stub) |
|
| Clear the job queue (stub) |
The last three are kept for API parity.
hermes-mcp-bridgeruns synchronously —hermes_askblocks until the full Agent response is ready.
6. REPL Context (Session Continuity)
Hermes remembers what you told it earlier — just keep talking in the same
Cursor chat. Cursor automatically reuses the same session_id across turns.
┌─────────────────────────────────────────────────────────┐
│ You say in Cursor │
├─────────────────────────────────────────────────────────┤
│ "Use Hermes to remember that my lucky number is 42" │
│ → Hermes remembers 42 │
│ │
│ "Ask Hermes what my lucky number is" │
│ → Hermes answers 42 │
│ (same session_id — context preserved) │
└─────────────────────────────────────────────────────────┘The bridge passes session_id through as the X-Hermes-Session-Id HTTP header.
The gateway uses it to maintain context across calls.
No special syntax. No session IDs to track. Just talk normally — Hermes remembers.
7. Configuration Reference
~/.config/hermes-mcp-bridge/config.toml
Key | Default | Description |
|
| Hermes Gateway HTTP API address |
| — | Must match |
|
| Must match a model ID from gateway |
|
| Max wait per |
Environment variable overrides (higher priority): HERMES_BRIDGE_API_URL, HERMES_BRIDGE_API_KEY.
8. Security
All network traffic is confined to the
127.0.0.1loopback interface.The API key lives in
~/.config/hermes-mcp-bridge/config.toml(mode600).The repository itself contains no keys, secrets, or credentials.
Cursor spawns the bridge via stdio — no ports are exposed.
9. License
Apache-2.0
Available Tools
4 toolshermes_askA
Delegate a task to Hermes Agent on this user's machine.
Use for things the calling LLM cannot do directly: scheduling cron jobs, browser-driven web search, sending email, creating/editing local documents, anything that should persist after this chat ends.
Args: prompt: Natural-language instruction for Hermes. session_id: Optional. Pass the same id across multiple calls in one chat to let Hermes remember prior steps (draft → refine → save). profile: Optional. Hermes profile to use (e.g. 'default', 'general_researcher'). Overrides the model in config.toml. Discover available profiles via the gateway's /v1/models endpoint.
Returns: Hermes's final answer text.
| Name | Required | Description | Default |
|---|---|---|---|
| prompt | Yes | ||
| profile | No | ||
| session_id | No |
Output Schema
| Name | Required | Description |
|---|---|---|
| result | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries full burden. It discloses that tasks persist after the chat and that session_id enables memory across calls. However, it does not mention potential side effects, permissions, rate limits, or whether the operation is synchronous (the return statement suggests it waits for final answer).
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is well-structured with a title, usage paragraph, and argument list. It is front-loaded with the core purpose and includes necessary details without excessive verbosity. The inclusion of a method to discover profiles is useful but slightly extraneous.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
The tool has three parameters, one required, and an output schema. The description covers the return value ('Hermes's final answer text') and distinguishes from siblings. While it does not discuss error handling or timeouts, the overall clarity is adequate for an AI agent to use the tool effectively.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 0%, but the description thoroughly explains all three parameters. 'prompt' is described as a natural-language instruction, 'session_id' as optional for step memory, and 'profile' as optional with a method to discover available profiles. This adds substantial meaning beyond the schema's bare structure.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's purpose: 'Delegate a task to Hermes Agent on this user's machine.' It lists specific examples of tasks (scheduling, web search, email, editing) that distinguish it from siblings (hermes_cancel, hermes_check, hermes_reset), which handle cancellation, status checking, and resetting respectively.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description explicitly says to use this tool 'for things the calling LLM cannot do directly' and provides a list of use cases. While it does not explicitly state when not to use it or name alternatives, the context of sibling tools and the emphasis on actions that persist after the chat ends gives clear guidance.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
hermes_cancelA
Not implemented. Kept for API parity with hermes-mcp.
| Name | Required | Description | Default |
|---|---|---|---|
| job_id | Yes |
Output Schema
| Name | Required | Description |
|---|---|---|
| result | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Without annotations, the description fully discloses that the tool is non-functional and kept only for API parity. This is complete transparency about its behavior (no-operation or failure).
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single sentence that conveys all necessary information about the tool's status without any extraneous content.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a stub tool, the description adequately covers its non-functional state. However, it omits any information about the return behavior or the significance of the job_id parameter, which slightly reduces completeness.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The description provides no explanation of the required 'job_id' parameter. With 0% schema description coverage, the agent receives no guidance on what this parameter represents, which is critical even for a stub tool.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description explicitly states 'Not implemented. Kept for API parity with hermes-mcp.' This clearly communicates that the tool is a placeholder and does not perform any functional operation.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description directly advises against functional use by stating it is not implemented. However, it does not suggest alternative tools among siblings (hermes_ask, hermes_check, hermes_reset) for any potential cancellation needs.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
hermes_checkC
Not implemented. Kept for API parity with hermes-mcp.
| Name | Required | Description | Default |
|---|---|---|---|
| job_id | Yes |
Output Schema
| Name | Required | Description |
|---|---|---|
| result | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description honestly states the tool is not implemented, providing full transparency about its behavioral trait of being a stub. With no annotations, this is sufficient disclosure.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is extremely brief, stating only the essential fact (not implemented) and the reason (API parity). Every word serves a purpose with no filler.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a stub tool, the description adequately communicates its non-functional status. However, it lacks information about expected behavior if implemented, which limits completeness for a tool that appears in a tool list.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 0%, and the description adds no meaning to the 'job_id' parameter beyond what the schema already shows. The description does not explain its purpose or constraints.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description explicitly states it is 'Not implemented' and kept for API parity, which clarifies it has no actual functionality. However, the name 'hermes_check' suggests a checking operation, creating a mismatch between expectation and reality.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
No usage guidance provided. The description does not advise when to use or avoid this tool, nor does it mention alternatives among siblings like hermes_ask or hermes_cancel.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
hermes_resetA
Not implemented. Kept for API parity with hermes-mcp.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
Output Schema
| Name | Required | Description |
|---|---|---|
| result | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries full responsibility. It fully discloses that the tool has no behavior because it is not implemented.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single sentence with no wasted words, achieving maximum conciseness while conveying essential information.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a non-implemented tool with no parameters and trivial output, the description fully covers what the agent needs to know: it does nothing and exists for API parity.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The tool has zero parameters; the description adds no parameter info, but none is needed. Baseline 4 applies per instructions.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description explicitly states the tool is 'Not implemented', clearly communicating its status as a placeholder. It lacks description of intended functionality, but is honest about its current state.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description effectively advises against using the tool by stating it is not implemented. It does not provide alternative tools among siblings, but the negative guidance is clear.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.
4 tool updates
v0.1.0- First observed
hermes_ask - First observed
hermes_cancel - First observed
hermes_check - First observed
hermes_reset
TDQS
All four tools have distinct names and clear descriptions. The three non-functional tools are explicitly marked as 'Not implemented', so an agent can easily distinguish the single functional tool from the stubs.
All tool names follow a consistent 'hermes_verb' pattern with imperative verbs (ask, cancel, check, reset), which is predictable and systematic.
With only one functional tool out of four, the effective tool count is very low for a server that claims to handle diverse tasks like scheduling, browsing, and email. The three stubs inflate the count without adding value.
The server is missing core lifecycle operations: there is no way to cancel a task, check its status, or reset a session, even though stubs for these exist. The single 'ask' tool cannot cover the full intended scope.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
Real-time chat for AI agents. Claude Code, Cursor, Cline and Codex join channels over MCP.
- QuallaaOAuthcom.quallaa
Talk to your public-facing AI from any MCP client — Claude, ChatGPT, Cursor, Cline, Windsurf.
Real-time chat hub for AI agents — Claude Code, Cursor, Cline, Codex over MCP or REST.
Portable memory for AI agents: capture once, recall across Claude, Cursor, and any MCP client.
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceActs as a bridge between Claude's desktop application and the Cursor editor, enabling seamless AI-powered automation and multi-instance management across platforms with standardized communication and secure token-based authentication.1367MIT
- FlicenseNot gradedqualityDmaintenanceAn MCP server wrapping the Cursor CLI agent, enabling Claude Code and other MCP clients to delegate tasks to Cursor's AI agent for file writing, bash commands, and codebase queries.-
- AlicenseAqualityBmaintenanceMCP server that lets any agent or MCP host delegate tasks to the Cursor CLI agent for fast, headless execution. Supports task delegation, project discovery, file analysis, and follow-up sessions.3142MIT
- AlicenseNot gradedqualityCmaintenanceMCP bridge from OpenCode to Cursor agent CLI, enabling code review, debugging, and planning via Cursor cloud.22MIT
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/nirvana6/hermes-mcp-bridge'
If you have feedback or need assistance with the MCP directory API, please join our Discord server