Skip to main content
Glama

Hermes MCP Bridge

Securely connect ChatGPT to a local Hermes Agent and Codex CLI running in WSL2, through an OpenAI Secure MCP Tunnel.

The bridge is a controlled local execution boundary, not a general remote shell. The current signed production release is v1.2.3. It has 27 MCP tools, local-only version/provenance reporting, and durable Codex worker supervision that preserves running while a worker is unavailable but its child remains alive.

Safety model

  • Hermes uses its authenticated local Runs API and its own approval policy.

  • An advertised Hermes approval-response endpoint does not by itself prove that the API profile can create an interactive approval session; v1.1.0 SSE approval integration is deferred pending an upstream contract.

  • Codex can use only explicitly allowlisted workspaces.

  • Codex permits only read-only and workspace-write; danger-full-access is rejected.

  • Every write job requires interactive approval in the local WSL2 terminal.

  • Approved Codex work is supervised by a durable local worker, which persists its terminal outcome independently of the tunnel process.

  • Workspace policies can restrict sandbox modes, runtime, prompt size, concurrency, approval lifetime, and configured pre-flight prompt patterns.

  • Audit logs are redacted, local-only, rotating JSONL files. Secrets, prompts, and outputs are not written to them.

  • A persistent Codex watchdog enforces each workspace runtime limit even when no client polls job status.

Related MCP server: chatgpt-deepseek-bridge

Start here

bash install.sh
./bridge.sh doctor
./bridge.sh codex-doctor
./bridge.sh diagnostics
./bridge.sh version

./bridge.sh version is local-only: it does not contact Hermes, Codex, the tunnel, GitHub, or another network service. It reports the installed bridge version, release/provenance fields, config-schema version, and MCP discovery contract. The MCP equivalent is the read-only bridge_version tool.

Run bash tunnel.sh init tunnel_YOUR_ID --force when changing the bridge directory or version; it updates the hermes-wsl profile and starts the tunnel. Later starts use bash tunnel.sh run.

Documentation

License

Licensed under Apache License 2.0.

The Local Hands design was inspired in part by Endeavor Hands (MIT). No Endeavor Hands source code or assets are incorporated in the current runtime; see Third-Party Notices.

Related MCP Connectors

Related MCP Servers