Hermes MCP Bridge
Provides tools for interacting with a local Hermes Agent, including health checks, model catalog access, task submission/status/result/cancel, recent tasks, and usage summary and export.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Hermes MCP Bridgesubmit a Hermes task to list my recent Codex jobs in WSL2"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Hermes MCP Bridge
Securely connect ChatGPT to a local Hermes Agent and Codex CLI running in WSL2, through an OpenAI Secure MCP Tunnel.
The bridge is a controlled local execution boundary, not a general remote shell. The current signed production release is v1.2.3. It has 27 MCP tools, local-only version/provenance reporting, and durable Codex worker supervision that preserves running while a worker is unavailable but its child remains alive.
Safety model
Hermes uses its authenticated local Runs API and its own approval policy.
An advertised Hermes approval-response endpoint does not by itself prove that the API profile can create an interactive approval session; v1.1.0 SSE approval integration is deferred pending an upstream contract.
Codex can use only explicitly allowlisted workspaces.
Codex permits only
read-onlyandworkspace-write;danger-full-accessis rejected.Every write job requires interactive approval in the local WSL2 terminal.
Approved Codex work is supervised by a durable local worker, which persists its terminal outcome independently of the tunnel process.
Workspace policies can restrict sandbox modes, runtime, prompt size, concurrency, approval lifetime, and configured pre-flight prompt patterns.
Audit logs are redacted, local-only, rotating JSONL files. Secrets, prompts, and outputs are not written to them.
A persistent Codex watchdog enforces each workspace runtime limit even when no client polls job status.
Related MCP server: chatgpt-deepseek-bridge
Start here
bash install.sh
./bridge.sh doctor
./bridge.sh codex-doctor
./bridge.sh diagnostics
./bridge.sh version./bridge.sh version is local-only: it does not contact Hermes, Codex, the tunnel, GitHub, or another network service. It reports the installed bridge version, release/provenance fields, config-schema version, and MCP discovery contract. The MCP equivalent is the read-only bridge_version tool.
Run bash tunnel.sh init tunnel_YOUR_ID --force when changing the bridge directory or version; it updates the hermes-wsl profile and starts the tunnel. Later starts use bash tunnel.sh run.
Documentation
v1.x acceptance checklist, compatibility matrix, and release runbook
Security and contributing
Local Hands v1.2.0 read-only setup and WSL2/DrvFS live acceptance
License
Licensed under Apache License 2.0.
The Local Hands design was inspired in part by Endeavor Hands (MIT). No Endeavor Hands source code or assets are incorporated in the current runtime; see Third-Party Notices.
This server cannot be deployed
Maintenance
Related MCP Connectors
Use your Mac, Windows or Linux computer from ChatGPT, Claude or Codex: files, commands, documents.
Operate Linux, macOS and Windows from your LLM. Every action runs through an auditable allowlist.
A paid remote MCP for OpenAI Codex agent coordination MCP, built to return verdicts, receipts, usage
Connect AI assistants to explicitly paired computers, servers, and VMs for permitted remote actions.
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceEnables MCP agents to delegate tasks to a local Hermes Agent for terminal, file, browser, and coding operations, and schedule recurring jobs.MIT
- AlicenseNot gradedqualityBmaintenanceEnables ChatGPT (or any MCP client) to delegate coding tasks to a local Hermes-backed agent with async job management, supporting read-only investigation, implementation, and continuation of sessions via secure MCP tunnel.1MIT
- AlicenseNot gradedqualityAmaintenanceEnables ChatGPT to securely inspect local Codex projects, read session history, and dispatch confirmed tasks to the Codex CLI through a local MCP bridge.Apache 2.0
- AlicenseNot gradedqualityBmaintenanceEnables ChatGPT conversations to directly inspect local workspaces and delegate coding tasks to a local Codex agent, with controlled concurrency, reusable sessions, and task/usage tracking.583 npmMIT