وسيط الاشتراكات
Subscription Proxy
ما هذه الصفحة، وماذا تحتوي.
المزوّد والنموذج: المزوّد هو الشركة التي تشغّل نموذج الذكاء الاصطناعي، والنموذج هو «العقل» الذي يفكّر لـHermes. Hermes نفسه لا يفكّر؛ هو ينظّم العمل ويستدعي النموذج. لذلك اختيار النموذج يحدّد جودة النتيجة وتكلفتها. ستستعمل هنا hermes portal وhermes proxy start، والقراءة نحو 5 دقائق. انتبه: الأغلى ليس دائمًا الأفضل لمهمتك. جرّب مهمة واحدة على نموذجين وقارن، وضع سقفًا للإنفاق من البداية.
Use your Nous Portal subscription (or other OAuth provider) as an OpenAI-compatible endpoint for external apps
نتائج مأخوذة من هذه الصفحة، لا من قالب.
- تعرف ما المزوّد والنموذج ولماذا قد تحتاجه.
- تنفّذ
hermes portalوhermes proxy startوتفهم ما يحدث بعدها. - تقرأ الجدول وتأخذ منه السطر الذي يخصّك فقط.
- تضبط
OPENAI_API_BASE_URLفي المكان الصحيح.
كما تظهر تمامًا داخل Hermes.
hermes portalhermes proxy starthermes proxy statushermes proxy providers
OPENAI_API_BASE_URLOPENAI_API_KEYINFERENCE_TEXT_MODEL
انتقل مباشرة إلى ما تحتاجه.
بلا اختصار أو حذف.
النص أدناه منقول من المصدر الرسمي بالإنجليزية حتى تبقى الأوامر والأسماء دقيقة كما هي. قبل كل قسم شرح عربي يوضّح ما بداخله.
The subscription proxy is a local HTTP server that lets external apps — OpenViking, Karakeep, Open WebUI, anything that speaks OpenAI-compatible chat completions — use your Hermes-managed provider subscription as their LLM endpoint. The proxy attaches the right credentials (refreshing them automatically) so the app never needs a static API key.
This is different from the API server:
| API server | Subscription proxy | |
|---|---|---|
| What it serves | Your agent (full toolset, memory, skills) | Raw model inference |
| Use case | "Use Hermes as a chat backend" | "Use my Portal sub from another app" |
| Auth | Your API_SERVER_KEY | Any bearer (proxy attaches the real one) |
| Tool calls | Yes — the agent runs tools | No — passthrough only |
Use the API server when you want the agent as a backend. Use the proxy when you just want the model through your subscription.
Quick Start
خطوات عملية بالترتيب. نفّذ خطوة وتأكد أنها نجحت قبل الانتقال للتالية. الأوامر هنا: hermes portal، hermes proxy start.
1. Log into your provider (one-time)
hermes portalThis opens your browser for the Nous Portal OAuth flow. Hermes stores
the refresh token in ~/.hermes/auth.json — the same place all Hermes
provider logins live.
2. Start the proxy
hermes proxy startStarting Hermes proxy for Nous Portal
Listening on: http://127.0.0.1:8645/v1
Forwarding to: (resolved per-request from your subscription)
Use any bearer token in the client — the proxy attaches your real credential.Leave this running in the foreground. Use tmux, nohup, or a systemd
unit if you want it to survive logout.
3. Point your app at it
Any OpenAI-compatible app config takes the same triple:
Base URL: http://127.0.0.1:8645/v1
API key: anything (e.g. "sk-unused")
Model: Hermes-4-70B # or Hermes-4.3-36B, Hermes-4-405BThe proxy ignores the Authorization header from your app and attaches
your real Portal credential to the upstream request. Refreshes happen
automatically when the bearer approaches expiry.
Available providers
أوامر تكتبها في الطرفية. افهم ما يفعله الأمر قبل نسخه. الأوامر هنا: hermes proxy providers.
hermes proxy providersCurrently shipped: nous (Nous Portal) and xai (xAI / Grok). More
OAuth providers can be added by implementing the UpstreamAdapter
interface in hermes_cli/proxy/adapters/.
Check status
أوامر تكتبها في الطرفية. افهم ما يفعله الأمر قبل نسخه. الأوامر هنا: hermes portal، hermes proxy status.
hermes proxy statusHermes proxy upstream adapters
[nous ] Nous Portal — ready (bearer expires 2026-05-15T06:43:21Z)If you see not logged in, run hermes portal. If you see
credentials need attention, your refresh token was revoked (rare —
happens if you signed out from the Portal web UI) — just re-run
hermes portal.
Allowed paths
جدول مرجعي. لا تقرأه كله، ابحث عن السطر الذي يخصّك فقط.
The proxy only forwards paths the upstream actually serves. For Nous Portal:
| Path | Purpose |
|---|---|
/v1/chat/completions | Chat completions (streaming + non-streaming) |
/v1/completions | Legacy text completions |
/v1/embeddings | Embeddings |
/v1/models | Model list |
Other paths (/v1/images/generations, /v1/audio/speech, etc.) return
404 with a clear error pointing at the allowed paths. This keeps stray
clients from leaking weird requests to the upstream.
Configuring OpenViking to use Portal
إعدادات تضبطها مرة وتنساها. غيّر واحدًا في كل مرة حتى تعرف أثر كل تغيير. الأوامر هنا: hermes proxy start.
OpenViking ↗ is a context
database that needs an LLM provider for its VLM (vision/language model
used to extract memories) and embedding model. With the proxy, you can
point its vlm.api_base at your local proxy:
Edit ~/.openviking/ov.conf:
{
"vlm": {
"provider": "openai",
"model": "Hermes-4-70B",
"api_base": "http://127.0.0.1:8645/v1",
"api_key": "unused-proxy-attaches-real-creds"
}
}Then start your proxy in a terminal alongside openviking-server:
# Terminal 1
hermes proxy start
# Terminal 2
openviking-serverOpenViking's VLM calls now flow through your Portal subscription. The
embedding model side still needs its own provider — Portal does serve
/v1/embeddings but the model selection depends on what your tier
supports; check portal.nousresearch.com/models.
Configuring Karakeep (or any bookmark/summarizer app)
إعدادات تضبطها مرة وتنساها. غيّر واحدًا في كل مرة حتى تعرف أثر كل تغيير. تضبط OPENAI_API_BASE_URL، OPENAI_API_KEY خارج المحادثة، في بيئة التشغيل.
Karakeep ↗ takes an OpenAI-compatible API for bookmark summarization. In its config:
# Karakeep .env
OPENAI_API_BASE_URL=http://127.0.0.1:8645/v1
OPENAI_API_KEY=any-non-empty-string
INFERENCE_TEXT_MODEL=Hermes-4-70BSame pattern works for Open WebUI, LobeChat, NextChat, or any other OpenAI-compatible client.
Exposing on LAN
أوامر تكتبها في الطرفية. افهم ما يفعله الأمر قبل نسخه. الأوامر هنا: hermes proxy start.
By default the proxy binds 127.0.0.1 (localhost only). To let other
machines on your network use it:
hermes proxy start --host 0.0.0.0 --port 8645⚠ Be aware: anyone on your network can now use your Portal subscription. The proxy has no auth of its own — it accepts any bearer. Use a firewall, VPN, or reverse proxy with proper auth if you expose this beyond your trusted network.
Rate limits
شرح للفكرة نفسها. اقرأه ببطء، فبقية الأقسام تبني عليه. تذكير: المزوّد هو الشركة التي تشغّل نموذج الذكاء الاصطناعي، والنموذج هو «العقل» الذي يفكّر لـHermes.
Your Portal tier's RPM/TPM limits apply across the whole proxy. The proxy doesn't fan out or pool — it's a single bearer with your full subscription quota. Monitor usage at portal.nousresearch.com ↗.
Architecture
شرح للفكرة نفسها. اقرأه ببطء، فبقية الأقسام تبني عليه.
The proxy is intentionally minimal. Per request:
- Receive
POST /v1/chat/completionsfrom your app - Look up the adapter's current credential (refresh if expiring)
- Forward the request body verbatim, with
Authorization: Bearer <minted-key> - Stream the response back unchanged (SSE preserved)
No transformation. No logging of request bodies. No agent loop. The proxy is a credential-attaching pass-through.
Future: more OAuth providers
شرح للفكرة نفسها. اقرأه ببطء، فبقية الأقسام تبني عليه.
The adapter system is pluggable. Adding a new provider (e.g.
HuggingFace, GitHub Copilot's chat endpoint, Anthropic via OAuth)
requires implementing UpstreamAdapter in
hermes_cli/proxy/adapters/<provider>.py and registering it in
adapters/__init__.py. Providers that aren't OpenAI-compatible at the
protocol level (Anthropic Messages API, for example) would need a
transformation layer, which is out of scope for the current shape.
4 أسئلة إجاباتها كلها في هذه الصفحة.
كل خيار اسم حقيقي من توثيق Hermes. حتى الخيارات الخاطئة حقيقية، لكنها من صفحات أخرى.