Academy → Developer guideOfficial documentation · clear explanation

Secret Source Plugins

Secret Source الإضافات

Developer11 minutes3 questions2026-08-09
The idea in one minute

Start with meaning, then move to detail.

This lesson explains Secret Source Plugins as part of Hermes internals and extension points. You will learn what it does, when it matters, and the smallest safe test that proves it works.

If you are new

If you are new, do not memorize names. Focus on three questions: what problem does this solve, what access does it need, and how can you verify the result?

For hands-on use

For practice, inspect the first example, identify its effects, run it on test data, and compare the result with the source claim.

For specialists

For advanced readers, inspect What the framework owns vs. what you own, Directory structure, The SecretSource ABC, then verify failure modes and version compatibility.

What do you need first?

Know Python, Git, and basic project structure before changing code.

What will you know?

A clear outcome before you read.

  • Understand Secret Source Plugins without assumed prior knowledge.
  • Separate the source description from what still needs testing in your environment.
  • Read the first command and identify its inputs and outputs before copying it.
Official page description

How to build a secret-manager backend plugin for Hermes Agent

Topic map

What does the source say, and in what order?

  1. 01
    What the framework owns vs. what you own

    Start here to understand the core idea or structure.

  2. 02
    Directory structure

    Read this after the foundation, then connect it to the previous step.

  3. 03
    The SecretSource ABC

    Read this after the foundation, then connect it to the previous step.

  4. 04
    Contract rules (enforced, not suggestions)

    Read this after the foundation, then connect it to the previous step.

  5. 05
    Choosing your shape

    Read this after the foundation, then connect it to the previous step.

  6. 06
    Optional hooks

    Read this after the foundation, then connect it to the previous step.

  7. 07
    Subprocess safety: use runsecretcli()

    Read this after the foundation, then connect it to the previous step.

  8. 08
    Registering

    Read this after the foundation, then connect it to the previous step.

  9. 09
    Users configure it like any other source

    Read this after the foundation, then connect it to the previous step.

  10. 10
    Validate with the conformance kit

    Finish here to verify the result and special cases.

Examples from the official page

Copy only after you understand the effect.

~/.hermes/plugins/my-vault/ ├── plugin.yaml # name, description └── __init__.py # SecretSource subclass + register(ctx)
### Contract rules (enforced, not suggestions) - **`fetch()` never raises.** Errors go in `result.error` + `result.error_kind`. A raising fetch is contained by the orchestrator and reported as `INTERNAL` — a contract violation, not a feature. - **`fetch()` never prompts.** Startup runs in non-TTY contexts (gateway, cron, Docker). `run_secret_cli()` closes stdin so a prompting helper fails fast. Interactive auth belongs in your CLI setup flow, never on the startup path. - **Sync, within budget.** The orchestrator enforces a wall-clock timeout (default 120s, user-tunable via `secrets.<name>.tim
Registration is rejected (with a log warning, never a crash) for: non-`SecretSource` instances, invalid/duplicate names, a `scheme` another source owns, wrong `api_version`, or a `shape` outside `mapped`/`bulk`. :::note Timing Plugin discovery runs later in startup than the first `load_hermes_dotenv()` call, so a plugin source is not consulted by the very first env load of the process that discovers it. It IS consulted by every subsequently spawned Hermes process (gateway children, cron sessions, subagents). Bundled sources cover first-process bootstrap. ::: ## Users configure it like any ot
Try it now

Read the first command and identify its inputs and outputs before copying it.

Match every command to your installed Hermes version, review the files and accounts it can reach, and use non-sensitive data for the first test. If this explanation differs from the source, the official source wins.

Knowledge check

Three decisions before completion.

1. What is the source of truth when “Secret Source Plugins” changes?
2. What is the best way to apply this lesson?
3. What should happen before a step can modify files or an external account?