Academy → Practical guidesOfficial documentation · clear explanation

Desktop Native Sign-In (RFC 8252)

Desktop Native Sign-In (RFC 8252)

Intermediate9 minutes3 questions2026-08-09
The idea in one minute

Start with meaning, then move to detail.

This lesson explains Desktop Native Sign-In (RFC 8252) as part of using Hermes through messaging channels. You will learn what it does, when it matters, and the smallest safe test that proves it works.

If you are new

If you are new, do not memorize names. Focus on three questions: what problem does this solve, what access does it need, and how can you verify the result?

For hands-on use

For practice, inspect the first example, identify its effects, run it on test data, and compare the result with the source claim.

For specialists

For advanced readers, inspect Why native sign-in, How it works, Capability detection & fallback, then verify failure modes and version compatibility.

What do you need first?

Prepare the channel account and understand allowlists and secret storage.

What will you know?

A clear outcome before you read.

  • Understand Desktop Native Sign-In (RFC 8252) without assumed prior knowledge.
  • Separate the source description from what still needs testing in your environment.
  • Read the first command and identify its inputs and outputs before copying it.
Lesson terms

Short definitions before the details.

Gateway
The process that connects Hermes to channels such as Telegram or Discord and routes messages.
Official page description

How the Hermes Desktop app signs in to a gated gateway using your system browser and PKCE — no embedded webview, no session cookies

Topic map

What does the source say, and in what order?

  1. 01
    Why native sign-in

    Start here to understand the core idea or structure.

  2. 02
    How it works

    Read this after the foundation, then connect it to the previous step.

  3. 03
    Capability detection & fallback

    Read this after the foundation, then connect it to the previous step.

  4. 04
    Token lifecycle

    Read this after the foundation, then connect it to the previous step.

  5. 05
    For gateway operators

    Read this after the foundation, then connect it to the previous step.

  6. 06
    See also

    Finish here to verify the result and special cases.

Examples from the official page

Copy only after you understand the effect.

Desktop app Gateway (/auth/native/*) Nous Portal (IDP) │ 1. open loopback 127.0.0.1:<random port> │ 2. system browser ─► /auth/native/authorize │ (PKCE challenge) (starts the normal PKCE login) ─► /oauth/authorize │ ◄──── code ──── /auth/callback ◄──┘ │ 3. mint one-time gateway code │ ◄─ 302 127.0.0.1/cb?code=… ─┘ │ 4. POST /auth/native/token (code + PKCE verifier) │ ◄─ 5. { access_token, refresh_token, expires_at } ───────┘ │ 6. store in OS keychain; use Bearer for REST + WS tickets
Try it now

Read the first command and identify its inputs and outputs before copying it.

Match every command to your installed Hermes version, review the files and accounts it can reach, and use non-sensitive data for the first test. If this explanation differs from the source, the official source wins.

Knowledge check

Three decisions before completion.

1. What is the source of truth when “Desktop Native Sign-In (RFC 8252)” changes?
2. What is the best way to apply this lesson?
3. What should happen before a step can modify files or an external account?