MiniMax OAuth
تسجيل الدخول إلى MiniMax
What this page is, and what it holds.
This page covers MiniMax OAuth. You will use hermes auth add minimax-oauth and hermes model here; about 6 minutes to read. Never put a key in a chat or in a config file you share. Use environment variables or a secret manager.
Log into MiniMax via browser OAuth and use MiniMax-M2.7 models in Hermes Agent — no API key required
Outcomes taken from this page, not a template.
- Understand what الأسرار والمفاتيح is and when you need it.
- Run
hermes auth add minimax-oauthandhermes modeland understand what happens next. - Read the table and take only the row that applies to you.
- Set
MINIMAX_CN_API_KEYin the right place.
Exactly as they appear in Hermes.
hermes auth add minimax-oauthhermes modelhermes config set modelhermes setuphermes doctorhermes auth logout minimax-oauth
MINIMAX_CN_API_KEYMINIMAX_CN_BASE_URLMINIMAX_API_KEYMINIMAX_BASE_URL
Jump to the part you need.
Nothing summarised away.
The documentation body below is reproduced from the official source so commands and identifiers stay exact. Each section carries a short note describing what it contains.
Hermes Agent supports MiniMax through a browser-based OAuth login flow, using the same credentials as the MiniMax portal ↗. No API key or credit card is required — log in once and Hermes automatically refreshes your session.
The transport reuses the anthropic_messages adapter (MiniMax exposes an Anthropic Messages-compatible endpoint at /anthropic), so all existing tool-calling, streaming, and context features work without any adapter changes.
Overview
A lookup table. Do not read it all; find the row that applies to you.
| Item | Value |
|---|---|
| Provider ID | minimax-oauth |
| Display name | MiniMax (OAuth) |
| Auth type | Browser OAuth (PKCE redirect flow) |
| Transport | Anthropic Messages-compatible (anthropic_messages) |
| Models | MiniMax-M2.7, MiniMax-M2.7-highspeed |
| Global endpoint | https://api.minimax.io/anthropic |
| China endpoint | https://api.minimaxi.com/anthropic |
| Requires env var | No (MINIMAX_API_KEY is not used for this provider) |
Prerequisites
Explains the idea itself. Read it slowly; the later sections build on it.
- Python 3.9+
- Hermes Agent installed
- A MiniMax account at minimax.io ↗ (global) or minimaxi.com ↗ (China)
- A browser available on the local machine (or use
--no-browserfor remote sessions)
Quick Start
Ordered, practical steps. Run one and confirm it worked before moving on. Commands here: hermes model.
# Launch the provider and model picker
hermes model
# → Select "MiniMax (OAuth)" from the provider list
# → Hermes opens your browser to the MiniMax authorization page
# → Approve access in the browser
# → Select a model (MiniMax-M2.7 or MiniMax-M2.7-highspeed)
# → Start chatting
hermesAfter the first login, credentials are stored under ~/.hermes/auth.json and are refreshed automatically before each session.
Logging In Manually
Settings you configure once. Change one at a time so you can see what each does. Commands here: hermes auth add minimax-oauth. Set MINIMAX_CN_API_KEY, MINIMAX_CN_BASE_URL in your environment, not in the chat.
You can trigger a login without going through the model picker:
hermes auth add minimax-oauthChina region
If your account is on the China platform (minimaxi.com), use the API-key-based minimax-cn provider instead — minimax-cn is registered with auth_type="api_key" only (no OAuth flow). Configure MINIMAX_CN_API_KEY (and optionally MINIMAX_CN_BASE_URL) directly:
echo 'MINIMAX_CN_API_KEY=your-key' >> ~/.hermes/.envRemote / headless sessions
On servers or containers where no browser is available:
hermes auth add minimax-oauth --no-browserHermes will print the verification URL and user code — open the URL on any device and enter the code when prompted.
The OAuth Flow
Explains the idea itself. Read it slowly; the later sections build on it.
Hermes implements a PKCE browser OAuth flow against the MiniMax OAuth endpoints:
- Hermes generates a PKCE verifier / challenge pair and a random state value.
- It POSTs to
{base_url}/oauth/codewith the challenge and receives auser_codeandverification_uri. - Your browser opens
verification_uri. If prompted, enter theuser_code. - Hermes polls
{base_url}/oauth/tokenuntil the token arrives (or the deadline passes). - Tokens (
access_token,refresh_token, expiry) are saved to~/.hermes/auth.jsonunder theminimax-oauthkey.
Token refresh (standard OAuth refresh_token grant) runs automatically at each session start when the access token is within 60 seconds of expiry.
Checking Login Status
Commands you type in a terminal. Understand what one does before copying it. Commands here: hermes doctor.
hermes doctorThe ◆ Auth Providers section will show:
✓ MiniMax OAuth (logged in, region=global)or, if not logged in:
⚠ MiniMax OAuth (not logged in)Switching Models
Commands you type in a terminal. Understand what one does before copying it. Commands here: hermes config set model, hermes model.
hermes model
# → Select "MiniMax (OAuth)"
# → Pick from the model listOr set the model directly:
hermes config set model.default MiniMax-M2.7
hermes config set model.provider minimax-oauthConfiguration Reference
Settings you configure once. Change one at a time so you can see what each does.
After login, ~/.hermes/config.yaml will contain entries similar to:
model:
default: MiniMax-M2.7
provider: minimax-oauth
base_url: https://api.minimax.io/anthropicRegion endpoints
| Provider id | Portal | Inference endpoint |
|---|---|---|
minimax-oauth (global) | https://api.minimax.io | https://api.minimax.io/anthropic |
minimax-cn (China) | https://api.minimaxi.com | https://api.minimaxi.com/anthropic |
Provider aliases
All of the following resolve to minimax-oauth:
hermes --provider minimax-oauth # canonical
hermes --provider minimax-portal # alias
hermes --provider minimax-global # alias
hermes --provider minimax_oauth # alias (underscore form)Environment Variables
Settings you configure once. Change one at a time so you can see what each does. Commands here: hermes setup. Set MINIMAX_API_KEY, MINIMAX_BASE_URL in your environment, not in the chat.
The minimax-oauth provider does not use MINIMAX_API_KEY or MINIMAX_BASE_URL. Those variables are for the API-key-based minimax and minimax-cn providers only.
| Variable | Effect |
|---|---|
MINIMAX_API_KEY | Used by minimax provider only — ignored for minimax-oauth |
MINIMAX_CN_API_KEY | Used by minimax-cn provider only — ignored for minimax-oauth |
To use minimax-oauth as the active provider, set model.provider: minimax-oauth in config.yaml (use hermes setup for the guided flow), or pass --provider minimax-oauth for a single invocation:
hermes --provider minimax-oauthModels
Explains the idea itself. Read it slowly; the later sections build on it.
| Model | Best for |
|---|---|
MiniMax-M2.7 | Long-context reasoning, complex tool-calling |
MiniMax-M2.7-highspeed | Lower latency, lighter tasks, auxiliary calls |
Both models support up to 200,000 tokens of context.
MiniMax-M2.7 is also used automatically as the auxiliary model for vision and delegation tasks when minimax-oauth is the primary provider.
Troubleshooting
A troubleshooting section. Find the symptom that matches yours rather than reading it end to end. Commands here: hermes auth add minimax-oauth, hermes model.
Token expired — not re-logging in automatically
Hermes refreshes the token on every session start if it is within 60 seconds of expiry. If the access token is already expired (for example, after a long offline period), the refresh happens automatically on the next request. If refresh fails with refresh_token_reused or invalid_grant, Hermes marks the session as requiring re-login.
When the refresh failure is terminal (HTTP 4xx, invalid_grant, revoked grant, etc.), Hermes marks the refresh token as dead and quarantines it locally so it doesn't keep replaying the doomed exchange. The agent surfaces a single "re-authentication required" message and stays out of the way until you log in again.
Fix: run hermes auth add minimax-oauth again to start a fresh login. The quarantine clears on the next successful exchange.
Authorization timed out
The device-code flow has a finite expiry window. If you don't approve the login in time, Hermes raises a timeout error.
Fix: re-run hermes auth add minimax-oauth (or hermes model). The flow starts fresh.
State mismatch (possible CSRF)
Hermes detected that the state value returned by the authorization server does not match what it sent.
Fix: re-run the login. If it persists, check for a proxy or redirect that is modifying the OAuth response.
Logging in from a remote server
If hermes cannot open a browser window, use --no-browser:
hermes auth add minimax-oauth --no-browserHermes prints the URL and code. Open the URL on any device and complete the flow there.
"Not logged into MiniMax OAuth" error at runtime
The auth store has no credentials for minimax-oauth. You have not logged in yet, or the credential file was deleted.
Fix: run hermes model and select MiniMax (OAuth), or run hermes auth add minimax-oauth.
Logging Out
Commands you type in a terminal. Understand what one does before copying it. Commands here: hermes auth logout minimax-oauth.
To remove stored MiniMax OAuth credentials:
hermes auth logout minimax-oauthSee Also
Explains the idea itself. Read it slowly; the later sections build on it.
4 questions answered by this page alone.
Every option is a real identifier from the Hermes documentation. The wrong ones are real too, just from other pages.