Academy → Hermes FeaturesOfficial documentation · Arabic guidance

Credential Pools

مجمّعات بيانات الاعتماد

Intermediate to advanced8 min readLesson 245 questions✓ 2026-08-18
Before you read

What this page is, and what it holds.

This page covers Credential Pools. It carries a source warning and takes about 8 minutes to read. Never put a key in a chat or in a config file you share. Use environment variables or a secret manager.

12sections
12code examples
4tables
6commands
1,319source words
The official one-line description

Pool multiple API keys or OAuth tokens per provider for automatic rotation and rate limit recovery.

What you will be able to do

Outcomes taken from this page, not a template.

  • Understand what الأسرار والمفاتيح is and when you need it.
  • Run hermes auth and hermes auth add and understand what happens next.
  • Read the table and take only the row that applies to you.
  • Set OPENROUTER_API_KEY in the right place.
Identifiers you will meet

Exactly as they appear in Hermes.

Commands
  • hermes auth
  • hermes auth add
  • hermes auth add anthropic
  • hermes model
  • hermes auth list
  • hermes auth add openrouter
Environment variables
  • OPENROUTER_API_KEY
  • ANTHROPIC_API_KEY
Page map

Jump to the part you need.

  1. 01How It Works
  2. 02Quick Start
  3. 03Interactive Management
  4. 04CLI Commands
  5. 05Rotation Strategies
  6. 06Error Recovery
  7. 07Custom Endpoint Pools
  8. 08Auto-Discovery
  9. 09Delegation & Subagent Sharing
  10. 10Thread Safety
  11. 11Architecture
  12. 12Storage
The full official page

Nothing summarised away.

The documentation body below is reproduced from the official source so commands and identifiers stay exact. Each section carries a short note describing what it contains.

Credential pools let you register multiple API keys or OAuth tokens for the same provider. When one key hits a rate limit or billing quota, Hermes automatically rotates to the next healthy key — keeping your session alive without switching providers.

This is different from fallback providers, which switch to a different provider entirely. Credential pools are same-provider rotation; fallback providers are cross-provider failover. Pools are tried first — if all pool keys are exhausted, then the fallback provider activates.

How It Works

Explains the idea itself. Read it slowly; the later sections build on it.

Text16 lines
Your request
  → Pick key from pool (round_robin / least_used / fill_first / random)
  → Send to provider
  → 429 rate limit?
      → Plan/usage limit reached (e.g. ChatGPT/Codex "usage limit reached")?
          → Rotate to next pool key immediately (no retry — the cap won't clear on retry)
      → Generic / transient 429?
          → Retry same key once (transient blip)
          → Second 429 → rotate to next pool key
      → All keys exhausted → fallback_model (different provider)
  → 402 billing error?
      → Immediately rotate to next pool key (1h cooldown)
  → 401 auth expired?
      → Try refreshing the token (OAuth)
      → Refresh failed → rotate to next pool key
  → Success → continue normally

Quick Start

Ordered, practical steps. Run one and confirm it worked before moving on. Commands here: hermes auth add anthropic, hermes auth list.

If you already have an API key set in .env, Hermes auto-discovers it as a 1-key pool. To benefit from pooling, add more keys:

Shell9 lines
# Add a second OpenRouter key
hermes auth add openrouter --api-key sk-or-v1-your-second-key

# Add a second Anthropic key
hermes auth add anthropic --type api-key --api-key sk-ant-api03-your-second-key

# Add an Anthropic OAuth credential (requires Claude Max plan + extra usage credits)
hermes auth add anthropic --type oauth
# Opens browser for OAuth login

Check your pools:

Shell1 line
hermes auth list

Output:

Text8 lines
openrouter (2 credentials):
  #1  OPENROUTER_API_KEY   api_key env:OPENROUTER_API_KEY ←
  #2  backup-key           api_key manual

anthropic (3 credentials):
  #1  hermes_pkce          oauth   hermes_pkce ←
  #2  claude_code          oauth   claude_code
  #3  ANTHROPIC_API_KEY    api_key env:ANTHROPIC_API_KEY

The ← marks the currently selected credential.

Interactive Management

Commands you type in a terminal. Understand what one does before copying it. Commands here: hermes auth.

Run hermes auth with no subcommand for an interactive wizard:

Shell1 line
hermes auth

This shows your full pool status and offers a menu:

Text6 lines
What would you like to do?
  1. Add a credential
  2. Remove a credential
  3. Reset cooldowns for a provider
  4. Set rotation strategy for a provider
  5. Exit

For providers that support both API keys and OAuth (Anthropic, Nous, Codex), the add flow asks which type:

Text4 lines
anthropic supports both API keys and OAuth login.
  1. API key (paste a key from the provider dashboard)
  2. OAuth login (authenticate via browser)
Type [1/2]:

CLI Commands

A lookup table. Do not read it all; find the row that applies to you.

CommandDescription
hermes authInteractive pool management wizard
hermes auth listShow all pools and credentials
hermes auth list <provider>Show a specific provider's pool
hermes auth add <provider>Add a credential (prompts for type and key)
hermes auth add <provider> --type api-key --api-key <key>Add an API key non-interactively
hermes auth add <provider> --type oauthAdd an OAuth credential via browser login
hermes auth remove <provider> <index>Remove credential by 1-based index
hermes auth reset <provider>Clear all cooldowns/exhaustion status

Rotation Strategies

A lookup table. Do not read it all; find the row that applies to you. Commands here: hermes auth.

Configure via hermes auth → "Set rotation strategy" or in config.yaml:

YAML3 lines
credential_pool_strategies:
  openrouter: round_robin
  anthropic: least_used
StrategyBehavior
fill_first (default)Use the first healthy key until it's exhausted, then move to the next
round_robinCycle through keys evenly, rotating after each selection
least_usedAlways pick the key with the lowest request count
randomRandom selection among healthy keys

Error Recovery

A troubleshooting section. Find the symptom that matches yours rather than reading it end to end.

The pool handles different errors differently:

ErrorBehaviorCooldown
429 Rate LimitRetry same key once (transient). Second consecutive 429 rotates to next key1 hour
402 Billing/QuotaImmediately rotate to next key1 hour
401 Auth ExpiredTry refreshing the OAuth token first. Rotate only if refresh fails5 minutes
All keys exhaustedFall through to fallback_model if configured—

Provider-supplied reset_at timestamps override these default cooldowns.

The has_retried_429 flag resets on every successful API call, so a single transient 429 doesn't trigger rotation.

Custom Endpoint Pools

Settings you configure once. Change one at a time so you can see what each does. Commands here: hermes model, hermes auth add.

Custom OpenAI-compatible endpoints (Together.ai, RunPod, local servers) get their own pools, keyed by the endpoint name from the providers: dict in config.yaml (or the legacy custom_providers list, which is auto-migrated).

When you set up a custom endpoint via hermes model, it auto-generates a name like "Together.ai" or "Local (localhost:8080)". This name becomes the pool key.

Shell8 lines
# After setting up a custom endpoint via hermes model:
hermes auth list
# Shows:
#   Together.ai (1 credential):
#     #1  config key    api_key config:Together.ai ←

# Add a second key for the same endpoint:
hermes auth add Together.ai --api-key sk-together-second-key

Custom endpoint pools are stored in auth.json under credential_pool with a custom: prefix:

JSON6 lines
{
  "credential_pool": {
    "openrouter": [...],
    "custom:together.ai": [...]
  }
}

Auto-Discovery

A lookup table. Do not read it all; find the row that applies to you. Commands here: hermes auth add.

Hermes automatically discovers credentials from multiple sources and seeds the pool on startup:

SourceExampleAuto-seeded?
Environment variablesOPENROUTER_API_KEY, ANTHROPIC_API_KEYYes
OAuth tokens (auth.json)Codex device code, Nous device codeYes
Claude Code credentials~/.claude/.credentials.jsonYes (Anthropic)
Hermes PKCE OAuth~/.hermes/auth.jsonYes (Anthropic)
Custom endpoint configmodel.api_key in config.yamlYes (custom endpoints)
Manual entriesAdded via hermes auth addPersisted in auth.json

Auto-seeded entries are updated on each pool load — if you remove an env var, its pool entry is automatically pruned. Manual entries (added via hermes auth add) are never auto-pruned.

Borrowed runtime secrets (for example env vars, Bitwarden/Vault/keyring/systemd references, and custom config values) are reference-only at the auth.json boundary. Hermes can use the resolved value in memory for the current run, but it persists only metadata such as the source ref, label, status, request counters, and a non-reversible fingerprint. Manual entries and Hermes-owned OAuth/device-code state keep the durable tokens they need to refresh.

Delegation & Subagent Sharing

Explains the idea itself. Read it slowly; the later sections build on it.

When the agent spawns subagents via delegate_task, the parent's credential pool is automatically shared with children:

  • Same provider — the child receives the parent's full pool, enabling key rotation on rate limits
  • Different provider — the child loads that provider's own pool (if configured)
  • No pool configured — the child falls back to the inherited single API key

This means subagents benefit from the same rate-limit resilience as the parent, with no extra configuration needed. Per-task credential leasing ensures children don't conflict with each other when rotating keys concurrently.

Thread Safety

Explains the idea itself. Read it slowly; the later sections build on it.

The credential pool uses a threading lock for all state mutations (select(), mark_exhausted_and_rotate(), try_refresh_current(), mark_used()). This ensures safe concurrent access when the gateway handles multiple chat sessions simultaneously.

Architecture

Explains the idea itself. Read it slowly; the later sections build on it.

For the full data flow diagram, see docs/credential-pool-flow.excalidraw ↗ in the repository.

The credential pool integrates at the provider resolution layer:

  1. agent/credential_pool.py — Pool manager: storage, selection, rotation, cooldowns
  2. hermes_cli/auth_commands.py — CLI commands and interactive wizard
  3. hermes_cli/runtime_provider.py — Pool-aware credential resolution
  4. run_agent.py — Error recovery: 429/402/401 → pool rotation → fallback

Storage

Settings you configure once. Change one at a time so you can see what each does. Set OPENROUTER_API_KEY in your environment, not in the chat.

Pool state is stored in ~/.hermes/auth.json under the credential_pool key:

JSON28 lines
{
  "version": 1,
  "credential_pool": {
    "openrouter": [
      {
        "id": "abc123",
        "label": "OPENROUTER_API_KEY",
        "auth_type": "api_key",
        "priority": 0,
        "source": "env:OPENROUTER_API_KEY",
        "secret_source": "bitwarden",
        "secret_fingerprint": "sha256:12ab34cd56ef7890",
        "last_status": "ok",
        "request_count": 142
      }
    ],
    "anthropic": [
      {
        "id": "manual1",
        "label": "personal-api-key",
        "auth_type": "api_key",
        "priority": 0,
        "source": "manual",
        "access_token": "sk-ant-api03-..."
      }
    ]
  }
}

The OpenRouter entry above was borrowed from an external source, so the raw key is not stored in auth.json. The manual Anthropic entry was intentionally added to Hermes' credential store, so its token remains persistable.

Strategies are stored in config.yaml (not auth.json):

YAML3 lines
credential_pool_strategies:
  openrouter: round_robin
  anthropic: least_used
Knowledge check

5 questions answered by this page alone.

Every option is a real identifier from the Hermes documentation. The wrong ones are real too, just from other pages.

1. In this lesson's table, what is the “Description” for “hermes auth add”?
2. Which of these environment variables actually appears in this lesson?
3. Which warning does the source state in this lesson?
4. Which of these headings does not appear in this lesson?
5. Which configuration key appears in this lesson's examples?