Academy → Hermes FeaturesOfficial documentation · Arabic guidance

Subscription Proxy

وسيط الاشتراكات

Intermediate5 min readLesson 374 questions✓ 2026-08-18
Before you read

What this page is, and what it holds.

This page covers Subscription Proxy. You will use hermes portal and hermes proxy start here; about 5 minutes to read. The priciest model is not always best for your task. Compare on one task and set a spend cap.

10sections
11code examples
2tables
4commands
786source words
The official one-line description

Use your Nous Portal subscription (or other OAuth provider) as an OpenAI-compatible endpoint for external apps

What you will be able to do

Outcomes taken from this page, not a template.

  • Understand what المزوّد والنموذج is and when you need it.
  • Run hermes portal and hermes proxy start and understand what happens next.
  • Read the table and take only the row that applies to you.
  • Set OPENAI_API_BASE_URL in the right place.
Identifiers you will meet

Exactly as they appear in Hermes.

Commands
  • hermes portal
  • hermes proxy start
  • hermes proxy status
  • hermes proxy providers
Environment variables
  • OPENAI_API_BASE_URL
  • OPENAI_API_KEY
  • INFERENCE_TEXT_MODEL
Page map

Jump to the part you need.

  1. 01Quick Start
  2. 02Available providers
  3. 03Check status
  4. 04Allowed paths
  5. 05Configuring OpenViking to use Portal
  6. 06Configuring Karakeep (or any bookmark/summarizer app)
  7. 07Exposing on LAN
  8. 08Rate limits
  9. 09Architecture
  10. 10Future: more OAuth providers
The full official page

Nothing summarised away.

The documentation body below is reproduced from the official source so commands and identifiers stay exact. Each section carries a short note describing what it contains.

The subscription proxy is a local HTTP server that lets external apps — OpenViking, Karakeep, Open WebUI, anything that speaks OpenAI-compatible chat completions — use your Hermes-managed provider subscription as their LLM endpoint. The proxy attaches the right credentials (refreshing them automatically) so the app never needs a static API key.

This is different from the API server:

API serverSubscription proxy
What it servesYour agent (full toolset, memory, skills)Raw model inference
Use case"Use Hermes as a chat backend""Use my Portal sub from another app"
AuthYour API_SERVER_KEYAny bearer (proxy attaches the real one)
Tool callsYes — the agent runs toolsNo — passthrough only

Use the API server when you want the agent as a backend. Use the proxy when you just want the model through your subscription.

Quick Start

Ordered, practical steps. Run one and confirm it worked before moving on. Commands here: hermes portal, hermes proxy start.

1. Log into your provider (one-time)

Shell1 line
hermes portal

This opens your browser for the Nous Portal OAuth flow. Hermes stores the refresh token in ~/.hermes/auth.json — the same place all Hermes provider logins live.

2. Start the proxy

Shell1 line
hermes proxy start
Text4 lines
Starting Hermes proxy for Nous Portal
  Listening on:  http://127.0.0.1:8645/v1
  Forwarding to: (resolved per-request from your subscription)
  Use any bearer token in the client — the proxy attaches your real credential.

Leave this running in the foreground. Use tmux, nohup, or a systemd unit if you want it to survive logout.

3. Point your app at it

Any OpenAI-compatible app config takes the same triple:

Text3 lines
Base URL:   http://127.0.0.1:8645/v1
API key:    anything (e.g. "sk-unused")
Model:      Hermes-4-70B    # or Hermes-4.3-36B, Hermes-4-405B

The proxy ignores the Authorization header from your app and attaches your real Portal credential to the upstream request. Refreshes happen automatically when the bearer approaches expiry.

Available providers

Commands you type in a terminal. Understand what one does before copying it. Commands here: hermes proxy providers.

Shell1 line
hermes proxy providers

Currently shipped: nous (Nous Portal) and xai (xAI / Grok). More OAuth providers can be added by implementing the UpstreamAdapter interface in hermes_cli/proxy/adapters/.

Check status

Commands you type in a terminal. Understand what one does before copying it. Commands here: hermes portal, hermes proxy status.

Shell1 line
hermes proxy status
Text3 lines
Hermes proxy upstream adapters

  [nous    ] Nous Portal — ready (bearer expires 2026-05-15T06:43:21Z)

If you see not logged in, run hermes portal. If you see credentials need attention, your refresh token was revoked (rare — happens if you signed out from the Portal web UI) — just re-run hermes portal.

Allowed paths

A lookup table. Do not read it all; find the row that applies to you.

The proxy only forwards paths the upstream actually serves. For Nous Portal:

PathPurpose
/v1/chat/completionsChat completions (streaming + non-streaming)
/v1/completionsLegacy text completions
/v1/embeddingsEmbeddings
/v1/modelsModel list

Other paths (/v1/images/generations, /v1/audio/speech, etc.) return 404 with a clear error pointing at the allowed paths. This keeps stray clients from leaking weird requests to the upstream.

Configuring OpenViking to use Portal

Settings you configure once. Change one at a time so you can see what each does. Commands here: hermes proxy start.

OpenViking ↗ is a context database that needs an LLM provider for its VLM (vision/language model used to extract memories) and embedding model. With the proxy, you can point its vlm.api_base at your local proxy:

Edit ~/.openviking/ov.conf:

JSON8 lines
{
  "vlm": {
    "provider": "openai",
    "model": "Hermes-4-70B",
    "api_base": "http://127.0.0.1:8645/v1",
    "api_key": "unused-proxy-attaches-real-creds"
  }
}

Then start your proxy in a terminal alongside openviking-server:

Shell5 lines
# Terminal 1
hermes proxy start

# Terminal 2
openviking-server

OpenViking's VLM calls now flow through your Portal subscription. The embedding model side still needs its own provider — Portal does serve /v1/embeddings but the model selection depends on what your tier supports; check portal.nousresearch.com/models.

Configuring Karakeep (or any bookmark/summarizer app)

Settings you configure once. Change one at a time so you can see what each does. Set OPENAI_API_BASE_URL, OPENAI_API_KEY in your environment, not in the chat.

Karakeep ↗ takes an OpenAI-compatible API for bookmark summarization. In its config:

Shell4 lines
# Karakeep .env
OPENAI_API_BASE_URL=http://127.0.0.1:8645/v1
OPENAI_API_KEY=any-non-empty-string
INFERENCE_TEXT_MODEL=Hermes-4-70B

Same pattern works for Open WebUI, LobeChat, NextChat, or any other OpenAI-compatible client.

Exposing on LAN

Commands you type in a terminal. Understand what one does before copying it. Commands here: hermes proxy start.

By default the proxy binds 127.0.0.1 (localhost only). To let other machines on your network use it:

Shell1 line
hermes proxy start --host 0.0.0.0 --port 8645

⚠ Be aware: anyone on your network can now use your Portal subscription. The proxy has no auth of its own — it accepts any bearer. Use a firewall, VPN, or reverse proxy with proper auth if you expose this beyond your trusted network.

Rate limits

Explains the idea itself. Read it slowly; the later sections build on it.

Your Portal tier's RPM/TPM limits apply across the whole proxy. The proxy doesn't fan out or pool — it's a single bearer with your full subscription quota. Monitor usage at portal.nousresearch.com ↗.

Architecture

Explains the idea itself. Read it slowly; the later sections build on it.

The proxy is intentionally minimal. Per request:

  1. Receive POST /v1/chat/completions from your app
  2. Look up the adapter's current credential (refresh if expiring)
  3. Forward the request body verbatim, with Authorization: Bearer <minted-key>
  4. Stream the response back unchanged (SSE preserved)

No transformation. No logging of request bodies. No agent loop. The proxy is a credential-attaching pass-through.

Future: more OAuth providers

Explains the idea itself. Read it slowly; the later sections build on it.

The adapter system is pluggable. Adding a new provider (e.g. HuggingFace, GitHub Copilot's chat endpoint, Anthropic via OAuth) requires implementing UpstreamAdapter in hermes_cli/proxy/adapters/<provider>.py and registering it in adapters/__init__.py. Providers that aren't OpenAI-compatible at the protocol level (Anthropic Messages API, for example) would need a transformation layer, which is out of scope for the current shape.

Knowledge check

4 questions answered by this page alone.

Every option is a real identifier from the Hermes documentation. The wrong ones are real too, just from other pages.

1. In this lesson's table, what is the “API server” for “What it serves”?
2. Which of these environment variables actually appears in this lesson?
3. Which of these headings does not appear in this lesson?
4. Which configuration key appears in this lesson's examples?