Aquaman credential-isolation plugin for the Hermes agent host — points Hermes at the aquaman loopback proxy so API keys never enter the agent process.
Project description
aquaman-hermes
Credential isolation for the Hermes agent host - using the vault you already have. API keys live in your existing backend (Keychain, 1Password, HashiCorp Vault, Bitwarden, KeePassXC, systemd-creds, or encrypted-file) and are injected by the aquaman proxy. They never enter the Hermes process, and you never copy them into a new store.
This is the optional, in-session "sugar" layer. The actual isolation is done by
aquaman-proxy: it runs an opt-in loopback listener and Hermes is pointed at it via
its native ANTHROPIC_BASE_URL / OPENAI_BASE_URL env vars (written to
~/.hermes/.env) plus a placeholder api_key that the proxy strips and replaces with
the real credential. This plugin adds:
/aquaman-status: slash command showing proxy reachability + wiring.aquaman_status: an agent-facing tool with the same info.on_session_start: a one-shot health probe that warns if the proxy is down.aquamansecret source (Hermes ≥ 0.18.1): resolves project/tool secrets — GitHub tokens, database URLs, anything undersecrets.aquaman.env— from your vault at startup, through the proxy's token-gated broker. See below.
How it works
Hermes process aquaman-proxy (separate process)
┌────────────────────────┐ ┌────────────────────────────────┐
│ ANTHROPIC_BASE_URL = │── HTTP ────▶│ 127.0.0.1:8585 loopback │
│ http://127.0.0.1:8585 │ (loopback, │ • validates loopback token │
│ /anthropic │ token- │ • injects real key from vault │
│ ANTHROPIC_API_KEY = │ gated) │ • forwards to api.anthropic │
│ <loopback token> │◀────────────│ • writes hash-chained audit │
│ NO real credentials │ └────────────────────────────────┘
└────────────────────────┘
Install
You need the proxy (aquaman-proxy, from npm) and this plugin (from PyPI):
# 1. Proxy + vault (Node)
npm install -g aquaman-proxy
aquaman setup # pick a backend, store keys
aquaman credentials add anthropic api_key sk-ant-...
# 2. This plugin (Python)
pip install aquaman-hermes # or: uv tool install aquaman-hermes
aquaman-hermes install # drops the plugin into ~/.hermes/plugins/aquaman/
hermes plugins enable aquaman # add to plugins.enabled
# 3. Wire Hermes at the proxy + start it
aquaman hermes setup # writes ~/.hermes/.env, enables the loopback listener
aquaman daemon & # start the proxy
# 4. Verify
aquaman hermes doctor # deep diagnostic (proxy side)
hermes # then run: /aquaman-status
aquaman-hermes install honors HERMES_HOME (the same var the Hermes CLI uses to
relocate its config dir); it defaults to ~/.hermes.
Project secrets (secret source, Hermes ≥ 0.18.1)
LLM keys are only half the problem — agents also need GitHub tokens, database URLs,
and other project secrets that usually end up in a plaintext .env. On Hermes ≥
0.18.1 this plugin registers an aquaman secret source so those come from your
vault instead. Bind them in ~/.hermes/config.yaml:
secrets:
aquaman:
enabled: true
env:
GITHUB_TOKEN: aquaman://github/token
DATABASE_URL: aquaman://supabase/db_url
At startup the source resolves each binding through the proxy's token-gated loopback broker (per-read, hash-chain audited) and hands the values to Hermes' secret orchestrator. Notes on the security model:
- LLM provider keys are refused.
ANTHROPIC_API_KEY/OPENAI_API_KEYbindings are rejected with a warning — those stay on the loopback proxy path, where the real key never enters the Hermes process at all. - Project secrets resolved this way do live in Hermes' process env (that's what a
Hermes secret source is). What you gain over a
.envline: vault-at-rest storage, per-read tamper-evident audit, instant rotation, and no plaintext files on disk. - Fail-open by design: if the proxy is down, Hermes still starts (with a warning).
- One bad ref never blocks the others; errors/warnings never contain the token.
Uninstall
hermes plugins disable aquaman
aquaman-hermes uninstall
Notes
- The status/command/hook surface holds no credentials — it only reads the provider
base-URL env vars and probes the proxy's token-exempt
/_healthendpoint. The secret source transits credentials only while handing them to Hermes' orchestrator. - It depends only on the Python standard library.
- LLM providers wired via base-URL: Anthropic + OpenAI. Channels are out of scope for the Hermes path (no base-URL lever); project secrets go through the secret source.
- Hermes >=0.17 "managed scope": a root-owned
/etc/hermes/.envoverrides~/.hermes/.env— if an admin pins theANTHROPIC_*/OPENAI_*vars there, the proxy is bypassed.aquaman hermes doctordetects and flags this. - With
gateway.multiplex_profilesenabled (off by default), env is scoped per profile — add the aquaman block to each profile's env file. - Hermes 0.18's cron exfil guard refuses cron jobs that pair a named provider with
an off-host
base_urloverride; normal jobs inheriting the session runtime (the env vars aquaman writes) are unaffected.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file aquaman_hermes-0.14.0.tar.gz.
File metadata
- Download URL: aquaman_hermes-0.14.0.tar.gz
- Upload date:
- Size: 18.6 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
075bebd1b86e28a7ecd18907d62511ede43d3ff5262ab15981f2fefbe8e52486
|
|
| MD5 |
01c670d7af817a53eb6bc85322fa0ee6
|
|
| BLAKE2b-256 |
b06c546e29349dcf81bef5c649d9aa0d631e58540e04bd3bdb905287b5778a8c
|
Provenance
The following attestation bundles were made for aquaman_hermes-0.14.0.tar.gz:
Publisher:
cd.yml on tech4242/aquaman
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
aquaman_hermes-0.14.0.tar.gz -
Subject digest:
075bebd1b86e28a7ecd18907d62511ede43d3ff5262ab15981f2fefbe8e52486 - Sigstore transparency entry: 2203511878
- Sigstore integration time:
-
Permalink:
tech4242/aquaman@969a1ed32948d16c77c18dabee8b5f9fda8835f8 -
Branch / Tag:
refs/tags/v0.14.0 - Owner: https://github.com/tech4242
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
cd.yml@969a1ed32948d16c77c18dabee8b5f9fda8835f8 -
Trigger Event:
release
-
Statement type:
File details
Details for the file aquaman_hermes-0.14.0-py3-none-any.whl.
File metadata
- Download URL: aquaman_hermes-0.14.0-py3-none-any.whl
- Upload date:
- Size: 12.6 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
7526599f0fa92ba772865439af1a38a98f603944194b104d91a2191ebb475d5d
|
|
| MD5 |
fbf2654219c6dab7bba470d690ae4d26
|
|
| BLAKE2b-256 |
9546c6700e604bad85830ffcee5543bec5e8a6165f4de183ce514913fff26e4d
|
Provenance
The following attestation bundles were made for aquaman_hermes-0.14.0-py3-none-any.whl:
Publisher:
cd.yml on tech4242/aquaman
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
aquaman_hermes-0.14.0-py3-none-any.whl -
Subject digest:
7526599f0fa92ba772865439af1a38a98f603944194b104d91a2191ebb475d5d - Sigstore transparency entry: 2203511906
- Sigstore integration time:
-
Permalink:
tech4242/aquaman@969a1ed32948d16c77c18dabee8b5f9fda8835f8 -
Branch / Tag:
refs/tags/v0.14.0 - Owner: https://github.com/tech4242
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
cd.yml@969a1ed32948d16c77c18dabee8b5f9fda8835f8 -
Trigger Event:
release
-
Statement type: