Skip to main content

hermes-mpp

hermes-mpp makes Hermes Agent HTTPX traffic payment-aware. It answers supported MPP 402 challenges with a Tempo charge and retries the request through the same client.

V1 targets Hermes Agent 0.19, HTTPX 0.27–0.28, and pympp 0.10.

Install

After installing Hermes, run:

uvx hermes-mpp install

The installer adds and enables the plugin, then prompts for a Tempo private key; leave it blank to generate one. It stores the key in ~/.hermes/.env with owner-only permissions and prints the address to fund.

The installer discovers standard, root, and PATH-based Hermes installations. For a custom environment, run uvx hermes-mpp install --hermes-python PATH or set HERMES_PYTHON.

Generated wallets start empty. For testnet resources, fund the printed address with the Tempo faucet.

Use a dedicated, low-balance key. By default, any origin presenting a valid MPP challenge can charge it without a prompt or spend cap. To restrict payments, set an exact, comma-separated allowlist:

MPP_ALLOWED_ORIGINS=https://mpp.dev,https://api.example.com

Paths and wildcards are rejected. Use plaintext http:// only for trusted local development; an on-path attacker can inject a payment challenge.

Use

Ask Hermes for the resource normally:

hermes chat -q "Make a request to https://mpp.dev/api/ping/paid"

The model gets one generic mpp_fetch tool for arbitrary HTTP APIs. Payment is not a separate tool call: it and every other in-process HTTPX client handle supported MPP challenges automatically.

Behavior

  • Existing and future sync and async clients retain their transport, pool, cookies, hooks, redirects, extensions, and streaming behavior. Response hooks observe the final logical response rather than the internal 402.
  • Free responses pass through. Malformed, unsupported, and disallowed challenges remain ordinary 402 responses.
  • A paid request is retried at most once. Distinct payments are serialized; equivalent, repeated, and uncertain attempts fail closed.
  • mpp_fetch blocks private-network redirects, hides sensitive response headers, and truncates large bodies.
  • Only HTTPX traffic in the Hermes process is instrumented. Shell commands and Requests, aiohttp, or urllib3 are not; use mpp_fetch for arbitrary HTTP.

If a payment outcome is uncertain, verify the wallet transaction before restarting Hermes; later payments remain blocked in that process.

Manage

hermes plugins list
uvx --refresh hermes-mpp install  # update or reconfigure
uvx hermes-mpp uninstall

Uninstalling leaves the private key in Hermes's .env file.

Develop

uv sync
uv run pytest
uv run ruff check .

CI tests Python 3.11–3.13 and HTTPX 0.27–0.28.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

hermes_mpp-0.1.1.tar.gz (155.1 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

hermes_mpp-0.1.1-py3-none-any.whl (14.8 kB view details)

Uploaded Python 3

File details

Details for the file hermes_mpp-0.1.1.tar.gz.

File metadata

  • Download URL: hermes_mpp-0.1.1.tar.gz
  • Upload date:
  • Size: 155.1 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.2.0 CPython/3.12.13

File hashes

Hashes for hermes_mpp-0.1.1.tar.gz
Algorithm Hash digest
SHA256 39f873a4a0dd3cf528bd4544bd0f3959efb4a77c5ca46ce6d9cde58b8d2c3aea
MD5 e6c3c875b2a088cdf1fd94f8cbc01335
BLAKE2b-256 d9d20aed8f13f5e04e0775751166a86536a2173b1a04c0e9e5a2b5389f5e4bc1

See more details on using hashes here.

File details

Details for the file hermes_mpp-0.1.1-py3-none-any.whl.

File metadata

  • Download URL: hermes_mpp-0.1.1-py3-none-any.whl
  • Upload date:
  • Size: 14.8 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.2.0 CPython/3.12.13

File hashes

Hashes for hermes_mpp-0.1.1-py3-none-any.whl
Algorithm Hash digest
SHA256 b74278530eec24df01227ed235b53c376c6547e2bf2b97651addb99974259c49
MD5 adf203830c3da18f63a963e0c4775f01
BLAKE2b-256 2c08455407a18dee6429f7deb79ed69a0b0d664668ee5f5adb82f9f920dc224b

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page