MPP for Hermes Agent
hermes-mpp makes Hermes Agent HTTPX
traffic payment-aware. It answers supported MPP 402 challenges with a Tempo
charge and retries the request through the same client.
Maintained by Tempo, the team behind MPP.
[!IMPORTANT] This is experimental v0 software. It can authorize real payments automatically with the configured Tempo key. Use a dedicated, low-balance key and restrict allowed origins.
v0 targets Hermes Agent 0.19, HTTPX 0.27–0.28, and pympp 0.10.
Install
After installing Hermes, run:
uvx hermes-mpp install --allowed-origin https://mpp.dev
The installer adds and enables the plugin, then prompts for a Tempo private key;
leave it blank to generate one. It stores the key in ~/.hermes/.env with
owner-only permissions, saves each --allowed-origin, and prints the address to
fund.
The installer discovers standard, root, and PATH-based Hermes installations.
For a custom environment, run uvx hermes-mpp install --hermes-python PATH or
set HERMES_PYTHON.
Generated wallets start empty. For testnet resources, fund the printed address with the Tempo faucet.
On first install, omitting --allowed-origin allows any origin presenting a valid
MPP challenge to charge the wallet. Repeat the option to allow multiple exact
origins. Reinstalling without it preserves the allowlist; passing it replaces the
list.
Paths and wildcards are rejected. Use plaintext http:// only for trusted local
development; an on-path attacker can inject a payment challenge.
Use
Ask Hermes for the resource normally:
hermes chat -q "Make a request to https://mpp.dev/api/ping/paid"
The model gets one generic mpp_fetch tool for arbitrary HTTP APIs. Payment is
not a separate tool call: it and every other in-process HTTPX client handle
supported MPP challenges automatically.
Behavior
- Existing and future sync and async clients retain their transport, pool,
cookies, hooks, redirects, extensions, and streaming behavior. Response hooks
observe the final logical response rather than the internal
402. - Free responses pass through. Malformed, unsupported, and disallowed
challenges remain ordinary
402responses. - A paid request is retried at most once. Distinct payments are serialized; equivalent, repeated, and uncertain attempts fail closed.
mpp_fetchblocks private-network redirects, hides sensitive response headers, and truncates large bodies.- Only HTTPX traffic in the Hermes process is instrumented. Shell commands and
Requests, aiohttp, or urllib3 are not; use
mpp_fetchfor arbitrary HTTP.
If a payment outcome is uncertain, verify the wallet transaction before restarting Hermes; later payments remain blocked in that process.
Manage
hermes plugins list
uvx --refresh hermes-mpp install # update
uvx hermes-mpp uninstall
Uninstalling leaves the private key in Hermes's .env file.
Develop
uv sync
uv run pytest
uv run ruff check .
CI tests Python 3.11–3.13 and HTTPX 0.27–0.28.
Security
Report vulnerabilities privately as described in SECURITY.md.
License
MIT
Release files for hermes-mpp 0.1.2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| hermes_mpp-0.1.2.tar.gz | 155.4 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| hermes_mpp-0.1.2-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 170.7 kB
Release files / hermes_mpp-0.1.2.tar.gz
| Download URL | hermes_mpp-0.1.2.tar.gz |
|---|---|
| Size | 155.4 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
bdaa6a7b0013b78b69fce375a72970ee47d8842b94079eea81c021736f792f75
|
|
BLAKE2b-256 checksum How to use checksums |
c7e62424a64666004cc96dc71e909b544ecf2537d9ce27b7957cf1281d7fc049
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.12.13
|
Release files / hermes_mpp-0.1.2-py3-none-any.whl
| Download URL | hermes_mpp-0.1.2-py3-none-any.whl |
|---|---|
| Size | 15.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
74fbdb3b63382bb2c2671b563f8828fd01ab83f6cbcd9e7b9c57158c351b440e
|
|
BLAKE2b-256 checksum How to use checksums |
59c496eee5e93c728bd17f159ddb54f88d4223b1391c706eb1a324b1ad3e7e8b
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.12.13
|