Spaces:
Running
title: Hermes Agent WebUI
emoji: 👁
colorFrom: blue
colorTo: gray
sdk: docker
app_port: 8787
pinned: false
license: mit
Hermes Agent WebUI Space
This Space runs the community Hermes WebUI with Hermes Agent source available in the container.
Required Space secrets
Set these in Hugging Face Space settings before exposing the app:
HERMES_WEBUI_PASSWORD: password for the browser UI.
Optional provider secrets:
DEEPSEEK_API_KEYOPENAI_API_KEYOPENROUTER_API_KEYANTHROPIC_API_KEYGOOGLE_API_KEYHF_TOKEN
Optional runtime secret:
HERMES_WEBUI_USER_PASSWORD: sets thehermeswebuiLinux user password and enables password-basedsudoinside the container. Use only when you need it.
Optional backup settings:
HERMES_BACKUP_REPO: private Dataset repo used for Hermes state backups, for exampleAcrabohan/hermes-webui-backup.HF_BACKUP_TOKEN: fine-grained Hugging Face token with read/write access to the private backup Dataset. Set this as a Space secret, not a public variable.HERMES_BACKUP_INTERVAL_SECONDS: backup interval, default1800.HERMES_BACKUP_INITIAL_DELAY_SECONDS: first backup delay after container start, default300.HERMES_RESTORE_ON_START: set to0to disable automatic restore on boot.HERMES_FORCE_RESTORE: set to1once if you want to overwrite local state from the backup archive on the next boot.
Workspace and state
The default workspace is /workspace.
Hermes reads and writes its state at /home/hermeswebui/.hermes. In this Space
that path is a symlink to /data/.hermes, so Hermes Agent and Hermes WebUI use
one shared home directory. On a free Space this is ephemeral and can be lost
after rebuilds. Enable Hugging Face persistent storage if you want Hermes memory,
sessions, and profile configuration to survive rebuilds.
If HERMES_BACKUP_REPO and HF_BACKUP_TOKEN are set, the container also backs
up Hermes state to the private Dataset as hermes-state.tar.gz. On startup, it
restores from that archive only when the local Hermes state is empty, unless
HERMES_FORCE_RESTORE=1 is set.
Security notes
Use a private or protected Space. This app can inspect files and run agent tools,
so do not publish it without HERMES_WEBUI_PASSWORD.
If you set HERMES_WEBUI_USER_PASSWORD, anyone who can control the WebUI may be
able to run privileged commands inside the container. Prefer baking system
packages into the Dockerfile instead of using sudo at runtime.
Keep the backup Dataset private. Hermes state can include memories, sessions,
provider configuration, and secrets. Do not set HERMES_BACKUP_REPO to this
public Space repo.
This repo intentionally does not include keep-alive automation. Free Spaces can sleep; for always-on usage, use paid hardware or accept cold starts.