Browser admin panel

Hermes Agent Dashboard

The Hermes web dashboard is the browser UI built into Hermes Agent. Run hermes dashboard and it opens http://127.0.0.1:9119, where you can edit config, manage API keys, browse and search sessions, schedule cron jobs, manage profiles, skills, MCP servers, and messaging channels, and chat with the agent in a browser tab.

It ships with Hermes — nothing extra to install — and by default listens only on your own machine with no login. Exposing it to a network requires an auth provider.

Checked against official Nous Research sources on September 26, 2026 (Hermes Agent v0.21.5).

Start it

Official commands
bash
$hermes dashboard # starts on 127.0.0.1:9119 and opens your browser
$hermes dashboard --port 8080 # different port
$hermes dashboard --no-open # don't open a browser (servers, SSH sessions)

One dashboard manages every profile on the machine: a profile switcher in the sidebar decides which profile the Config, API Keys, Skills, MCP, Models, and Chat pages read and write, and the choice lives in the URL (?profile=worker). Running worker dashboard from a profile alias opens the existing machine dashboard with that profile selected; --isolated runs a separate per-profile server instead.

Dashboard, Desktop, CLI — and community web UIs

All official front ends drive the same agent and share config, sessions, skills, and memory. Pick by what you are doing:

SurfaceBest forLaunch
Web dashboard (this page)Admin: config, keys, sessions, cron, profiles, channels, analytics — from any browserhermes dashboard
Hermes DesktopDaily chat and multi-agent work in a native app, including Bot ModeDesktop installer or hermes desktop
CLI / TUITerminal-first work and scriptinghermes / hermes --tui
Community report: Search results for “Hermes web UI” also surface community projects such as hermes-webui on GitHub. Those are separate third-party apps, not the dashboard described here. Review what any third-party UI does with your .env before installing it.

What each page does

PageWhat you can do
StatusVersion, gateway state and connected platforms, active and recent sessions (auto-refreshes every 5 s)
ChatThe real Hermes TUI in the browser, with a session switcher and workspace picker; resume any session from Sessions
ConfigForm editor for config.yaml, grouped by category
API KeysManage the .env file: provider keys, tool keys, messaging tokens
SessionsBrowse, filter (Chats / Automation / All) and full-text search every session
AnalyticsTokens, cache-hit %, and estimated or actual cost over 7, 30, or 90 days
CronCreate and manage scheduled prompts with delivery to local, Telegram, Discord, Slack, or email
ProfilesCreate, clone, and inspect profiles (the same profiles Bot Mode shows as bots)
Skills / MCPToggle installed skills and toolsets, install from the hub, manage MCP servers
Channels / Pairing / WebhooksConnect messaging platforms, approve paired users, manage webhook subscriptions
SystemHost stats, update status, Nous Portal and Tool Gateway routing, memory provider, credential pool

The Telegram page under messaging has a Create with QR button that creates the bot and writes its token and your user ID for you — see Hermes Telegram setup.

Native Windows: the Chat tab needs a POSIX pseudo-terminal, so on a native Windows install it shows a banner pointing to WSL2; the other pages work.

Reaching the dashboard from another machine

The dashboard can read and write your API keys and run agent commands, so treat it like SSH access. The official options, from safest:

  1. Keep it on loopback and tunnel: run it on the server with --no-open, then from your laptop ssh -L 9119:localhost:9119 user@server and open http://localhost:9119.
  2. Private network: bind to a Tailscale IP (--host <tailscale-ip>) with a username and password set.
  3. Public internet: the docs say not to expose a password-protected dashboard directly; use the Nous Portal OAuth provider instead.

Any non-loopback bind engages an auth gate and refuses to start without an auth provider. The old --insecure flag is now a no-op. For the username/password provider, put these in ~/.hermes/.env:

~/.hermes/.env (then chmod 600)
bash
$HERMES_DASHBOARD_BASIC_AUTH_USERNAME=admin
$HERMES_DASHBOARD_BASIC_AUTH_PASSWORD=choose-a-strong-password
# Stable signing secret so logins survive restarts:
$HERMES_DASHBOARD_BASIC_AUTH_SECRET=<output of: openssl rand -base64 32>

Check the gate from another machine with curl -s http://HOST:9119/api/status: auth_required should be true and auth_providers should include "basic". This same server is what Hermes Desktop attaches to as a remote backend — see Hermes Desktop. For a full server walkthrough, see Hermes on a VPS.

Docker: the official compose example publishes port 9119 and sets HERMES_DASHBOARD=1 to run the dashboard alongside the gateway. Keep the same auth rules if that port is reachable from outside the host; see Hermes in Docker.

When it doesn't work

  • Missing dependencies or a broken frontend build: hermes dashboard tells you what is missing; hermes pm repair repairs damaged dependencies. The frontend builds itself on first launch if npm is available.
  • Desktop says the remote backend is ready but chat never works: the readiness probe only checks the public /api/status. Chat also needs you to be signed in and the dashboard bound to an address the client can reach under the same host name it bound to.
  • A key added in the dashboard isn't used yet: type /reload in a running chat to re-read .env.
Not tested by this site: This page summarizes the official web dashboard documentation. We have not independently tested every page or the remote setups above.

Primary sources

HermesAgentAI.org is an independent educational documentation resource and community guide. It is not affiliated with, sponsored by, or endorsed by Nous Research or FlyHermes. Hermes Agent is released under the MIT License by Nous Research.

Where to go next