Hermes Agent on a VPS
To self-host Hermes Agent on a server, install it on any Linux VPS and run its messaging gateway as a service, so Telegram, Discord, scheduled jobs, and bots keep working when your own computer is off. There are three documented ways in: DigitalOcean's Hermes 1-Click image, the official installer on any Ubuntu or Debian server, or the official Docker image.
You run the server: updates, security, backups, and restarts are yours, and model usage is billed separately by whichever provider you configure. If you'd rather not administer a server, compare managed options on Hermes hosting; for the monthly arithmetic, see Hermes cost.
Checked against official Nous Research sources on September 26, 2026 (Hermes Agent v0.21.5).
Pick a path
| Path | What you get | Where Hermes data lives | How it updates |
|---|---|---|---|
| DigitalOcean 1-Click | Ubuntu 24.04 Droplet with Hermes preinstalled for a dedicated hermes user | /home/hermes/.hermes/ | hermes update (listed in DigitalOcean's getting-started notes) |
| Manual install (any provider) | Official install script on your own Ubuntu/Debian server | ~/.hermes/ | hermes update |
| Docker (any provider) | Official nousresearch/hermes-agent image with a mounted data volume | Host directory mounted at /opt/data | Pull a newer image and recreate the container |
Path 1: DigitalOcean Hermes 1-Click
DigitalOcean publishes an official Hermes Agent 1-Click App in its Marketplace. As listed on September 26, 2026: Hermes Agent 2026.9.14 on Ubuntu 24.04, with Python 3.12.3 and the OpenAI SDK 2.24.0. It is still a self-managed Droplet — DigitalOcean preinstalls Hermes; it does not run it for you.
- Hermes is installed for a dedicated
hermesuser. Config is in/home/hermes/.hermes/config.yaml, keys in/home/hermes/.hermes/.env, and the workspace in/home/hermes/workspace; the install itself is under/opt/hermes/. - The image is preconfigured for DigitalOcean Serverless Inference (
https://inference.do-ai.run/v1, default modelminimax-m2.5) with a DigitalOcean model access key. Runhermes modelto use any other provider. - DigitalOcean's API example creates the Droplet at size
s-2vcpu-4gb(4 GiB RAM, 2 vCPUs, 80 GiB SSD; $24/month on the Basic Regular tier).
# After SSH-ing in, as the hermes user$hermes --version # compare with the latest release$hermes update # the image may lag the current release$hermes setup # or: hermes model$hermes doctor$hermes gateway setup # only if you want messaging$hermes gateway start
hermes --version and update after deploying. DigitalOcean's notes use hermes gateway start and do not say whether the gateway is installed as a boot-time service — check with hermes gateway status, and if it is not, install the service as in step 4 below.Path 2: Manual install on any VPS
The provider-independent path. It works on any Ubuntu or Debian server, a DigitalOcean Droplet without the 1-Click image, or an always-on machine at home. The official gateway docs cover two ways to keep Hermes running after you log out — a system service, or a user service with lingering. Pick one.
Provision VPS & Create Dedicated System User
Avoid running autonomous AI agents as root. Create a dedicated unprivileged "hermes" user with sudo rights for package management:
# As root on fresh Ubuntu 22.04 / 24.04:$apt update && apt upgrade -y$apt install -y curl git xz-utils ufw$# Create dedicated non-root user$adduser --gecos "" hermes$usermod -aG sudo hermes$# Switch to the hermes user$su - hermes
Install Hermes Agent
Run the official one-line installer as the hermes user to install the binary and CLI toolchain:
$curl -fsSL https://hermes-agent.nousresearch.com/install.sh | bash$# Reload shell environment$export PATH="$HOME/.local/bin:$PATH"$# Verify installation$hermes --version
Configure Provider API Keys
Configure your provider via the interactive wizard or store keys securely in ~/.hermes/.env. Browser sign-ins (Nous Portal and other OAuth providers) need the loopback callback forwarded over SSH on a headless server — see the official "OAuth over SSH" guide:
# Run interactive setup or Nous Portal login$hermes setup --portal$# Or manually create environment file:$mkdir -p ~/.hermes$cat << "EOF" > ~/.hermes/.env$OPENROUTER_API_KEY=sk-or-v1-...$ANTHROPIC_API_KEY=sk-ant-...$EOF$chmod 600 ~/.hermes/.env
Install Systemd Daemon with Official CLI
Hermes Agent includes a built-in command to generate and register a system service for VPS and headless hosts:
# Generate and register the boot-time system service$sudo hermes gateway install --system$# Start the installed background service$sudo hermes gateway start --system
Alternative: User Service with Lingering
If you prefer the user service, install it and enable lingering so it starts at boot and survives logout:
# Install and start the user service$hermes gateway install$hermes gateway start$# Enable lingering as root or with sudo$sudo loginctl enable-linger hermes$# Verify linger status:$loginctl show-user hermes | grep Linger
Hardening & Firewall (UFW)
Protect your VPS by restricting open ports. Port 9119 is the default for the Hermes web dashboard and the remote backend Desktop connects to. Keep it on loopback and use SSH port forwarding (or a private network such as Tailscale with a dashboard password):
# Allow SSH only$sudo ufw default deny incoming$sudo ufw default allow outgoing$sudo ufw allow OpenSSH$sudo ufw enable$# After starting hermes dashboard --no-open on the VPS,# view the Web Dashboard from your laptop:# Run on your local machine:# ssh -L 9119:localhost:9119 hermes@your-vps-ip
Service Monitoring & Log Streaming
Manage and inspect the live Hermes daemon process using standard systemd commands:
$sudo hermes gateway status --system
$journalctl -u hermes-gateway -f
$sudo systemctl restart hermes-gateway
This stops the current process right away. The official docs prefer hermes gateway restart when in-flight turns matter, because it drains them first.
$hermes update --check # preview$sudo hermes update # system service: root is needed to restart the gateway afterwards
With the system service, a non-root hermes update tries passwordless sudo and otherwise skips the gateway restart. Run it with sudo, grant the service account passwordless sudo for systemctl on hermes-gateway*, or use the user service + linger instead. (Official messaging-gateway docs, checked September 26, 2026.)
VPS Troubleshooting & Gotchas
If you chose the user-service alternative, check whether sudo loginctl enable-linger hermes has been run. Lingering lets the user service survive logout and start at boot.
Check which tools and concurrent jobs were active. Browser automation and local models can need substantially more memory; move to a larger plan or configure swap based on the workload.
Path 3: Docker
Nous publishes an official image, nousresearch/hermes-agent. All state — config, API keys, sessions, skills, memories — lives in one host directory mounted at /opt/data; the image itself is stateless, so upgrading means pulling a newer image. This is orientation only; the official Docker guide covers profiles, the dashboard, and logs, and our Docker page covers storage, ports, and update pitfalls.
$docker run -it --rm -v ~/.hermes:/opt/data nousresearch/hermes-agent setup
services:hermes:image: nousresearch/hermes-agent:latestcontainer_name: hermesrestart: unless-stoppedcommand: gateway runvolumes:- ~/.hermes:/opt/data
- Upgrade:
docker compose pull, thendocker compose up -d. Running gateways come back up after a restart or upgrade. - Never point two gateway containers at the same data directory — the docs warn that session and memory stores are not built for concurrent writers.
- On Docker Desktop for macOS or Windows, bind mounts can corrupt the session database under concurrent access; on a Linux VPS a normal bind mount or named volume is fine.
How big a server?
Hermes has no single official VPS size requirement. Neither the installation docs nor the Docker guide state a minimum CPU, RAM, or disk figure. What exists are a few documented anchors — useful as reference points, not requirements:
| Source | Size | What it is |
|---|---|---|
| DigitalOcean 1-Click docs | 2 vCPU / 4 GiB (s-2vcpu-4gb) | The size in DigitalOcean's API example for the Hermes image |
| DigitalOcean tutorial | At least 2 vCPUs / 4 GB RAM | DigitalOcean's own manual-install tutorial |
| Official Docker guide | memory: 4G, cpus: "2.0" | Resource limits in the example docker-compose file |
| Hermes Cloud | Medium: 2 GB / 4 vCPU; Large: 4 GB / 8 vCPU | What Nous provisions for 10 or 20 concurrent sessions |
What pushes the size up: browser automation, many concurrent sessions or profiles, the dashboard, and above all local models, which need hardware sized for the model rather than for Hermes. With an API or Portal model the model runs elsewhere and the server only runs the agent.
Backups and moving to another server
Everything that makes your agent yours — config, API keys, memories, skills, sessions, profiles — is in the Hermes data directory (~/.hermes/, or /opt/data in Docker). The install itself can be recreated.
| Tool | Use it for | Includes credentials? |
|---|---|---|
hermes backup | Full machine migration: a zip of the data root, all profiles | Yes (.env and auth.json) |
hermes backup --quick | Quick state snapshot; not a migration backup | — |
hermes profile export | Moving or sharing one profile (.tar.gz) | No (stripped) |
| Provider snapshots | Whole-server rollback, e.g. DigitalOcean backups (+20% weekly / +30% daily of the Droplet price) | Yes — the whole disk |
# Old server$hermes backup # writes ~/hermes-backup-<timestamp>.zip$scp ~/hermes-backup-*.zip newserver:~/$# New server, after installing Hermes$hermes import ~/hermes-backup-<timestamp>.zip$hermes setup # confirm keys and provider
- The full backup skips downloaded models, runtimes, and browser profiles, and reports files it could not copy — read that report before deleting the old server.
- The zip contains your API keys. Store it like a password file.
- Stop the gateway on the old server before starting it on the new one, so two gateways don't answer the same bots.
Restore details, quick snapshots, and Docker-specific steps: Hermes backup and restore.
Primary sources
- DigitalOcean Marketplace — Hermes Agent 1-Click
- DigitalOcean docs — Hermes Agent 1-Click (getting started)
- DigitalOcean — Droplet and backup pricing
- DigitalOcean — How to deploy Hermes (tutorial, sizing)
- Installation — official docs
- Messaging gateway (system/user service, updates) — official docs
- Docker — official docs
- FAQ: hermes backup, import, profile export — official docs
- Hermes Agent releases
HermesAgentAI.org is an independent educational documentation resource and community guide. It is not affiliated with, sponsored by, or endorsed by Nous Research or FlyHermes. Hermes Agent is released under the MIT License by Nous Research.
Where to go next
Compare a VPS with Hermes Cloud, FlyHermes, and Hostinger Managed.
Wire a Telegram bot with user allowlists to the running gateway.
Manage the server from a browser over an SSH tunnel.
Server price plus model spend, with worked examples.