Self-managed server guide

Hermes Agent on a VPS

To self-host Hermes Agent on a server, install it on any Linux VPS and run its messaging gateway as a service, so Telegram, Discord, scheduled jobs, and bots keep working when your own computer is off. There are three documented ways in: DigitalOcean's Hermes 1-Click image, the official installer on any Ubuntu or Debian server, or the official Docker image.

You run the server: updates, security, backups, and restarts are yours, and model usage is billed separately by whichever provider you configure. If you'd rather not administer a server, compare managed options on Hermes hosting; for the monthly arithmetic, see Hermes cost.

Checked against official Nous Research sources on September 26, 2026 (Hermes Agent v0.21.5).

Pick a path

PathWhat you getWhere Hermes data livesHow it updates
DigitalOcean 1-ClickUbuntu 24.04 Droplet with Hermes preinstalled for a dedicated hermes user/home/hermes/.hermes/hermes update (listed in DigitalOcean's getting-started notes)
Manual install (any provider)Official install script on your own Ubuntu/Debian server~/.hermes/hermes update
Docker (any provider)Official nousresearch/hermes-agent image with a mounted data volumeHost directory mounted at /opt/dataPull a newer image and recreate the container

Path 1: DigitalOcean Hermes 1-Click

DigitalOcean publishes an official Hermes Agent 1-Click App in its Marketplace. As listed on September 26, 2026: Hermes Agent 2026.9.14 on Ubuntu 24.04, with Python 3.12.3 and the OpenAI SDK 2.24.0. It is still a self-managed Droplet — DigitalOcean preinstalls Hermes; it does not run it for you.

  • Hermes is installed for a dedicated hermes user. Config is in /home/hermes/.hermes/config.yaml, keys in /home/hermes/.hermes/.env, and the workspace in /home/hermes/workspace; the install itself is under /opt/hermes/.
  • The image is preconfigured for DigitalOcean Serverless Inference (https://inference.do-ai.run/v1, default model minimax-m2.5) with a DigitalOcean model access key. Run hermes model to use any other provider.
  • DigitalOcean's API example creates the Droplet at size s-2vcpu-4gb (4 GiB RAM, 2 vCPUs, 80 GiB SSD; $24/month on the Basic Regular tier).
First steps on the 1-Click Droplet (from DigitalOcean's notes)
bash
# After SSH-ing in, as the hermes user
$hermes --version # compare with the latest release
$hermes update # the image may lag the current release
$hermes setup # or: hermes model
$hermes doctor
$hermes gateway setup # only if you want messaging
$hermes gateway start
Sources disagree: The image lags the current release. The Marketplace listing ships Hermes 2026.9.14 (v0.21.3); the latest GitHub release is v0.21.5 (2026.9.24). Check hermes --version and update after deploying. DigitalOcean's notes use hermes gateway start and do not say whether the gateway is installed as a boot-time service — check with hermes gateway status, and if it is not, install the service as in step 4 below.

Path 2: Manual install on any VPS

The provider-independent path. It works on any Ubuntu or Debian server, a DigitalOcean Droplet without the 1-Click image, or an always-on machine at home. The official gateway docs cover two ways to keep Hermes running after you log out — a system service, or a user service with lingering. Pick one.

1

Provision VPS & Create Dedicated System User

Avoid running autonomous AI agents as root. Create a dedicated unprivileged "hermes" user with sudo rights for package management:

# As root on fresh Ubuntu 22.04 / 24.04:
$apt update && apt upgrade -y
$apt install -y curl git xz-utils ufw
$
# Create dedicated non-root user
$adduser --gecos "" hermes
$usermod -aG sudo hermes
$
# Switch to the hermes user
$su - hermes
2

Install Hermes Agent

Run the official one-line installer as the hermes user to install the binary and CLI toolchain:

$curl -fsSL https://hermes-agent.nousresearch.com/install.sh | bash
$
# Reload shell environment
$export PATH="$HOME/.local/bin:$PATH"
$
# Verify installation
$hermes --version
3

Configure Provider API Keys

Configure your provider via the interactive wizard or store keys securely in ~/.hermes/.env. Browser sign-ins (Nous Portal and other OAuth providers) need the loopback callback forwarded over SSH on a headless server — see the official "OAuth over SSH" guide:

# Run interactive setup or Nous Portal login
$hermes setup --portal
$
# Or manually create environment file:
$mkdir -p ~/.hermes
$cat << "EOF" > ~/.hermes/.env
$OPENROUTER_API_KEY=sk-or-v1-...
$ANTHROPIC_API_KEY=sk-ant-...
$EOF
$chmod 600 ~/.hermes/.env
4

Install Systemd Daemon with Official CLI

Hermes Agent includes a built-in command to generate and register a system service for VPS and headless hosts:

# Generate and register the boot-time system service
$sudo hermes gateway install --system
$
# Start the installed background service
$sudo hermes gateway start --system
5

Alternative: User Service with Lingering

If you prefer the user service, install it and enable lingering so it starts at boot and survives logout:

# Install and start the user service
$hermes gateway install
$hermes gateway start
$
# Enable lingering as root or with sudo
$sudo loginctl enable-linger hermes
$
# Verify linger status:
$loginctl show-user hermes | grep Linger
This is an alternative to the system service above — pick one, never both. The official docs recommend this user service + linger for headless VMs you rarely log into, because hermes update can then restart the gateway without root.
6

Hardening & Firewall (UFW)

Protect your VPS by restricting open ports. Port 9119 is the default for the Hermes web dashboard and the remote backend Desktop connects to. Keep it on loopback and use SSH port forwarding (or a private network such as Tailscale with a dashboard password):

# Allow SSH only
$sudo ufw default deny incoming
$sudo ufw default allow outgoing
$sudo ufw allow OpenSSH
$sudo ufw enable
$
# After starting hermes dashboard --no-open on the VPS,
# view the Web Dashboard from your laptop:
# Run on your local machine:
# ssh -L 9119:localhost:9119 hermes@your-vps-ip
Operations & Maintenance

Service Monitoring & Log Streaming

Manage and inspect the live Hermes daemon process using standard systemd commands:

Check Live Service Status
$sudo hermes gateway status --system
Follow Live Journal Logs
$journalctl -u hermes-gateway -f
Restart the service
$sudo systemctl restart hermes-gateway

This stops the current process right away. The official docs prefer hermes gateway restart when in-flight turns matter, because it drains them first.

Update Hermes
$hermes update --check # preview
$sudo hermes update # system service: root is needed to restart the gateway afterwards

With the system service, a non-root hermes update tries passwordless sudo and otherwise skips the gateway restart. Run it with sudo, grant the service account passwordless sudo for systemctl on hermes-gateway*, or use the user service + linger instead. (Official messaging-gateway docs, checked September 26, 2026.)

VPS Troubleshooting & Gotchas

1. Alternative user service stops when closing SSH:

If you chose the user-service alternative, check whether sudo loginctl enable-linger hermes has been run. Lingering lets the user service survive logout and start at boot.

2. Out of Memory (OOM) crashes:

Check which tools and concurrent jobs were active. Browser automation and local models can need substantially more memory; move to a larger plan or configure swap based on the workload.

Path 3: Docker

Nous publishes an official image, nousresearch/hermes-agent. All state — config, API keys, sessions, skills, memories — lives in one host directory mounted at /opt/data; the image itself is stateless, so upgrading means pulling a newer image. This is orientation only; the official Docker guide covers profiles, the dashboard, and logs, and our Docker page covers storage, ports, and update pitfalls.

One-time interactive setup
bash
$docker run -it --rm -v ~/.hermes:/opt/data nousresearch/hermes-agent setup
docker-compose.yaml — persistent gateway
yaml
services:
hermes:
image: nousresearch/hermes-agent:latest
container_name: hermes
restart: unless-stopped
command: gateway run
volumes:
- ~/.hermes:/opt/data
  • Upgrade: docker compose pull, then docker compose up -d. Running gateways come back up after a restart or upgrade.
  • Never point two gateway containers at the same data directory — the docs warn that session and memory stores are not built for concurrent writers.
  • On Docker Desktop for macOS or Windows, bind mounts can corrupt the session database under concurrent access; on a Linux VPS a normal bind mount or named volume is fine.

How big a server?

Hermes has no single official VPS size requirement. Neither the installation docs nor the Docker guide state a minimum CPU, RAM, or disk figure. What exists are a few documented anchors — useful as reference points, not requirements:

SourceSizeWhat it is
DigitalOcean 1-Click docs2 vCPU / 4 GiB (s-2vcpu-4gb)The size in DigitalOcean's API example for the Hermes image
DigitalOcean tutorialAt least 2 vCPUs / 4 GB RAMDigitalOcean's own manual-install tutorial
Official Docker guidememory: 4G, cpus: "2.0"Resource limits in the example docker-compose file
Hermes CloudMedium: 2 GB / 4 vCPU; Large: 4 GB / 8 vCPUWhat Nous provisions for 10 or 20 concurrent sessions

What pushes the size up: browser automation, many concurrent sessions or profiles, the dashboard, and above all local models, which need hardware sized for the model rather than for Hermes. With an API or Portal model the model runs elsewhere and the server only runs the agent.

Community report: Many hosting-provider guides in current search results quote minimums such as “2 GB RAM and 10 GB disk” or “1 vCPU / 2 GB”. We could not find those figures in Nous Research's docs; treat them as the provider's claim.

Backups and moving to another server

Everything that makes your agent yours — config, API keys, memories, skills, sessions, profiles — is in the Hermes data directory (~/.hermes/, or /opt/data in Docker). The install itself can be recreated.

ToolUse it forIncludes credentials?
hermes backupFull machine migration: a zip of the data root, all profilesYes (.env and auth.json)
hermes backup --quickQuick state snapshot; not a migration backup—
hermes profile exportMoving or sharing one profile (.tar.gz)No (stripped)
Provider snapshotsWhole-server rollback, e.g. DigitalOcean backups (+20% weekly / +30% daily of the Droplet price)Yes — the whole disk
Migrate to a new server (official FAQ)
bash
# Old server
$hermes backup # writes ~/hermes-backup-<timestamp>.zip
$scp ~/hermes-backup-*.zip newserver:~/
$
# New server, after installing Hermes
$hermes import ~/hermes-backup-<timestamp>.zip
$hermes setup # confirm keys and provider
  • The full backup skips downloaded models, runtimes, and browser profiles, and reports files it could not copy — read that report before deleting the old server.
  • The zip contains your API keys. Store it like a password file.
  • Stop the gateway on the old server before starting it on the new one, so two gateways don't answer the same bots.

Restore details, quick snapshots, and Docker-specific steps: Hermes backup and restore.

Primary sources

HermesAgentAI.org is an independent educational documentation resource and community guide. It is not affiliated with, sponsored by, or endorsed by Nous Research or FlyHermes. Hermes Agent is released under the MIT License by Nous Research.

Where to go next