HERMES AGENT MANUAL

Vault & Credential Security

Brokered credential leasing, ChaCha20-Poly1305 local keyrings, and zero-leak guarantees.

Architecture Overview

The Hermes Vault ensures that third-party API tokens (Stripe, Anthropic, OpenRouter) are never hardcoded into scripts or visible in raw terminal output.

[SECURITY BOUNDARY]
The Vault acts as a local proxy broker. Subagents request short-lived cryptographic leases rather than retrieving plaintext secret keys.

Issuing a Credential Lease

terminal
$ hermes vault lease request --provider openrouter --ttl 1800
→ Validating policy... Authorized
→ Issuing short-lived lease token: hvs_lease_892f1a9c...
✓ Lease active for 30 minutes.

Inspecting Security Audit Log

terminal
$ hermes vault audit
[14:32:01] LEASE_ISSUED   provider=openrouter ttl=1800s status=OK
[14:02:15] LEASE_EXPIRED  provider=anthropic   status=CLEARED
✓ Zero credential leaks detected.