HERMES AGENT MANUAL
Vault & Credential Security
Brokered credential leasing, ChaCha20-Poly1305 local keyrings, and zero-leak guarantees.
Architecture Overview
The Hermes Vault ensures that third-party API tokens (Stripe, Anthropic, OpenRouter) are never hardcoded into scripts or visible in raw terminal output.
[SECURITY BOUNDARY]
The Vault acts as a local proxy broker. Subagents request short-lived cryptographic leases rather than retrieving plaintext secret keys.
Issuing a Credential Lease
$ hermes vault lease request --provider openrouter --ttl 1800 → Validating policy... Authorized → Issuing short-lived lease token: hvs_lease_892f1a9c... ✓ Lease active for 30 minutes.
Inspecting Security Audit Log
$ hermes vault audit [14:32:01] LEASE_ISSUED provider=openrouter ttl=1800s status=OK [14:02:15] LEASE_EXPIRED provider=anthropic status=CLEARED ✓ Zero credential leaks detected.