Companion to the how-to: Use AgentKit with Hermes.
Hermes talks. Scalekit holds the tokens. GitHub answers as usr_8f3a2c. This repo is not a Hermes clone.
you
hermes chat
/hermes-delegated-auth
tool_exec.py
Scalekit vault
github-connect
github_user_get_authenticated
sequenceDiagram
participant You
participant Hermes
participant Skill as hermes-delegated-auth
participant Scalekit
participant GitHub
You->>Hermes: /hermes-delegated-auth who am I on GitHub?
Hermes->>Skill: load host skill
Skill->>Scalekit: execute github_user_get_authenticated
Note over Scalekit: tokens for usr_8f3a2c stay here
Scalekit->>GitHub: GET /user
GitHub-->>Scalekit: login
Scalekit-->>Hermes: result
Hermes-->>You: GitHub login
this repo/ # install + env + one proven read
~/.hermes/skills/
hermes-delegated-auth/ # host skill (not this repo)
Scalekit # token vault
github-connect # dashboard connection name
hermes skills install scalekit-inc/authstack/kits/agentkit/host/hermes-delegated-authThen check:
hermes skills listThe table should list hermes-delegated-auth as enabled. In chat, use /hermes-delegated-auth.
Copy .env.example to ~/.hermes/.env (or merge the four names into the file you already have).
| Name | What it is |
|---|---|
SCALEKIT_ENVIRONMENT_URL |
Dashboard → Developers → Settings → API Credentials |
SCALEKIT_CLIENT_ID |
Same page |
SCALEKIT_CLIENT_SECRET |
Same page. Do not commit it. |
SCALEKIT_IDENTIFIER |
Opaque user id you choose. Sample: usr_8f3a2c |
SCALEKIT_IDENTIFIER is a lookup label. It is not a dashboard credential. Do not use an email.
Create a GitHub connection in Dashboard → AgentKit → Connections. Copy the exact Connection name. This example uses github-connect.
From the installed skill scripts:
cd "${HERMES_HOME:-$HOME/.hermes}/skills/hermes-delegated-auth/scripts"
uv run tool_exec.py --list-connections --provider GITHUB
uv run tool_exec.py --generate-link --connection-name github-connectIf status is not ACTIVE, open the magic link, then run --generate-link again.
Proven read:
uv run tool_exec.py --execute-tool \
--tool-name github_user_get_authenticated \
--connection-name github-connect \
--tool-input '{}'Or from this repo:
./scripts/github-whoami.shThat call returns the GitHub login for SCALEKIT_IDENTIFIER. We ran it live against github-connect.
In Hermes chat:
/hermes-delegated-auth who am I on GitHub?
Draft. Not live-verified yet.
Use this when you want a scoped tool list on a gateway you operate. One host. One bearer. You remint.
- Create the Virtual MCP config once. Save
mcp_server_url. - Run
scripts/mint-session-token.py. - Put the token in
SCALEKIT_MCP_SESSION_TOKEN. - Point Hermes at
examples/hermes-vmcp.config.yaml. - Restart, or
/reload-mcp. - Before expiry: mint again, write the env var,
/reload-mcp.
The mint script reads SCALEKIT_* from the environment or ~/.hermes/.env. It also needs SCALEKIT_MCP_CONFIG_ID. Put the saved URL in SCALEKIT_MCP_SERVER_URL.
uv run --with scalekit-sdk-python scripts/mint-session-token.pyDo not run hermes mcp login. Do not set auth: oauth.
- Gmail. This environment has no Gmail connection. Do not treat unread mail as proven here.
- App-code SDKs. That is integrate AgentKit in app code, not this host skill.
MIT