Hermes Agent platform message integration

The Messaging Gateway enablesSame Agent—The same memories, skills, and tools—running seamlessly across 20+ platforms.

This chapter will introduce Gateway configuration and deployment, session lifecycle, multi-user isolation policies, and security access control.


Message Gateway Overview

The message gateway is a resident background process that centrally manages connections, sessions, scheduled tasks, and media delivery for all messaging platforms.

Everything you teach the Agent in the CLI—memory, skills, preferences—is fully consistent across all platforms.

Supported platforms

Hermes Supported 20+ MessagePlatform:CLI、Telegram、Discord、Slack、WhatsApp、Signal、Matrix、Mattermost、Email、SMS、DingTalk、Feishu/Lark、WeChat Work、micro信、QQ、元宝、BlueBubbles(iMessage)、Home Assistant、Microsoft Teams、Google Chat etc.

Platform Capability Comparison

PlatformSpeechImagesFilemessage stringEmoji reactionTyping indicatorStreaming output
TelegramSupportedSupportedSupportedSupported—SupportedSupported
DiscordSupportedSupportedSupportedSupportedSupportedSupportedSupported
SlackSupportedSupportedSupportedSupportedSupportedSupportedSupported
WhatsApp—SupportedSupported——SupportedSupported
Signal—SupportedSupported——SupportedSupported
Feishu/LarkSupportedSupportedSupportedSupportedSupportedSupportedSupported
WeChat WorkSupportedSupportedSupported————
DingTalk—SupportedSupported—Supported—Supported
Microsoft Teams—Supported—Supported—Supported—
Email—SupportedSupportedSupported———
SMS———————
MatrixSupportedSupportedSupportedSupportedSupportedSupportedSupported

Cross-platform session continuity: the same Agent can maintain context across different platforms. For example, if you are mid-conversation with the Agent on Telegram and switch to Discord, the Agent still remembers the previous conversation.


Gateway startup and configuration

Desktop version configuration

Open the Messaging Platforms item in the left menu to see the supported platforms. Click the corresponding platform to configure it:

Configuration in Interactive Mode

Use the interactive wizard to complete the initial configuration for all platforms:

hermes gateway setup

The wizard will guide you through configuring each platform: selecting the platform, filling in the Bot Token, setting the allowed user list, etc.

For example, after selecting Feishu, you can choose to create a bot by scanning a QR code or by using the APP ID:

Gateway Management Commands

Example

# Run in foreground (for debugging)
hermes gateway

# Install as a user-level system service (Linux systemd / macOS launchd)
hermes gateway install

# Linux: Install as a system service that starts on boot
sudo hermes gateway install --system

# Service Control
hermes gateway start       # Start Service
hermes gateway stop        # Stop Service
hermes gateway restart     # Restart Service
hermes gateway status      # View Service Status

Telegram Bot integration hands-on

Take Telegram as an example to complete a full Bot integration process.

Step 1: Create a Telegram Bot.

In Telegram, search for @BotFather, send the /newbot command, and set the Bot name and username as prompted.

BotFather will return a Bot API Token, formatted similar to:1234567890:ABCdefGHIjklMNOpqrsTUVwxyz。

Step 2: Configure the Hermes Gateway.

Example

# File path: ~/.hermes/config.yaml
# Telegram Platform Configuration
platforms
:
  telegram
:
    enabled
: true
    bot_token
: "1234567890:ABCdefGHIjklMNOpqrsTUVwxyz"
    # Optional: list of allowed user IDs (whitelist mode).
    allowed_users
:
     - "123456789"
    # Optional: whether it needs to be @mentioned in the group to respond
    require_mention
: true
    # Optional: list of channels that do not require @mention
    free_response_channels
:
     - "-1001234567890"

Step 3: Start and test.

Example

# Start Gateway
hermes gateway start

# Send a test message to your Bot in Telegram

For the initial integration, it is recommended to use whitelist mode (allowed_users), allowing only your own account to interact with the Agent, and then open it to others after verifying everything works properly.

Slash commands available within the platform

The following commands are available on any messaging platform:

CommandFeatures
/new or /resetStart new session
/model [name]View or Switch Models
/retryRetry Last Message
/undoUndo Last Conversation Turn
/stopInterrupt Current Task
/approve / /denyApprove/Reject dangerous commands
/background <task>Run Tasks in Background Sessions
/statusShow current session information
/usageDisplay the Token usage for this session.
/voice [on/off/tts]Control Voice Replies
/compressManually compress conversation context
/resume [title]Resume a previously named session
/<skill-name>Invoke any installed skill
/reload-mcpReload MCP server
/updateUpdate Hermes to the Latest Version
/helpShow all available commands

Session Lifecycle

Session is the core concept in Hermes Gateway for managing conversations.

Understanding how Session works helps you configure appropriate session isolation policies and reset rules.

SessionSource: message source descriptor

Every message entering the Gateway carries a SessionSource, which records "where this message came from."

FieldsTypeDescription
platformstringPlatform name (telegram, discord, slack, etc.)
chat_idstringSession identifier (private chat ID, group ID, channel ID)
chat_typestringSession types: dm (direct message), group, channel, thread
user_idstringPlatform ID of the message sender
user_namestringDisplay name of the message sender
thread_idstringForum topic ID (Telegram forum) / Discord thread ID
guild_idstringDiscord server ID (used for server isolation)

Session Key generation rules

Session Key is a deterministic string composed of fields from the SessionSource.

It determines which messages belong to the same session. The format is as follows:

agent:main:{platform}:{chat_type}:{chat_id}:{thread_id}:{user_id}

Examples of Session Keys in different scenarios:

ScenariosSession Key
Telegram Private Chatagent:main:telegram:dm:12345
Telegram Groupagent:main:telegram:group:-10012345:user_abc
Telegram forum topicsagent:main:telegram:group:-10012345:thread_678:user_abc
Discord private chatagent:main:discord:dm:12345
Discord server channelsagent:main:discord:channel:12345:user_abc
Discord threadagent:main:discord:thread:12345:thread_678

The Session Key generation rule is one of the most important Gateway configurations. If misconfigured, it may cause cross-talk between different users' sessions—two different people seeing each other's conversation content.

SessionEntry: active session record

Each Session Key corresponds to a SessionEntry, which records the session's metadata and state.

FieldsDescription
session_idSession unique identifier, format: YYYYMMDD_HHMMSS_8-digit random hex
created_atSession Creation Time
updated_atLast activity time (used for idle timeout determination)
total_tokensCumulative token consumption
estimated_cost_usdCumulative cost estimate (USD)
suspendedWhether it has been forcibly suspended (/stop command or abnormal loop)
resume_pendingWhether it is waiting for recovery (restart recovery flag after a crash)

Multi-User Isolation Policy

Multi-user isolation determines whether multiple users in the same group or channel share a single session or have their own independent sessions.

This configuration directly affects the user experience—a shared session means user A can see user B's conversation context.

Isolation Policy Configuration

Configuration ItemDefault valueMeaning
group_sessions_per_usertrueEach user in a group/channel has an independent session
thread_sessions_per_userfalseAll users in the thread share the same session

Behavior in Different Scenarios

ScenariosDefault behaviorDescription
Private Chat (DM)Always independentPrivate chat is always private and not configurable
Groups/ChannelsEach user has an independent sessionUser A and User B each have independent session contexts in the same group
Thread (forum topic)All users share a sessionIn Telegram forum topics and Discord threads, all participants share the same context

System prompt changes for shared sessions

When the session is in shared mode (shared_multi_user_session = true), the system prompt will change:

  • Instead of a fixed username, it prompts "Multi-user session—message prefix includes sender name"
  • Each user message is prefixed with the sender's display name so the Agent knows who is speaking
  • This design maintains the effectiveness of prompt caching (the system prompt does not change with the sender)

The default isolation policy (per-user for groups, shared for threads) is a best practice verified through extensive real-world use. Unless you have special requirements, it is not recommended to change it.


Gateway Security Configuration

User Access Control

By default, the gateway rejects all users not on the whitelist—This is the secure default setting for a Bot with terminal access privileges.

Configure allowed users (in the .env file):

Example

# File path: ~/.hermes/.env
# User whitelist for specific platforms
TELEGRAM_ALLOWED_USERS=123456789,987654321
DISCORD_ALLOWED_USERS=123456789012345678
SLACK_ALLOWED_USERS=U012AB3CD,U012EF4GH
FEISHU_ALLOWED_USERS=ou_xxxxxxxx,ou_yyyyyyyy
WECOM_ALLOWED_USERS=user-id-1,user-id-2
TEAMS_ALLOWED_USERS=aad-object-id-1

# Whitelist that applies to all platforms
GATEWAY_ALLOWED_USERS=123456789,987654321

# Allow all users (not recommended for bots with terminal access)
GATEWAY_ALLOW_ALL_USERS=true

DM pairing (alternative to whitelist)

No need to manually configure user IDs. When a new user DMs the Bot, they will receive a one-time pairing code:

Example

# After user DMs the bot, they will see: "Pairing code: XKGH5N7P"
# You approve the user's access
hermes pairing approve telegram XKGH5N7P

# View pending + approved user list
hermes pairing list

# Revoke a user's access permissions
hermes pairing revoke telegram 123456789

The pairing code expires after 1 hour, has rate limiting, and is generated using cryptographic random numbers.

Silent token

Used in group chats, Hooks, and automated workflows to make the Agent send no messages under specific conditions:

# Agent 回复中仅包含以下内容之一时,网关不会向平台发送任何消息:
[SILENT]
SILENT
NO_REPLY
NO REPLY

silence isDelivery decision, without affecting the session record—the reply is still stored in the session history, ensuring the conversation turn-taking logic works normally.

Session Reset Policy

Configure when the session automatically resets to prevent unlimited context growth:

Example

{
  "reset_by_platform": {
    "telegram": { "mode": "idle", "idle_minutes": 240 },
    "discord":  { "mode": "idle", "idle_minutes": 60 },
    "slack":    { "mode": "daily", "reset_hour": 4 }
  }
}
PolicyDefault valueDescription
daily4:00 AMReset session at a specific time each day
idle1440 minutesReset session after idle timeout
bothcombinationWhichever triggers first resets the session

Quick Reference for Common Commands

Example

# ─── Gateway Management ────────────────────────────────────────────────
hermes gateway setup                  # Interactive platform configuration
hermes gateway                        # Run in foreground (debug)
hermes gateway install                # Install as user service
hermes gateway start / stop / restart # Service Control
hermes gateway status                 # View Service Status

# ─── User Pairing ────────────────────────────────────────────────
hermes pairing list                   # View Pairing List
hermes pairing approve <platform> <code>   # Approve Pairing
hermes pairing revoke <platform> <user_id> # Revoke Access

# ─── SessioninsideSlash Commands ──────────────────────────────────────────
/new                                  # Start a new session
/model [Name]                         # View or switch model
/retry                                # Retry the last message
/undo                                 # Undo previous turn
/stop                                 # Interrupt Current Task
/approve / /deny                      # Approve/Reject Dangerous Commands
/background <Task>                    # Run Task in Background
/status                               # Current Session Information
/usage                                # Token usage
/voice [on/off/tts]                   # Control Voice
/compress                             # Compress context
/resume [Title]                         # Restore Session
/<skill-name>                         # Invoke Skill
/reload-mcp                           # Reload MCP
/update                               # Update Hermes
/help                                 # All Commands
other extensions