1. Why Run Hermes Agent on a Mac mini?
Hermes Agent is designed to stay up: it keeps persistent memories, runs scheduled tasks with its built-in cron, and improves its own skills between conversations. None of that works on a laptop that sleeps or a shared VPS that reboots. A dedicated Mac mini from MyRemoteMac gives you Apple Silicon (Tier 1 for Hermes), full root via SSH and VNC, 1 Gbps included, and a flat monthly price, with the option to run a local Ollama model on the same machine so that inference costs nothing per token.
| Feature | Cloud VPS (AI tier) | Mac mini (MyRemoteMac) |
|---|---|---|
| Monthly Cost | GPU-tier pricing (varies) | M4 from $85/mo · M6 from $149/mo (flat) |
| Hermes Platform Tier | Linux (Tier 1) | macOS Apple Silicon (Tier 1) |
| Local LLM (Ollama) | Extra cost / limited | Native on Apple Silicon unified memory |
| Always-On Uptime | Yes | Yes (99.9% SLA) |
| Hardware | Shared, virtualized | Dedicated 1:1 physical Mac |
| Access | SSH | SSH + VNC, full root |
Key Advantage: Hermes' learning loop (memories, agent-created skills, cron jobs) only pays off if the agent is online continuously. A dedicated Mac mini runs the gateway 24/7 under launchd and can host a local tool-calling model via Ollama, route routine tasks to the free local model and keep a frontier API model for the hard ones.
2. Prerequisites
The official installer is deliberately light. You do not need Homebrew, Python or Node.js: Hermes downloads its own pinned uv and Python 3.14, and Node.js is only required later if you enable the WhatsApp bridge. Here is what you actually need:
- A dedicated Mac mini from MyRemoteMac, M4 from $85/mo or M6 from $149/mo. Both are Apple Silicon, which is Tier 1 for Hermes.
- SSH access to your Mac mini (provided with your MyRemoteMac subscription)
- git and curl on the Mac (plus tar and a SHA-256 tool, all preinstalled on macOS, git via the Xcode Command Line Tools). The installer hard-fails only when git or curl is missing.
- An LLM provider: an API key (Anthropic, OpenRouter, OpenAI and 25+ others), a Nous Portal subscription, or a local Ollama model. The model must offer at least 64,000 tokens of context and support tool calling.
- A messaging account on Telegram, Discord or WhatsApp (Telegram is the quickest to set up)
3. Step 1: Connect via SSH and Run the Installer
SSH into your Mac mini with the credentials from your MyRemoteMac dashboard. The installer needs git and curl (plus tar and a SHA-256 tool, all preinstalled on macOS), then does everything else itself: it clones the source into ~/.hermes/hermes-agent, downloads a pinned, SHA-256-verified uv, provisions Python 3.14, installs dependencies, creates ~/.hermes/config.yaml and ~/.hermes/.env (chmod 600), and launches an interactive setup.
Connect via SSH and Check the Requirements
# Connect to your Mac mini
ssh admin@your-server-ip
# Confirm Apple Silicon (Tier 1 platform for Hermes Agent)
uname -m
# arm64
# The installer requires only git and curl: both ship with macOS
git --version && curl --version
Run the Official One-Line Installer
This is the same command the official README and installation page publish. Do not use Homebrew: brew install hermes-agent is listed as an unsupported method in the official docs. If you are scripting the install over SSH, add --non-interactive (alias --skip-setup) and run the wizard yourself afterwards.
# Official one-line installer (Linux / macOS / WSL2)
curl -fsSL https://hermes-agent.nousresearch.com/install.sh | bash
# What it does:
# - clones the source into ~/.hermes/hermes-agent
# - downloads a pinned, sha256-verified uv and provisions Python 3.14
# - creates ~/.hermes/config.yaml and ~/.hermes/.env (chmod 600)
# - launches the interactive setup wizard
# Scripting over SSH? Skip the wizard and run it later with `hermes model`:
curl -fsSL https://hermes-agent.nousresearch.com/install.sh | bash -s -- --non-interactive
Reload Your Shell and Verify
The installer adds ~/.local/bin to your PATH in ~/.zshrc and ~/.zprofile. Reload the shell (or open a new SSH session), then run the built-in diagnostics:
# Reload the shell so ~/.local/bin/hermes is on PATH
source ~/.zshrc # or open a new SSH session
# Verify the install
hermes --version
# Built-in diagnostics (add --fix to attempt automatic repairs)
hermes doctor
4. Step 2: Configure a Model Provider (API or Local Ollama)
Hermes keeps secrets in ~/.hermes/.env and everything else in ~/.hermes/config.yaml, and it exposes three official ways to pick a model. Whatever you choose, the model needs at least 64,000 tokens of context. Note that Nous' own Hermes 4 chat model is not what the agent loop wants, the Nous Portal docs recommend a frontier tool-calling model instead.
Option A or B: the Interactive Wizard or Nous Portal
The wizard walks you through providers, API keys and OAuth logins. Nous Portal is a subscription that gives the agent access to 300+ models through a single OAuth login (pricing is on the Nous Portal site, not in the docs).
# Option A: interactive wizard (providers, API keys, OAuth logins)
hermes model
# Option B: Nous Portal subscription via OAuth (300+ models)
hermes setup --portal
Option C: Set a Key and Model Non-Interactively
UPPER_SNAKE keys such as ANTHROPIC_API_KEY, OPENROUTER_API_KEY or OPENAI_API_KEY are routed to .env; dotted or lowercase keys go to config.yaml. The model id below is the example used in the official quickstart, pick whatever current model your provider offers with 64k+ context and tool calling.
# Option C: non-interactive, UPPER_SNAKE keys go to ~/.hermes/.env
hermes config set ANTHROPIC_API_KEY sk-ant-YOUR_API_KEY_HERE
# Dotted / lowercase keys go to ~/.hermes/config.yaml
# (model id below is the example from the official quickstart)
hermes config set model anthropic/claude-opus-4.6
# Review the active configuration
hermes config show
Optional: a Free Local Model with Ollama
Your Mac mini can host the model itself. The official Hermes Ollama guide uses gemma4:31b (about 20 GB on disk, 24+ GB of RAM, tool calling supported), on MyRemoteMac a 24 GB configuration (Mac mini M4 24 GB at $129/mo or M6 24 GB at $219/mo) meets that documented minimum, with little headroom left for macOS and the 64k context window, if you want margin on a 24 GB Mac mini, pick a smaller tool-calling model instead. Ollama's default context window is far below Hermes' 64k requirement, so the docs have you create a Modelfile that raises num_ctx. Install Ollama for macOS from ollama.com/download first; Ollama also documents a guided path with ollama launch hermes.
# 1. Install Ollama for macOS from https://ollama.com/download
# 2. Pull a tool-calling model (~20 GB on disk, 24+ GB RAM)
ollama pull gemma4:31b
# 3. Hermes needs 64k context: build a Modelfile that raises num_ctx
printf 'FROM gemma4:31b\nPARAMETER num_ctx 64000\n' > Modelfile
ollama create gemma4-64k -f Modelfile
# 4. Point Hermes at the local OpenAI-compatible endpoint
hermes setup
# Choose "Custom Endpoint": base URL http://localhost:11434/v1, model gemma4-64k
# Alternative guided path documented by Ollama:
ollama launch hermes
Smoke Test Before Adding Anything Else
The quickstart is explicit: if Hermes cannot complete a normal chat, do not add the gateway, cron or skills yet. Run one clean conversation first:
# Classic CLI chat
hermes
# Or the terminal UI
hermes --tui
Config precedence: CLI arguments override ~/.hermes/config.yaml, which overrides ~/.hermes/.env, which overrides the built-in defaults. Use hermes config show, hermes config get <key> and hermes config path to inspect what is active.
5. Step 3: Connect Messaging Channels
One Hermes gateway process serves all your platforms: the official docs count 20+ from one gateway, including Telegram, Discord, Slack, WhatsApp, Signal, Google Chat, Microsoft Teams, Matrix, Mattermost and iMessage bridges. Below are the three we have verified against the dedicated docs pages. The gateway is deny-by-default, until you allowlist your user ID, the bot ignores everyone.
Telegram (recommended first channel)
Create a bot with @BotFather (/newbot gives you the token) and get your numeric user ID from @userinfobot, Telegram allowlists use numeric IDs, not @usernames. Then run the gateway wizard, which writes the values to ~/.hermes/.env. Long polling is the default, so no inbound port or firewall rule is needed.
# 1. In Telegram, open @BotFather, send /newbot and copy the token
# 2. Open @userinfobot to get your numeric user ID
# 3. Run the gateway wizard (writes the values to ~/.hermes/.env)
hermes gateway setup
# Equivalent manual entries in ~/.hermes/.env:
# TELEGRAM_BOT_TOKEN=123456789:ABC...
# TELEGRAM_ALLOWED_USERS=123456789
# Optional: chat that receives scheduled-task results (or send /sethome in a chat)
# TELEGRAM_HOME_CHANNEL=123456789
Discord (optional)
Create an application in the Discord Developer Portal, copy the bot token, and enable both the Message Content Intent and the Server Members Intent under Privileged Gateway Intents, without Message Content Intent the bot receives events with empty text. Invite the bot with permission integer 274878286912, then allowlist your user ID.
# In the Discord Developer Portal (https://discord.com/developers/applications):
# 1. New Application > Bot > copy the Bot Token
# 2. Privileged Gateway Intents: enable Message Content Intent + Server Members Intent
# 3. Invite the bot with permission integer 274878286912
hermes gateway setup # choose Discord
# Equivalent manual entries in ~/.hermes/.env:
# DISCORD_BOT_TOKEN=...
# DISCORD_ALLOWED_USERS=284102345871466496
# DISCORD_REQUIRE_MENTION=true (default)
WhatsApp (optional)
WhatsApp uses an unofficial bridge (Baileys) that needs Node.js v18+ and a dedicated phone number paired via QR code. The official docs warn that it carries a small risk of account restrictions, and the session directory grants full access to the account, never share it.
# Requires Node.js v18+ on the Mac mini (only needed for WhatsApp)
node --version
# Pair a dedicated phone number via QR code
hermes whatsapp
# ~/.hermes/.env:
# WHATSAPP_ENABLED=true
# WHATSAPP_MODE=bot
# WHATSAPP_ALLOWED_USERS=15551234567 (country code, no +)
# Session is stored in ~/.hermes/platforms/whatsapp/session: never share it
# Meta Business Cloud API alternative: hermes whatsapp-cloud
Test the Gateway in the Foreground
Start the gateway in your SSH session, send your bot a message, confirm it replies, then press Ctrl-C. hermes gateway status shows the service state; message the bot to confirm end-to-end.
# Run the gateway in the foreground
hermes gateway
# Send your bot a message from Telegram / Discord: it should reply.
# Press Ctrl-C to stop (the persistent service is set up in Step 4)
Security checklist from the official docs: explicit allowlists on every platform (never GATEWAY_ALLOW_ALL_USERS=true on a public bot), keep ~/.hermes/.env at chmod 600, leave approvals.mode on smart (YOLO mode disables all checks except a hardline blocklist), consider hermes config set terminal.backend docker with Docker Desktop installed so tool execution runs in a container, and keep Hermes updated.
6. Step 4: Run 24/7 with launchd, Update, Migrate
hermes gateway install registers a user-level LaunchAgent at ~/Library/LaunchAgents/ai.hermes.gateway.plist (label ai.hermes.gateway) so the gateway starts at login (RunAtLoad) and is supervised by macOS. One important detail from the official FAQ: the plist snapshots your full shell PATH at install time. Install Node.js, ffmpeg or Ollama before this step, or re-run hermes gateway install afterwards.
Install and Start the Service
# Register the launchd LaunchAgent
# (writes ~/Library/LaunchAgents/ai.hermes.gateway.plist with your current PATH)
hermes gateway install
# Start it now
hermes gateway start
# Service status
hermes gateway status
# Live logs
tail -f ~/.hermes/logs/gateway.log
# Other commands: hermes gateway stop | restart | list
# Foreground run (no launchd): hermes gateway run
Verify launchd Supervises It (and Reboot-Test Once)
hermes gateway status shows the service state; message the bot to confirm end-to-end, and query launchctl directly to confirm launchd actually owns the process. Because a user-level LaunchAgent only loads once your user session exists, make sure Automatic login is enabled for your admin user (System Settings > Users & Groups > Automatic login) before the reboot-test, otherwise the gateway will not come back on a headless Mac mini. Then reboot once (sudo reboot) and message the bot again.
# Confirm launchd owns the gateway (state, PID, last exit code)
launchctl print gui/$(id -u)/ai.hermes.gateway
# Check the PATH that was captured in the plist
/usr/libexec/PlistBuddy -c "Print :EnvironmentVariables:PATH" ~/Library/LaunchAgents/ai.hermes.gateway.plist
# LaunchAgents load at login: enable Automatic login first
# (System Settings > Users & Groups > Automatic login)
# Reboot-test once, then message the bot again
sudo reboot
Update Hermes Agent
hermes update pulls the latest code into ~/.hermes/hermes-agent, re-syncs dependencies and restarts the gateway drain-first: it refuses new turns and waits for in-flight chat, cron and API work (up to 30 minutes by default) before restarting. Output is mirrored to ~/.hermes/logs/update.log. Use --check to preview, --backup to snapshot ~/.hermes first, and --no-gateway-restart to defer the restart.
# Preview what would change
hermes update --check
# Update (snapshot ~/.hermes first, drain-first gateway restart)
hermes update --backup
# Adopt any new configuration options
hermes config check && hermes config migrate
# Confirm the running version
hermes --version
Optional: Migrate from OpenClaw on the Same Mac
Already running OpenClaw from our other guide? The official migration command imports SOUL.md, memories and user profiles (to ~/.hermes/memories/), skills (to ~/.hermes/skills/openclaw-imports/) from ~/.openclaw, and writes a pre-migration-*.zip restore point in ~/.hermes/backups/ first. Secrets are not imported by default: add --migrate-secrets explicitly to carry over API keys and messaging tokens (Telegram, Discord, Slack, Signal, Matrix, Mattermost). WhatsApp is not token-migrated, only its allowlist is mapped, and must be re-paired with hermes whatsapp. Always start with a dry run.
# Preview the migration from ~/.openclaw
hermes claw migrate --dry-run
# Migrate (writes a pre-migration-*.zip restore point in ~/.hermes/backups/ first)
# --migrate-secrets is required to carry over API keys and messaging tokens
hermes claw migrate --migrate-secrets
# Later, rename leftover OpenClaw directories to .pre-migration/
hermes claw cleanup
7. Troubleshooting Common Issues
"hermes: command not found" right after install
The shell has not reloaded the PATH entry the installer added. The binary lives in ~/.local/bin:
# Reload the shell profile the installer edited
source ~/.zshrc
# Or call the binary directly
~/.local/bin/hermes --version
# Still broken? Run the diagnostics
~/.local/bin/hermes doctor --fix
The bot never answers on Telegram or Discord
Most often the allowlist is empty, the gateway denies everyone by default. Check that your numeric ID is set, then test in the foreground:
# Allowlist resolution order (official security guide):
# per-platform allow-all -> DM-pairing list -> TELEGRAM_ALLOWED_USERS / DISCORD_ALLOWED_USERS
# -> GATEWAY_ALLOWED_USERS -> GATEWAY_ALLOW_ALL_USERS=true -> deny
# Check what is stored (Telegram IDs are numeric, from @userinfobot)
grep TELEGRAM_ALLOWED_USERS ~/.hermes/.env
# Fix it, then watch the gateway in the foreground while you message the bot
hermes config set TELEGRAM_ALLOWED_USERS 123456789
hermes gateway
# Discord only: confirm Message Content Intent is enabled in the Developer Portal
Gateway cannot find node, ffmpeg or ollama (works in your shell)
The launchd plist captured PATH when you ran hermes gateway install. Re-run the install after adding tools, then restart:
# See the PATH launchd is using
/usr/libexec/PlistBuddy -c "Print :EnvironmentVariables:PATH" ~/Library/LaunchAgents/ai.hermes.gateway.plist
# Re-capture your current shell PATH and reload the service
hermes gateway install
hermes gateway start
# Check the logs
tail -50 ~/.hermes/logs/gateway.log
Local Ollama model fails or truncates context
Hermes requires a 64,000-token context; Ollama's default is far lower. Build a Modelfile that raises num_ctx and point Hermes at the resulting model:
# Rebuild the model with a 64k context window
printf 'FROM gemma4:31b\nPARAMETER num_ctx 64000\n' > Modelfile
ollama create gemma4-64k -f Modelfile
# Make sure Hermes targets the 64k variant on the local endpoint
hermes setup # Custom Endpoint: http://localhost:11434/v1, model gemma4-64k
# Note: the model must also support tool calling (gemma4:31b does, per the official guide)
Gateway does not come back after a reboot
A user-level LaunchAgent starts at login, not at boot: on a headless Mac mini, enable Automatic login for your admin user first (System Settings > Users & Groups). Then confirm launchd actually loaded the LaunchAgent rather than a detached fallback process, and re-install the service if needed:
# Is the LaunchAgent registered and running?
launchctl print gui/$(id -u)/ai.hermes.gateway
# Not listed? Re-register and start it (and check Automatic login is on)
hermes gateway install
hermes gateway start
hermes gateway status
# Then reboot-test again
sudo reboot
8. Cost Analysis vs. Cloud VPS
Hermes Agent itself is free (MIT). What you pay for is the host and the LLM usage. The host comparison below reuses the cloud VPS figures from our OpenClaw guide; LLM API usage is billed separately by your provider in both columns and is identical on either host, unless you run a local Ollama model on the Mac mini, in which case inference costs $0.
| Use Case | AI Calls/Month | Cloud VPS Cost | MyRemoteMac Cost | Monthly Savings |
|---|---|---|---|---|
| Personal assistant (API model) | ~500 calls | $120/mo (basic GPU VPS) | $85/mo (Mac mini M4) | $35/mo |
| Small team bot + cron jobs | ~5,000 calls | $200/mo | $85/mo (Mac mini M4) | $115/mo |
| Local LLM (gemma4:31b) + agent | Unlimited (local) | $350+/mo (GPU VPS) | $129/mo (Mac mini M4, 24 GB, documented minimum) | $221+/mo |
| Multi-agent, heavy automation | 10,000+ calls | $600+/mo | $149/mo (Mac mini M6) | $451+/mo |
Assumptions: VPS prices are the same ranges used across our guides for GPU-capable AI-tier instances and are not quotes from a specific provider; MyRemoteMac prices are the current monthly rates in USD (1 Gbps included). Nous Portal subscription pricing is not published in the Hermes docs, so it is not included.
Bottom Line: A dedicated Mac mini costs less than a GPU VPS at every usage level, and Apple Silicon's unified memory lets a 24 GB configuration host a tool-calling local LLM (at the documented minimum for gemma4:31b) that turns per-token API costs into zero for routine work.
9. Hermes Agent vs. OpenClaw
Both are open-source (MIT), self-hosted, always-on personal AI agents driven from your messaging apps, both install with a one-line curl command, both run a long-lived gateway, and both register their own launchd LaunchAgent (ai.hermes.gateway vs ai.openclaw.gateway). The differences are in the stack and the pitch. OpenClaw is TypeScript on Node.js (26.1+ or 24.16+ via Homebrew), installed with npm, with its own openclaw gateway install service command. Hermes is Python bootstrapped by a pinned uv, lives entirely in ~/.hermes, needs only git and curl (Node.js only for the WhatsApp bridge), and uses hermes gateway install. Hermes' pitch is self-improvement: agent-created skills, persistent memories and SOUL.md, built-in cron, and seven terminal backends (local, Docker, SSH, Modal, Daytona, Vercel Sandbox, Singularity). OpenClaw's pitch is breadth and the larger community, on 2026-09-28 GitHub showed roughly 391k stars for OpenClaw versus 250k for Hermes.
If you already run OpenClaw, the migration is first-class: hermes claw migrate (see Step 4) is a forward migration that writes a pre-migration-*.zip restore point in ~/.hermes/backups/ first. If you are starting from scratch, read our OpenClaw on Mac mini guide as well and pick the harness whose workflow you prefer, the Mac mini, the launchd service and the local Ollama option are identical for both.
10. FAQ
Is Hermes Agent free to use?
Yes. Hermes Agent is MIT-licensed and free; you pay only for LLM usage from the provider you choose. A local Ollama model on your Mac mini is free to run. The Mac mini itself is from $85/month (M4) or $149/month (M6) at MyRemoteMac.
Do I need to install Python, Node.js or Homebrew first?
No. The installer needs only git and curl (both on macOS by default). It downloads a pinned, SHA-256-verified uv and provisions Python 3.14 itself. Node.js v18+ is required only if you enable the WhatsApp bridge, and Homebrew installs are explicitly unsupported by the official docs.
Which Mac mini configuration should I pick for Hermes?
If Hermes uses an API model (Anthropic, OpenRouter, Nous Portal, etc.), the entry 16 GB Mac mini M4 at $85/month is enough, the agent itself is light. If you want to host a local model, follow the official Ollama guide's sizing: gemma4:31b needs 24+ GB of RAM, so a 24 GB configuration (Mac mini M4 24 GB or Mac mini M6 24 GB) meets the documented minimum, with little headroom for macOS and the 64k context, so a smaller tool-calling model is the safer choice on that tier.
Does Hermes survive a reboot of the Mac mini?
Yes, once you run hermes gateway install: it registers a user-level launchd LaunchAgent (ai.hermes.gateway) that starts the gateway at login (RunAtLoad). On a headless Mac mini that means Automatic login must be enabled for your user. Verify with launchctl print gui/$(id -u)/ai.hermes.gateway and reboot-test once, as described in Step 4.
Can I migrate my existing OpenClaw setup to Hermes?
Yes. hermes claw migrate --dry-run previews, then hermes claw migrate imports SOUL.md, memories and skills from ~/.openclaw after writing a pre-migration-*.zip restore point in ~/.hermes/backups/. API keys and messaging tokens (Telegram, Discord, Slack, Signal, Matrix, Mattermost) are only carried over when you pass --migrate-secrets explicitly; WhatsApp must be re-paired with hermes whatsapp. The OpenClaw install stays in place until you run hermes claw cleanup.
Which messaging platforms does Hermes support?
The official docs list 20+ platforms served by a single gateway process, including Telegram, Discord, Slack, WhatsApp (Baileys bridge or Cloud API), Signal, Google Chat, Microsoft Teams, Matrix, Mattermost, LINE, IRC, email, SMS, iMessage bridges (BlueBubbles, Photon), webhooks and an API server, plus the CLI and TUI locally.
11. Sources and Further Reading
Every command and requirement in this guide was checked on September 28, 2026 against the official Hermes Agent documentation and repository (latest release v2026.9.24). Hermes ships date-tagged releases and moves fast, so consult these pages for the current list of flags:
- Hermes Agent GitHub repository (NousResearch/hermes-agent)
- Official installation guide
- Quickstart (providers, 64k context requirement, smoke test)
- Platform support (Tier 1 macOS Apple Silicon, unsupported methods)
- Updating Hermes Agent
- Configuration reference (config.yaml, .env, precedence)
- Security guide (allowlists, approvals, Docker backend)
- Messaging overview (platform list, gateway install/start/stop)
- Telegram setup
- Discord setup
- WhatsApp setup
- CLI commands reference
- FAQ (macOS launchd PATH, gateway.log)
- Local Ollama setup guide (gemma4:31b, num_ctx 64000)
- Migrate from OpenClaw
- Nous Portal integration
- Ollama integration page (ollama launch hermes)
Related Guides
Install OpenClaw on Mac mini
The other leading self-hosted AI agent harness, same Mac mini recipe on Node.js/npm with its own gateway-install LaunchAgent.
Run LLMs on Mac mini M4
Run Ollama, llama.cpp and local language models natively on Apple Silicon for zero-cost AI inference.
Rent a Mac mini M6
Apple's newest Mac mini with a 12-core M6 and dual 16-core Neural Engine, dedicated 1:1 from $149/month.