> guide --full
The complete guide.
Everything you need to go from zero to commanding your agent: install the server, pair your phone, and get the most out of every screen. No magic steps — every command is right here.
01 > cat --resumen
Start here
Hermes Console is the Android app. It connects directly to the Hermes Agent running on your server, PC or VPS.
Current version: Hermes Console 1.2.7 (915). Install only officially published builds; do not install or share qa, debug, or profile variants.
You only need to answer one question:
- I don't have Hermes yet. Go to “Install Hermes”.
- I already have Hermes. Go to “Prepare the connection”; it works even if you don't know whether the ports are ready.
Both paths end with a QR in the server terminal. Scan it with your phone and the app configures the connection automatically. Grant camera, microphone, or notification access only when you use the related feature.
02 > install --instalar
I don't have Hermes: install it
Choose the system running Hermes Agent — not your phone system.
It is not detected automatically because you may be viewing this site on another device.
curl -fsSL https://raw.githubusercontent.com/xP3ta/hermes-setup/main/hermes-mobile-setup.sh | sh irm https://raw.githubusercontent.com/xP3ta/hermes-setup/main/hermes-mobile-setup.ps1 | iex It can be a VPS, homelab, mini-PC or PC running Linux, macOS, Termux or Windows. For WSL2, choose Windows and run the command in Windows PowerShell, outside WSL; that lets setup configure networking, Firewall and persistent startup correctly.
- The command installs Hermes Agent.
- It prepares Gateway, Dashboard and Mobile Bridge, including a private-network-only firewall rule when needed.
- It verifies service identity, authentication, Bridge updates and the exact address the phone will use.
- Only then does it show SCAN THIS QR WITH HERMES CONSOLE and a QR.
Services persist through systemd on Linux, launchd on macOS and Scheduled Tasks—or Windows startup as a fallback—on Windows. If a Unix environment has no supported service manager, the installer warns you and keeps the current session working.
On Windows, setup shows an administrator UAC prompt only if it needs to create the restricted private rule. Approve that step; Hermes and its tasks still stay in your account. It never opens these ports to the whole Internet.
The infrastructure is now ready; on a fresh install you still choose your AI provider/model from the Dashboard in the app.
Leave the QR visible, return to the app and tap “I can see the QR · open camera”.
03 > prepare --preparar
I have Hermes: prepare the connection
Choose the system running Hermes Agent — not your phone system.
It is not detected automatically because you may be viewing this site on another device.
curl -fsSL https://raw.githubusercontent.com/xP3ta/hermes-setup/main/hermes-mobile-setup.sh | sh irm https://raw.githubusercontent.com/xP3ta/hermes-setup/main/hermes-mobile-setup.ps1 | iex If you don't know whether Hermes is ready for mobile, you don't need to check ports or find keys. Run the command for your system shown above.
It is idempotent: if Hermes already exists, it doesn't reinstall it or replace a strong key or existing password. It repairs and starts what is needed, and shows the QR only after all three services pass.
You can also copy the message offered by the app and send it directly to Hermes. It will reply with a hermes://pair… link; copy it and tap “Paste link” on the phone.
Technical details
It prepares Gateway (8642), Dashboard (9119) and Mobile Bridge (9131), preserves the existing API key and prioritizes Tailscale or a private LAN. It verifies /health, the authenticated sessions API, Bridge capabilities and self-update, and real Dashboard state. Public HTTP and loopback never produce a QR; use HTTPS for a public server.
04 > pair --qr
It's ready: show the QR
Choose the system running Hermes Agent — not your phone system.
It is not detected automatically because you may be viewing this site on another device.
curl -fsSL https://raw.githubusercontent.com/xP3ta/hermes-setup/main/hermes-pair.sh | sh irm https://raw.githubusercontent.com/xP3ta/hermes-setup/main/hermes-pair.ps1 | iex The command for your system shows the QR again without reinstalling or restarting anything. It first rechecks Gateway, Dashboard and Bridge; if one is down or unauthenticated, it does not expose credentials and asks you to run the full repair.
- Wait for SCAN THIS QR WITH HERMES CONSOLE.
- Leave the QR visible on the server screen.
- In the app tap “I can see the QR · open camera” and scan it.
If the link is on the same phone, use “Paste link” instead of the camera. The QR and link contain the Gateway, Dashboard, Bridge URL and Bridge token; the new app version fills and stores all of them per instance.
Security: treat them like a password; don't share them or publish screenshots.
05 > ls --tour
App tour
- Chat — token-by-token streaming, selectable text and code blocks, image and document attachments with visible progress, and image generation right in the conversation.
- Voice — choose per instance between the phone engine and Hermes server; dictation, read aloud, and manual conversation remain available with optional continuity. Voice guide →
- Sessions — every conversation of your agent, including the ones you started on desktop.
- Kanban — the agent's task board: backlog, in progress, review, and blocked; its results can notify you and open the related work.
- Models — switch the active model, Ollama catalog, and external providers (LM Studio, OpenAI-compatible).
- MoA — Mixture-of-Agents recipes editable from the app: several models propose, one aggregates the final answer.
- SSH terminal — a real shell with a PTY against any machine, plus an SFTP browser to move files.
- Cron — scheduled jobs: create, edit, pause, trigger manually, and receive a notification that opens the right run.
- Memory — read and edit the agent's persistent memory, with local drafts.
- SOUL — the agent's identity document (its persona), editable with templates and autosave.
- Skills — browse the skills installed on your agent.
- Task Center — every run launched from the app, with live tracking.
- Approvals — when the agent wants to run something sensitive, it arrives with its risk level: approve or reject, right from the notification.
- Spark — the Hermes mascot: mirrors your agent's state (thinking, connecting, celebrating).
06 > set --configuracion
Settings
- Appearance — dark and light themes (including pure OLED and the "Hermes Console" theme), text size and a font picker.
- Language — Spanish and English, or follow the system.
- Security — app lock with biometrics or PIN; the API key lives encrypted in the Android Keystore.
- Notifications — approvals and terminal Cron/Kanban results, deduplicated and linked to their conversation or run: zero Google, zero third-party push.
- Voice — choose “On this phone” or “Hermes server” per instance; conversation mode can be disabled without losing dictation or read aloud. Set up voice →
- Accessibility — consistent switches, collapsible technical details, and selectors that adapt to large text and narrow screens.
- Server — from the app itself: update Hermes, restart the Gateway and repair/update the Bridge when it gets old (a banner warns you).
07 > permissions --permisos
Android permissions, without fine print
- Camera — opens only when you scan a QR or take a photo attachment. The QR is processed on-device; the photo goes to your Hermes only when you send the message.
- Microphone — starts after you begin dictation or a conversation. Keeping a conversation active outside the app requires a separate opt-in and a persistent notification with controls.
- Notifications — local alerts for approvals, runs, and Cron/Kanban, plus controls for Voice or Read Aloud that you started. No third-party push is used.
- Biometrics — only for optional App Lock. Android performs the check; Hermes Console does not access biometric templates.
- Photos and documents — selected through Android's pickers. On modern Android, the app does not enumerate or import general storage.
The Google Play variant is remote-only and does not include the permissions or app queries used by the full variant for Termux or F-Droid integration.
08 > fix --problemas
If something breaks
- "Can't connect". Check phone and server share a network (Tailscale up on both?) and the port is
8642. You can rerun the installer for your system: it is safe and idempotent, and repairs or starts the required services. - Windows blocks the connection. Rerun setup and approve its UAC prompt to create private-network-only rules. If the LAN is marked “Public”, switch it to “Private” or use Tailscale.
- TLS certificate error. On a private network connect over LAN or Tailscale (internal HTTP is fine there); for a public domain use a valid certificate on the proxy.
- QR expired or missing. Use “show the QR” and choose the system of the machine running Hermes.
- "Bridge outdated". Tap the banner: the app uses the Bridge's authenticated self-update channel, validates version and SHA-256, and confirms the restart.
- No notifications. Enable background listening in Settings → Notifications and grant the notification permission (Android 13+).
09 > lock --seguridad
Security and networking, in short
- Connect over LAN or Tailscale whenever you can; don't open
8642/9119/9131to the public internet. - If you need access from outside, Tailscale gives you an encrypted private network with no open ports; HTTPS with a valid certificate is the alternative.
- Your API key never leaves the phone except towards your server, and is stored encrypted in the Keystore.
- The dashboard is password-protected from first boot (the installer sets it for you).
- Messages and attachments go to the Hermes you configure; XPeta Lab operates no backend, account, or tracking. Optional providers and the on-device ZXing QR scanner are covered in the full privacy policy →