Metadata-Version: 2.5
Name: ory-hermes
Version: 1.3.1
Summary: Ory Agent Security for the Hermes agent framework — per-tool authorization, activity logging, and identity propagation by wrapping the tool registry. Built on ory-argus.
Author: Ory
License-Expression: Apache-2.0
Keywords: agent,ai,authorization,hermes,hermes-agent,nous,ory,permissions
Requires-Python: >=3.10
Requires-Dist: ory-argus<2,>=1
Provides-Extra: dev
Requires-Dist: pytest>=8; extra == 'dev'
Requires-Dist: ruff>=0.6; extra == 'dev'
Description-Content-Type: text/markdown

# ory-hermes

Ory Agent Security for the [Hermes agent framework](https://github.com/NousResearch/hermes-agent).

Wraps your Hermes tool registry so every call is authorized against Ory Permissions,
audited, and tied to the user → agent identity — built on
[`ory-argus`](https://pypi.org/project/ory-argus/).

```bash
pip install ory-hermes
```

Hermes drives its loop from a `{name: callable}` tool registry (`model_tools`).
Gate it before handing it to the agent:

```python
from ory_hermes import guard_function_map

tools = guard_function_map(model_tools)   # returns a gated copy of the registry
```

Tool objects (with a `run` / `_run` method) work too:

```python
from ory_hermes import guard_tools

tools = guard_tools([search_tool, shell_tool])
```

In **enforce** mode a denied tool raises `OryDenialError`
before the tool body runs; Hermes surfaces the denial and the tool never executes. In
**observe** mode (default) the tool runs and a `permission.observe_deny` activity event is recorded.
Network / rate-limit errors fail open.

> The integration is SDK-free: it wraps Hermes' plain Python registry by duck typing.
> Hermes is installed through its own bootstrap process and does not publish an
> installable Python SDK, so this package intentionally has no Hermes dependency or
> external real-SDK compatibility test.

Credentials come from the shared `~/.config/ory-agent-plugins/config.json`, so a login
performed by any other Ory harness plugin or SDK integration is reused here.
