The shape rule (a platform prefix plus _TOKEN/_SECRET/_PASSWORD/_KEY) also matched variables Hermes never reads: the platform list holds plain words (LOCAL, GATEWAY, WEBHOOK, SLACK), so a user's SLACK_USER_TOKEN, LOCAL_LLM_API_KEY or GATEWAY_API_KEY vanished from the terminal and terminal.env_passthrough could not bring them back. The prefix census it leaned on also failed open (an unreadable plugins dir cached an empty set). Adapter secrets now come from what adapters declare: password entries of the messaging OPTIONAL_ENV_VARS (built-ins plus every platform plugin manifest) and secret-named keys of the gateway env-override table, both Tier 1 and refused by passthrough; plus the secret-named required_env of adapters registered in the current profile scope, read per spawn without loading deferred adapters, Tier 2 only because required_env is an unchecked setup list. Secrets nothing declared get a manifest entry (TELEGRAM_WEBHOOK_SECRET, PHOTON_SIDECAR_TOKEN, A2A_PUSH_SECRET, TEAMS_GRAPH_ACCESS_TOKEN, TEAMS_INCOMING_WEBHOOK_URL) or join the policy's read-in-code list (QQ_STT_API_KEY, the two MSGRAPH names).
97 lines
4.5 KiB
YAML
97 lines
4.5 KiB
YAML
name: photon-platform
|
|
label: iMessage via Photon
|
|
kind: platform
|
|
version: 0.3.0
|
|
description: >
|
|
Photon Spectrum gateway adapter for Hermes Agent.
|
|
Connects to iMessage (and other Spectrum interfaces) through Photon's
|
|
managed Spectrum platform. Both directions run over the `spectrum-ts`
|
|
SDK's long-lived gRPC stream via a small supervised Node sidecar —
|
|
inbound messages arrive on the SDK's `app.messages` stream (no webhook,
|
|
no public URL, no signing secret), and outbound messages are sent over
|
|
the same sidecar.
|
|
|
|
The plugin ships with a `hermes photon` CLI for the one-time device
|
|
login + project + user setup. Runtime credentials are written to
|
|
``~/.hermes/.env`` (``PHOTON_PROJECT_ID`` = the Spectrum project id,
|
|
``PHOTON_PROJECT_SECRET``) like every other channel, with management
|
|
metadata (device token, dashboard project id) in ``~/.hermes/auth.json``.
|
|
Photon's free shared-line model lets users get started without a paid plan.
|
|
author: NousResearch
|
|
requires_env:
|
|
- name: PHOTON_PROJECT_ID
|
|
description: "Spectrum project id (the project's spectrumProjectId; set by `hermes photon setup`)"
|
|
prompt: "Photon Spectrum project id"
|
|
url: "https://app.photon.codes/"
|
|
password: false
|
|
- name: PHOTON_PROJECT_SECRET
|
|
description: "Project secret paired with the Spectrum project id (set by `hermes photon setup`)"
|
|
prompt: "Photon project secret"
|
|
url: "https://app.photon.codes/"
|
|
password: true
|
|
optional_env:
|
|
- name: PHOTON_SIDECAR_PORT
|
|
description: "Loopback port for the Node sidecar control + inbound channel (default 8789)"
|
|
prompt: "Sidecar control port"
|
|
password: false
|
|
- name: PHOTON_SIDECAR_TOKEN
|
|
description: "Shared secret for the loopback sidecar channel (default: random per start)"
|
|
prompt: "Sidecar token"
|
|
password: true
|
|
- name: PHOTON_SIDECAR_AUTOSTART
|
|
description: "Spawn the Node sidecar on connect (true/false, default true)"
|
|
prompt: "Auto-start the sidecar?"
|
|
password: false
|
|
- name: PHOTON_NODE_BIN
|
|
description: "Path to the node binary (default: PM's pinned node, then PATH)"
|
|
prompt: "Node executable path"
|
|
password: false
|
|
- name: PHOTON_DASHBOARD_HOST
|
|
description: "Photon Dashboard API host (default https://app.photon.codes)"
|
|
prompt: "Dashboard host"
|
|
password: false
|
|
- name: PHOTON_SPECTRUM_HOST
|
|
description: "Photon Spectrum API host (default https://spectrum.photon.codes)"
|
|
prompt: "Spectrum API host"
|
|
password: false
|
|
- name: PHOTON_ALLOWED_USERS
|
|
description: "Comma-separated E.164 phone numbers allowed to talk to the bot"
|
|
prompt: "Allowed users (comma-separated)"
|
|
password: false
|
|
- name: PHOTON_ALLOW_ALL_USERS
|
|
description: "Allow any sender to trigger the bot (dev only — disables allowlist)"
|
|
prompt: "Allow all users? (true/false)"
|
|
password: false
|
|
- name: PHOTON_READ_RECEIPTS
|
|
description: "Mark inbound iMessages read after forwarding to Hermes (true/false, default true)"
|
|
prompt: "Send read receipts? (true/false)"
|
|
password: false
|
|
- name: PHOTON_REQUIRE_MENTION
|
|
description: "Ignore group-chat messages unless they match a mention wake word (true/false, default false)"
|
|
prompt: "Require a mention in group chats?"
|
|
password: false
|
|
- name: PHOTON_MENTION_PATTERNS
|
|
description: "Mention wake-word regexes for group chats (JSON list or comma/newline-separated; defaults to Hermes wake words)"
|
|
prompt: "Group mention patterns"
|
|
password: false
|
|
- name: PHOTON_HOME_CHANNEL
|
|
description: "Default Photon target for cron / notification delivery: Spectrum space id, DM GUID, or bare E.164 phone number"
|
|
prompt: "Home Photon target"
|
|
password: false
|
|
- name: PHOTON_HOME_CHANNEL_NAME
|
|
description: "Human label for the home channel"
|
|
prompt: "Home channel display name"
|
|
password: false
|
|
- name: PHOTON_TELEMETRY
|
|
description: "Enable Spectrum SDK telemetry in the sidecar (true/false, default false; toggle with `hermes photon telemetry on|off`)"
|
|
prompt: "Enable Spectrum telemetry? (true/false)"
|
|
password: false
|
|
- name: PHOTON_MARKDOWN
|
|
description: "Send agent replies as markdown — iMessage renders it natively, other Spectrum platforms degrade to plain text (true/false, default true)"
|
|
prompt: "Render replies as markdown? (true/false)"
|
|
password: false
|
|
- name: PHOTON_REACTIONS
|
|
description: "Tapback 👀/👍/👎 on messages as processing status and route tapbacks on bot messages to the agent (true/false, default false)"
|
|
prompt: "Enable reaction tapbacks? (true/false)"
|
|
password: false
|