Files
hermes-agent/tools
teknium1 c265f776a8 fix(auth): a removed env:XAI_API_KEY no longer overrides xai-oauth for x_search
`hermes auth remove xai` records `env:XAI_API_KEY` in `suppressed_sources`
and tells the user "Hermes will ignore XAI_API_KEY until you run
`hermes auth add xai`". That promise only guarded credential-pool
re-seeding; `tools.tool_backend_helpers.resolve_provider_secret` (the
resolver behind `resolve_xai_http_credentials(prefer_api_key=True)`, TTS
and STT) still read the variable straight from the process environment,
so a dead key inherited by a long-running gateway across `hermes update`
restarts silently won over the working OAuth grant.

Skip the env/.env tier in `resolve_provider_secret` while `env:<VAR>` is
suppressed for that provider; explicit config, the profile secret scope's
multiplex fail-closed rule and the credential pool are unchanged, and the
check is scoped to the provider being resolved.

Co-authored-by: apoapostolov <apoapostolov@users.noreply.github.com>
Co-authored-by: joaomarcos <joaomarcosdias444@gmail.com>
2026-09-20 10:17:04 -07:00
..