Files
hermes-agent/hermes_cli/web_models.py
shannonsands a6ee31f55a feat(wisdom): add Hermes Collective Wisdom Agent V1 (#94266)
* feat(wisdom): add trusted publish and install foundation

* feat(wisdom): add private contribution loop

* feat(wisdom): add managed consumption workflows

* fix(wisdom): close cross-repository safety gaps

* fix(wisdom): align local package and lifecycle policy

* fix(wisdom): require explicit profile setup

* docs(wisdom): repin reconciled gateway head

* fix(wisdom): fence content downloads and approval receipts

* docs(wisdom): record generation-fenced downloads

* docs(wisdom): record unified delivery PR

* fix(ci): stop passing invalid classifier inputs

* docs(wisdom): remove internal requirements ledger

* feat(wisdom): localize dashboard and desktop copy

* feat(wisdom): complete local contribution and consumption UX

* style(wisdom): satisfy desktop lint

* chore(wisdom): refresh requirements pin

* test(dashboard): allow formatted profile copy

* test(wisdom): stabilize desktop interaction coverage

* fix(wisdom): surface dashboard action failures

* fix(wisdom): add repeatable Portal demo login

* feat(wisdom): add actionable skill notifications

* feat(wisdom): add notification install and update actions

* fix(wisdom): make Telegram skill alerts actionable

* fix(wisdom): always refresh demo Agent login

* feat(wisdom): embed Telegram notification actions

* fix(wisdom): preserve Telegram notifications after actions

* fix(wisdom): keep Telegram notification cards readable

* feat(wisdom): add Telegram candidate approval flow

* feat(wisdom): explain Telegram qualification reasons

* fix(wisdom): reconcile cross-surface candidate actions

* feat(telegram): add Collective Wisdom management command

* chore(wisdom): refresh Gateway contract pin

* chore(wisdom): advance Gateway contract pin

* feat(wisdom): align command UX across clients

* feat(slack): add Collective Wisdom management parity

* feat(wisdom): add security and professionalism reviews

* feat(wisdom): add first-time qualification guidance

* feat(wisdom): simplify qualification sharing choices

* feat(skills): add optional editorial metadata

* feat(wisdom): enrich legacy skill presentation

* fix(wisdom): harden review and update boundaries

* fix(wisdom): emit canonical review timestamps

* fix(wisdom): align with merged gateway and main

* wisdom: add agent-led sharing core (policy, evidence, schemas, templates, delivery, weekly job, share/install flows)

- hermes_wisdom/agent_led/: policy resolution (server > local > defaults),
  7-day evidence builder that excludes bundled/hub/managed skills and
  dismissed/handled/recently-suggested content hashes, strict pydantic
  schemas for agent output with repair-or-reject, fixed copy templates
  (Share / Teammate / Published / Update / Mute), idempotent retried
  delivery ledger with stale-action resolution, weekly review job,
  resumable Share and Install flows.
- prompts/: candidate review, recipient recommendation, share packaging.
- tests/wisdom/test_agent_led.py: 30 tests.

* wisdom: agent-led renderers and button action dispatcher

- render.py: Telegram HTML, Slack blocks, Desktop payload; editorial name
  is the emphasized line, product label stays separate.
- actions.py: resolve opaque wa:<action>:<dedup> targets via the delivery
  ledger; Not now -> dismissal, Mute -> fixed options, Share -> resumable
  packaging flow, Install/Update -> plan command. Never publishes/installs.

* wisdom: CLI verbs, agent_led config default, conversational catalog skill

- hermes wisdom browse/review-week/act/share/dismiss/mute (all --json).
- wisdom.agent_led config block, default enabled.
- SKILL.md rewritten so natural-language catalog questions map to the CLI
  verbs, share/install flows and fixed notification templates.

* wisdom: wire agent-led weekly review into gateway tick and Telegram buttons

- gateway housekeeping tick calls maybe_run_weekly_review with a home
  channel sender when a Telegram adapter is available.
- Telegram: wa: callbacks resolved through the ledger (stale-safe), mute
  duration keyboard, send_wisdom_agent_recommendation rich card + fallback.

* fix(wisdom): integrate local mediation and harden model and setup boundaries

* fix(wisdom): honor authoritative recommendation policy and defer on failure

* fix(wisdom): synchronize opaque suppression and recheck delivery preferences

* feat(wisdom): route weekly selection through the session-owned assessment queue

* fix(wisdom): prepare and submit the reviewed generated share package

* feat(wisdom): separate native Share preparation from publication consent

* feat(wisdom): sync native mute choices through a leased preference outbox

* feat(wisdom): bind native mute controls to durable preference choices

* feat(wisdom): add scoped desktop and dashboard notification settings

* fix(wisdom): revalidate feed recommendations before assessment and delivery

* fix(wisdom): persist validated delivery receipts before completing notices

* feat(wisdom): add private notification claim and receipt client

* Persist Wisdom send reservations and recover delivery acknowledgements

* Route legacy Wisdom controls through current native review

* Add typed private Wisdom operation outcome client

* fix(wisdom): make agent-led advice usable in the local demo

* fix(wisdom): keep requested consent outside proactive limits

* fix(wisdom): distinguish unavailable assessments and preserve digest text

* fix(wisdom): assess ongoing usefulness beyond the current task

* fix(wisdom): restore immediate qualification sharing controls

* fix(wisdom): separate qualification review from installation advice

* fix(wisdom): collapse review checklists and simplify sharing copy

* fix(wisdom): show compact sharing progress and publication receipts

* fix(wisdom): require credential prefixes rather than matching skill names

* fix(wisdom): finish package checks before presenting sharing consent

* fix(wisdom): scan local skills before qualification cards

* fix(wisdom): update moderation results on existing sharing cards

* fix(wisdom): keep sharing review accessible from receipt cards

* fix(wisdom): align mediated review cards and collapsible checks

* fix(wisdom): clarify clean security summary wording

* fix(wisdom): normalize consent plans and add explicit recheck

* fix(wisdom): keep install and update receipts concise

* fix(wisdom): collapse assessments and deduplicate operation cards

* fix(wisdom): restore private Portal review from native cards

* fix(wisdom): sync Portal publication to original consent card

* fix(wisdom): show local skill version on sharing cards

* fix(wisdom): skip agent recommendations for self-published versions

* fix(wisdom): simplify candidate notices and local-edit recovery copy

* feat(wisdom): submit locally reviewed packages with one confirmation

* feat(wisdom): expose safe receipt and outcome sync recovery

* wisdom: onboarding notice says detect and share, names the user's own skill

Copy review from the product owner on the first and returning
qualification notices (fixed delivery mode):
- the feature blurb now says the org enabled detection *and sharing*
- both notices say the detected skill is one the user created
- both close with an exclamation mark

Applied identically to hermes_wisdom.notice, the desktop and web i18n
strings, and the tests that assert the sentences.

* wisdom: one opener, no approval line, ask to share after the skill is shown

Product owner review of the candidate card.

- The Hermes written card now opens with the same sentence as the fixed card
  ("Your organisation has enabled Collective Wisdom, a feature designed to
  automatically detect and share useful skills across all team members.")
  instead of its own blurb, so there is one first time message.
- "Nothing is shared without your approval." removed from Telegram, Slack
  and Desktop. The buttons already make the permission explicit.
- "Would you like to share?" no longer appears before the skill is named.
  It is now the last line, after the skill name, description, why suggested
  and the checks, and reads "Would you like to share it?" (matching the
  agent led template wording).

Tests updated for the new order; proposalNotice removed from all desktop locales.

* wisdom: American spelling, organization

Product owner decision: user facing copy uses American spelling.
Changes "Your organisation" to "Your organization" in the chat notice,
the Hermes written card opener, the desktop and web strings, and the
tests that assert them. Identifiers such as nas_organisation:* and the
German and French locales are untouched.

* wisdom: candidate card copy round 4 (owner review)

Apply the product owner's round 4 copy decisions to the Hermes Collective
Wisdom candidate card on Telegram, Slack, Desktop and the shared views:

1. Hermes-written cards are titled "Hermes Collective Wisdom" instead of
   the bare "Collective Wisdom".
2. The "Reusable skill ready to review" line is gone from the candidate
   card (Telegram rich card and plain fallback, legacy agent-led share
   template).
3. The skill name and description are labelled: "Skill name: <name>" and
   "What it does: <description>" (Telegram, Slack, Desktop).
4. "Why suggested:" is now "Why others might benefit:".
5. A passing professionalism review reads "Safe to share at work ✓ (no
   inappropriate content found)" with no per-check bullets and no "Pass";
   a failed review reads "Needs a look before sharing at work (possible
   inappropriate content)" and lists only the checks that flagged
   something. Pending/unavailable wording is unchanged.
6. Telegram button toasts: "Will ask later...", "Preparing more
   details...", "Sharing...".
7. Qualification reasons: "You used this skill consistently across many
   days." and "You've really refined this skill."
8. prompts/wisdom_candidate_review.md asks for a compelling
   editorial_name, a simple one_line_description and a compelling
   why_coworkers_benefit under 300 characters; "Be concise and
   convincing." becomes "Be concise and compelling: the goal is that the
   user wants to share it."

Tests updated for the new strings; review_text() gains direct coverage.

* wisdom: re-apply owner copy after rebase

- Native share cards (advice_view/interaction_view): drop the approval line, ask "Would you like to share it?" as the last line after the checks
- Hermes-written completion card titled "Hermes Collective Wisdom"
- Qualification reasons use the owner wording (consistently across many days / really refined)
- American spelling (organization) in remaining English copy
- Desktop test asserts the current Share button; web test matches the returning notice

* fix(wisdom): pin reconciled Gateway and verify Unicode hash vectors

Pin Gateway 60cd2d6b613ae3cd4a6e65155d1142006d907e78 and byte-identical producer artifacts. Verify every content-order case and package-manifest binding. Validation: 186 focused Python tests, Ruff and contract verifier.

* fix(wisdom): reconcile optional SDK tests and frontend lint

* fix(wisdom): default to agent-written notification summaries

* fix(wisdom): restore deferred install review and browse controls

* feat(wisdom): inspect installed setup with exact package provenance

* feat(wisdom): run native-approved installed setup steps with durable evidence

* fix(wisdom): recover interrupted setup with explicit native consent

* feat(wisdom): hand native installs into guided setup review

* fix(wisdom): continue requested setup with fixed notification copy

* fix(wisdom): preserve setup while waiting for a session model

* fix(wisdom): expose canonical setup review controls on desktop

* fix(wisdom): resume setup after recorded automatic updates

* fix(wisdom): make missing setup prerequisites recheckable

* chore(wisdom): align Agent with verified Gateway contract

* fix(wisdom): stop guessing team slugs in portal links

* fix(wisdom): retire pending advice on account sign-out

* fix(wisdom): cancel advice after terminal account revocation

* fix(wisdom): fence feed responses across account sign-out

* fix(wisdom): checkpoint signed-out feed before reactivation

* fix(wisdom): link proactive advice to scoped notification settings

* fix(wisdom): coalesce queued publication recommendations by version

* fix(wisdom): keep package review navigation local and deferable

* fix(wisdom): reflect installed state in discovery controls

* fix(wisdom): show exact checks before command confirmation

* chore(wisdom): pin bounded analytics privacy contract

* chore(wisdom): pin retired legacy notification contract

* feat(wisdom): review publisher usage with exact sharing copy

* fix(wisdom): align discovery and review check summaries

* fix(wisdom): show expired consent before confirmation

* fix(wisdom): require fresh review for legacy install controls

* fix(wisdom): preserve review expiry across check toggles

* fix(wisdom): retain update policy in native install reviews

* fix(wisdom): surface failed native card edits

* fix(wisdom): persist local command approval reviews

* fix(wisdom): use saved approvals for messaging commands

* test(wisdom): provide scan result in setup handoff fixture

* test(wisdom): exercise Telegram approvals with saved review state

* fix(wisdom): retain suppression policy for offline deferral

* fix(wisdom): reconsider candidates after deferred suppression expires

* fix(wisdom): bind review checks and report verified readiness separately

* fix(wisdom): persist accepted publication intent and recover exact outcomes

* fix(sync): pin UTF-8 tree ordering across writers

* chore(wisdom): pin organisation-scoped Gateway authorization

* fix(wisdom): restrict consent delivery to user-facing sessions

* chore(wisdom): refresh reviewed Gateway contract pin

* fix(wisdom): preserve kept tools in Blank Slate exclusions

* test(auth): reset anonymous fixture with a profile-scoped cache

* fix(wisdom): gate local surfaces and work on current profile entitlement

* fix(wisdom): invalidate quiet tool cache on entitlement changes

* test(wisdom): authorize local consent gateway fixtures

* fix(wisdom): keep entitlement decoding free of native crypto imports

* test(wisdom): provide local entitlement to demo CLI subprocess

* ci: leave upstream workflow unchanged in Wisdom PR

* fix(wisdom): ship package and contracts in Nix wheels

---------

Co-authored-by: hbizi <36184542+hbizi@users.noreply.github.com>
2026-09-11 19:04:06 +10:00

647 lines
19 KiB
Python

"""Pydantic request/response models for the Hermes dashboard web server."""
from __future__ import annotations
import math
from typing import Any, Dict, List, Literal, Optional
from pydantic import BaseModel, Field, SecretStr, StrictBool, field_validator
class ConfigUpdate(BaseModel):
config: dict
profile: Optional[str] = None
class EnvVarUpdate(BaseModel):
key: str
value: str
profile: Optional[str] = None
# Bearer for the OPENAI_BASE_URL connectivity probe (auth-gated /v1/models otherwise looks
# "reachable but empty"); ignored by plain PUT /api/env.
api_key: str = ""
class EnvVarDelete(BaseModel):
key: str
profile: Optional[str] = None
class EnvVarReveal(EnvVarDelete):
pass
class MemoryProviderConfigUpdate(BaseModel):
values: Dict[str, Any] = {}
class MemoryProviderSetupRequest(BaseModel):
values: Dict[str, Any] = {}
class CustomEndpointUpdate(BaseModel):
id: str = ""
name: str
base_url: str
model: str
api_key: Optional[str] = None
context_length: Optional[int] = None
discover_models: bool = True
make_default: bool = False
models: Optional[List[str]] = None
class MessagingPlatformUpdate(BaseModel):
enabled: Optional[bool] = None
env: Dict[str, str] = {}
clear_env: List[str] = []
# Explicit body profile beats the switcher's query param (same as other scoped writes).
profile: Optional[str] = None
class TelegramOnboardingStart(BaseModel):
bot_name: Optional[str] = None
class TelegramOnboardingApply(BaseModel):
allowed_user_ids: List[str]
profile: Optional[str] = None
class WhatsAppOnboardingStart(BaseModel):
mode: Optional[str] = "bot"
allowed_users: Optional[str] = ""
profile: Optional[str] = None
class WhatsAppOnboardingApply(BaseModel):
mode: Optional[str] = None
allowed_users: Optional[str] = None
profile: Optional[str] = None
class AudioTranscriptionRequest(BaseModel):
data_url: str
mime_type: Optional[str] = None
class ManagedFileUpload(BaseModel):
path: str
data_url: str
overwrite: bool = True
class ChatImageUpload(BaseModel):
data_url: str
filename: Optional[str] = None
class ManagedDirectoryCreate(BaseModel):
path: str
class ManagedFileDelete(BaseModel):
path: str
recursive: bool = False
class ModelAssignment(BaseModel):
"""POST /api/model/set — assign a provider/model to a slot.
scope="main" → model.provider + model.default; scope="auxiliary" → auxiliary.<task>.*
(task="" = every auxiliary slot, task="__reset__" = reset every slot to provider="auto").
"""
scope: str
provider: str
model: str
task: str = ""
# Custom/local endpoint URL + key, honored on main AND auxiliary slots: the runtime resolvers
# read model.base_url / auxiliary.<task>.base_url (+ .api_key) and ignore OPENAI_BASE_URL.
base_url: str = ""
api_key: str = ""
confirm_expensive_model: bool = False
profile: Optional[str] = None
class MoaModelSlot(BaseModel):
provider: str = ""
model: str = ""
# Declared so a GET round-trip doesn't strip and wipe it.
reasoning_effort: Optional[str] = None
enabled: bool = True
class _MoaReferenceControls(BaseModel):
# None = no per-preset override; inherits auxiliary.moa_reference.timeout (900s default).
reference_timeout: Optional[float] = None
degraded_reference_policy: Literal["loud", "silent"] = "loud"
@field_validator("reference_timeout", mode="before")
@classmethod
def _validate_reference_timeout(cls, value: Any) -> Optional[float]:
"""Reject JSON booleans/non-finite values before float coercion."""
if value is None or value == "":
return None
try:
timeout = float(value) if not isinstance(value, bool) else math.nan
except (TypeError, ValueError) as exc:
raise ValueError("reference_timeout must be a finite positive number") from exc
if not math.isfinite(timeout) or timeout <= 0:
raise ValueError("reference_timeout must be a finite positive number")
return timeout
class MoaPresetPayload(_MoaReferenceControls):
reference_models: list[MoaModelSlot] = []
aggregator: MoaModelSlot = MoaModelSlot()
# None = temperature omitted from API calls (provider default), as for single-model agents.
reference_temperature: Optional[float] = None
aggregator_temperature: Optional[float] = None
# Newer per-preset knobs (moa_config._normalize_preset): optional for older clients,
# declared so GET round-trips don't erase them.
fanout: Optional[str] = None
enabled: bool = True
class MoaConfigPayload(_MoaReferenceControls):
default_preset: str = "default"
active_preset: str = ""
presets: dict[str, MoaPresetPayload] = {}
# Backward-compatible flat payload fields for older dashboard/desktop clients.
reference_models: list[MoaModelSlot] = []
aggregator: MoaModelSlot = MoaModelSlot()
reference_temperature: Optional[float] = None
aggregator_temperature: Optional[float] = None
fanout: Optional[str] = None
enabled: bool = True
profile: Optional[str] = None
class FsWriteText(BaseModel):
path: str
content: str
class GitPathBody(BaseModel):
path: str
class GitFileBody(BaseModel):
path: str
file: Optional[str] = None
class GitPrListBody(BaseModel):
path: str
branches: List[str] = []
# PRs a session recovered from its transcript — known by number, not branch.
numbers: List[int] = []
class SessionPrScanBody(BaseModel):
ids: List[str] = []
class GitCommitBody(BaseModel):
path: str
message: str
push: bool = False
class GitWorktreeAddBody(BaseModel):
path: str
name: Optional[str] = None
branch: Optional[str] = None
base: Optional[str] = None
existingBranch: Optional[str] = None
class GitWorktreeRemoveBody(BaseModel):
path: str
worktreePath: str
force: bool = False
class GitBranchSwitchBody(BaseModel):
path: str
branch: str
class CuratorPause(BaseModel):
paused: bool
class LearningNodeRef(BaseModel):
id: str
profile: Optional[str] = None
class LearningNodeEdit(BaseModel):
id: str
content: str
profile: Optional[str] = None
class WisdomSuggestRequest(BaseModel):
skill: Optional[str] = None
local_skill_id: Optional[str] = None
description: Optional[str] = None
system_specification: Optional[Dict[str, Any]] = None
send_for_owner_only_server_review: bool = False
profile: Optional[str] = None
class WisdomSetupRequest(BaseModel):
accept_disclosure: bool = False
profile: Optional[str] = None
class WisdomScanRequest(BaseModel):
skill: Optional[str] = None
profile: Optional[str] = None
class WisdomReviewRequest(BaseModel):
draft_id: str
acknowledge: bool = False
profile: Optional[str] = None
expected_hashes: Optional[Dict[str, str]] = None
class WisdomPublicationRequest(BaseModel):
draft_id: str
expected_hashes: Dict[str, str]
publication_mode: Literal["open", "managed", "moderated"]
profile: Optional[str] = None
interaction_id: Optional[str] = None
session_id: Optional[str] = None
class WisdomEditedFile(BaseModel):
path: str = Field(min_length=1, max_length=1024)
content_utf8: str = Field(max_length=256 * 1024)
class WisdomPreparedSaveRequest(BaseModel):
draft_id: str
author_description: str = Field(min_length=1, max_length=4096)
files: List[WisdomEditedFile] = Field(min_length=2, max_length=32)
profile: Optional[str] = None
class WisdomCandidateDismissRequest(BaseModel):
local_skill_id: str
content_hash: str
profile: Optional[str] = None
class WisdomCandidateEventRequest(BaseModel):
event_id: str
profile: Optional[str] = None
class WisdomReviseRequest(BaseModel):
draft_id: str
author_description: str = Field(min_length=1, max_length=4096)
files: List[WisdomEditedFile] = Field(min_length=2, max_length=32)
expected_content_hash: str
expected_author_description_hash: str
expected_package_manifest_hash: str
send_for_owner_only_server_review: bool = False
profile: Optional[str] = None
class WisdomDecisionRequest(BaseModel):
draft_id: str
profile: Optional[str] = None
class WisdomInstallPlanRequest(BaseModel):
reference: str
update_mode: Optional[Literal["MANUAL", "AUTO_WITH_NOTICE", "REQUIRED"]] = None
profile: Optional[str] = None
class WisdomInstallApplyRequest(BaseModel):
receipt: str
accept_partial: bool = False
profile: Optional[str] = None
class WisdomCheckRequest(BaseModel):
apply_automatic: bool = False
profile: Optional[str] = None
class WisdomUpdatePlanRequest(BaseModel):
skill_id: str
profile: Optional[str] = None
class WisdomUpdateApplyRequest(BaseModel):
receipt: str
accept_sensitive: bool = False
accept_partial: bool = False
preserve_modified: bool = False
profile: Optional[str] = None
class WisdomUninstallRequest(BaseModel):
skill_id: str
profile: Optional[str] = None
class WisdomNotificationRequest(BaseModel):
mark_seen: bool = False
profile: Optional[str] = None
class WisdomConsentRequest(BaseModel):
model_config = {"extra": "forbid"}
interaction_id: str = Field(min_length=1, max_length=64)
session_id: str = Field(min_length=1, max_length=256)
action: str = Field(pattern=r"^(inspect(?:\.[0-9]{1,4})?|defer|confirm|recheck|setup\.(status|recover|clear))$")
profile: Optional[str] = None
class WisdomSyncRetryRequest(BaseModel):
model_config = {"extra": "forbid"}
profile: Optional[str] = None
class WisdomMutePrepareRequest(BaseModel):
model_config = {"extra": "forbid"}
profile: Optional[str] = None
class WisdomMuteChooseRequest(WisdomMutePrepareRequest):
control_id: str = Field(pattern=r"^[a-f0-9]{32}$")
duration: Optional[Literal["1_day", "1_week", "30_days", "forever"]]
class DebugShareRequest(BaseModel):
# Redaction scrubs credential-shaped tokens before logs leave the machine; opt-out only.
redact: bool = True
lines: int = 200 # recent log lines in the summary tail (full logs are separate)
class TTSSpeakRequest(BaseModel):
text: str
class TTSLeaseRequest(BaseModel):
"""POST /api/audio/tts-lease: ``lease`` names the toggle/surface holding the lease
(``desktop:read-aloud``, ``desktop:conversation``); ``active`` True acquires + warms, False releases."""
lease: str
active: bool = True
class OAuthSubmitBody(BaseModel):
session_id: str
code: str
class BulkDeleteSessions(BaseModel):
ids: List[str]
profile: Optional[str] = None
class SessionImport(BaseModel):
sessions: List[Dict[str, Any]]
profile: Optional[str] = None
class SessionRename(BaseModel):
title: Optional[str] = None
archived: Optional[bool] = None
hidden: Optional[bool] = None # also used by cross-profile reconciliation
pinned: Optional[bool] = None # durable "keep" (Desktop pins); exempt from auto_archive
# Read-state watermark (sessions.last_read_at): True = unread, False = read now, None = leave.
unread: Optional[bool] = None
profile: Optional[str] = None # session owned by another profile (opens its state.db)
class SessionOwnerBackfill(BaseModel):
"""POST /api/sessions/owner-backfill (legacy migration). ``profile`` scopes WHICH state.db is
stamped; the stamped value is always that store's own serving-profile identity — the caller
cannot inject an arbitrary owner."""
profile: Optional[str] = None
class SessionPrune(BaseModel):
older_than_days: Optional[float] = 90
source: Optional[str] = None
profile: Optional[str] = None
# Extended filters (all optional, ANDed — mirrors the CLI flags); *_before/after = epoch s
started_before: Optional[float] = None
started_after: Optional[float] = None
title_like: Optional[str] = None
end_reason: Optional[str] = None
cwd_prefix: Optional[str] = None
min_messages: Optional[int] = None
max_messages: Optional[int] = None
model_like: Optional[str] = None
provider: Optional[str] = None
user_id: Optional[str] = None
chat_id: Optional[str] = None
chat_type: Optional[str] = None
branch_like: Optional[str] = None
min_tokens: Optional[int] = None
max_tokens: Optional[int] = None
min_cost: Optional[float] = None
max_cost: Optional[float] = None
min_tool_calls: Optional[int] = None
max_tool_calls: Optional[int] = None
include_archived: bool = False
dry_run: bool = False
class CronJobCreate(BaseModel):
paused: StrictBool = False
paused_reason: Optional[str] = None
prompt: str = ""
schedule: str
name: str = ""
deliver: str = "local"
skills: Optional[List[str]] = None
model: Optional[str] = None
provider: Optional[str] = None
base_url: Optional[str] = None
script: Optional[str] = None
context_from: Optional[Any] = None
enabled_toolsets: Optional[List[str]] = None
workdir: Optional[str] = None
no_agent: bool = False
class CronJobUpdate(BaseModel):
updates: dict
class AutomationBlueprintInstantiate(BaseModel):
blueprint: str # blueprint key, e.g. "morning-brief"
values: Dict[str, Any] = {} # filled slot values from the form
class MCPServerCreate(BaseModel):
name: str
url: Optional[str] = None
command: Optional[str] = None
args: List[str] = []
env: Dict[str, str] = {} # KEY=VALUE for stdio servers (API keys, etc.)
auth: Optional[str] = None # "none" | "oauth" | "header" | None
# One-time provisioning input; persisted only to the profile's .env.
bearer_token: Optional[SecretStr] = None
profile: Optional[str] = None
class MCPServersReplace(BaseModel):
# Whole-map replace (name → raw config) for the GUI mcp.json editor.
servers: Dict[str, Dict[str, Any]] = {}
profile: Optional[str] = None
class MCPEnabledToggle(BaseModel):
enabled: bool
profile: Optional[str] = None
class MCPCatalogInstall(BaseModel):
name: str
env: Dict[str, str] = {} # KEY=VALUE for entries declaring required env vars
enable: bool = True
profile: Optional[str] = None
class PairingApprove(BaseModel):
platform: str
code: str = ""
request_id: str = ""
profile: Optional[str] = None
class PairingRevoke(BaseModel):
platform: str
user_id: str
profile: Optional[str] = None
class WebhookCreate(BaseModel):
name: str
description: Optional[str] = None
events: List[str] = []
prompt: Optional[str] = None
script: Optional[str] = None
skills: List[str] = []
deliver: str = "log"
deliver_only: bool = False
deliver_chat_id: Optional[str] = None
secret: Optional[str] = None # omit to auto-generate
class WebhookEnabledToggle(BaseModel):
enabled: bool
class CredentialPoolAdd(BaseModel):
provider: str
api_key: str # OAuth pooling stays CLI-only (needs an interactive browser flow)
label: Optional[str] = None
class MemoryProviderSelect(BaseModel):
provider: str # "" or "built-in" disables the external provider
class MemoryReset(BaseModel):
target: str = "all" # "all" | "memory" | "user"
class BackupRequest(BaseModel):
output: Optional[str] = None # defaults to a timestamped zip in the home dir
class ImportRequest(BaseModel):
archive: str
# --force: the spawned `hermes import` has stdin=DEVNULL, so its "Continue? [y/N]" prompt would
# hit EOF and abort; the dashboard confirms in its own modal.
force: bool = False
class HookCreate(BaseModel):
event: str
command: str
matcher: Optional[str] = None
timeout: Optional[int] = None
# Also write the consent allowlist entry; without it the hook won't fire until approved.
approve: bool = True
class HookDelete(BaseModel):
event: str
command: str
class SkillInstallRequest(BaseModel):
identifier: str
profile: Optional[str] = None
class SkillUninstallRequest(BaseModel):
name: str
profile: Optional[str] = None
class SkillsUpdateRequest(BaseModel):
profile: Optional[str] = None
class ProfileCreate(BaseModel):
name: str
clone_from: Optional[str] = None
clone_from_default: bool = False # legacy clients; new ones send clone_from explicitly
clone_all: bool = False
no_skills: bool = False
description: Optional[str] = None
provider: Optional[str] = None
model: Optional[str] = None
# Profile-builder additions, applied best-effort AFTER the profile dir exists (a hiccup never 500s).
mcp_servers: List["MCPServerCreate"] = []
keep_skills: List[str] = [] # skills to KEEP: non-empty = replace semantics (unlisted seeded ones disabled)
# Installed async via `hermes -p <name> skills install` (skills_hub.SKILLS_DIR is import-time-bound,
# so HERMES_HOME can't redirect it); PIDs go back for the UI to poll.
hub_skills: List[str] = []
class ProfileRename(BaseModel):
new_name: str
class ProfileExport(BaseModel):
extra_files: Dict[str, str] = {} # extra root-level files, filename → text
output: str = "" # archive path; empty → a staging path under HERMES_HOME
class ProfileImport(BaseModel):
archive: str # profile .tar.gz on the backend's filesystem
name: Optional[str] = None # overrides the name inferred from the archive root
class ProfileSoulUpdate(BaseModel):
content: str
class ProfileActiveUpdate(BaseModel):
name: str
class ProfileDescriptionUpdate(BaseModel):
description: str = ""
class ProfileModelUpdate(BaseModel):
provider: str
model: str
class ProfileDescribeAuto(BaseModel):
overwrite: bool = False
class SkillToggle(BaseModel):
name: str
enabled: bool
profile: Optional[str] = None
class SkillCreate(BaseModel):
name: str
content: str
category: Optional[str] = None
profile: Optional[str] = None
class SkillContentUpdate(BaseModel):
name: str
content: str
profile: Optional[str] = None
class ToolsetToggle(BaseModel):
enabled: bool
profile: Optional[str] = None
class ToolsetProviderSelect(BaseModel):
provider: str
# Web-only scope 'search' | 'extract'; omitted → whole-provider (legacy web.backend path).
capability: Optional[str] = None
profile: Optional[str] = None
class ToolsetModelSelect(BaseModel):
model: str
provider: Optional[str] = None
profile: Optional[str] = None
class ToolsetEnvUpdate(BaseModel):
env: Dict[str, str]
profile: Optional[str] = None
class ToolsetPostSetup(BaseModel):
key: str
profile: Optional[str] = None
class TerminalBackendSelect(BaseModel):
backend: str
profile: Optional[str] = None
class RawConfigUpdate(BaseModel):
yaml_text: str
profile: Optional[str] = None
class ThemeSetBody(BaseModel):
name: str
class FontSetBody(BaseModel):
font: str
class _AgentPluginInstallBody(BaseModel):
identifier: str
force: bool = False
enable: bool = True
# Install by curated-catalog name (resolves repo + pinned SHA server-side).
catalog_name: Optional[str] = None
# Pin a custom source to one full 40-hex commit SHA (same contract as ``--ref``).
ref: Optional[str] = None
class _PluginProvidersPutBody(BaseModel):
memory_provider: Optional[str] = None
context_engine: Optional[str] = None
class _PluginVisibilityBody(BaseModel):
hidden: bool