* fix(auth): close the free tier's gaps against the gateway's welcome-tier contract The inference gateway's welcome tier (NousResearch/api DOCS/anon-tier/plan.md) serves an anonymous account exactly one model on its own host, refuses everything else with a structured 429, cross-refuses a request on the wrong host with a 400 (403 while the tier is dark), and tells a signed-in account that still asks for `nous/welcome` what to switch to in an `x-nous-model-switch` header. Four client-side gaps against that contract: - Auxiliary calls were refused on every session. The auxiliary client asked the welcome host for the Portal's recommended compaction/vision model, a guaranteed 429 `model_not_free` before each fallback. On the welcome host it now uses `nous/welcome` (its backing model covers auxiliary work) and skips Nous for vision, which the welcome model does not take. - The structured 429 body was never read. The classifier now parses `reason` / `retry_after` / `alternates` / `upgrade_url`: `model_not_free` and `feature_not_free` are non-retryable gates that fall back; `at_capacity`, `admission_closed` and `rate_limited` are rate limits that honour `retry_after` and never rotate the free tier's only credential. The wrong-host 400 and the dark-tier 403 are deterministic, so they abort this route and fall back instead of retrying or re-exchanging. The terminal paths say what happened and name the sign-in (`/login` in a chat, `hermes auth upgrade` in a terminal). - The `x-nous-model-switch` header was ignored. The chat-completions transport records it beside the rate-limit and credits headers; the next call moves the session, and the config default when it still names `nous/welcome`, to the backing model the gateway named. - A guest fell back to the paid host. With `inference_base_url` absent from the exchange or outside the host allowlist, routing defaulted to inference-api, where every request is a 400. A guest now defaults to the welcome literal at the exchange, in the shared store's shape, and in effective routing. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> (cherry picked from commit fc758aad7efceff6223fc144a9b5c69f13e41bd8) * feat(auth): the free tier is set up on request; nous.guest_setup decides whether also on first use A caller that names nous/welcome on a Nous route with no Nous identity in reach — the guided setup's session (provider=nous, which skips the resolver's nothing-configured rung), the free-tier picker row, a bare --provider nous pointed at it — is asking for the free tier. The OAuth runtime rung now sets it up there instead of failing "not logged in", so the guided chat no longer races the root profile's first-run mint. nous.guest_setup is the policy seam: "auto" (default) keeps today's first-use setup wherever nothing else is configured; "on-request" mints only when the free tier is asked for by name (nous/welcome, /login, hermes auth upgrade, replacing a retired identity). Implicit callers — the resolver's last rung, the first-run check, free_tier.status, the CLI's background setup, the connector token path — still adopt what the shared store holds, so every profile follows the one identity the guided setup created, but never create one on their own. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> (cherry picked from commit ae915ddc65ecdb81b81e29b604671d15cd49233c) (cherry picked from commit 62ad1ff3ab200ea064975a32c502041b25910165) * feat(auth): the guided setup provisions the free tier explicitly; nous.guest_setup is auto | explicit Two questions govern the free tier: may it exist (nous.guest) and who may CREATE the identity (nous.guest_setup). "auto" (default) keeps today's first-use setup wherever nothing else is configured. "explicit" means Hermes never creates one on its own: the only creator is the new provision_free_tier() primitive, exposed as the free_tier.provision RPC, which the guided setup on Hermes Desktop calls as its first step — on the root gateway, before the setup profile and before the guided chat exists — so the identity lands in the root store every profile reads through and is there before any session asks for nous/welcome. That closes the race against the backend's own setup, and makes "only when the setup-bot flow is used" literally true. The earlier "on-request" tier is replaced: it minted whenever any caller named nous/welcome (the hermes model row, --provider nous), which treated a model name as intent and was broader than the guided setup. Under "explicit" a nous/welcome request with no identity fails "not logged in" as before the free tier existed, and /login or hermes auth upgrade report nothing to sign in from. Implicit callers still adopt an identity the shared store holds, and a retired credential is replaced (a continuation, not a creation). Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> (cherry picked from commit c63d2c935c1e59016164fdfb90cf70b4094466a0) * fix(auth): remove the nous.guest_setup knob; the free tier is created on first use `nous.guest_setup: auto | explicit` decided who may CREATE the free-tier identity. Under its default every line it added was inert (`may_mint` always true), nothing in tree set `explicit`, unknown values read as `auto`, and under `explicit` a CLI-only install could never get an identity, which contradicts the first-run contract (first command mints, then chats). The mint race the knob accompanied is already benign: every caller takes the profile lock then the shared-store lock, and the loser adopts what the winner wrote. What makes the guided setup win deterministically is `provision_free_tier()` behind the `free_tier.provision` RPC, which stays. `nous.guest` remains the only free-tier policy. Removed: `guest_setup_policy()` and its constants, the `explicit=` / `may_mint=` threading through `ensure_portal_identity` and `_reconcile_and_provision`, the flag at the three replacement call sites (now no-ops), the config default, the docs section, and the four `guest_setup` test-config entries. The three policy tests that hold regardless of the knob are kept under `TestExplicitProvision`; the two that only tested the knob are deleted. (cherry picked from commit d8a50526d93c374c0067dd935b5a65055e0af261) * fix(gateway): a server-driven model switch off nous/welcome does not evict the cached agent When a signed-in account still asks the paid host for `nous/welcome`, the inference gateway serves the current backing model and names it in `x-nous-model-switch`. `apply_model_switch` moves the live session to that model and moves `config.yaml`'s default off the alias in the same step. The messaging gateway's fallback-eviction check compares the agent's model with the config default and evicts on any mismatch that is not a /model override, so when the config write did not land (unreadable config, lock) the cached agent was evicted once per turn, and prompt caching with it. `apply_model_switch` now stamps the alias it moved the session off on the agent, and `_is_intentional_model_switch` treats "agent moved off the alias the config still carries" as deliberate, beside the existing /model override case. The check takes the agent and the config model instead of a bare model string; its one caller in `_run_agent_evict_on_fallback` passes them. (cherry picked from commit 696d1ec86b69db28bf002c841e9389b85178a954) * fix(auth): the free tier outranks implicit host credentials in provider resolution On a fresh install with a leftover ~/.aws profile, resolve_provider("auto") reached the Bedrock rung before the free-tier rung, so the first turn ran on Bedrock and failed 403 while the free tier was still being minted in the background at agent setup (NS-829). Live on a Mac with ~/.aws present: 28 s, three retries, no answer; the next process then switched to nous/welcome. The free-tier rung now sits directly above the Bedrock chain: when nous.guest is on, an existing free-tier identity answers, else a blocking mint runs, and only then does the boto chain get a say. Everything above is unchanged and still wins: CLI creds, config.yaml model.provider, env keys, the OpenRouter pool, a logged-in active_provider. nous.guest: false skips the rung, and a failed mint still falls through to Bedrock and the no-provider guidance. Tests: six precedence cases (identity present, fresh mint, free tier off, env key still wins, sign-in still wins, failed mint falls through). The opt-out test now neutralizes the AWS chain like the precedence tests do; on a machine with ~/.aws it was failing for the same reason as the bug. Live after the fix, same Mac, AWS credentials visible, isolated shared store: identity minted 2 s in, turn on model=nous/welcome provider=nous, answer in 11 s. (cherry picked from commit a04b05260cd334dd7199ad9b6cd5b2538364c75a) * fix(auth): review follow-ups for the free-tier rung (NS-829) - tests/agent/test_bedrock_integration.py: the Bedrock auto-detect test switches the free tier off; its contract is the boto chain, and the free tier now sits above it. - gateway/run_notifications.py: the free-tier startup line reads auth.json before consulting the resolver, so a gateway boot on a machine with AWS credentials never mints or refreshes over the network. - hermes_cli/anon_auth.py: module docstring says where the free tier sits in the ladder instead of "the ladder is untouched". - tests/hermes_cli/test_provider_precedence.py: two invariant tests instead of six (parametrized ladder cases; a failed mint that returns None or raises falls through to Bedrock). scripts/run_tests.sh on the five affected files: 147 passed, 0 failed. (cherry picked from commit 10790d148c60ada11b9ecdde2cd2c836c6a82a11) * feat(auth): HERMES_GUEST_ONBOARDING=1 is the one launch gate for the free tier; HERMES_FORCE_GUEST is gone The free tier is pre-GA. Until GA it must not exist for anyone who did not ask for it: no identity minted, no portal traffic, no free-tier copy on any surface. One environment variable now decides that, and one function reads it. `guest_enabled()` returns False unless `HERMES_GUEST_ONBOARDING` is exactly "1"; only then does `nous.guest` (the user's off switch) get consulted. Every free-tier site already funnels through `guest_enabled()`, so the gate closes minting, routing, connector entitlement, status lines and the picker row in one place. With the variable unset, `resolve_provider("auto")` on a fresh install raises `no_provider_configured` exactly as upstream does. `HERMES_FORCE_GUEST` and `force_guest_mode()` are removed. They inverted the gate (forced the tier ON over `nous.guest: false`), their "new" value re-minted identities as a side effect of provider resolution, and `_has_any_provider_ configured` read them ahead of every other check, making the CLI a second reader of a flag that must have exactly one. `_forced_new_done` and the `force` parameter of `_reconcile_and_provision` go with them. Supersedes the dev lever introduced in fcf9d11679 (rung 1) and hardened in b5c162c3ec. Ruling: NS-845 Q1.1 (recorded on NS-847). Not a user preference: the variable is never written to config.yaml or .env and never shown in setup. It is deleted at GA together with its comment in anon_auth.py. This is a deliberate, temporary exception to the "no new HERMES_* env vars for non-secret config" rule. Tests: fixtures set the gate instead of deleting the old lever; one new invariant (`test_launch_gate_off_means_no_free_tier_at_all`) proves that "", "0", "true" and "new" all leave the tier off with zero portal calls, red on the previous commit. The `HERMES_FORCE_GUEST=new` re-mint test is deleted with the feature. * feat(auth): the free-tier identity is created in one place, at boot; every other site is a read Before this commit eight sites could create a Nous free-tier identity as a side effect of something else: resolving a provider, the CLI's first-run check, the CLI's session setup (in the background beside an own key), a connector bearer read, the desktop polling `free_tier.status`, the sign-in precondition, the desktop's `free_tier.provision`, and the dead-credential re-mint. A poll could mint. Provider resolution could hit the network. Two of them raced each other on a fresh install. Now `hermes_cli/free_tier_bootstrap.py::run_bootstrap` is the only creator. `hermes serve` runs it on a daemon thread from `_lifespan` beside the other background boots; `cmd_chat` runs it synchronously before the first-run guard. It inventories credentials first (`resolve_provider("auto", skip_free_tier=True)`: what would carry inference if the free tier did not exist), creates the identity only when `guest_enabled()`, resolves inference, records a `SetupRecord` in process memory and broadcasts ONE `setup.ready` event. It runs on every boot; only the mint is gated. `ensure_portal_identity` now requires `explicit=True` and raises otherwise. Its callers are the bootstrap, the desktop's `free_tier.provision` (the explicit retry when the boot could not create the identity) and the two dead-credential replacements (`auth_nous.resolve_nous_runtime_credentials`, `managed_tool_gateway._replace_dead_guest_token`). The background thread path and `provision_free_tier` are deleted with their last callers. Reads that used to mint and now only read: `auth.py::resolve_provider` rung 7 (an existing identity still outranks the Bedrock chain, NS-829 ordering kept), `main.py::_has_any_provider_configured`, `cli_agent_setup_mixin._ensure_runtime_credentials`, `managed_tool_gateway.read_nous_access_token` (no identity -> None), `anon_sign_in.run_sign_in` (no identity -> Unavailable), `methods_free_tier` `free_tier.status`. `setup.status` answers from the record for the launch profile, blocking up to 8 s while the bootstrap is in flight so a client's first poll lands after the identity exists rather than racing it; a named profile, or a process that never ran the bootstrap, keeps today's live probe. The record's fields ride along additively (`ready`, `free_tier`, `other_providers`, `inference_provider`). Identity and inference are decoupled (NS-845 Q1.3): the mint sets `active_provider="nous"` only when the inventory found nothing else usable (`_mint_locked(carries_inference=)`); an adopted account always does. A token refresh no longer re-elects the provider it refreshed (`_save_provider_state_to_source` writes credentials, not the user's choice) — that write was how an own-key install ended up on the free tier after the first connector call. Supersedes the mint sites in fcf9d11679, a42d0748fc (first-run check), bbbaa8935a (CLI background setup), 0179efc989 (`free_tier.status` mint), 62ad1ff3ab / c63d2c935c / d8a50526d9 (the `nous.guest_setup` knob and `provision_free_tier`), and a04b05260c (blocking mint in the resolver). Ruling: NS-845 Q1.2 + Q1.3, recorded on NS-847. Tests: `TestBootstrapIsTheOneCreator` (one mint per process; own key keeps inference; reads never reach the portal; a refused mint is memoised), `free_tier.status` fails loudly if it ever calls the creator, the resolver stub fails loudly if resolution ever mints, `setup.status` reads the record, `skip_free_tier` proves the inventory question. The three sign-in tests for the deleted pre-mint collapse into one (`no identity -> Unavailable, zero portal calls`). Live: real `_lifespan` boot with a fake portal, gate on and off (/tmp/ns847-recon/evidence/e2e-rung5-c2-serve-boot.txt), and the CLI matrix incl. an own-key cell (e2e-rung5-c2-bootstrap.txt), 20/20. * fix(credits): the welcome host is free-tier evidence, so a free-tier identity never sees "run /topup" A free-tier identity carries $0 by design, so the portal seed reports `paid_access=False` for it. `is_free_tier_model` did not know the welcome host, read that as a depleted account, and every free-tier turn ended with the credits-depleted notice telling the user to top up an account they do not have. Rule (4) in `is_free_tier_model`: a `base_url` on the Nous welcome host (`anon_auth.route_is_welcome_host`) is the free tier. The host is the evidence, not the model name: the paid inference host can serve `nous/welcome` to a named account and that account's depletion is real, so `("nous/welcome", <inference host>)` stays False. Local data only, like the three rules above it. Restores the two contracts dropped by hermes-magic 674e11d1eaa (the prototype line ran without unit tests): the welcome host is free without any pricing evidence; the model name alone is not. The first is red without this fix. * fix(copy): free-tier text stops promising a connector transfer and never names the config key Sign-in copy on every surface said "Sign in to keep your connectors" and ended with "Your connectors are kept." The transfer registry that would make that true is empty (NS-821): nothing carries over today. The copy now says what signing in does give ("unlock more models and tools") and the completion line names the account, not a transfer. The docs page loses the "connectors carry over" paragraph for the same reason. The picker's off-state line exposed `nous.guest: false` and the word "guest"; user copy names the free tier only (R-USR-1). The docs page gains the pre-rollout note: until GA nothing on it happens without `HERMES_GUEST_ONBOARDING=1`. Its "first command mints" and "replaced on next use" sentences now describe the boot bootstrap. zh is a strict locale: the `freeTier` block was English placeholder text copied from `en`; it is now Chinese. `connectorsKept` is renamed `completedBody` since it no longer talks about connectors. * feat(desktop): the free-tier launch flag is decided once in Electron and stamped onto every backend spawn The Python backend reads `HERMES_GUEST_ONBOARDING` and treats exactly "1" as on. Until now nothing in the desktop set it, so a packaged app could never turn the free tier on, and a backend spawned by the app could disagree with the app about whether the tier was live. `electron/guest-onboarding.ts` owns the decision: `guestOnboardingEnabled` is true when the launch env has `HERMES_GUEST_ONBOARDING=1` or argv has `--guest-onboarding` (the packaged-app spelling). It is read ONCE at launch into a module constant. `desktopBackendSpawnEnv` wraps every backend env as the outermost call and writes the flag LAST, as "1" or an explicit "0", so no earlier spread (`process.env`, `backend.env`) can resurrect a stray value from the parent shell. Stamped onto all three spawn sites: the primary `serve` spawn, the pooled per-profile spawn, and the remote SSH `exec env ...` command (which gains ` HERMES_GUEST_ONBOARDING=1` only when on). The embedded terminal PTY and the backend probes are not backend spawns and do not get it: a `hermes --tui` typed in the pane must not mint. The renderer learns the same fact read-only through the existing `hermes:launch-flags` sync IPC (`guestOnboarding`) and preload (`window.hermesDesktop.guestOnboardingEnabled`). Ruling: NS-845 Q1.1 / Q2 (env var is the contract, `--guest-onboarding` maps to it in main). Two invariant tests on the pure helpers: only "1" or the argv flag enables; the spawn env carries "1"/"0" as the last word and preserves every other key. * feat(desktop): the renderer learns free-tier readiness from one `setup.ready` push, not a 60 s poll The backend's boot bootstrap now announces `setup.ready` once, after it has created (or refused) the free-tier identity and resolved the inference route. The renderer used to discover both by polling `setup.status`, `setup.runtime_check` and `free_tier.status` every 60 s from `useStatusSnapshot`; a fresh install's chip, notice strip and onboarding overlay could sit stale for up to a minute after boot, and three RPCs a minute per window kept asking a question whose answer changes only at boundaries the backend already announces. `handleLifecycleEvent` routes `setup.ready` (active source only, like `skin.changed`) to `notifySetupReady()`, a one-shot tick atom in `live-sync.ts` beside the other change ticks. `useStatusSnapshot` listens to it and runs one readiness round at once (`setup.status` + `setup.runtime_check` + `free_tier.status`). The readiness legs also run once on open and on return from another app, as today. The 60 s tick keeps only `getStatus()`. `SetupStatusSnapshot` types the record's additive fields (`ready`, `free_tier`, `other_providers`, `inference_provider`); readiness semantics are unchanged and still key on `provider_configured` + `runtime_check`. Ruling: NS-845 Q1.2 (renderer half). Tests: the lifecycle branch fires one refresh from the active source and none from another; the snapshot hook's contract is three legs on open, one leg on the tick. * fix(cli): the banner names the free tier's model instead of "no model configured" The welcome banner prints before credentials resolve, so on a fresh install `model` is empty and the banner said, in red, "no model configured — run /model or hermes setup". Under the free tier that is false: the route is already known from local state (identity on disk, tier on), and the first message will run on `nous/welcome`. `_banner_left_lines` now asks the route the same question when `model` is empty (`guest_carries_inference()`, a local read) and shows `welcome · Nous Research`. When nothing resolves the red line stays. Ruling: NS-845 ("the banner's 'no model configured' line reads the resolved route"). Live: fresh HERMES_HOME + fake portal, gate on -> `welcome · Nous Research`; gate off -> the red line, zero portal calls. * fix(aux): vision on the free tier uses nous/welcome too The text-only modality on the gateway's `nous/welcome` row is DeepSeek V4 Flash's, the backing model until the repoint; `z-ai/glm-5.3-flash` is natively multimodal and the repoint declares the welcome row `text+image->text`. Skipping Nous for vision on the welcome host would have sent every image step past the free tier for no reason, so the auxiliary client pins the route's one model for every lane. A backing model that takes no images answers with the upstream's own error, which the ladder handles as it always has. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> (cherry picked from commit 7456e028faba55480db43015dc2c8df3e393a415) * fix(gateway): hermes gateway run is a boot owner of the free tier too Rung 5 made every demand-time free-tier site a read: resolve_provider, the connector token, the /login precondition. That is only correct if every process that can reach those sites ran the bootstrap first. The CLI (cmd_chat) and hermes serve (_lifespan) did; the standalone messaging gateway did not. A fresh HERMES_HOME with the gate on and `hermes gateway run` reached provider resolution with no identity to consume, and /login returned Unavailable. Reported by @andrexibiza on #107697 (P1). GatewayRunner.start now runs `free_tier_bootstrap.run_bootstrap` on an executor thread right after startup recovery and BEFORE any adapter connects, so a fast first DM cannot arrive with nothing to resolve. It is its own step, not part of the turn-machinery warm-up: the warm-up is an optimisation with an off switch (HERMES_STARTUP_WARMUP_TIMEOUT<=0); the bootstrap is correctness and must always run. With the gate unset it is a local inventory and no network. Live, real GatewayRunner.start against a fake portal in a fresh home: gate on -> 1 create, identity persisted, resolve_runtime_provider=nous, /login precondition sees the identity gate off -> 0 portal calls, no identity, no_provider_configured Before the fix the gate-on row was identical to the gate-off row. Test: the bootstrap seam runs before _start_prefilter_platforms and delegates to the one creator. Red on 5554eb6993 (no seam), green here. --------- Co-authored-by: Robin Fernandes <robin@soal.org> Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
43 KiB
sidebar_position, title, description
| sidebar_position | title | description |
|---|---|---|
| 2 | Slash Commands Reference | Complete reference for interactive CLI and messaging slash commands |
Slash Commands Reference
Hermes has two slash-command surfaces, both driven by a central COMMAND_REGISTRY in hermes_cli/commands.py:
- Interactive CLI slash commands — dispatched by
cli.py, with autocomplete from the registry - Messaging slash commands — dispatched by
gateway/run.py, with help text and platform menus generated from the registry
Installed skills are also exposed as dynamic slash commands on both surfaces. (/plan used to be one of these; it is now a built-in command — see the Session table below.)
Permissions and admin/user split
Every messaging platform that supports a per-user allowlist (Telegram, Discord, Slack, Matrix, Mattermost, Signal, …) also supports a two-tier slash command split: admins get every registered command, regular users only get the names you list in user_allowed_commands (plus the always-allowed floor /help and /whoami). Configure allow_admin_from and user_allowed_commands (and the per-group equivalents group_allow_admin_from / group_user_allowed_commands) inside the platform's extra: block in ~/.hermes/config.yaml.
See the per-platform docs for examples — the structure is identical across platforms:
If allow_admin_from is unset for a scope, that scope stays in unrestricted backward-compat mode — every allowed user can run every command.
Interactive CLI slash commands
Type / in the CLI to open the autocomplete menu. Built-in commands are case-insensitive.
Session
| Command | Description |
|---|---|
/new [name] (alias: /reset) |
Start a new session (fresh session ID + history). Optional [name] sets the initial session title — e.g. /new my-experiment opens a fresh session already titled my-experiment so it's easy to find later with /resume or /sessions. Append now, --yes, or -y to skip the confirmation modal — e.g. /reset now, /new --yes my-experiment. |
/clear |
Clear screen and start a new session |
/history |
Show conversation history (respects /timestamps) |
/save |
Save the current conversation |
/prompt (alias: /compose) |
Compose your next prompt in $EDITOR (markdown) instead of the inline input — useful for long, multi-line, or carefully-formatted prompts. |
/retry |
Retry the last message (resend to agent) |
/undo |
Remove the last user/assistant exchange |
/title |
Set a title for the current session (usage: /title My Session Name) |
/compress [here [N] | focus topic] |
Manually compress conversation context (flush memories + summarize). /compress here [N] summarizes everything except the most recent N exchanges (default 2), kept verbatim — pick your own compression boundary. A focus topic narrows what a full summary preserves. |
/rollback |
List or restore filesystem checkpoints (usage: /rollback [number]) |
/diff [staged|all|session] [--stat] [path...] |
Show git changes in the working directory. Default: unstaged changes plus untracked files. staged shows what's staged for commit, all everything since HEAD, and session the cumulative diff of everything Hermes changed here (from the earliest retained checkpoint baseline — requires checkpoints to be enabled; complements /rollback diff <N>). --stat prints just the changed-file summary; path arguments restrict the diff. |
/snapshot [create|restore <id>|prune] (alias: /snap) |
Create or restore state snapshots of Hermes config/state. create [label] saves a snapshot, restore <id> reverts to it, prune [N] removes old snapshots, or list all with no args. Database restores write through SQLite's backup API so live processes (gateway, dashboard) see the restored data safely; if that path fails while another process still holds the database open, the restore refuses instead of risking corruption — stop the holder and retry. |
/stop |
Kill all running background processes |
/queue <prompt> (alias: /q) |
Queue a prompt for the next turn (doesn't interrupt the current agent response). |
/steer <prompt> |
Inject a mid-run note that arrives at the agent after the next tool call — no interrupt, no new user turn. The text is appended to the last tool result's content once the current tool completes, giving the agent new context without breaking the current tool-calling loop. Use this to nudge direction mid-task (e.g. "focus on the auth module" while the agent is running tests). |
/goal <text> |
Set a standing goal Hermes works toward across turns — our take on the Ralph loop. After each turn an auxiliary judge model decides whether the goal is done; if not, Hermes auto-continues. Subcommands: /goal status, /goal pause, /goal resume, /goal clear. Budget defaults to 20 turns (goals.max_turns); any real user message preempts the continuation loop, and state survives /resume. See Persistent Goals for the full walkthrough. |
/subgoal <text> |
Append a user-supplied criterion to the active goal mid-loop. The continuation prompt surfaces all subgoals to the agent verbatim, and the judge factors them into its DONE/CONTINUE verdict — so the goal isn't marked done until the original goal and every subgoal are met. Subcommands: /subgoal (list), /subgoal remove <N>, /subgoal clear. Requires an active /goal. |
/heartbeat every <interval> <prompt> (alias: /hb) |
Set a recurring prompt that re-enters this session as a normal user turn whenever it's idle and the interval has elapsed (min 60s; missed ticks coalesce). Subcommands: /heartbeat status, /heartbeat pause, /heartbeat resume, /heartbeat clear. Session-scoped and in-process — use hermes cron for durable isolated schedules. See Session Heartbeats. |
/refine [focus] |
Run the background memory/skill self-improvement review now instead of waiting for the automatic post-turn trigger. Optional focus text steers the review (e.g. /refine save the deploy workflow as a skill). Runs in a background fork against a conversation snapshot — the live session and prompt cache are untouched; results are reported when done. |
/review [instructions] |
Spawn an independent, full-privilege reviewer subagent to review the work just discussed — a PR, code, docs, any artifact referenced in the last 10 chat messages. It investigates in the background (opens the PR, reads the diff, runs code) and its full review re-enters this session as a background-subagent completion the primary agent can act on. Pin a dedicated review model via auxiliary.review in config.yaml (defaults to your main model). See Subagent Delegation. |
/moa <prompt> |
Run a single prompt through the default Mixture of Agents preset, then restore your current model. One-shot — does not change your session model. |
/resume [name] |
Resume a previously-named session |
/sessions (TUI alias: /switch) |
Classic CLI: browse and resume previous sessions in an interactive picker. TUI: open the live session switcher for currently open TUI sessions. Use /sessions new in the TUI to start another live session immediately. |
/egress [status] |
Show Docker egress proxy status — enabled/configured/running state, credential source, token mappings, uncovered providers, and next remediation step. Works in CLI, TUI, Desktop chat, and messaging gateway. |
/redraw |
Force a full UI repaint (recovers from terminal drift after tmux resize, mouse selection artifacts, etc.) |
/status |
Show session info — model, provider, profile, session ID, working directory, title, created/updated timestamps, token totals, agent-running state — followed by a local Session recap block (recent user/assistant turn counts, tool result count, top tools used, last few files touched, the latest user prompt, and the latest assistant reply). The recap is computed locally from the in-memory conversation; no LLM call, no prompt-cache impact. |
/context [all] (alias: /ctx) |
Visual context-window breakdown. On the CLI/TUI: a 5×20 glyph block grid (each cell ≈ 1% of the model window) plus an estimated per-category table — system prompt, tool definitions, rules, skills index, MCP, subagents, memory, conversation — versus free space. On messaging platforms: a usage gauge with auto-compression threshold/headroom, compression stats, cumulative throughput, and the same category table in plain text. /context all appends per-skill and per-toolset cost listings (index cost vs SKILL.md load cost; schema tokens per toolset). Read-only and computed locally — no LLM call, no prompt-cache impact. |
/agents (alias: /tasks) |
Show active agents and running tasks across the current session. |
/bg <prompt> |
Run a prompt in a separate background session. The agent processes your prompt independently — your current session stays free for other work. Results appear as a panel when the task finishes. See CLI Background Sessions. |
/btw <question> |
Ask a quick side question about the current conversation without interrupting it. A one-shot auxiliary LLM call answers from a read-only snapshot of the transcript — the live session's history and prompt cache are untouched, and the current turn keeps running. For independent work with a fresh context, use /bg. |
/branch [name] (alias: /fork) |
Branch the current session (explore a different path) |
/worktree [new [name]|list] |
CLI only. Inspect or create isolated git worktrees mid-session (inspired by Copilot CLI's /worktree new). Bare /worktree shows the active worktree; /worktree list lists the repo's worktrees; /worktree new [name] creates a worktree under .worktrees/ (branched from the freshly-fetched remote tip, honoring worktree_sync) and retargets the session's terminal and file tools into it. Named trees use your name (hermes/<name> branch); unnamed ones get a random hermes-<id>. On exit the tree is kept only if it has unpushed commits — same lifecycle as hermes -w. See Git Worktrees. |
/handoff <platform> |
CLI only. Hand the current session off to a messaging platform (Telegram, Discord, Slack, WhatsApp, Signal, Matrix). The gateway picks it up immediately, creates a fresh thread on platforms that support threads (Telegram topics, Discord text-channel threads, Slack message-anchored threads), re-binds the destination to your CLI session_id so the full role-aware transcript replays, and forges a synthetic user turn so the agent confirms it's working in the new place. Your CLI exits cleanly on success with a /resume hint; resume locally any time with /resume <title>. Refused mid-turn. Requires the gateway to be running and a home channel configured for the target platform (/sethome from the destination chat). See Cross-Platform Handoff. |
/journey [list|delete <id>|edit <id>] (aliases: /learning, /memory-graph) |
Open the learning journey timeline of learned skills + memories. Works in the classic CLI, as a TUI overlay, and in the desktop app (Star Map panel). Not available on messaging platforms. See Learning Journey. |
Configuration
| Command | Description |
|---|---|
/config |
Show current configuration |
/model [model-name] |
Show or change the current model. Supports: /model claude-sonnet-4, /model provider:model (switch providers), /model custom:model (custom endpoint), /model custom:name:model (named custom provider), /model custom (auto-detect from endpoint), and user-defined aliases (/model fav, /model grok — see Custom model aliases). Flags: --global persists the change to config.yaml; --session forces session-only; --once applies to the next turn only; --refresh re-fetches the provider's model list; --provider <name> switches backend (session-only unless --global). A plain /model <name> is session-only unless model.persist_switch_by_default: true is set — except when no model.default/model.provider is configured yet, in which case the first pick persists so the profile gets a real default. The same rule governs the desktop composer picker. Interactive picker: running /model with no arguments opens the provider→model picker; on the model list you can type to fuzzy-filter the models (e.g. type grok to narrow to matching models), Backspace to trim the filter, Esc to clear it (or close the picker). Selection always resolves to one concrete model — the filter only narrows the list, it never guesses. Note: /model can only switch between already-configured providers. To add a new provider, exit the session and run hermes model from your terminal. Cost note: switching models mid-conversation resets the prompt cache — the cache key includes the model, so your next turn re-reads the entire conversation at full input price instead of the ~75%-discounted cached rate. Expected and unavoidable, but worth knowing on long sessions. |
/codex-runtime [auto|codex_app_server|on|off] |
Toggle the optional Codex app-server runtime for OpenAI/Codex models. auto (default) uses Hermes' standard chat completions; codex_app_server hands turns to a codex app-server subprocess for native shell, apply_patch, ChatGPT subscription auth, and migrated Codex plugins. Effective on next session. |
/personality |
Set a predefined personality. /personality none (or default / neutral) clears the overlay and returns to base behavior. |
/verbose |
Cycle tool progress display: off → new → all → verbose. Can be enabled for messaging via config. |
/focus [on|off|status] |
Toggle focus view — a display-only reduced-output mode showing just your prompt and the final response. Composes with /verbose: turning it on snaps tool progress to off and remembers your previous mode, and /focus off restores it. Each turn ends with a dim recovery line (⋯ 7 tool lines hidden · /focus off to show) and a persistent ◉ focus badge sits in the status bar so you always know you're in the reduced view. Nothing is sent differently to the model — detail is hidden, never discarded. |
/fast [normal|fast|auto|cold|status] |
Fast mode — OpenAI Priority Processing / Anthropic Fast Mode. fast = every request; auto = only requests in the first agent.fast_auto_seconds (default 60s) of each turn; cold = that same window on the first turn of a session only. Default normal (off). See Fast mode. |
/reasoning [level|show|hide|full|clamp] [--global] |
Manage reasoning effort and display. Levels include none / minimal / low / medium / high / xhigh / max / ultra. show / hide (or on / off) toggle reasoning display; full and clamp adjust how reasoning is shown. --global persists effort to config. |
/skin |
Show or change the display skin/theme |
/export [profile] [-o out.tar.gz] |
CLI only. Pack a profile into a shareable .tar.gz — skills, memory, persona, crons, plugins, settings, and (from the desktop) themes and layout. Credentials (auth.json, .env) are stripped. Defaults to the active profile and <name>.tar.gz in the current directory. Same archive as hermes profile export; for a versioned, updatable share use a profile distribution instead. |
/import <archive.tar.gz> [--name <name>] |
CLI only. Install a profile archive as a new profile, inferring the name from the archive unless --name is given. Refuses to overwrite an existing profile and cannot import as default. Creates a shell wrapper when the name is free. See Export and import a profile file. |
/statusbar (alias: /sb) |
Toggle the context/model status bar on or off |
/battery [on|off|status] |
Toggle a color-coded battery read-out as the first status-bar element (off by default; no-op without a battery). |
/voice [on|off|tts|status] |
Toggle CLI voice mode and spoken playback. Recording uses voice.record_key (default: Ctrl+B). |
/yolo |
Toggle YOLO mode — skip all dangerous command approval prompts. |
/approvals [manual|smart|off] |
Show or set the persistent dangerous-command approval mode. |
/footer [on|off|status] |
Toggle the gateway runtime-metadata footer on final replies (shows model, context %, and cwd). |
/busy [queue|steer|interrupt|status] |
Control what happens when you message while Hermes is working — queue the new message, steer mid-turn, or interrupt immediately. Works in the CLI and messaging gateway. |
/indicator [kaomoji|emoji|unicode|ascii] |
CLI-only: pick the TUI busy-indicator style. |
/timestamps [on|off|status] |
CLI-only: toggle [HH:MM] timestamps on messages and in /history. |
/wake [on|off|status] |
CLI-only: toggle the "Hey Hermes" wake word listener. |
Tools & Skills
| Command | Description |
|---|---|
/tools [list|disable|enable] [name...] |
Manage tools: list available tools, or disable/enable specific tools for the current session. Disabling a tool removes it from the agent's toolset and triggers a session reset. |
/toolsets |
List available toolsets |
/browser [connect|disconnect|status] |
Manage a local Chromium-family CDP connection. connect attaches browser tools to a running Chrome, Brave, Chromium, or Edge instance (default: http://127.0.0.1:9222). disconnect detaches. status shows current connection. Auto-launches a supported Chromium-family browser if no debugger is detected. |
/skills |
Search, install, inspect, or manage skills from online registries. Also the review surface for the skill write-approval gate: /skills pending, /skills diff <id>, /skills approve <id>, /skills reject <id>, /skills approval on|off. See Gating agent skill writes. |
/memory [pending|approve|reject|approval] |
Review pending memory writes staged by the write-approval gate (memory.write_approval) and toggle the gate. See Controlling memory writes. |
/bundles |
List configured skill bundles — /<name> slash aliases that preload several skills at once. Configure under bundles: in ~/.hermes/config.yaml. See Skill Bundles. |
/learn <what to learn from> |
Distill a reusable skill from anything you describe — a directory, a URL, the workflow you just walked the agent through, or pasted notes. Open-ended: the agent gathers the sources with its own tools and authors a SKILL.md following the house authoring standards. Works in the CLI, the messaging gateway, the TUI, and the dashboard Skills page. |
/plan [task] |
Write a markdown implementation plan to .hermes/plans/ in the active workspace — planning only, no execution. Empty argument infers the task from the conversation. (Formerly the bundled plan skill; now built-in so it survives the Telegram/Discord command-menu caps.) |
/init [notes] |
Generate or update AGENTS.md project instructions from a repo scan (port of Codex /init). The agent inspects manifests, layout, and toolchain configs with its read-only tools, then writes a concise AGENTS.md — or, if one exists, merge-updates it preserving your content. Optional notes steer the emphasis. Works in the CLI, the messaging gateway, and the TUI. |
/cron |
Manage scheduled tasks (list, add/create, edit, pause, resume, run, remove) |
/suggestions [accept|dismiss N|catalog|clear] (alias: /suggest) |
Review suggested automations. Use /suggestions to list pending suggestions, /suggestions accept <id> to create the proposed automation, /suggestions dismiss <id> to reject one, /suggestions catalog to add curated starter automations, and /suggestions clear to clear resolved suggestion records. Accepted jobs preserve the current surface as the delivery origin. |
/blueprint [name] [slot=value ...] (alias: /bp) |
Set up an automation from a blueprint template. Bare /blueprint lists the catalog; /blueprint <name> starts a guided slot-filling flow on the next agent turn; /blueprint <name> slot=value ... creates the job directly. |
/curator |
Background skill maintenance — status, run, pin, archive. See Curator. |
/kanban <action> |
Drive the multi-profile, multi-project collaboration board without leaving chat. Full hermes kanban surface is available: /kanban list, /kanban show t_abc, /kanban create "title" --assignee X, /kanban comment t_abc "text", /kanban unblock t_abc, /kanban dispatch, etc. Multi-board support included: /kanban boards list, /kanban boards create <slug>, /kanban boards switch <slug>, /kanban --board <slug> <action>. See Kanban slash command. |
/reload-mcp (alias: /reload_mcp) |
Reload MCP servers from config.yaml and re-probe tool availability (credentials/daemons that appeared mid-session) |
/reload-skills (alias: /reload_skills) |
Re-scan ~/.hermes/skills/ for newly installed or removed skills |
/reload |
Reload .env variables into the running session (picks up new API keys without restarting) |
/plugins |
List installed plugins and their status |
/pet [list|<slug>] |
Toggle or adopt a petdex mascot. /pet toggles the pane, /pet list shows installed pets, /pet <slug> adopts a specific one. |
/hatch <description> (alias: /generate-pet) |
Generate a brand-new petdex pet from a text description, using the configured image backend (OpenRouter / Nous Portal). See Pets. |
Info
| Command | Description |
|---|---|
/help |
Show available commands, grouped by category. Core commands are shown by default with skill commands collapsed to a one-line count; /help skills lists all skill commands, and /help <text> filters commands (and matching skills) by substring. |
/palette |
Open the fuzzy command palette (also Ctrl+P) — type to filter all commands + skills, ↑/↓ to move, Enter to insert the selected command into the composer (never auto-runs), Esc to cancel. Matching is ranked by command name first, so a short query stays precise. |
/version |
Show Hermes Agent version, build, and environment info. |
/whoami |
Show your slash command access level (admin / user). |
/usage |
Show token usage, cost breakdown, session duration, and — when available from the active provider — an Account limits section with remaining quota / credits / plan usage pulled live from the provider's API. |
/topup |
Show your Nous balance and manage billing on the portal (replaces the old /credits and /billing commands). |
/subscription (alias: /upgrade) |
CLI only. View your Nous plan and change it in the browser. |
/login |
Sign in with a Nous account. Runs off-turn: the consent link and code arrive in the session, and the sign-in settles when you approve it in the browser. See Nous free tier. |
/insights |
Show usage insights and analytics (last 30 days) |
/update |
Update Hermes Agent to the latest version. |
/platforms (alias: /gateway) |
Show gateway/messaging platform status (CLI-only summary view). |
/paste |
Attach a clipboard image |
/copy [number] |
Copy the last assistant response to clipboard (or the Nth-from-last with a number). CLI-only. |
/image <path> |
Attach a local image file for your next prompt. |
/debug |
Upload debug report (system info + logs) and get shareable links. Also available in messaging. |
/update |
Update Hermes Agent to the latest version. |
/profile |
Show active profile name and home directory |
Exit
| Command | Description |
|---|---|
/quit |
Exit the CLI (also: /exit). |
Dynamic CLI slash commands
| Command | Description |
|---|---|
/<skill-name> |
Load any installed skill as an on-demand command. Example: /gif-search, /github-pr-workflow, /excalidraw. |
/skills ... |
Search, browse, inspect, install, audit, publish, and configure skills from registries and the official optional-skills catalog. |
Quick Commands
User-defined quick commands map a short slash command to either a shell command or another slash command. Configure them in ~/.hermes/config.yaml:
quick_commands:
status:
type: exec
command: systemctl status hermes-agent
deploy:
type: exec
command: scripts/deploy.sh
inbox:
type: alias
target: /gmail unread
Then type /status, /deploy, or /inbox in the CLI or a messaging platform. Quick commands are resolved at dispatch time and may not appear in every built-in autocomplete/help table.
String-only prompt shortcuts are not supported as quick commands. Put longer reusable prompts in a skill, or use type: alias to point at an existing slash command.
Custom model aliases
Define your own short names for models you use often, then reach them with /model <alias> in a running session, hermes chat --model <alias> at startup, or any messaging platform. Aliases work identically in these paths, on session-only (default) and --global switches.
Two config formats are supported:
Full form — pin an exact model, provider, and optionally a base URL. Put this in ~/.hermes/config.yaml:
model_aliases:
fav:
model: claude-sonnet-4.6
provider: anthropic
grok:
model: grok-4
provider: x-ai
ollama-qwen:
model: qwen3-coder:30b
provider: custom
base_url: http://localhost:11434/v1
theta:
model: theta-1
provider: custom
base_url: https://theta.example.com/v1
key_env: THETA_API_KEY # or: api_key: "${THETA_API_KEY}"
An alias with its own base_url can carry that endpoint's credential via
api_key (a literal, or a "${VAR}" reference) or key_env (an environment
variable name); api_key wins if both are set. With neither set, the key is
resolved from the alias host
and never inherited from the provider that was active before the switch.
Short form — provider/model in one string. Set from the shell without editing YAML:
hermes config set model.aliases.fav anthropic/claude-opus-4.6
hermes config set model.aliases.grok x-ai/grok-4
Then in chat:
/model fav # session-only
/model grok --global # also persists current-model change to config.yaml
User aliases take precedence over built-in short names, so naming an alias sonnet, kimi, opus, etc. will shadow the built-in. Alias names are case-insensitive.
Alias Resolution
Commands support prefix matching: typing /h resolves to /help, /mod resolves to /model. When a prefix is ambiguous (matches multiple commands), the first match in registry order wins. Full command names and registered aliases always take priority over prefix matches.
Messaging slash commands
Slack thread commands (
!prefix): Slack itself blocks native slash commands inside message threads ("/queue is not supported in threads. Sorry!") and never delivers them to Hermes. Inside a Slack thread, use the!prefix instead —!stop,!new,!status— and the gateway dispatches it exactly like the slash form.@Hermes !stopand@Hermes /stopwork in threads too. Only the first token is checked against the known command list, so messages like!nice workpass through to the agent unchanged. See Using commands inside threads for details.
The messaging gateway supports the following built-in commands inside Telegram, Discord, Slack, WhatsApp, Signal, Email, Home Assistant, and Teams chats:
| Command | Description |
|---|---|
/start |
Platform-protocol command. Many chat platforms (Telegram, Discord, …) send /start automatically the first time a user opens a bot conversation. Hermes acknowledges the ping silently — no agent reply, no session burn — so first-contact handshakes don't waste a turn. You can also send it explicitly to confirm the gateway is reachable. |
/new [name] (alias: /reset) |
Start a new session (fresh session ID + history). Optional [name] sets the initial session title. Append now, --yes, or -y to skip the confirmation modal — e.g. /reset now, /new --yes my-experiment. |
/status |
Show session info, followed by a local Session recap block (recent turn counts, top tools used, files touched, latest prompt + reply). |
/stop |
Kill all running background processes and interrupt the running agent. |
/model [provider:model] |
Show or change the model. Supports provider switches (/model zai:glm-5), custom endpoints (/model custom:model), named custom providers (/model custom:local:qwen), auto-detect (/model custom), and user-defined aliases (/model fav, /model grok — see Custom model aliases). Use --global to persist the change to config.yaml. Note: /model can only switch between already-configured providers. To add a new provider or set up API keys, use hermes model from your terminal (outside the chat session). Cost note: a mid-session model switch resets the prompt cache (the cache key includes the model), so the next message re-reads the whole conversation at full input price. |
/codex-runtime [auto|codex_app_server|on|off] |
Toggle the optional Codex app-server runtime. Persists to model.openai_runtime in config.yaml and evicts the cached agent so the next message picks up the new runtime. Effective on next session. |
/personality [name] |
Set a personality overlay for the session. /personality none (or default / neutral) clears it. |
/fast [normal|fast|auto|cold|status] |
Fast mode — OpenAI Priority Processing / Anthropic Fast Mode. auto/cold open a bounded fast window per turn / per session. |
/retry |
Retry the last message. |
/undo |
Remove the last exchange. |
/sethome (alias: /set-home) |
Mark the current chat as the platform home channel for deliveries. |
/compress [here [N] | focus topic] |
Manually compress conversation context. /compress here [N] keeps the most recent N exchanges (default 2) verbatim and summarizes the rest. A focus topic narrows what a full summary preserves. |
/topic [off|help|session-id] |
Telegram DM only. Manage user-managed multi-session topic mode. /topic enables it or shows status; /topic off disables it and clears bindings; /topic help shows usage; /topic <session-id> inside a topic restores a previous session. See Multi-session DM mode. |
/title [name] |
Set or show the session title. |
/resume [name] |
Resume a previously named session. |
/sessions [all] [search <query>] |
List previous sessions for this chat; the active session appears with a (current) marker. /sessions search <query> filters by title/id match (most recently active first); /sessions all lists across origins (admin only — non-admins get a notice and the chat-scoped list). |
/usage |
Show token usage, estimated cost breakdown (input/output), context window state, session duration, and — when available from the active provider — an Account limits section with remaining quota / credits pulled live from the provider's API. |
/topup |
Show your Nous balance and manage billing on the portal. |
/login |
Sign in with a Nous account. Paired direct messages only — in a group, channel, or broadcast-shaped platform Hermes refuses. On Slack use /hermes login. See Nous free tier. |
/whoami |
Show your slash command access level (admin / user). |
/insights [days] |
Show usage analytics. |
/reasoning [level|show|hide|full|clamp] [--global] |
Change reasoning effort (levels up to max / ultra) or toggle reasoning display (full / clamp included). --global persists to config. |
/voice [on|off|tts|join|channel|leave|status] |
Control spoken replies in chat. join/channel/leave manage Discord voice-channel mode. |
/rollback [number] |
List or restore filesystem checkpoints. |
/diff [staged|all|session] [--stat] |
Show git changes in the working directory (fenced and truncated to platform message limits). session shows the cumulative diff of everything Hermes changed; --stat shows just the summary. |
/bg <prompt> |
Run a prompt in a separate background session. Results are delivered back to the same chat when the task finishes. See Messaging Background Sessions. |
/btw <question> |
Ask a side question about the current conversation without interrupting it. Answered from a transcript snapshot; the answer is sent to the chat when ready. |
/queue <prompt> (alias: /q) |
Queue a prompt for the next turn without interrupting the current one. |
/steer <prompt> |
Inject a message after the next tool call without interrupting — the model picks it up on its next iteration rather than as a new turn. |
/goal <text> |
Set a standing goal Hermes works toward across turns — our take on the Ralph loop. A judge model checks after each turn; if not done, Hermes auto-continues until it is, you pause/clear it, or the turn budget (default 20) is hit. Subcommands: /goal status, /goal pause, /goal resume, /goal clear. Safe to run mid-agent for status/pause/clear; setting a new goal requires /stop first. See Persistent Goals. |
/subgoal <text> |
Append criteria to the active /goal mid-loop (/subgoal, /subgoal remove <N>, /subgoal clear). |
/heartbeat every <interval> <prompt> (alias: /hb) |
Set a recurring prompt that re-enters this session when idle. Subcommands: status, pause, resume, clear. On Slack use /hermes heartbeat …. |
/refine [focus] |
Run the memory/skill self-improvement review now, optionally with focus instructions. On Slack use /hermes refine …. |
/review [instructions] |
Spawn an independent reviewer subagent for the work just discussed (PR, code, docs); its review re-enters this chat when done. On Slack use /hermes review …. |
/moa <prompt> |
Run one prompt through the default Mixture of Agents preset, then restore the session model. |
/branch [name] (alias: /fork) |
Branch the current session (explore a different path). |
/agents (alias: /tasks) |
Show active agents and running tasks. |
/sessions |
Browse and resume previous sessions. |
/context [all] (alias: /ctx) |
Context-window usage gauge and category breakdown (messaging-friendly text form). /context all adds per-skill / per-toolset cost detail. |
/egress [status] |
Show Docker egress proxy status. |
/init [notes] |
Generate or update AGENTS.md from a repo scan. |
/learn <what to learn from> |
Distill a reusable skill from anything you describe. |
/plan [task] |
Write a markdown implementation plan to .hermes/plans/; no execution. |
/bundles |
List configured skill bundles (/<name> aliases that preload several skills). |
/reload-skills (alias: /reload_skills) |
Re-scan ~/.hermes/skills/ for newly installed or removed skills. |
/footer [on|off|status] |
Toggle the runtime-metadata footer on final replies (shows model, context %, and cwd). |
/curator [status|run|pin|archive] |
Background skill maintenance controls. |
/suggestions [accept|dismiss N|catalog|clear] |
Review suggested automations right in chat. /suggestions lists pending suggestions, catalog adds curated starter automations, and clear prunes resolved suggestion records. Accepted suggestions keep this chat/thread as the job delivery origin. |
/blueprint [name] [slot=value ...] |
Browse cron blueprints, start a guided slot-filling conversation, or create a blueprint job directly. Directly created jobs deliver back to the current chat/thread. |
/memory [pending|approve|reject|approval] |
Review pending memory writes staged by the write-approval gate (memory.write_approval) — approve or reject them right in chat — and toggle the gate with /memory approval on|off. See Controlling memory writes. |
/skills [pending|approve|reject|diff|approval] |
Review pending skill writes staged by the write-approval gate (skills.write_approval). Shows a one-line gist per staged write; /skills diff <id> is truncated for chat — read the full diff on the CLI or in ~/.hermes/pending/skills/<id>.json. Only appears when the gate is on (or staged writes remain); search/install stay CLI-only. |
/kanban <action> |
Drive the multi-profile, multi-project collaboration board from chat — identical argument surface to the CLI. Bypasses the running-agent guard, so /kanban unblock t_abc, /kanban comment t_abc "…", /kanban list --mine, /kanban boards switch <slug>, etc. work mid-turn. /kanban create … auto-subscribes the originating chat to the new task's terminal events. See Kanban slash command. |
/platform <list|pause|resume> [name] |
Operate a running gateway platform right from chat. /platform list shows every adapter and its state (running, paused-by-breaker, manually-paused); /platform pause <name> stops dispatching new messages to that adapter without unloading it; /platform resume <name> re-enables it and clears a tripped circuit breaker once the upstream is healthy. |
/reload-mcp (alias: /reload_mcp) |
Reload MCP servers from config and re-probe tool availability. |
/verbose |
Cycle tool progress display. Off by default on messaging — enable with display.tool_progress_command: true in config.yaml. |
/yolo |
Toggle YOLO mode — skip all dangerous command approval prompts. |
/commands [page] |
Browse all commands and skills (paginated). |
/approve [session|always] |
Approve and execute a pending dangerous command. session approves for this session only; always adds to permanent allowlist. |
/deny |
Reject a pending dangerous command. |
/update |
Update Hermes Agent to the latest version. |
/restart |
Gracefully restart the gateway after draining active runs. When the gateway comes back online, it sends a confirmation to the requester's chat/thread. |
/debug |
Upload debug report (system info + logs) and get shareable links. |
/help |
Show messaging help. |
/<skill-name> |
Invoke any installed skill by name. |
Notes
/skin,/snapshot,/export,/import,/reload,/tools,/toolsets,/browser,/config,/cron,/platforms,/paste,/image,/statusbar,/battery,/focus,/plugins,/indicator,/wake,/journey,/redraw,/clear,/history,/save,/copy,/handoff,/prompt,/pet,/hatch,/timestamps,/subscription, and/quitare CLI-only commands./skillsis CLI-only for search/browse/install; its write-approval review subcommands (pending,approve,reject,diff,approval) also work on messaging platforms whenskills.write_approvalis on./memoryworks on both surfaces./verboseis CLI-only by default, but can be enabled for messaging platforms by settingdisplay.tool_progress_command: trueinconfig.yaml. When enabled, it cycles thedisplay.tool_progressmode and saves to config./focusand/verboseshare one suppression path (display.tool_progress), so they can never contradict each other:/focus onpins tool progress tooffand stashes your mode underdisplay.focus_saved_tool_progress;/focus offrestores it; cycling/verbosewhile focus is on takes the mode back and clears the focus badge. Focus view is display-only — it never changes conversation history, the system prompt, or anything sent to the model, so it has zero prompt-cache impact./sethome,/restart,/approve,/deny,/topic,/platform, and/commandsare messaging-only commands./status,/egress,/version,/whoami,/bg,/btw,/queue,/steer,/voice,/reload-mcp,/reload-skills,/rollback,/diff,/debug,/fast,/approvals,/busy,/footer,/curator,/kanban,/topup,/login,/suggestions,/blueprint,/learn,/init,/sessions, and/yolowork in both the CLI and the messaging gateway./voice join,/voice channel, and/voice leaveare only meaningful on Discord.- In the TUI,
/sessionsshows live sessions in the current TUI process. Use/resume [name]orhermes --tui --resume <id-or-title>for saved or closed transcripts.
Confirmation prompts for destructive commands
The CLI prompts before running slash commands that throw away unsaved session state. The current destructive set is:
| Command | What it destroys |
|---|---|
/clear |
Clears the screen and starts a fresh session — current session ID and in-memory history are gone. |
/new / /reset |
Starts a fresh session (new session ID + empty history). |
/undo |
Removes the last user/assistant exchange from history. |
/exit --delete / /quit --delete |
Exits and permanently deletes the current session's SQLite history and on-disk transcripts. |
For each of these the CLI opens a three-choice modal: Approve Once (proceed this time), Always Approve (proceed and persist approvals.destructive_slash_confirm: false so future destructive commands run without prompting), or Cancel.
Inline skip: append now, --yes, or -y to bypass the modal for a single invocation — e.g. /reset now, /new --yes my-session, /clear -y, /undo -y. Useful when the modal doesn't render correctly on your terminal (see issue #30768 for native Windows PowerShell) or when scripting against the CLI.
Set approvals.destructive_slash_confirm: false in ~/.hermes/config.yaml to disable the prompts globally; set it back to true to re-enable. See Security — Destructive slash command confirmation for context.