Files
hermes-agent/plugins/platforms/teams/plugin.yaml
kshitijk4poor ee942a7bbf fix(terminal-env): adapter secrets are the declared ones, not any platform-named variable
The shape rule (a platform prefix plus _TOKEN/_SECRET/_PASSWORD/_KEY) also
matched variables Hermes never reads: the platform list holds plain words
(LOCAL, GATEWAY, WEBHOOK, SLACK), so a user's SLACK_USER_TOKEN,
LOCAL_LLM_API_KEY or GATEWAY_API_KEY vanished from the terminal and
terminal.env_passthrough could not bring them back. The prefix census it
leaned on also failed open (an unreadable plugins dir cached an empty set).

Adapter secrets now come from what adapters declare: password entries of
the messaging OPTIONAL_ENV_VARS (built-ins plus every platform plugin
manifest) and secret-named keys of the gateway env-override table, both
Tier 1 and refused by passthrough; plus the secret-named required_env of
adapters registered in the current profile scope, read per spawn without
loading deferred adapters, Tier 2 only because required_env is an
unchecked setup list. Secrets nothing declared get a manifest entry
(TELEGRAM_WEBHOOK_SECRET, PHOTON_SIDECAR_TOKEN, A2A_PUSH_SECRET,
TEAMS_GRAPH_ACCESS_TOKEN, TEAMS_INCOMING_WEBHOOK_URL) or join the
policy's read-in-code list (QQ_STT_API_KEY, the two MSGRAPH names).
2026-09-29 02:06:58 +05:30

65 lines
2.6 KiB
YAML

name: teams-platform
label: Microsoft Teams
kind: platform
version: 1.0.0
description: >
Microsoft Teams gateway adapter for Hermes Agent.
Connects to Microsoft Teams via the Bot Framework and relays messages
between Teams chats (personal DMs, group chats, channel posts) and
the Hermes agent. Supports Adaptive Card approval prompts.
author: Aamir Jawaid
# ``requires_env`` entries are surfaced in ``hermes config`` UI via the
# platform-plugin env var injector in ``hermes_cli/config.py``.
requires_env:
- name: TEAMS_CLIENT_ID
description: "Azure AD application (Bot Framework) client ID"
prompt: "Teams / Azure AD client ID"
url: "https://portal.azure.com/"
password: false
- name: TEAMS_CLIENT_SECRET
description: "Azure AD application client secret"
prompt: "Teams / Azure AD client secret"
url: "https://portal.azure.com/"
password: true
- name: TEAMS_TENANT_ID
description: "Azure AD tenant ID hosting the bot application"
prompt: "Teams / Azure AD tenant ID"
password: false
optional_env:
- name: TEAMS_PORT
description: "Webhook listen port (Bot Framework default: 3978)"
prompt: "Webhook port"
password: false
- name: TEAMS_HOST
description: "Webhook bind host (default: unset → dual-stack, all interfaces IPv4+IPv6)"
prompt: "Webhook host"
password: false
- name: TEAMS_ALLOWED_USERS
description: "Comma-separated Teams user IDs / UPNs allowed to talk to the bot"
prompt: "Allowed users (comma-separated)"
password: false
- name: TEAMS_ALLOW_ALL_USERS
description: "Allow any Teams user to trigger the bot (dev only)"
prompt: "Allow all users? (true/false)"
password: false
- name: TEAMS_REQUIRE_MENTION
description: "Only answer channel/group-chat messages that @mention the bot or reply to it (default false; needed once the app has RSC message-read consent)"
prompt: "Require @mention in channels and group chats? (true/false)"
password: false
- name: TEAMS_HOME_CHANNEL
description: "Default chat/channel ID for cron / notification delivery"
prompt: "Home channel (or empty)"
password: false
- name: TEAMS_HOME_CHANNEL_NAME
description: "Display name for the Teams home channel"
prompt: "Home channel display name"
password: false
- name: TEAMS_INCOMING_WEBHOOK_URL
description: "Incoming-webhook URL for meeting-summary delivery in webhook mode (the URL is the credential)"
prompt: "Incoming webhook URL (or empty)"
password: true
- name: TEAMS_GRAPH_ACCESS_TOKEN
description: "Microsoft Graph access token for meeting-summary delivery in graph mode"
prompt: "Graph access token (or empty)"
password: true