The shape rule (a platform prefix plus _TOKEN/_SECRET/_PASSWORD/_KEY) also matched variables Hermes never reads: the platform list holds plain words (LOCAL, GATEWAY, WEBHOOK, SLACK), so a user's SLACK_USER_TOKEN, LOCAL_LLM_API_KEY or GATEWAY_API_KEY vanished from the terminal and terminal.env_passthrough could not bring them back. The prefix census it leaned on also failed open (an unreadable plugins dir cached an empty set). Adapter secrets now come from what adapters declare: password entries of the messaging OPTIONAL_ENV_VARS (built-ins plus every platform plugin manifest) and secret-named keys of the gateway env-override table, both Tier 1 and refused by passthrough; plus the secret-named required_env of adapters registered in the current profile scope, read per spawn without loading deferred adapters, Tier 2 only because required_env is an unchecked setup list. Secrets nothing declared get a manifest entry (TELEGRAM_WEBHOOK_SECRET, PHOTON_SIDECAR_TOKEN, A2A_PUSH_SECRET, TEAMS_GRAPH_ACCESS_TOKEN, TEAMS_INCOMING_WEBHOOK_URL) or join the policy's read-in-code list (QQ_STT_API_KEY, the two MSGRAPH names).
40 lines
1.5 KiB
YAML
40 lines
1.5 KiB
YAML
name: telegram-platform
|
|
label: Telegram
|
|
kind: platform
|
|
version: 1.0.0
|
|
description: >
|
|
Telegram gateway adapter for Hermes Agent.
|
|
Connects to Telegram via python-telegram-bot and relays messages between
|
|
Telegram chats/groups/topics and the Hermes agent. Supports threads/topics,
|
|
streaming edits, native media, inline keyboards, slash commands, fallback
|
|
network transport (direct-IP failover), notification modes, mention gating,
|
|
and per-user/chat allowlists.
|
|
author: NousResearch
|
|
requires_env:
|
|
- name: TELEGRAM_BOT_TOKEN
|
|
description: "Telegram bot token from @BotFather"
|
|
prompt: "Telegram bot token"
|
|
url: "https://t.me/BotFather"
|
|
password: true
|
|
optional_env:
|
|
- name: TELEGRAM_ALLOWED_USERS
|
|
description: "Comma-separated Telegram user IDs allowed to talk to the bot"
|
|
prompt: "Allowed users (comma-separated)"
|
|
password: false
|
|
- name: TELEGRAM_ALLOW_ALL_USERS
|
|
description: "Allow any Telegram user to trigger the bot (dev only)"
|
|
prompt: "Allow all users? (true/false)"
|
|
password: false
|
|
- name: TELEGRAM_HOME_CHANNEL
|
|
description: "Default chat ID for cron / notification delivery"
|
|
prompt: "Home channel ID"
|
|
password: false
|
|
- name: TELEGRAM_HOME_CHANNEL_NAME
|
|
description: "Display name for the Telegram home channel"
|
|
prompt: "Home channel display name"
|
|
password: false
|
|
- name: TELEGRAM_WEBHOOK_SECRET
|
|
description: "Secret token Telegram sends with each webhook update (required with TELEGRAM_WEBHOOK_URL)"
|
|
prompt: "Webhook secret"
|
|
password: true
|