Open source · Courier agent

Hermes: The Messenger Agent

A dedicated, isolated agent whose only job is to deliver signals between your AI workforce, your humans, and the outside world. Every notification, every webhook, every translation, every retry: logged and signed.

OpenClawPro ships Hermes as a standard add-on on Managed Pro+ and Self-Hosted Advanced+ plans. It runs in its own container: no shared memory, no shared secrets, no cross-contamination.

What Hermes Does

Six capabilities that turn a chaotic multi-agent setup into a clean, observable messaging layer.

Multi-Channel Delivery

Dispatches signals to WhatsApp, Telegram, Discord, Slack, email, and any webhook endpoint. One agent, every channel.

Smart Routing

Routes notifications by priority and recipient with rules you define: critical alerts to the on-call channel, digests to the team room.

Isolated by Design

Runs in its own Docker container on a dedicated network. No access to your other agents' memory, code, or secrets, unless you grant it.

Audit-Logged

Every message, every delivery attempt, every retry: timestamped and kept, so you can reconstruct exactly what was sent, where and when.

Inbound Webhooks Too

Accepts incoming webhooks and turns them into channel messages: point any service that can POST at it, and the event lands where your team reads.

Human Approval Requests

Carries an approve-or-deny question to your channel and returns the answer to the requesting agent. The decision stays with a person, and it is logged.

Real Use Cases

How Hermes is deployed in the wild: patterns we install for every Managed Pro+ and Self-Hosted Advanced+ customer.

1

Daily Standups

Your agents post status updates; Hermes delivers them to your team channel on the schedule you set. One place to read what ran overnight.

2

Customer Notifications

When your support agent resolves a ticket, Hermes sends the confirmation email (with the customer's preferred language) and updates the CRM.

3

Approval Gates

Before any spend or production change, Hermes sends an approval request to the human on call. Nothing moves until a person answers.

4

Incident Routing

A monitoring alert reaches the on-call human in the channel they actually read, with the context attached. No pager theatre, just delivery.

Why a Separate Agent?

A messaging layer that lives inside the same process as your business agents is a liability: one prompt-injection in a customer email can pivot into your CRM, your code, your spending. Hermes is built to prevent that.

  • Runs in its own Docker container, on a dedicated Docker network.
  • No read access to other agents' memory, code, or secrets: explicit allow-list only.
  • Outbound calls go through a small, audited set of HTTP libraries: no exec, no eval, no file system.
  • Every inbound payload is parsed, validated, and re-emitted as a typed event: no raw forwarding.
  • Token budget and rate limits are enforced at the container boundary, not at the LLM layer.

Included in Pro+ and Advanced+ Plans

Hermes Messaging Agent

Free with any plan

Standard add-on at no extra cost with any Managed plan or Self-Hosted install. Standalone install also available for existing OpenClaw deployments.

Hermes in the OpenClaw Family

Each OpenClaw component has a clear role. Hermes is the messenger.

Ship Signals, Not Surprises.

Stop juggling webhooks, retries, channel formats, and translations across half a dozen agents. Hermes does it once, in one container, with one audit log.

Paperclip, NeMo, Nemotron and other product names are trademarks of their respective owners. OpenClawPro provides independent setup, hosting and support and is not affiliated with or endorsed by them.

Need it built for you?

WarMachine33: AI automation agency. We design and ship custom AI workflows for your business.

Discover WarMachine33 →