Hermes Agent on a VPS: Install and Run It 24/7 on Linux
- September 21, 2026
- 9:00 am
- By Adrien Roche
- Updated October 3, 2026
- Tutorials

What Hermes Agent is, and why it needs a VPS
Hermes Agent is an open-source, MIT-licensed AI agent from Nous Research, pitched as "the agent that grows with you". What separates it from most agent frameworks is a built-in learning loop: it creates skills from its own experience, improves them during use, searches its past conversations, and builds a persistent memory of you and your projects across sessions. Around that core it stacks task delegation to isolated subagents, natural-language scheduling for reports and backups, web search and browser automation, and sandboxed command execution across multiple backends: local, Docker, SSH, and serverless options such as Modal and Daytona.
Every one of those features assumes the agent is actually running. Memory that only accumulates while your laptop is awake, or a scheduled morning briefing that fires only if your desktop happens to be on, defeats the point. Nous Research says as much in its own docs: Hermes "lives wherever you put it — a $5 VPS, a GPU cluster, or serverless infrastructure." For most people the right answer is the first one: a small Linux VPS that is always on, always reachable, and cheap enough to forget about. This guide walks the whole path on Ubuntu: install, model configuration, the built-in systemd service, remote access, and honest sizing.
Prerequisites: what an Ubuntu VPS actually needs
The official requirements are refreshingly short. Hermes supports Linux, macOS, WSL2, and even Android (Termux) through its terminal installer; the desktop app exists only for macOS 12+ and Windows 10/11 and is not needed on a server. On Debian or Ubuntu, the documented prerequisites are git, curl, and xz-utils, nothing else:
sudo apt update
sudo apt install -y git curl xz-utilsEverything heavier is bundled by the installer itself: it ships its own Python 3.11 and Node.js v26, plus ripgrep and ffmpeg, so you do not manage language runtimes yourself or worry about the distro's Python colliding with the agent's. Any recent Ubuntu LTS with SSH access and a sudo-capable user will do. If you have self-hosted an agent before (say by following our guide to deploying OpenClaw on a VPS), the shape of what follows will feel familiar, minus most of the dependency wrangling.
Install Hermes Agent on Ubuntu, step by step
1. Run the official installer
Nous Research publishes a single install script that handles the repository clone, virtual environment, dependencies, and a global hermes command:
curl -fsSL https://hermes-agent.nousresearch.com/install.sh | bashAs with any piped installer, you are free to download the script first and read it before executing, a sensible habit on a machine that will hold API keys.
2. Reload your shell
The installer adds hermes to your PATH, so pick up the change:
source ~/.bashrc # or: source ~/.zshrc3. Start the agent
Run hermes for the classic CLI, or hermes --tui for the modern terminal UI the docs recommend. On first launch it walks you into setup. Later, hermes --continue (short form hermes -c) resumes your most recent session, so a dropped SSH connection costs you nothing.
4. Verify the install
hermes doctor diagnoses configuration and dependency problems, and hermes update detects how you installed and applies the matching update path. Both are worth knowing before anything breaks.
Point it at a model: keys and providers
Hermes is deliberately model-agnostic, and the docs describe two paths:
- Nous Portal (fastest):
hermes setup --portalruns one OAuth flow that covers model access plus four hosted tools: web search, image generation, text-to-speech, and browser automation. Portal is the subscription route, with paid tiers that include monthly model credits and a large model catalog. - Bring your own provider:
hermes modelopens an interactive picker across 40+ providers (OpenAI, Anthropic, Google Gemini, xAI, DeepSeek, OpenRouter, AWS Bedrock, Azure, Ollama, and custom endpoints among them). Most just need an environment variable such asOPENROUTER_API_KEY, or an OAuth login triggered from the picker.
Configuration lives in ~/.hermes/config.yaml, readable and writable through hermes config get and hermes config set, and hermes setup re-runs the full wizard whenever you change course (a --non-interactive flag exists for scripted rebuilds). Switching models later is a menu, not a migration: no code changes, no lock-in.
Run it 24/7: the built-in systemd gateway service
This is where the VPS earns its keep, and where Hermes is better-behaved than most agents. You do not need PM2, tmux, or hand-written unit files: the messaging gateway (the long-running process that connects your agent to Telegram, Discord, Slack, WhatsApp, Signal, email, and more) ships with native service management. Configure your platforms, then install it as a systemd service:
hermes gateway setup # interactive platform configuration
hermes gateway install # install as a systemd user service
hermes gateway start
hermes gateway statusOn a headless server there is one extra, easily missed step. A systemd user service normally stops when you log out, so tell systemd to keep your user's services alive without an active session:
sudo loginctl enable-linger $USERAlternatively, install it as a system-level service that starts at boot with sudo hermes gateway install --system. The documented run modes break down like this:
| Mode | Command | Best for |
|---|---|---|
| Foreground | hermes gateway run | Testing, plus environments like Docker, WSL2, or Termux |
| User service | hermes gateway install | A VPS you administer as one user: add enable-linger for headless boxes |
| System service | sudo hermes gateway install --system | Boot-time startup on a dedicated agent server |
Logs land in ~/.hermes/logs/gateway.log and are also reachable through hermes logs; hermes gateway restart and hermes gateway stop do what they say, and hermes gateway list shows every profile's gateway state. Because the gateway registers as a normal systemd unit, it shows up alongside everything else on the box. Our refresher on listing and managing systemd services helps when you want to see it in context.
Remote access: fully headless, driven from your chat apps
A fair question for any agent on a server: do you need a screen? For Hermes the answer is a clean no. The terminal install is a first-class citizen, not a degraded fallback: the CLI, TUI, gateway, and sandboxed execution all work over plain SSH with no display server and no desktop app. Day to day you will rarely even SSH in: once the gateway runs, the agent is reachable from whichever messaging platforms you configured, with one shared memory across all of them ("one agent, one memory, every surface", as the project puts it). Ask for a status report from Telegram on your phone, continue the same conversation from Slack at your desk, and let scheduled automations post results wherever you want them.
Security basics for an always-on agent
An agent that executes commands and holds API keys deserves a slightly paranoid setup. The good news: nothing in this guide required opening an inbound port. The gateway connects outward to the messaging platforms, and you manage the box over the SSH access you already had. Keep it that way:
- Verify nothing is exposed. After setup, check which ports are open on your Linux server and confirm the only thing reachable from the internet is SSH. And remember: firewalls and port choices reduce exposure, they are not a substitute for real authentication.
- Use DM pairing. Hermes avoids hardcoded user allowlists: an unknown account that messages your agent receives a pairing code, which you approve explicitly with
hermes pairing approve telegram <CODE>. Codes expire after one hour. Never approve a code you did not trigger yourself. - Protect your keys. Provider credentials live under
~/.hermes/, so keep that directory readable only by your user, keep it out of any git repository, and usehermes backup, which archives configuration and sessions to a zip, instead of ad-hoc copies. - Contain execution. Hermes supports command approval and multiple sandbox backends; on a server, the Docker backend adds a genuine isolation boundary between the agent's shell and your host.
VPS sizing: the honest answer
Nous Research publishes no minimum RAM or CPU figures, so any hard number you read elsewhere is invented. What the docs do say is directional: Hermes "lives wherever you put it — a $5 VPS, a GPU cluster, or serverless infrastructure." That claim is credible because of the architecture. When you use Nous Portal or any hosted provider, inference happens on someone else's GPUs; your VPS only runs the agent process (the bundled Python and Node.js runtimes, the gateway, and whatever shell commands the agent executes). That is a modest footprint. Plan bigger only when your workload demands it: Docker-sandboxed execution adds container overhead, media tasks lean on ffmpeg, and pointing hermes model at a local Ollama endpoint changes the math entirely, because model weights need RAM the API route never touches.
What matters more than raw size is that the machine is genuinely yours and genuinely always on. A Linux VPS from rdp.monster gives you full root access for the installer and its systemd service, dedicated CPU and RAM that are not shared away while your agent thinks, unlimited (fair-use) bandwidth for its web tools, and no KYC (pay in crypto if you prefer). Servers are ready about 10 seconds after payment confirms, which means Hermes can be installed, paired with your Telegram, and already learning before your coffee cools.
Frequently Asked Questions
What are the minimum server requirements for Hermes Agent?
git, curl, and xz-utils; the installer bundles Python 3.11, Node.js v26, ripgrep, and ffmpeg. Because inference runs on your model provider's hardware, the VPS only hosts the agent runtime and gateway, which Nous says fits a $5 VPS. Add headroom if you enable Docker sandboxing or run local models through Ollama, which need far more RAM.Is Hermes Agent free to use?
hermes model). A local model through Ollama avoids per-token fees but demands far more server resources.How is Hermes Agent different from OpenClaw and similar agents?
Can Hermes Agent run without a screen or GUI?
hermes CLI or TUI, and keep it alive headless with hermes gateway install plus sudo loginctl enable-linger $USER. Once the gateway is up, you interact from Telegram, Discord, Slack, WhatsApp, Signal, or email, with no monitor, RDP session, or X server involved.Adrien Roche, Infrastructure & Hosting Editor
Systems engineer with 10+ years operating Windows Server and Linux fleets. Adrien runs the rdp.monster infrastructure documentation and writes our guides on RDP, VPS hosting, server administration, networking and privacy tooling.




