PTENES
MODULE 1.5

🔑 OAuth vs. API key

The two ways to connect a model to Hermes. OAuth is the button you can revoke; the API key is the key you keep and can rotate. Knowing which one to use helps you avoid setup errors.

The provider Does it offer OAuth? YES NO 🔘 OAuth log in + click Allow in the browser Grok, ChatGPT revocable: take it back 🗝️ API Key sk-xxxx... on the server Claude and others rotatable: the old one dies
6
Topics
20
Minutes
Basic
Level
Practical
Type
1

🔘 What OAuth is

No OAuth, opens the browser, you log in and click "Allow". The connection is ready — without handling any keys. It's the simplest and safest method when available.

1

Open the browser

Hermes takes you to the provider's page.

2

Log in and click "Allow"

You authorize access with your account.

3

Connection ready

No key to store; you can revoke it whenever you want.

2

🗝️ What an API key is

A API key is a string of characters that lives on a server and grants access to all models from the provider. This is the method used when there’s no OAuth.

What an API key looks like (illustrative)

sk-or-v1-3f9a...   ← string secreta, vive no servidor
# dá acesso a todos os modelos do provedor
# fonte de modelos para comparar: openrouter.ai/models

📊 Features

  • •It's a secret string — treat it like a password
  • •Provides broad access to the provider's models
  • •Lives on a server, not in your browser
3

🔁 Rotate Keys

You can rotate the API key at any time. When you rotate it, the old key never works again — it’s your defense if a key leaks.

✓ When to rotate

  • ✓Suspected leak
  • ✓You accidentally pasted the key somewhere
  • ✓Periodic security routine

✗ What NOT to forget

  • ✗The old key stops working immediately
  • ✗Update wherever the key was in use
  • ✗Never paste the key into chat (Track 2/3)
4

🧭 Who uses what

Not every provider offers OAuth. Grok and ChatGPT connect via OAuth; the Claude does NOT offer OAuth — only via API key.

🔘 Via OAuth

  • •Grok
  • •ChatGPT

🗝️ Via API key

  • •Claude (doesn't support OAuth)
  • •OpenRouter and most others

Avoids frustration: don’t look for an OAuth button for Claude — it simply doesn’t exist. Use an API key.

5

⚙️ homes setup: the terminal workflow

In practice, the two methods meet in the command homes setup: you choose the provider, then use OAuth (reauthenticate) or paste the API key.

Illustrative flow

$ homes setup
? Escolha o provider:  > OpenRouter / OpenAI / xAI / Anthropic ...
? Método:              > OAuth (reauthenticate)  |  Colar API key
# OAuth  -> abre o navegador, login, Allow
# API key -> cola a string (ex.: de openrouter.ai/models)

💡 Practical tip

If you get "reauthenticate," just redo OAuth — log in and click Allow again. There's no key to look for.

6

⚖️ The key analogy

The image that brings it all together: OAuth is the button you can take back at any time; the An API key is a key that needs to be stored and can be rotated.

🔘 OAuth = button

  • ✓Nothing to store
  • ✓You can "turn off" permission whenever you want
  • ✓More convenient

🗝️ API key = key

  • •Needs to be stored carefully
  • •Can be rotated (the old one is invalidated)
  • •More control, more responsibility

Summary: convenience vs. control. Both work; choose based on what the provider offers.

7

🛡️ Common security mistakes

Connecting models involves credentials. The most common errors have to do with how you store (or don’t store) your key.

✓ Do it

  • ✓Prefer OAuth when the provider offers it
  • ✓Keep the API key outside the chat (Track 2/3)
  • ✓Rotate it at the first sign of a leak

✗ Never

  • ✗Pasting the API key into the chat (everything is indexed)
  • ✗Reusing the same key in multiple places without control
  • ✗Looking for OAuth where it doesn't exist (e.g., Claude)

Quick-reference summary (illustrative)

OAuth   = botão (login + Allow)   -> revogável, nada para guardar
API key = chave (sk-xxxx no server) -> rotacionável, guarde fora do chat

📌 Module Summary

✓
OAuth — browser login + Allow; no key; revocable.
✓
API key — secret string on the server; broad access to models.
✓
Rotation — once rotated, the old key is dead.
✓
Who uses what — Grok/ChatGPT: OAuth; Claude: API key only.
✓
homes setup — choose a provider, use OAuth, or paste the key.

Next Module:

1.6 — Choosing a Model