🧰 The Swiss Army knife
Hermes comes with several integrations already built in: text-to-speech, image generation, vision, web search, and more. Each one is a "blade" in the Swiss Army knife—you open the one you need, without programming anything. It’s what connects your whole world to a single agent.
💡 Practical tip
Don’t turn everything on at once. Enable one blade at a time, as the need arises — fewer active integrations mean a smaller risk surface and fewer tokens spent.
🔑 You only provide the API key
For most integrations, the only requirement is the API key from the service — a string that authenticates Hermes with that tool. Setup is simple, but how you store that key makes all the difference (next topics).
📊 What Is an API Key
- A secret string that proves the call is yours
- Provides access to the service — and whoever has it
- Can be rotated (when you switch, the old one stops working)
🛡️ NEVER paste the key into chat
This is the golden rule: everything you type in the chat is saved and indexed. If you paste an API key into the conversation, it becomes part of the history—and if you make daily backups (e.g., to GitHub), that key is stored in every backup. A silent, permanent leak.
⚠️ Why this is dangerous
- •The chat becomes part of the full-text search memory (module 2.1).
- •Daily backups copy the key off your machine.
- •Whoever has the key has full access to the service — and your account.
✗ NEVER do this
- ✗Pasting "my key is sk-abc123..." into the chat
- ✗Send the key in a message "just to test"
- ✗Leave the key in a version-controlled Git file
✓ Always do
- ✓Store the key as an environment variable
- ✓Paste the key only into the terminal (topic 4)
- ✓Rotate it if you suspect a leak
📦 Store It as an Environment Variable
The right way: ask Hermes for a terminal command to add the key to the environment. It gives you the command with a placeholder; you replace the placeholder with your actual key and paste it into the terminal—outside the chat.
Ask Hermes for the command
"Give me the terminal command to add the ElevenLabs key to env." It responds with a placeholder.
Replace the placeholder with your key
In your editor/terminal, replace SUA_KEY_AQUI with the actual key.
Paste it into the terminal, not the chat
The key goes into the system environment. The chat never sees it.
Command in the terminal (illustrative)
# placeholder que o Hermes te dá: export ELEVENLABS_API_KEY="SUA_KEY_AQUI" # você troca SUA_KEY_AQUI pela key real e cola NO TERMINAL # a integração lê a variável de ambiente — nunca o chat
💡 Practical tip
If the key ended up in the chat by mistake, rotate it immediately in the service dashboard. Rotating it invalidates the old one — it's the only safe way to “undo” this.
📓 Example: Granola
Granola captures meeting notes. Connected to Hermes, you can ask things like: "what was the last meeting and 1 action I promised?" — and it responds based on the notes. It’s integration solving a real everyday problem.
💬 What you can ask
- •"Summarize my last meeting in 3 bullets."
- •"What actions did I promise to take but haven’t done yet?"
- •"Who was on yesterday’s call?"
🔗 Why this example is strong
It combines integration (access to notes) with memory (knowing what you promised) — two Track 2 capabilities working together for something you’d use every day.
🔓 Some have OAuth
Not every integration needs an API key. Some — like Granola MCP — use OAuth: you just provide the MCP name and authorize it in the browser by clicking "Allow". No keys to store, no risk of pasting it in the wrong place.
🔑 API key
String that lives in the env. You manage, rotate, and protect it. Risk: it can leak if stored carelessly.
🔓 OAuth
Browser login + "Allow." No key to store; connection can be revoked at any time.
💡 When you have a choice, prefer OAuth
OAuth eliminates the risk of handling the wrong key. But many services only offer API keys—in that case, use env, never chat. The concept of MCP is covered in module 2.5.
📌 Module Summary
Next Module:
2.4 — Computer Actions: browser, bash, real cursor