PTENES
MODULE 2.3

🧰 Integrations

"Swiss Army knife." Hermes comes with several integrations ready to go—you just provide the tool’s API key. Here you’ll see what’s available, how to connect securely (env, never in chat), and real examples like Granola.

6
Topics
22
Minutes
Interm.
Level
Practice
Type
1

🧰 The Swiss Army knife

Hermes comes with several integrations already built in: text-to-speech, image generation, vision, web search, and more. Each one is a "blade" in the Swiss Army knife—you open the one you need, without programming anything. It’s what connects your whole world to a single agent.

🧰 Hermes Swiss Army knife 🔊 Text-to-Speech 🎨 image generation 👁️ vision 🌐 web search 📓 Granola …

💡 Practical tip

Don’t turn everything on at once. Enable one blade at a time, as the need arises — fewer active integrations mean a smaller risk surface and fewer tokens spent.

2

🔑 You only provide the API key

For most integrations, the only requirement is the API key from the service — a string that authenticates Hermes with that tool. Setup is simple, but how you store that key makes all the difference (next topics).

🔊
TTS
voice provider key
🎨
Image
generator key
🌐
Web search
search engine key

📊 What Is an API Key

  • A secret string that proves the call is yours
  • Provides access to the service — and whoever has it
  • Can be rotated (when you switch, the old one stops working)
3

🛡️ NEVER paste the key into chat

This is the golden rule: everything you type in the chat is saved and indexed. If you paste an API key into the conversation, it becomes part of the history—and if you make daily backups (e.g., to GitHub), that key is stored in every backup. A silent, permanent leak.

⚠️ Why this is dangerous

  • •The chat becomes part of the full-text search memory (module 2.1).
  • •Daily backups copy the key off your machine.
  • •Whoever has the key has full access to the service — and your account.

✗ NEVER do this

  • ✗Pasting "my key is sk-abc123..." into the chat
  • ✗Send the key in a message "just to test"
  • ✗Leave the key in a version-controlled Git file

✓ Always do

  • ✓Store the key as an environment variable
  • ✓Paste the key only into the terminal (topic 4)
  • ✓Rotate it if you suspect a leak
4

📦 Store It as an Environment Variable

The right way: ask Hermes for a terminal command to add the key to the environment. It gives you the command with a placeholder; you replace the placeholder with your actual key and paste it into the terminal—outside the chat.

1

Ask Hermes for the command

"Give me the terminal command to add the ElevenLabs key to env." It responds with a placeholder.

2

Replace the placeholder with your key

In your editor/terminal, replace SUA_KEY_AQUI with the actual key.

3

Paste it into the terminal, not the chat

The key goes into the system environment. The chat never sees it.

Command in the terminal (illustrative)

# placeholder que o Hermes te dá:
export ELEVENLABS_API_KEY="SUA_KEY_AQUI"

# você troca SUA_KEY_AQUI pela key real e cola NO TERMINAL
# a integração lê a variável de ambiente — nunca o chat

💡 Practical tip

If the key ended up in the chat by mistake, rotate it immediately in the service dashboard. Rotating it invalidates the old one — it's the only safe way to “undo” this.

5

📓 Example: Granola

Granola captures meeting notes. Connected to Hermes, you can ask things like: "what was the last meeting and 1 action I promised?" — and it responds based on the notes. It’s integration solving a real everyday problem.

💬 What you can ask

  • •"Summarize my last meeting in 3 bullets."
  • •"What actions did I promise to take but haven’t done yet?"
  • •"Who was on yesterday’s call?"

🔗 Why this example is strong

It combines integration (access to notes) with memory (knowing what you promised) — two Track 2 capabilities working together for something you’d use every day.

6

🔓 Some have OAuth

Not every integration needs an API key. Some — like Granola MCP — use OAuth: you just provide the MCP name and authorize it in the browser by clicking "Allow". No keys to store, no risk of pasting it in the wrong place.

🔑 API key

String that lives in the env. You manage, rotate, and protect it. Risk: it can leak if stored carelessly.

🔓 OAuth

Browser login + "Allow." No key to store; connection can be revoked at any time.

💡 When you have a choice, prefer OAuth

OAuth eliminates the risk of handling the wrong key. But many services only offer API keys—in that case, use env, never chat. The concept of MCP is covered in module 2.5.

📌 Module Summary

✓
Swiss Army knife — ready-made integrations: TTS, image, vision, web search.
✓
API key — secret string that connects each tool.
✓
Never in chat — everything is indexed and goes into backups; permanent risk.
✓
Env via terminal — ask for the command, replace the placeholder, paste it into the terminal.
✓
OAuth whenever possible — Granola MCP authorizes in the browser, with no key.

Next Module:

2.4 — Computer Actions: browser, bash, real cursor