Model Provider Guide
Hermes Agent + Google AI Studio: Run Hermes on a Gemini API Key
Google AI Studio is where most people get a Gemini API key. Hermes Agent has a native provider for exactly that key. This guide walks through creating the key, wiring it into Hermes, choosing a Gemini model for a chat-app bot, and the errors people hit first, based on the current upstream Hermes docs.
Three Google things that get mixed up
| Name | What it is | Where it fits with Hermes |
|---|---|---|
| Google AI Studio | Google’s browser playground for Gemini, and the console where you create Gemini API keys | Source of the key Hermes uses (this guide) |
| Gemini models | The model family itself: Flash, Pro, Flash Lite, plus Gemma through the same API | What Hermes thinks with — see Hermes Agent + Gemini |
| Gemini CLI | Google’s open-source coding agent for the terminal | A separate tool Hermes can call — see Hermes Agent + Gemini CLI |
If you only want to try prompts in a browser, AI Studio on its own is fine. The moment you want an assistant that answers on Telegram at 3 a.m., remembers past chats and runs scheduled jobs, you need an agent such as Hermes on the other end of that key. Our OpenClaw Launch vs Google AI Studio page covers that difference in more depth.
Step 1: Create a Gemini API key in Google AI Studio
- Open aistudio.google.com/apikey and sign in with a Google account.
- Create a key. AI Studio attaches it to a Google Cloud project, creating one if needed.
- Copy the key somewhere safe. Treat it like a password: anyone holding it can spend against that project.
- For a bot you plan to keep, turn on billing for that Cloud project. The Hermes docs are blunt that the free tier is too small for long-running agent sessions, since one message can fan out into several model calls.
Two details worth knowing before you paste it anywhere. First, Google now issues AQ.-prefixed keys for both AI Studio and Vertex AI express mode, while the older AIza… format is being phased out, so you cannot tell from the prefix which service a key belongs to. Second, Google’s terms treat unpaid and paid Gemini API usage differently, including how prompts may be used; read the current terms before sending private chats through a free key.
Step 2: Point Hermes at the key
Hermes lists AI Studio as its own provider. In the source it is the gemini provider, displayed as “Google AI Studio”, and it checks both GOOGLE_API_KEY and GEMINI_API_KEY. The quickest route is the interactive picker:
# Store the key where Hermes reads secrets
echo "GOOGLE_API_KEY=your-key-here" >> ~/.hermes/.env
# Pick the provider and a model
hermes model
# -> "More providers..." -> "Google AI Studio"
# -> Hermes checks the key's tier and lists Gemini modelsThat writes the model block into ~/.hermes/config.yaml. If you prefer to edit it yourself, this is the shape the upstream docs show:
model:
default: gemini-3.7-flash
provider: gemini
base_url: https://generativelanguage.googleapis.com/v1betaUse the native endpoint above rather than Google’s OpenAI-compatible one (…/v1beta/openai/). Hermes has a native Gemini adapter that maps tool calls, tool results, streaming and multimodal input straight onto generateContent, and for Gemini 3 it replays the thought signatures attached to function calls, which multi-step tool use depends on. If an old GEMINI_BASE_URL pointing at the /openai path is sitting in your .env, remove it.
Have a Vertex AI express-mode key instead of an AI Studio one? Keep the same gemini provider but add GEMINI_BASE_URL=https://aiplatform.googleapis.com. Hermes decides the surface from the base URL, never from the key’s prefix, so a crossed pairing shows up as 403 PERMISSION_DENIED.
Step 3: Check it, then put it on a chat app
hermes doctor # confirms GOOGLE_API_KEY / GEMINI_API_KEY resolves
hermes chat # quick terminal test
hermes gateway setup # connect Telegram, Discord, Slack, WhatsApp...
hermes gateway startThe gateway reads the same config.yaml, so every connected platform uses the Gemini model you just picked. Walkthroughs for specific platforms start at Hermes Agent + Telegram.
Picking a Gemini model for a gateway bot
These are the IDs the upstream Hermes Gemini guide lists as common choices. Google changes availability often, so treat hermes model as the source of truth for what your key can use today.
| Model ID | Upstream description | Good fit for |
|---|---|---|
gemini-3.7-flash | Recommended default balance of speed, capability and multimodal understanding | A general chat bot, the sensible first pick |
gemini-3.8-flash | Most capable Flash model for long-horizon agentic and coding work | Bots that run long tool chains or scheduled jobs |
gemini-3.1-pro-preview | Most capable reasoning, math and coding model | Hard analysis where latency and cost matter less |
gemini-3.5-flash-lite | Fastest and lowest-cost option for lightweight tasks | High-volume groups and simple Q&A |
- Use native IDs. With
provider: geminithe model isgemini-3.7-flash, notgoogle/gemini-3.7-flash; the prefixed form is for OpenRouter. - Pin or float deliberately. Google’s moving aliases
gemini-flash-latestandgemini-pro-latestupgrade you automatically, and the price can move with them. A bot other people depend on is easier to reason about on an explicit ID. - Leave Gemma for testing. Gemma models are reachable through the same key, but Hermes hides low-throughput ones from the picker and their Gemini API caps are low. Fine for a compatibility check, not for a busy group chat.
- Switch mid-chat with
/model gemini-3.1-pro-previewand back./modelonly moves between providers you have already configured; it does not collect new keys. - Add a fallback. If Gemini rate-limits you, Hermes can hop to another provider mid-session.
hermes fallback addmanages the list, and Gemini entries acceptgemini,google,google-geminiorgoogle-ai-studioas the provider name. More in Hermes fallback models.
# ~/.hermes/config.yaml - Gemini first, OpenRouter as the backup
model:
default: gemini-3.7-flash
provider: gemini
base_url: https://generativelanguage.googleapis.com/v1beta
fallback_providers:
- provider: openrouter
model: anthropic/claude-sonnet-4First errors people hit
- “Gemini native client requires an API key” — Hermes found neither
GOOGLE_API_KEYnorGEMINI_API_KEY. Add one to~/.hermes/.envand runhermes modelagain. - “This Google API key is on the free tier” — the setup probe’s warning. Enable billing on the key’s Cloud project, regenerate the key if needed, then rerun
hermes model. - 404 model not found — the model is not enabled for your account, region or key. Pick another from the current list.
- 403 PERMISSION_DENIED — usually an AI Studio key sent to the Vertex host or the reverse. Check
GEMINI_BASE_URL. - Tool calls fail with schema errors — update Hermes and rerun
hermes model; the native adapter sanitizes tool schemas for Gemini’s stricter format, older builds may not.
Source for all of the above: the upstream Hermes Google Gemini guide and Fallback Providers page, plus the provider table in the Hermes source on GitHub.
The same key on OpenClaw
OpenClaw reads the same key. Its google provider accepts GEMINI_API_KEY or GOOGLE_API_KEY, onboarding takes it with openclaw onboard --auth-choice gemini-api-key, and model refs keep the provider prefix, for example google/gemini-3.1-pro-preview as agents.defaults.model.primary. Note the naming flip compared with Hermes: OpenClaw wants the google/ prefix, Hermes’s gemini provider wants the bare ID. Details in the OpenClaw Google provider docs and our OpenClaw + Gemini guide.
When managed hosting is the easier path
Everything above assumes you run Hermes on a machine that stays on, keep it updated, and watch the gateway. If that is the part you would rather not own, OpenClaw Launch runs Hermes Agent or OpenClaw for you with chat platforms connected from the dashboard. Gemini models are in the model picker, and AI credits are included with a plan, so you can start without a Google key at all. If you would rather pay Google directly, the API Keys page has a Google AI (Gemini) card for an AI Studio key; the full list of keys you can bring is on API providers, and Hermes Agent BYOK explains how bring-your-own-key works in general.
Hermes + Google AI Studio FAQ
Does Hermes Agent support Google AI Studio keys natively?
Yes. Hermes has a built-in provider named gemini, labelled “Google AI Studio” in hermes model. It reads GOOGLE_API_KEY or GEMINI_API_KEY and talks to Gemini’s native generateContent API at generativelanguage.googleapis.com/v1beta, so no extra Python package or proxy is needed.
Is the Google AI Studio free tier enough for a Hermes bot?
Usually not for real use. The Hermes docs say the free tier is too small for long-running agent sessions, because one user message can trigger several model calls (tool use, retries, context compression). Hermes probes the key during setup and warns when it is on the free tier. Enable billing on the Google Cloud project behind the key for a bot other people rely on.
Should I write gemini-3.7-flash or google/gemini-3.7-flash?
With provider: gemini, use Google’s native IDs such as gemini-3.7-flash. The google/ prefix is the OpenRouter style and only belongs in configs that route through OpenRouter.
Why does my new Gemini key return 403 PERMISSION_DENIED?
Google now issues AQ.-prefixed keys for both AI Studio and Vertex AI express mode, so the prefix no longer tells you which service a key belongs to. Hermes routes by base URL, not key shape. An AI Studio key needs the default host (leave GEMINI_BASE_URL unset); a Vertex express key needs GEMINI_BASE_URL=https://aiplatform.googleapis.com. A 403 usually means the key and host are crossed.
Is Google AI Studio the same as Gemini CLI?
No. AI Studio is Google’s web playground and the place you create Gemini API keys. Gemini CLI is a separate open-source terminal agent. An AI Studio key is what lets Hermes itself use Gemini as its model. See Hermes Agent + Gemini CLI for running the CLI alongside Hermes.