← Home

Guide

Hermes Agent + n8n: Connect Your Agent to Workflows

n8n is good at moving data between apps on a schedule or a trigger. Hermes Agent is good at the steps that need judgment — reading, deciding, writing. Hermes has no n8n plugin, and does not need one: it already exposes an HTTP API and a signed-webhook receiver, and it can call any URL itself. That covers all three directions you are likely to want.

Three Ways to Connect Them

  • n8n asks Hermes and uses the answer — n8n's HTTP Request node calls the Hermes API server and gets the reply back in the same request.
  • n8n hands Hermes a job and moves on — n8n POSTs a signed event to a Hermes webhook route, and Hermes delivers the result to Telegram, Discord, Slack or another chat.
  • Hermes starts an n8n workflow — Hermes calls an n8n Webhook trigger URL, so the agent can kick off an existing automation.

Option 1: Call Hermes from n8n (API Server)

Hermes ships an OpenAI-compatible API server as one of its gateway platforms. It serves /v1/chat/completions, /v1/responses, /v1/models and /health, and it listens on port 8642 by default. Setting a key in ~/.hermes/.env is what turns it on (unless config.yaml explicitly disables the API server):

API_SERVER_KEY=choose-a-long-random-key
# optional
API_SERVER_PORT=8642
API_SERVER_HOST=127.0.0.1

Then restart with hermes gateway restart. The server will not start without a key, even on a loopback bind, and every API call must send it as a Bearer token (only the health checks, /health and /v1/health, are open). The host defaults to 127.0.0.1, so if n8n runs on another machine you must widen the bind or put a reverse proxy in front. Either way, never expose the port without the key.

In n8n, add an HTTP Request node:

  • Method: POST
  • URL: http://your-hermes-host:8642/v1/chat/completions
  • Header: Authorization: Bearer <API_SERVER_KEY>
  • Body (JSON):
{
  "model": "hermes-agent",
  "messages": [
    { "role": "user", "content": "Summarise this support ticket and suggest a reply: {{ $json.body }}" }
  ]
}

The reply text is at choices[0].message.content, ready for the next node. The model name is whatever /v1/models advertises; by default that is the profile name, or hermes-agent. Behind it is a full agent run with your tools, skills and memory — not a raw model call — so give the node a timeout long enough for tool use.

Because the API is OpenAI-compatible, n8n's own OpenAI chat-model credential can also point at it: set the base URL to http://your-hermes-host:8642/v1 and the API key to your API_SERVER_KEY.

Option 2: Trigger Hermes with a Webhook

When n8n should not wait for the answer, send it to Hermes's webhook platform instead. Turn it on with hermes gateway setup (pick Webhook), or directly in ~/.hermes/config.yaml. The hermes webhook commands below check this setting, so set it here rather than only in .env:

platforms:
  webhook:
    enabled: true
    extra:
      port: 8644   # the default

Restart the gateway, then create a route with the webhook CLI:

hermes webhook subscribe new-lead \
  --secret "a-long-shared-secret" \
  --prompt "New lead from {name} at {company}: {message}. Research the company and draft a reply." \
  --deliver telegram   --deliver-chat-id "<your-telegram-chat-id>"

The route listens at POST /webhooks/new-lead. The prompt template reads payload fields with dot notation ({lead.email}), and {__raw__} drops in the payload as JSON (truncated to 4,000 characters). --deliver sends the agent's result to a connected chat platform (give it a chat ID, or set a home channel for that platform); leave it as the default log and the result is only written to the log. Other useful flags: --skills loads specific skills for the run, and --deliver-only forwards the rendered text straight to the chat without calling the model at all.

Deliveries must be authenticated (the only exception is a loopback-only test route). For a generic sender like n8n, the recommended scheme is HMAC-SHA256 over <timestamp>.<body> using the route secret:

  • X-Webhook-Timestamp: the current Unix time in seconds
  • X-Webhook-Signature-V2: the hex HMAC-SHA256 of timestamp + "." + body

Requests more than five minutes out of date are rejected, which limits the replay window. Send a unique X-Request-ID per event (and reuse it on retries) so Hermes can drop duplicates. In n8n, compute the signature with a Crypto node (HMAC, SHA256, hex) or a Code node, then send it from an HTTP Request node. Sign the exact bytes you send: if n8n re-serialises the JSON after you sign it, verification fails. Test a route without n8n using hermes webhook test new-lead.

Option 3: Let Hermes Start an n8n Workflow

Give an n8n workflow a Webhook trigger node and copy its production URL. Hermes can call it with its terminal tool (a plain curl) whenever you ask — or, better, save the call as a skill so the agent knows when and how to use it:

curl -X POST https://n8n.example.com/webhook/create-invoice \
  -H "Content-Type: application/json" \
  -d '{"customer":"Acme","amount":1200}'

Protect the n8n webhook with header authentication and keep that credential in the Hermes .env, not in the skill text. The agent should never see a secret it does not need.

Which One Should You Use?

  • Need the answer inside the workflow? API server.
  • Fire-and-forget, with the result going to a chat? Webhook route.
  • Want the agent to run existing automations? Hermes calls n8n.

Most setups use two of the three: n8n for plumbing and schedules, Hermes for the parts that need reasoning.

On OpenClaw Launch

Managed Hermes bots on OpenClaw Launch have both halves built in. Use in Another App turns on a private OpenAI-compatible endpoint with its own key, for server-side callers like n8n. Receive Webhooks gives the bot a public HTTPS webhook address, and you add routes with the same hermes webhook subscribe command from the dashboard Terminal. Both are off by default; turning on webhooks restarts the bot once.

On OpenClaw

OpenClaw connects to n8n the same two ways — n8n calls the OpenClaw gateway API, and the agent calls n8n webhooks — but through OpenClaw's own gateway instead of Hermes's API server and webhook routes. See OpenClaw + n8n Integration. The n8n side (HTTP Request and Webhook nodes) is the same for both frameworks.

Frequently Asked Questions

Does Hermes Agent have an n8n node?

No. Hermes has no dedicated n8n node, and it does not need one. Its API server is OpenAI-compatible, so n8n's HTTP Request node, or its OpenAI credential with a custom base URL, talks to it directly.

What port does the Hermes API server use?

8642 by default, bound to 127.0.0.1. Change it with API_SERVER_PORT and API_SERVER_HOST. The webhook platform uses 8644.

Why does my n8n webhook to Hermes get rejected?

Usually the signature. Sign timestamp.body with the route secret, send the exact same body bytes, and use a timestamp within five minutes of the server clock.

Can I do the same with OpenClaw?

Yes, through OpenClaw's own mechanisms. The OpenClaw + n8n guide linked above covers that route.

Related Guides

Connect n8n to a Bot That's Already Running

OpenClaw Launch hosts Hermes Agent with an API endpoint and webhook ingress ready to switch on.

Deploy Managed Hermes