The complete Hermes โ Codex integration bundle โ Codex as a first-class Hermes tool, DeepSeek V4 Flash on the native Responses API, with bidirectional consult and cross-session context.
One picture, the whole architecture โ every layer tested and verified end-to-end:
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ LAYER 1 ยท MAIN BRAIN โ
โ Hermes Agent โ memory, persona, orchestration โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ main loop (Responses API) โฒ reverse consult
โผ โ (two channels)
โโโโโโโโโโโโโโโโโโโโโโโโโโ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ LAYER 2 ยท MODEL โ โ LAYER 3a ยท REVERSE CONSULT โ
โ deepseek-responses โ โ codex-plus-hermes-team MCP โ
โ api_mode: โ โ hermes_team_ask_agent โ
โ
โ codex_responses โ โ auto-resume live session โ
โ
โ api.deepseek.com โ โ model/provider pinned โ
โ
โ 1M context ยท no VPN โ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โโโโโโโโโโโโโโโโโโโโโโโโโโ โฒ
โ dispatch โ mcp__hermes_team__*
โผ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ LAYER 3b ยท EXECUTION TOOL (this repo) โ
โ codex tool โ Codex CLI 0.146+ โ
โ DeepSeek official models.json adapter โ
โ apply_patch native ยท effort levels ยท no VPN โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ session artifacts
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ LAYER 4 ยท CONTEXT & FALLBACK BRIDGE โ
โ Athena backend /hermes/ask (HTTP, any caller) โ
โ auto-resume live session ยท recall cache ยท memory read โ
โ standby role: L2 covers ask; Athena stays as fallback โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
็ฎไฝไธญๆ็
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ ็ฌฌ 1 ๅฑ ยท ไธป่ โ
โ Hermes Agent โโ ่ฎฐๅฟ ยท ไบบ่ฎพ ยท ็ผๆ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ ไธปๅพช็ฏ๏ผResponses API๏ผ โฒ ๅๅๅจ่ฏข๏ผๅ้้๏ผ
โผ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ ็ฌฌ 2 ๅฑ ยท ๆจกๅ โ โ ็ฌฌ 3a ๅฑ ยท ๅๅๅจ่ฏข โ
โ deepseek-responses โ โ codex-plus-hermes-team MCP โ
โ api_mode: codex_responses โ โ hermes_team_ask_agent โ
โ
โ api.deepseek.com โ โ ่ชๅจ resume ๅฝๅไผ่ฏ โ
โ
โ 1M ไธไธๆ ยท ๅ
ๆขฏๅญ โ โ ๆจกๅ/้้ pin ๅทฒไฟฎ โ
โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ ๆดพๅ โฒ mcp__hermes_team__*
โผ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ ็ฌฌ 3b ๅฑ ยท ๆง่กไฝ๏ผๆฌไปๅบ๏ผ โ
โ codex ๅทฅๅ
ท โ Codex CLI 0.146+ โ
โ DeepSeek ๅฎๆน models.json ้้
โ
โ apply_patch ๅ็ ยท ๆจ็ๆกฃไฝ ยท ๅ
ๆขฏๅญ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ ไผ่ฏไบง็ฉ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ ็ฌฌ 4 ๅฑ ยท ไธไธๆไธๅ
ๅบๆกฅ โ
โ Athena ๅ็ซฏ /hermes/ask๏ผHTTP๏ผไปปๆ่ฐ็จๆน๏ผ โ
โ ่ชๅจ resume ๅฝๅไผ่ฏ ยท recall ็ผๅญ ยท ่ฎฐๅฟ่ฏปๅ โ
โ ๅค็จ่ง่ฒ๏ผL2 ๅทฒ่ฆ็ ask๏ผAthena ้็บงไธบๅ
ๅบ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
The closed loop: Hermes thinks on the native Responses API โ dispatches to
Codex โ Codex executes with DeepSeek's official adaptation โ Codex consults
Hermes back through two verified channels โ native MCP (hermes_team_ask_agent,
auto-resumes the live Hermes session) and the HTTP fallback (Athena
/hermes/ask, any caller) โ context survives sessions (resume, read-only).
- The stack at a glance
- What this is
- Quick Start
- Repository layout
- Usage
- Orchestration rules
- Reverse consult (bidirectional loop)
- Configuration
- Troubleshooting
- Acknowledgements
- License
This is not just a plugin โ it is the assembled, tested recipe for the full Hermes โ Codex closed loop (see the diagram above):
- Hermes thinks over DeepSeek's native Responses API (
deepseek-responsesprovider, 1M context) - Hermes dispatches to Codex through the
codextool (this repo's plugin) - Codex executes with DeepSeek's official Codex adaptation (apply_patch, effort levels, multi-agent v2)
- Codex consults Hermes back โ native MCP (
hermes_team_ask_agent, auto-resumes the live session) or HTTP fallback (Athena/hermes/ask) - Context survives sessions โ both channels resume the live Hermes session read-only, so reverse-asks carry the real conversation, not a vacuum
See ARCHITECTURE.md for layer ownership details and INTEGRATION.md for the step-by-step assembly guide (every step verified on Windows 11).
Why this combination?
- DeepSeek officially adapted V4 Flash for Codex (native Responses API, full
models.jsonmetadata, one-click setup) โ no other agent CLI gets this depth. api.deepseek.comis reachable directly from China โ no VPN required.- Your API keys never touch disk: everything reads from env / Hermes
.env.
Full stack takes ~10 minutes following INTEGRATION.md. Plugin-only is ~2 minutes if Codex + DeepSeek are already configured.
Step 0 โ health check (recommended):
bash scripts/check-setup.sh # โ
all green โ proceed; โ tells you exactly what's missing# 1. Install the plugin into Hermes
# (ZIP downloads extract to <repo>-main/ โ rename or adjust the path)
cp -r hermes-codex-loop /path/to/hermes/runtime-data/plugins/
# 2. Point Codex CLI at DeepSeek (official one-click script โ choose deepseek-v4-flash)
# Windows: irm https://cdn.deepseek.com/api-docs/codex-deepseek-setup-en.ps1 | iex
# macOS/Linux: bash <(curl -fsSL https://cdn.deepseek.com/api-docs/codex-deepseek-setup-en.sh)
# 2b. IMPORTANT โ un-break MCP tool visibility (DeepSeek setup pitfall, openai/codex#36382):
# The official setup writes supports_search_tool=true + tool_mode=null, which
# silently hides ALL configured MCP tools in exec mode. Fix in ~/.codex/models.json:
# set "supports_search_tool": false for every deepseek model. check-setup.sh [7/7]
# detects the conflict automatically.
# 3. Make sure DEEPSEEK_API_KEY is visible to Hermes
export DEEPSEEK_API_KEY="sk-..." # or put it in your Hermes .envRestart Hermes. You now have a codex tool.
First smoke test โ ask Hermes:
Use the codex tool to create a hello.py in a git repo and run it.
Expected: Hermes calls codex, Codex writes the file, runs it, and reports the real output.
For the full stack (native Responses API main loop + reverse consult + recall), follow INTEGRATION.md โ it's the exact tested path.
hermes-codex-loop/
โโโ __init__.py # the plugin: `codex` tool + guidance + delegate injection
โโโ README.md # you are here
โโโ ARCHITECTURE.md # four-layer closed-loop diagram
โโโ INTEGRATION.md # step-by-step assembly (verified on Windows 11)
โโโ config/
โ โโโ hermes-config.example.yaml # deepseek-responses provider + Athena MCP blocks
โ โโโ codex-config.example.toml # ~/.codex/config.toml blocks (deepseek/zen/hermes-team)
โ โโโ team.example.yaml # codex-plus-hermes-team team.yaml template
โโโ LICENSE
| Parameter | Type | Default | Description |
|---|---|---|---|
task |
string | โ | What to build/fix/refactor. Be specific: files, expected behavior, constraints. |
model |
flash | pro |
flash |
flash โ deepseek-v4-flash๏ผpro โ deepseek-v4-pro๏ผๆไธๅฏ็จ๏ผๅฎๆน Codex ้ๆ 2026 ๅนด 8 ๆๅๅผๆพ๏ผๅฝๅ่ฟๅ invalid_request_error๏ผ |
directory |
string | cwd | Working directory (should be a git repo) |
verify |
bool | true |
Runs git diff --stat after execution |
# Daily fix
codex(task="Fix the flaky test in tests/auth_test.py and make sure the suite passes",
directory="/path/to/project")
# Complex architecture work
codex(task="Refactor the auth module into a plugin architecture with clear interfaces",
model="pro",
directory="/path/to/project")
# Skip verification for scratch work
codex(task="Scaffold a minimal FastAPI app", verify=false, directory="/tmp/scratch")
{
"status": "ok",
"model": "deepseek-v4-flash",
"output": "โฆreal output from Codexโฆ",
"git_diff_stat": " auth.py | 12 ++++++++++++"
}status is based on the real exit code โ this plugin never fabricates results.
Codex is the primary coding executor โ Hermes dispatches coding work to Codex instead of doing it inline. Three constraints + one boundary (inline one-line edits are allowed; everything else goes to Codex) are codified in AGENTS.md and enforced by the plugin's session guidance and delegate injection.
Two verified channels let Codex ask Hermes back โ both carry the live
conversation context (auto --resume of the most recent active session,
read-only, no pollution):
| L2 ยท native MCP | L1 ยท HTTP fallback | |
|---|---|---|
| How | mcp__hermes_team__hermes_team_ask_agent |
curl POST http://127.0.0.1:8390/hermes/ask |
| Requires | ~/.codex/config.toml hermes-team MCP + startup_timeout_sec=120 |
Athena backend running (Hermes venv python, PATH prefix) |
| Model pin | team.yaml: model: deepseek-v4-flash, provider: deepseek |
built into hermes.py |
| Context | auto-resume live session | auto-resume live session (or explicit session_id) |
| Status | โ verified (29s round trip, real answer) | โ verified (15s round trip) |
| Role | primary channel | fallback / any non-codex caller (scripts, other agents) |
Codex-side trigger โ ~/.codex/AGENTS.md (global) defines when to
reverse-ask: project conventions / user preferences / historical decisions
missing and material to the task. Ask once, verbatim answer, never block on
failure. Verified live: Codex asked a naming convention mid-task and followed
Hermes's answer (count_by_extension).
MCP toolset status (10 tools):
| Tool | Status | Notes |
|---|---|---|
hermes_team_ask_agent |
โ verified | sync consult, ~15-30s |
hermes_team_health / list_agents / inspect_agent / discover_roles |
โ present | diagnostics |
hermes_team_route / ask_panel |
โธ single-profile | meaningful with 2+ Hermes profiles |
hermes_team_create_task / get_task / collect_result |
โธ needs kanban | set kanban.enabled: true + Hermes kanban board |
All optional. Defaults work for the common Hermes layout.
| Env var | Default | Purpose |
|---|---|---|
CODEX_BIN |
D:/Agent/codex/node_modules/.bin/codex.cmd โ codex on PATH |
Codex CLI binary path |
HERMES_HOME |
โ | Hermes home dir (for .env discovery) |
HERMES_ENV_FILE |
โ | Explicit path to an .env file holding DEEPSEEK_API_KEY |
Key lookup order: DEEPSEEK_API_KEY env var โ $HERMES_HOME/.env โ ~/.hermes/.env โ <cwd>/.env.
delegate_task integration: for coding goals, the plugin auto-injects Codex
execution instructions into subagent context (marked with codex-injected to
avoid double injection).
| Symptom | Cause | Fix |
|---|---|---|
401 Unauthorized: Your api key: ****HERE> is invalid |
Codex sends the literal experimental_bearer_token placeholder from config.toml |
Use env_key = "DEEPSEEK_API_KEY" instead of experimental_bearer_token |
Codex writes nothing: "read-only sandbox" even with --sandbox workspace-write |
Known bug on Windows (codex 0.145/0.146): workspace-write behaves read-only | This plugin already uses --dangerously-bypass-approvals-and-sandbox โ keep it to trusted directories |
| Tool reports "codex CLI ๆชๆพๅฐ" | CODEX_BIN not set and Codex not on PATH |
Set CODEX_BIN to your codex.cmd/codex path, or add Codex to PATH |
| Tool reports "็ผบๅฐ DEEPSEEK_API_KEY" | Key not in env, Hermes .env, or HERMES_ENV_FILE |
Export the key or add it to one of the .env candidates |
Plugin loads but codex tool missing from the toolset |
Hermes hasn't reloaded plugins | Restart the Hermes session |
| Athena MCP bridge returns 502 to backend | System proxy (Clash/v2rayN) hijacks localhost via httpx | Set NO_PROXY=127.0.0.1,localhost in the MCP server env |
Athena backend: ModuleNotFoundError: backend |
Running backend/launcher.py directly |
Use python -m backend.launcher from the repo root |
Athena /hermes/ask โ 503 WinError 2 |
backend can't find hermes on its process PATH (Windows) |
Prefix PATH with hermes.exe's dir when launching backend โ see INTEGRATION.md |
MCP tools silently missing in codex exec (hermes-team tools never appear) |
DeepSeek official setup writes supports_search_tool=true + tool_mode=null in models.json โ hides all MCP tools (openai/codex#36382) |
Set "supports_search_tool": false for deepseek models in ~/.codex/models.json; check-setup.sh [7/7] verifies |
| MCP server "was not ready" / tools appear intermittently | hermes-team server starts slower than codex's default MCP timeout | Add startup_timeout_sec = 120 under [mcp_servers.hermes-team] in ~/.codex/config.toml |
Reverse-ask returns Zen 401 CreditsError |
hermes-team server didn't pin model/provider โ profile falls back to a paid gateway model | team.yaml: model: "deepseek-v4-flash", provider: "deepseek" (schema must include the fields โ keep dist in sync with src if you build manually) |
More traps (Windows build, npm registry, MSYS paths) in INTEGRATION.md.
โ ๏ธ Third-party license note: this repo is MIT and contains no third-party source code. It only links to and configures upstream projects. Upstream licenses: hermes-agent / hermes-code-bridge / codex-plus-hermes-team are MIT. Athena declares no license (no LICENSE file as of 2026-08) โ check its repo before depending on it for your own project.
The plugin is a thin, parameterized fork of patterns from; the bundle relies on:
- deepseek-router โ in-repo plugin pattern (
register_tool+pre_session_init+pre_tool_callhooks) - hermes-code-bridge โ Hermes-as-control-plane dispatch protocols
- Athena โ workspace orchestration, Hermes MCP bridge, recall
- codex-plus-hermes-team โ Codex consulting Hermes via MCP
- NousResearch/hermes-agent โ the platform this extends
- DeepSeek official Codex integration (models.json, setup scripts)