Model or dataset
AaronWong1999/hermesclaw avatar
AaronWong1999/hermesclaw

HermesClaw takes the iLink token away from both gateways and hands it back over localhost

Run Hermes Agent and OpenClaw on the same WeChat account

747 stars80 forksPythonMIT

At a glance

What is it?
A Python proxy of roughly 500 lines that becomes the sole poller for one WeChat iLink account, then feeds two local proxy servers and an ACP bridge so three coding agents stop fighting over the same connection. The installer edits two config keys in place and step eight is a systemd service.
Who is it for?
HermesClaw solves a narrow problem cleanly, and the narrowness is the point. If you want Hermes Agent and OpenClaw both reachable from one WeChat account, the alternative is two gateways contending for one iLink connection until one of them starts returning 403 and dropping messages.
Can I use it commercially?
Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 5 days ago.
What is it written in?
Mainly Python, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on October 5, 2026, and from our analysis. They are not legal advice.

Editorial analysis

The installer takes the token and repoints two other projects

The problem this addresses is a connection, not a feature. Both Hermes Agent and OpenClaw support WeChat natively, but each gateway takes an exclusive lock on the iLink connection. Run both against one account and one of them starts returning 403 and dropping messages. HermesClaw inserts itself between them: it becomes the sole iLink poller and token owner, then serves two local proxies, one for Hermes and one for OpenClaw, plus a direct ACP bridge for OpenCode. Each gateway keeps believing it is talking to the real iLink API.

What the installer actually does is worth reading line by line, because it edits files it does not own. Its eight steps are: detect which gateways are installed and configured; extract the iLink token from gateway account files; patch the `baseUrl` of `openclaw-weixin` to `http://127.0.0.1:19999`; patch Hermes `WEIXIN_BASE_URL` to `http://127.0.0.1:19998`; detect the OpenCode CLI as an optional step that enables `/opencode` and `/three`; install the Python dependencies; create an OpenClaw media symlink described as a workaround for a media path mismatch; and set up the `hermesclaw` systemd service.

Two ports, two config keys, one token, and a symlink. There is no configuration file of its own in the repository tree, so the state of the install lives entirely in the files the installer rewrote.

The architecture diagram calls the proxy v3 and the newest tag is v0.4.0

The architecture block draws the path from the iLink API at `ilinkai.weixin.qq.com` down through a box labelled sole poller and token owner, into a box labelled `HermesClaw v3`, which routes by `/hermes`, `/openclaw`, `/opencode` and `/three` and queues raw iLink messages. The diagram stops partway through the box below that one.

The version label in the diagram does not line up with the release history. The newest tag is `v0.4.0`, titled macOS Support, from 2026-06-15. Before it sit `v0.3.6` from 2026-04-29, titled macOS bash 3 compat plus a curl to bash stdin fix, and `v0.3.5` from 2026-04-28, whose title is in Chinese and describes automatic detection of conflicting leftover services. Nothing in the tags reaches 3, so `v3` in the diagram refers to something other than the package version, and the page does not say what.

The scope statement that follows the diagram is the clearest description of the project's limits. HermesClaw is described as a thin Python proxy of about 500 lines that does not process media, does not call agent APIs and does not touch agent memory. It queues and forwards raw iLink protocol messages. Each gateway handles its own media decryption, its own markdown formatting and its own AI interaction natively.

The command table stops in the middle of the /both row

Routing is driven entirely by slash commands sent in WeChat. The documented set is `/hermes` to route to Hermes only, `/openclaw` to route to OpenClaw only, `/opencode` to route to OpenCode only through the ACP bridge, `/both` to route to Hermes and OpenClaw together, and `/three` for all three. The header line puts it as one iLink account and three AI brains switched with those five commands.

The table describing them ends partway through the `/both` row, after the words reply from bot, so what `/both` actually replies with, and what `/three` does differently from `/both`, are not on the page. The comparison table above it fills in some of that by implication: without the proxy, both agents on one account is a token conflict producing 403s, and all three is impossible; with it, `/both` and `/three` are the two states that make those rows check out.

The same table also shows where the proxy stops working. Voice messages and images, video and files are marked as handled natively by each agent on its own, and with HermesClaw as transcription forwarded and raw iLink message forwarded. That matches the stated scope of the proxy: it queues and forwards raw protocol messages and leaves decryption and formatting to each gateway.

One capability claim belongs to the OpenCode path rather than the proxy. Sending voice messages in WeChat for coding is attributed to OpenCode, backed by four free models, one of which is named as MiniMax M2.5 Free.

curl to a bash script is still the primary install

The quick install is one line:

bash
curl -fsSL https://raw.githubusercontent.com/AaronWong1999/hermesclaw/main/install.sh | bash

For non-interactive or automated installs, which skip every confirmation prompt, there is a second form:

bash
curl -fsSL https://raw.githubusercontent.com/AaronWong1999/hermesclaw/main/install.sh | HERMESCLAW_YES=1 bash
# or, when running the script directly:
bash install.sh -y

The `HERMESCLAW_YES=1` prefix and the `-y` flag are the two documented ways to remove the prompts, which means the default path asks before each of its eight steps. After the install finishes you are told to restart your gateways and send `/whoami` in WeChat, which is both the smoke test and the only verification step described anywhere.

The pipe form is worth noting against the release history. `v0.3.6` is titled as a curl to bash stdin fix, so the exact form promoted here had a stdin defect until April 2026. `install.sh` lives in the repository root, so `bash install.sh -y` from a clone avoids the pipe entirely and lets you read the script first, which matters more than usual here because the script edits the configuration of two other projects.

There is also a `fix_hermes_splitting.sh` at the repository root, a second shell script whose purpose the page never explains, alongside `hermesclaw.py`, `requirements.txt`, `tests/` and a `docs/` directory.

The AI-assisted install prompt ends in the middle of a command

The page offers a prompt to paste into any AI agent running on the target machine. It instructs the agent to run the curl to bash install, then read `README.md` and `install.sh` from the installed directory, detect whether Hermes Agent, OpenClaw, their WeChat gateways, python3, pip3 and systemd are present, extract the iLink token from the first available gateway account file, patch the `openclaw-weixin` `baseUrl` to `http://127.0.0.1:19999` and the Hermes `WEIXIN_BASE_URL` to `http://127.0.0.1:19998`, install the dependencies and the systemd service, and then detect the OpenCode CLI by running a `command -v` check.

That last instruction stops partway through, after `command -v open`, with no closing and no further steps. The block therefore ends while it is still describing the optional third agent, which is also the one whose addition is newest in this project.

What the prompt does establish is the intended division of labour. A human is expected to read `install.sh` before the agent runs it, and the agent is expected to stop if no gateway is configured. The prerequisite is at least one of two things: OpenClaw with clawbot, the package called `openclaw-weixin`, installed and logged into WeChat; or Hermes Agent with a WeChat gateway configured through `hermes gateway`. Both installed gives full dual-open, one installed gives single-agent mode with the option to add the other later.

systemd is step eight, which the macOS release title does not explain

The eighth installer step is setting up the `hermesclaw` systemd service, and the AI-assisted prompt lists `systemd` among the things to detect. Nothing else in the project offers a different supervision story, and there is no launchd plist, no Docker file and no Windows service anywhere in the repository tree.

That sits awkwardly beside the release history. `v0.4.0` is titled macOS Support. `v0.3.6` is titled macOS bash 3 compat plus a curl to bash stdin fix. Both of those read as installer compatibility work: getting a bash script to behave under the bash that ships with macOS, and getting the pipe form to accept stdin correctly. Neither title mentions the service manager, and the installer step that does depend on one is unconditional.

So the documented path is Linux, with the scripts made portable enough to run on macOS up to the point where the service is created. If you are on macOS, step eight is where the documented procedure stops, and the page offers no alternative.

The `.github/` directory and `tests/` are the only other places the project's own quality gates live, and neither is referenced by the install path or the commands.

Two dependencies with open lower bounds and no lockfile

`requirements.txt` is two lines long. It asks for `requests>=2.28` and `python-dotenv>=1.0`, which is the entire dependency set for a process that has to hold a live token, poll a network endpoint, keep a queue of raw protocol messages and speak HTTP to two local gateways.

Both are lower bounds with no upper pin and no lockfile in the repository, so a fresh install resolves whatever versions the index offers at that moment. There is no `pyproject.toml`, no package manifest and no build configuration of any kind; the project is run as a script, `hermesclaw.py`, at the repository root next to `install.sh`.

That file size is the other half of the story. At roughly 500 lines, and with media handling, agent API calls and memory explicitly out of scope, the entire security surface is the token it reads from another tool's account file plus the two config keys it rewrites. The token is what authenticates your WeChat account to the iLink API, and after the install it is not new information to anyone who already had gateway access, but it is new information to whatever else reads those account files.

For a proxy that has to be the only process talking to a third party service on your behalf, that is a reasonable size to read end to end before you install it.

Editorial conclusion

HermesClaw solves a narrow problem cleanly, and the narrowness is the point. If you want Hermes Agent and OpenClaw both reachable from one WeChat account, the alternative is two gateways contending for one iLink connection until one of them starts returning 403 and dropping messages. Making a single process the sole poller and pointing both gateways at `127.0.0.1` removes the contention without either gateway knowing it happened. `/hermes`, `/openclaw`, `/opencode`, `/both` and `/three` then become the whole user interface.

Read the installer before you pipe it into a shell, because it reaches into other tools' configuration. It extracts the iLink token from gateway account files, rewrites the `baseUrl` of `openclaw-weixin` and the `WEIXIN_BASE_URL` of Hermes to point at localhost, and creates a media symlink in the OpenClaw install. Those are edits to files owned by other projects, and the token it copies is a live credential for your account. `install.sh` is in the repository root, so read it rather than trusting the pipe.

Two limitations to accept up front. Step eight installs a systemd service, so the documented path is Linux only even though a release is titled macOS Support; the macOS work in the release history is installer compatibility. And the two Python dependencies are declared with open lower bounds, `requests>=2.28` and `python-dotenv>=1.0`, with no lockfile in the repository, so what a fresh install resolves is not pinned. The proxy itself is small enough to read end to end, which is the strongest argument for trying it.

Frequently asked questions

What problem does HermesClaw actually solve?

Hermes Agent and OpenClaw each take an exclusive lock on the WeChat iLink connection, so running both on one account makes one of them return 403 and drop messages. HermesClaw becomes the sole poller and serves two local proxies so each gateway connects to localhost instead.

Which ports does HermesClaw use?

Two. The installer patches the baseUrl of openclaw-weixin to http://127.0.0.1:19999 and the WEIXIN_BASE_URL of Hermes to http://127.0.0.1:19998. OpenCode is reached through a direct ACP bridge rather than a port of its own.

What does the HermesClaw installer change on my machine?

It detects installed gateways, extracts the iLink token from gateway account files, rewrites two base URL keys to point at localhost, installs requests and python-dotenv, creates an OpenClaw media symlink as a workaround for a media path mismatch, and sets up a hermesclaw systemd service.

Does HermesClaw handle images, video and voice messages itself?

No. It is described as a thin proxy of about 500 lines that does not process media, call agent APIs or touch agent memory, and simply queues and forwards raw iLink protocol messages. Each gateway does its own media decryption and formatting.

Can I install HermesClaw without the interactive prompts?

Yes. Prefix the install with HERMESCLAW_YES=1 in front of bash, or run bash install.sh -y if you are running the script from a clone. Both forms skip every confirmation prompt.

Does HermesClaw work on macOS?

The installer carries macOS compatibility work: v0.3.6 is titled macOS bash 3 compat plus a curl to bash stdin fix, and v0.4.0 is titled macOS Support. Step eight of the install still sets up a systemd service, and no alternative service manager is described.

Official sources

  1. AaronWong1999/hermesclaw on GitHub
  2. Issues
  3. License: MIT
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/aaronwong1999-hermesclaw.svg)](https://hysenlabs.com/projects/aaronwong1999-hermesclaw)