chore(hermes): pin payments-enabled agent image - #648

Closed
bussyjd wants to merge 2 commits into
integration/v0.11.0from
codex/hermes-agent-stripe-image
Closed

chore(hermes): pin payments-enabled agent image#648
bussyjd wants to merge 2 commits into
integration/v0.11.0from
codex/hermes-agent-stripe-image

Conversation

@bussyjd

@bussyjdbussyjd commented Jun 16, 2026

Copy link
Copy Markdown
Contributor

Summary

Bump the default Hermes agent image used by both Obol-managed Hermes runtimes to a digest-pinned upstream image that contains the new optional payments skills:

  • internal/hermes/hermes.go master agent default: nousresearch/hermes-agent:v2026.6.5 -> nousresearch/hermes-agent:main@sha256:e9f2892b626468d2a65abeae9f94ec0a71872d7d9643906b956ab29c9bf328a9
  • internal/serviceoffercontroller/agent_render.go Agent CRD/sub-agent default: same pinned image ref

Why main@sha256: the latest dated Docker tag visible on Docker Hub is still v2026.6.5, published before Hermes commit 5bfed0fe0 (feat(skills): add optional payments skills (Stripe Link, MPP, Projects)). Docker Hub shows main/latest updated after that commit, and the current multi-arch manifest digest is pinned here:

nousresearch/hermes-agent:main@sha256:e9f2892b626468d2a65abeae9f94ec0a71872d7d9643906b956ab29c9bf328a9

This keeps the train reproducible while we wait for Hermes to publish the next dated release tag containing the optional payments skills. Once that tag exists, replace this temporary digest pin with the release tag plus digest.

Compatibility Pass Map

flowchart TB
A["Hermes upstream main image pinned by digest"] --> B["Optional payments skills available in agent pod"]
B --> C["stripe-link-cli skill"]
B --> D["mpp-agent skill"]
C --> E["Stripe Link approval + Shared Payment Token"]
D --> F["MPP client probes HTTP 402 merchant"]
G["Obol seller card route"] --> H{"402 challenge wire"}
H -->|"current Obol"| I["PAYMENT-REQUIRED JSON + X-PAYMENT retry"]
H -->|"Hermes/Stripe MPP target"| J["WWW-Authenticate: Payment method=stripe"]
E --> K["Buyer retries with payment credential"]
F --> K
K --> L["x402-verifier card gate"]
L --> M["Stripe PaymentIntent authorize"]
M --> N["Proxy upstream"]
N --> O{"Upstream <400?"}
O -->|"yes"| P["Capture PaymentIntent + return receipt"]
O -->|"no"| Q["Cancel hold + return failure"]
I -.-> R["Follow-up: bridge/dual-advertise wire format"]
J -.-> R
Loading

Stripe / SPT Flow

sequenceDiagram
autonumber
participant Buyer as Hermes agent payment skill
participant StripeLink as Stripe Link CLI
participant Seller as Obol paid service
participant Verifier as x402-verifier card gate
participant Stripe as Stripe PaymentIntents
participant Upstream as Seller upstream
Buyer->>Seller: Request paid resource without credential
Seller-->>Buyer: 402 with Stripe MPP challenge
Buyer->>StripeLink: Create approved spend request for shared_payment_token
StripeLink-->>Buyer: SPT credential after user approval
Buyer->>Seller: Retry with payment credential
Seller->>Verifier: Route to card gate
Verifier->>Stripe: Authorize manual-capture PaymentIntent with SPT
Stripe-->>Verifier: requires_capture
Verifier->>Upstream: Proxy request
alt upstream succeeds
Upstream-->>Verifier: 2xx/3xx response
Verifier->>Stripe: Capture PaymentIntent
Stripe-->>Verifier: succeeded
Verifier-->>Buyer: Upstream response + payment receipt
else upstream fails
Upstream-->>Verifier: 4xx/5xx or no response
Verifier->>Stripe: Cancel PaymentIntent hold
Verifier-->>Buyer: Failure, buyer not charged
end
Loading

MPP / x402 Compatibility Work Remaining

flowchart LR
A["Current Obol card path"] --> B["Scheme card / network stripe in x402 PaymentRequired"]
A --> C["Credential read from X-PAYMENT"]
A --> D["Receipt in X-PAYMENT-RESPONSE"]
E["Hermes + Stripe MPP expectation"] --> F["WWW-Authenticate: Payment ... method=stripe"]
E --> G["Authorization: Payment ... credential"]
E --> H["Authentication-Info receipt"]
E --> I["networkId is Stripe profile_ / profile_test_ id"]
B --> J["Compatibility pass"]
C --> J
D --> J
F --> J
G --> J
H --> J
I --> J
J --> K["Emit MPP challenge alongside x402 challenge"]
J --> L["Accept MPP Authorization credential or translate to existing SPT payload"]
J --> M["Return MPP receipt while preserving x402 receipt for existing buyers"]
J --> N["Update CLI/docs from stripenet_* examples to profile_* / profile_test_*"]
Loading

Validation

  • git diff --check
  • go test ./internal/hermes ./internal/serviceoffercontroller ./internal/agentcrd -count=1
  • docker buildx imagetools inspect nousresearch/hermes-agent:main
  • Docker Hub tag listing checked: no dated tag newer than v2026.6.5 is currently published; main/latest resolve to sha256:e9f2892b626468d2a65abeae9f94ec0a71872d7d9643906b956ab29c9bf328a9.

Follow-up

  • Replace this temporary main@sha256:... pin with the next dated Hermes release tag plus digest once available.
  • Implement the MPP wire compatibility pass described above before declaring Obol card payments interoperable with Hermes/Stripe Link.

@bussyjdbussyjd changed the title chore(hermes): use payments-enabled agent imagechore(hermes): pin payments-enabled agent imageJun 16, 2026
@bussyjdbussyjd closed this Jun 16, 2026
@bussyjd
bussyjd deleted the codex/hermes-agent-stripe-image branch June 16, 2026 17:11
@bussyjd

Copy link
Copy Markdown
ContributorAuthor

Closed after renaming the head branch off the codex/ prefix. Replacement PR with the corrected branch name and fixed Mermaid diagram: #649.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@bussyjd
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

chore(hermes): pin payments-enabled agent image - #648

Closed
bussyjd wants to merge 2 commits into
integration/v0.11.0from
codex/hermes-agent-stripe-image
Closed

chore(hermes): pin payments-enabled agent image#648
bussyjd wants to merge 2 commits into
integration/v0.11.0from
codex/hermes-agent-stripe-image

Conversation

@bussyjd

@bussyjdbussyjd commented Jun 16, 2026

Copy link
Copy Markdown
Contributor

Summary

Bump the default Hermes agent image used by both Obol-managed Hermes runtimes to a digest-pinned upstream image that contains the new optional payments skills:

  • internal/hermes/hermes.go master agent default: nousresearch/hermes-agent:v2026.6.5 -> nousresearch/hermes-agent:main@sha256:e9f2892b626468d2a65abeae9f94ec0a71872d7d9643906b956ab29c9bf328a9
  • internal/serviceoffercontroller/agent_render.go Agent CRD/sub-agent default: same pinned image ref

Why main@sha256: the latest dated Docker tag visible on Docker Hub is still v2026.6.5, published before Hermes commit 5bfed0fe0 (feat(skills): add optional payments skills (Stripe Link, MPP, Projects)). Docker Hub shows main/latest updated after that commit, and the current multi-arch manifest digest is pinned here:

nousresearch/hermes-agent:main@sha256:e9f2892b626468d2a65abeae9f94ec0a71872d7d9643906b956ab29c9bf328a9

This keeps the train reproducible while we wait for Hermes to publish the next dated release tag containing the optional payments skills. Once that tag exists, replace this temporary digest pin with the release tag plus digest.

Compatibility Pass Map

flowchart TB
A["Hermes upstream main image pinned by digest"] --> B["Optional payments skills available in agent pod"]
B --> C["stripe-link-cli skill"]
B --> D["mpp-agent skill"]
C --> E["Stripe Link approval + Shared Payment Token"]
D --> F["MPP client probes HTTP 402 merchant"]
G["Obol seller card route"] --> H{"402 challenge wire"}
H -->|"current Obol"| I["PAYMENT-REQUIRED JSON + X-PAYMENT retry"]
H -->|"Hermes/Stripe MPP target"| J["WWW-Authenticate: Payment method=stripe"]
E --> K["Buyer retries with payment credential"]
F --> K
K --> L["x402-verifier card gate"]
L --> M["Stripe PaymentIntent authorize"]
M --> N["Proxy upstream"]
N --> O{"Upstream <400?"}
O -->|"yes"| P["Capture PaymentIntent + return receipt"]
O -->|"no"| Q["Cancel hold + return failure"]
I -.-> R["Follow-up: bridge/dual-advertise wire format"]
J -.-> R
Loading

Stripe / SPT Flow

sequenceDiagram
autonumber
participant Buyer as Hermes agent payment skill
participant StripeLink as Stripe Link CLI
participant Seller as Obol paid service
participant Verifier as x402-verifier card gate
participant Stripe as Stripe PaymentIntents
participant Upstream as Seller upstream
Buyer->>Seller: Request paid resource without credential
Seller-->>Buyer: 402 with Stripe MPP challenge
Buyer->>StripeLink: Create approved spend request for shared_payment_token
StripeLink-->>Buyer: SPT credential after user approval
Buyer->>Seller: Retry with payment credential
Seller->>Verifier: Route to card gate
Verifier->>Stripe: Authorize manual-capture PaymentIntent with SPT
Stripe-->>Verifier: requires_capture
Verifier->>Upstream: Proxy request
alt upstream succeeds
Upstream-->>Verifier: 2xx/3xx response
Verifier->>Stripe: Capture PaymentIntent
Stripe-->>Verifier: succeeded
Verifier-->>Buyer: Upstream response + payment receipt
else upstream fails
Upstream-->>Verifier: 4xx/5xx or no response
Verifier->>Stripe: Cancel PaymentIntent hold
Verifier-->>Buyer: Failure, buyer not charged
end
Loading

MPP / x402 Compatibility Work Remaining

flowchart LR
A["Current Obol card path"] --> B["Scheme card / network stripe in x402 PaymentRequired"]
A --> C["Credential read from X-PAYMENT"]
A --> D["Receipt in X-PAYMENT-RESPONSE"]
E["Hermes + Stripe MPP expectation"] --> F["WWW-Authenticate: Payment ... method=stripe"]
E --> G["Authorization: Payment ... credential"]
E --> H["Authentication-Info receipt"]
E --> I["networkId is Stripe profile_ / profile_test_ id"]
B --> J["Compatibility pass"]
C --> J
D --> J
F --> J
G --> J
H --> J
I --> J
J --> K["Emit MPP challenge alongside x402 challenge"]
J --> L["Accept MPP Authorization credential or translate to existing SPT payload"]
J --> M["Return MPP receipt while preserving x402 receipt for existing buyers"]
J --> N["Update CLI/docs from stripenet_* examples to profile_* / profile_test_*"]
Loading

Validation

  • git diff --check
  • go test ./internal/hermes ./internal/serviceoffercontroller ./internal/agentcrd -count=1
  • docker buildx imagetools inspect nousresearch/hermes-agent:main
  • Docker Hub tag listing checked: no dated tag newer than v2026.6.5 is currently published; main/latest resolve to sha256:e9f2892b626468d2a65abeae9f94ec0a71872d7d9643906b956ab29c9bf328a9.

Follow-up

  • Replace this temporary main@sha256:... pin with the next dated Hermes release tag plus digest once available.
  • Implement the MPP wire compatibility pass described above before declaring Obol card payments interoperable with Hermes/Stripe Link.

@bussyjdbussyjd changed the title chore(hermes): use payments-enabled agent imagechore(hermes): pin payments-enabled agent imageJun 16, 2026
@bussyjdbussyjd closed this Jun 16, 2026
@bussyjd
bussyjd deleted the codex/hermes-agent-stripe-image branch June 16, 2026 17:11
@bussyjd

Copy link
Copy Markdown
ContributorAuthor

Closed after renaming the head branch off the codex/ prefix. Replacement PR with the corrected branch name and fixed Mermaid diagram: #649.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@bussyjd
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(hermes): pin payments-enabled agent image - #648

Closed
bussyjd wants to merge 2 commits into
integration/v0.11.0from
codex/hermes-agent-stripe-image
Closed

chore(hermes): pin payments-enabled agent image#648
bussyjd wants to merge 2 commits into
integration/v0.11.0from
codex/hermes-agent-stripe-image

Conversation

@bussyjd

@bussyjdbussyjd commented Jun 16, 2026

Copy link
Copy Markdown
Contributor

Summary

Bump the default Hermes agent image used by both Obol-managed Hermes runtimes to a digest-pinned upstream image that contains the new optional payments skills:

  • internal/hermes/hermes.go master agent default: nousresearch/hermes-agent:v2026.6.5 -> nousresearch/hermes-agent:main@sha256:e9f2892b626468d2a65abeae9f94ec0a71872d7d9643906b956ab29c9bf328a9
  • internal/serviceoffercontroller/agent_render.go Agent CRD/sub-agent default: same pinned image ref

Why main@sha256: the latest dated Docker tag visible on Docker Hub is still v2026.6.5, published before Hermes commit 5bfed0fe0 (feat(skills): add optional payments skills (Stripe Link, MPP, Projects)). Docker Hub shows main/latest updated after that commit, and the current multi-arch manifest digest is pinned here:

nousresearch/hermes-agent:main@sha256:e9f2892b626468d2a65abeae9f94ec0a71872d7d9643906b956ab29c9bf328a9

This keeps the train reproducible while we wait for Hermes to publish the next dated release tag containing the optional payments skills. Once that tag exists, replace this temporary digest pin with the release tag plus digest.

Compatibility Pass Map

flowchart TB
A["Hermes upstream main image pinned by digest"] --> B["Optional payments skills available in agent pod"]
B --> C["stripe-link-cli skill"]
B --> D["mpp-agent skill"]
C --> E["Stripe Link approval + Shared Payment Token"]
D --> F["MPP client probes HTTP 402 merchant"]
G["Obol seller card route"] --> H{"402 challenge wire"}
H -->|"current Obol"| I["PAYMENT-REQUIRED JSON + X-PAYMENT retry"]
H -->|"Hermes/Stripe MPP target"| J["WWW-Authenticate: Payment method=stripe"]
E --> K["Buyer retries with payment credential"]
F --> K
K --> L["x402-verifier card gate"]
L --> M["Stripe PaymentIntent authorize"]
M --> N["Proxy upstream"]
N --> O{"Upstream <400?"}
O -->|"yes"| P["Capture PaymentIntent + return receipt"]
O -->|"no"| Q["Cancel hold + return failure"]
I -.-> R["Follow-up: bridge/dual-advertise wire format"]
J -.-> R
Loading

Stripe / SPT Flow

sequenceDiagram
autonumber
participant Buyer as Hermes agent payment skill
participant StripeLink as Stripe Link CLI
participant Seller as Obol paid service
participant Verifier as x402-verifier card gate
participant Stripe as Stripe PaymentIntents
participant Upstream as Seller upstream
Buyer->>Seller: Request paid resource without credential
Seller-->>Buyer: 402 with Stripe MPP challenge
Buyer->>StripeLink: Create approved spend request for shared_payment_token
StripeLink-->>Buyer: SPT credential after user approval
Buyer->>Seller: Retry with payment credential
Seller->>Verifier: Route to card gate
Verifier->>Stripe: Authorize manual-capture PaymentIntent with SPT
Stripe-->>Verifier: requires_capture
Verifier->>Upstream: Proxy request
alt upstream succeeds
Upstream-->>Verifier: 2xx/3xx response
Verifier->>Stripe: Capture PaymentIntent
Stripe-->>Verifier: succeeded
Verifier-->>Buyer: Upstream response + payment receipt
else upstream fails
Upstream-->>Verifier: 4xx/5xx or no response
Verifier->>Stripe: Cancel PaymentIntent hold
Verifier-->>Buyer: Failure, buyer not charged
end
Loading

MPP / x402 Compatibility Work Remaining

flowchart LR
A["Current Obol card path"] --> B["Scheme card / network stripe in x402 PaymentRequired"]
A --> C["Credential read from X-PAYMENT"]
A --> D["Receipt in X-PAYMENT-RESPONSE"]
E["Hermes + Stripe MPP expectation"] --> F["WWW-Authenticate: Payment ... method=stripe"]
E --> G["Authorization: Payment ... credential"]
E --> H["Authentication-Info receipt"]
E --> I["networkId is Stripe profile_ / profile_test_ id"]
B --> J["Compatibility pass"]
C --> J
D --> J
F --> J
G --> J
H --> J
I --> J
J --> K["Emit MPP challenge alongside x402 challenge"]
J --> L["Accept MPP Authorization credential or translate to existing SPT payload"]
J --> M["Return MPP receipt while preserving x402 receipt for existing buyers"]
J --> N["Update CLI/docs from stripenet_* examples to profile_* / profile_test_*"]
Loading

Validation

  • git diff --check
  • go test ./internal/hermes ./internal/serviceoffercontroller ./internal/agentcrd -count=1
  • docker buildx imagetools inspect nousresearch/hermes-agent:main
  • Docker Hub tag listing checked: no dated tag newer than v2026.6.5 is currently published; main/latest resolve to sha256:e9f2892b626468d2a65abeae9f94ec0a71872d7d9643906b956ab29c9bf328a9.

Follow-up

  • Replace this temporary main@sha256:... pin with the next dated Hermes release tag plus digest once available.
  • Implement the MPP wire compatibility pass described above before declaring Obol card payments interoperable with Hermes/Stripe Link.

@bussyjdbussyjd changed the title chore(hermes): use payments-enabled agent imagechore(hermes): pin payments-enabled agent imageJun 16, 2026
@bussyjdbussyjd closed this Jun 16, 2026
@bussyjd
bussyjd deleted the codex/hermes-agent-stripe-image branch June 16, 2026 17:11
@bussyjd

Copy link
Copy Markdown
ContributorAuthor

Closed after renaming the head branch off the codex/ prefix. Replacement PR with the corrected branch name and fixed Mermaid diagram: #649.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@bussyjd
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(hermes): pin payments-enabled agent image - #648

Closed
bussyjd wants to merge 2 commits into
integration/v0.11.0from
codex/hermes-agent-stripe-image
Closed

chore(hermes): pin payments-enabled agent image#648
bussyjd wants to merge 2 commits into
integration/v0.11.0from
codex/hermes-agent-stripe-image

Conversation

@bussyjd

@bussyjdbussyjd commented Jun 16, 2026

Copy link
Copy Markdown
Contributor

Summary

Bump the default Hermes agent image used by both Obol-managed Hermes runtimes to a digest-pinned upstream image that contains the new optional payments skills:

  • internal/hermes/hermes.go master agent default: nousresearch/hermes-agent:v2026.6.5 -> nousresearch/hermes-agent:main@sha256:e9f2892b626468d2a65abeae9f94ec0a71872d7d9643906b956ab29c9bf328a9
  • internal/serviceoffercontroller/agent_render.go Agent CRD/sub-agent default: same pinned image ref

Why main@sha256: the latest dated Docker tag visible on Docker Hub is still v2026.6.5, published before Hermes commit 5bfed0fe0 (feat(skills): add optional payments skills (Stripe Link, MPP, Projects)). Docker Hub shows main/latest updated after that commit, and the current multi-arch manifest digest is pinned here:

nousresearch/hermes-agent:main@sha256:e9f2892b626468d2a65abeae9f94ec0a71872d7d9643906b956ab29c9bf328a9

This keeps the train reproducible while we wait for Hermes to publish the next dated release tag containing the optional payments skills. Once that tag exists, replace this temporary digest pin with the release tag plus digest.

Compatibility Pass Map

flowchart TB
A["Hermes upstream main image pinned by digest"] --> B["Optional payments skills available in agent pod"]
B --> C["stripe-link-cli skill"]
B --> D["mpp-agent skill"]
C --> E["Stripe Link approval + Shared Payment Token"]
D --> F["MPP client probes HTTP 402 merchant"]
G["Obol seller card route"] --> H{"402 challenge wire"}
H -->|"current Obol"| I["PAYMENT-REQUIRED JSON + X-PAYMENT retry"]
H -->|"Hermes/Stripe MPP target"| J["WWW-Authenticate: Payment method=stripe"]
E --> K["Buyer retries with payment credential"]
F --> K
K --> L["x402-verifier card gate"]
L --> M["Stripe PaymentIntent authorize"]
M --> N["Proxy upstream"]
N --> O{"Upstream <400?"}
O -->|"yes"| P["Capture PaymentIntent + return receipt"]
O -->|"no"| Q["Cancel hold + return failure"]
I -.-> R["Follow-up: bridge/dual-advertise wire format"]
J -.-> R
Loading

Stripe / SPT Flow

sequenceDiagram
autonumber
participant Buyer as Hermes agent payment skill
participant StripeLink as Stripe Link CLI
participant Seller as Obol paid service
participant Verifier as x402-verifier card gate
participant Stripe as Stripe PaymentIntents
participant Upstream as Seller upstream
Buyer->>Seller: Request paid resource without credential
Seller-->>Buyer: 402 with Stripe MPP challenge
Buyer->>StripeLink: Create approved spend request for shared_payment_token
StripeLink-->>Buyer: SPT credential after user approval
Buyer->>Seller: Retry with payment credential
Seller->>Verifier: Route to card gate
Verifier->>Stripe: Authorize manual-capture PaymentIntent with SPT
Stripe-->>Verifier: requires_capture
Verifier->>Upstream: Proxy request
alt upstream succeeds
Upstream-->>Verifier: 2xx/3xx response
Verifier->>Stripe: Capture PaymentIntent
Stripe-->>Verifier: succeeded
Verifier-->>Buyer: Upstream response + payment receipt
else upstream fails
Upstream-->>Verifier: 4xx/5xx or no response
Verifier->>Stripe: Cancel PaymentIntent hold
Verifier-->>Buyer: Failure, buyer not charged
end
Loading

MPP / x402 Compatibility Work Remaining

flowchart LR
A["Current Obol card path"] --> B["Scheme card / network stripe in x402 PaymentRequired"]
A --> C["Credential read from X-PAYMENT"]
A --> D["Receipt in X-PAYMENT-RESPONSE"]
E["Hermes + Stripe MPP expectation"] --> F["WWW-Authenticate: Payment ... method=stripe"]
E --> G["Authorization: Payment ... credential"]
E --> H["Authentication-Info receipt"]
E --> I["networkId is Stripe profile_ / profile_test_ id"]
B --> J["Compatibility pass"]
C --> J
D --> J
F --> J
G --> J
H --> J
I --> J
J --> K["Emit MPP challenge alongside x402 challenge"]
J --> L["Accept MPP Authorization credential or translate to existing SPT payload"]
J --> M["Return MPP receipt while preserving x402 receipt for existing buyers"]
J --> N["Update CLI/docs from stripenet_* examples to profile_* / profile_test_*"]
Loading

Validation

  • git diff --check
  • go test ./internal/hermes ./internal/serviceoffercontroller ./internal/agentcrd -count=1
  • docker buildx imagetools inspect nousresearch/hermes-agent:main
  • Docker Hub tag listing checked: no dated tag newer than v2026.6.5 is currently published; main/latest resolve to sha256:e9f2892b626468d2a65abeae9f94ec0a71872d7d9643906b956ab29c9bf328a9.

Follow-up

  • Replace this temporary main@sha256:... pin with the next dated Hermes release tag plus digest once available.
  • Implement the MPP wire compatibility pass described above before declaring Obol card payments interoperable with Hermes/Stripe Link.

@bussyjdbussyjd changed the title chore(hermes): use payments-enabled agent imagechore(hermes): pin payments-enabled agent imageJun 16, 2026
@bussyjdbussyjd closed this Jun 16, 2026
@bussyjd
bussyjd deleted the codex/hermes-agent-stripe-image branch June 16, 2026 17:11
@bussyjd

Copy link
Copy Markdown
ContributorAuthor

Closed after renaming the head branch off the codex/ prefix. Replacement PR with the corrected branch name and fixed Mermaid diagram: #649.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@bussyjd
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

chore(hermes): pin payments-enabled agent image - #648

Closed
bussyjd wants to merge 2 commits into
integration/v0.11.0from
codex/hermes-agent-stripe-image
Closed

chore(hermes): pin payments-enabled agent image#648
bussyjd wants to merge 2 commits into
integration/v0.11.0from
codex/hermes-agent-stripe-image

Conversation

@bussyjd

@bussyjdbussyjd commented Jun 16, 2026

Copy link
Copy Markdown
Contributor

Summary

Bump the default Hermes agent image used by both Obol-managed Hermes runtimes to a digest-pinned upstream image that contains the new optional payments skills:

  • internal/hermes/hermes.go master agent default: nousresearch/hermes-agent:v2026.6.5 -> nousresearch/hermes-agent:main@sha256:e9f2892b626468d2a65abeae9f94ec0a71872d7d9643906b956ab29c9bf328a9
  • internal/serviceoffercontroller/agent_render.go Agent CRD/sub-agent default: same pinned image ref

Why main@sha256: the latest dated Docker tag visible on Docker Hub is still v2026.6.5, published before Hermes commit 5bfed0fe0 (feat(skills): add optional payments skills (Stripe Link, MPP, Projects)). Docker Hub shows main/latest updated after that commit, and the current multi-arch manifest digest is pinned here:

nousresearch/hermes-agent:main@sha256:e9f2892b626468d2a65abeae9f94ec0a71872d7d9643906b956ab29c9bf328a9

This keeps the train reproducible while we wait for Hermes to publish the next dated release tag containing the optional payments skills. Once that tag exists, replace this temporary digest pin with the release tag plus digest.

Compatibility Pass Map

flowchart TB
A["Hermes upstream main image pinned by digest"] --> B["Optional payments skills available in agent pod"]
B --> C["stripe-link-cli skill"]
B --> D["mpp-agent skill"]
C --> E["Stripe Link approval + Shared Payment Token"]
D --> F["MPP client probes HTTP 402 merchant"]
G["Obol seller card route"] --> H{"402 challenge wire"}
H -->|"current Obol"| I["PAYMENT-REQUIRED JSON + X-PAYMENT retry"]
H -->|"Hermes/Stripe MPP target"| J["WWW-Authenticate: Payment method=stripe"]
E --> K["Buyer retries with payment credential"]
F --> K
K --> L["x402-verifier card gate"]
L --> M["Stripe PaymentIntent authorize"]
M --> N["Proxy upstream"]
N --> O{"Upstream <400?"}
O -->|"yes"| P["Capture PaymentIntent + return receipt"]
O -->|"no"| Q["Cancel hold + return failure"]
I -.-> R["Follow-up: bridge/dual-advertise wire format"]
J -.-> R
Loading

Stripe / SPT Flow

sequenceDiagram
autonumber
participant Buyer as Hermes agent payment skill
participant StripeLink as Stripe Link CLI
participant Seller as Obol paid service
participant Verifier as x402-verifier card gate
participant Stripe as Stripe PaymentIntents
participant Upstream as Seller upstream
Buyer->>Seller: Request paid resource without credential
Seller-->>Buyer: 402 with Stripe MPP challenge
Buyer->>StripeLink: Create approved spend request for shared_payment_token
StripeLink-->>Buyer: SPT credential after user approval
Buyer->>Seller: Retry with payment credential
Seller->>Verifier: Route to card gate
Verifier->>Stripe: Authorize manual-capture PaymentIntent with SPT
Stripe-->>Verifier: requires_capture
Verifier->>Upstream: Proxy request
alt upstream succeeds
Upstream-->>Verifier: 2xx/3xx response
Verifier->>Stripe: Capture PaymentIntent
Stripe-->>Verifier: succeeded
Verifier-->>Buyer: Upstream response + payment receipt
else upstream fails
Upstream-->>Verifier: 4xx/5xx or no response
Verifier->>Stripe: Cancel PaymentIntent hold
Verifier-->>Buyer: Failure, buyer not charged
end
Loading

MPP / x402 Compatibility Work Remaining

flowchart LR
A["Current Obol card path"] --> B["Scheme card / network stripe in x402 PaymentRequired"]
A --> C["Credential read from X-PAYMENT"]
A --> D["Receipt in X-PAYMENT-RESPONSE"]
E["Hermes + Stripe MPP expectation"] --> F["WWW-Authenticate: Payment ... method=stripe"]
E --> G["Authorization: Payment ... credential"]
E --> H["Authentication-Info receipt"]
E --> I["networkId is Stripe profile_ / profile_test_ id"]
B --> J["Compatibility pass"]
C --> J
D --> J
F --> J
G --> J
H --> J
I --> J
J --> K["Emit MPP challenge alongside x402 challenge"]
J --> L["Accept MPP Authorization credential or translate to existing SPT payload"]
J --> M["Return MPP receipt while preserving x402 receipt for existing buyers"]
J --> N["Update CLI/docs from stripenet_* examples to profile_* / profile_test_*"]
Loading

Validation

  • git diff --check
  • go test ./internal/hermes ./internal/serviceoffercontroller ./internal/agentcrd -count=1
  • docker buildx imagetools inspect nousresearch/hermes-agent:main
  • Docker Hub tag listing checked: no dated tag newer than v2026.6.5 is currently published; main/latest resolve to sha256:e9f2892b626468d2a65abeae9f94ec0a71872d7d9643906b956ab29c9bf328a9.

Follow-up

  • Replace this temporary main@sha256:... pin with the next dated Hermes release tag plus digest once available.
  • Implement the MPP wire compatibility pass described above before declaring Obol card payments interoperable with Hermes/Stripe Link.

@bussyjdbussyjd changed the title chore(hermes): use payments-enabled agent imagechore(hermes): pin payments-enabled agent imageJun 16, 2026
@bussyjdbussyjd closed this Jun 16, 2026
@bussyjd
bussyjd deleted the codex/hermes-agent-stripe-image branch June 16, 2026 17:11
@bussyjd

Copy link
Copy Markdown
ContributorAuthor

Closed after renaming the head branch off the codex/ prefix. Replacement PR with the corrected branch name and fixed Mermaid diagram: #649.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@bussyjd
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(hermes): pin payments-enabled agent image - #648

Closed
bussyjd wants to merge 2 commits into
integration/v0.11.0from
codex/hermes-agent-stripe-image
Closed

chore(hermes): pin payments-enabled agent image#648
bussyjd wants to merge 2 commits into
integration/v0.11.0from
codex/hermes-agent-stripe-image

Conversation

@bussyjd

@bussyjdbussyjd commented Jun 16, 2026

Copy link
Copy Markdown
Contributor

Summary

Bump the default Hermes agent image used by both Obol-managed Hermes runtimes to a digest-pinned upstream image that contains the new optional payments skills:

  • internal/hermes/hermes.go master agent default: nousresearch/hermes-agent:v2026.6.5 -> nousresearch/hermes-agent:main@sha256:e9f2892b626468d2a65abeae9f94ec0a71872d7d9643906b956ab29c9bf328a9
  • internal/serviceoffercontroller/agent_render.go Agent CRD/sub-agent default: same pinned image ref

Why main@sha256: the latest dated Docker tag visible on Docker Hub is still v2026.6.5, published before Hermes commit 5bfed0fe0 (feat(skills): add optional payments skills (Stripe Link, MPP, Projects)). Docker Hub shows main/latest updated after that commit, and the current multi-arch manifest digest is pinned here:

nousresearch/hermes-agent:main@sha256:e9f2892b626468d2a65abeae9f94ec0a71872d7d9643906b956ab29c9bf328a9

This keeps the train reproducible while we wait for Hermes to publish the next dated release tag containing the optional payments skills. Once that tag exists, replace this temporary digest pin with the release tag plus digest.

Compatibility Pass Map

flowchart TB
A["Hermes upstream main image pinned by digest"] --> B["Optional payments skills available in agent pod"]
B --> C["stripe-link-cli skill"]
B --> D["mpp-agent skill"]
C --> E["Stripe Link approval + Shared Payment Token"]
D --> F["MPP client probes HTTP 402 merchant"]
G["Obol seller card route"] --> H{"402 challenge wire"}
H -->|"current Obol"| I["PAYMENT-REQUIRED JSON + X-PAYMENT retry"]
H -->|"Hermes/Stripe MPP target"| J["WWW-Authenticate: Payment method=stripe"]
E --> K["Buyer retries with payment credential"]
F --> K
K --> L["x402-verifier card gate"]
L --> M["Stripe PaymentIntent authorize"]
M --> N["Proxy upstream"]
N --> O{"Upstream <400?"}
O -->|"yes"| P["Capture PaymentIntent + return receipt"]
O -->|"no"| Q["Cancel hold + return failure"]
I -.-> R["Follow-up: bridge/dual-advertise wire format"]
J -.-> R
Loading

Stripe / SPT Flow

sequenceDiagram
autonumber
participant Buyer as Hermes agent payment skill
participant StripeLink as Stripe Link CLI
participant Seller as Obol paid service
participant Verifier as x402-verifier card gate
participant Stripe as Stripe PaymentIntents
participant Upstream as Seller upstream
Buyer->>Seller: Request paid resource without credential
Seller-->>Buyer: 402 with Stripe MPP challenge
Buyer->>StripeLink: Create approved spend request for shared_payment_token
StripeLink-->>Buyer: SPT credential after user approval
Buyer->>Seller: Retry with payment credential
Seller->>Verifier: Route to card gate
Verifier->>Stripe: Authorize manual-capture PaymentIntent with SPT
Stripe-->>Verifier: requires_capture
Verifier->>Upstream: Proxy request
alt upstream succeeds
Upstream-->>Verifier: 2xx/3xx response
Verifier->>Stripe: Capture PaymentIntent
Stripe-->>Verifier: succeeded
Verifier-->>Buyer: Upstream response + payment receipt
else upstream fails
Upstream-->>Verifier: 4xx/5xx or no response
Verifier->>Stripe: Cancel PaymentIntent hold
Verifier-->>Buyer: Failure, buyer not charged
end
Loading

MPP / x402 Compatibility Work Remaining

flowchart LR
A["Current Obol card path"] --> B["Scheme card / network stripe in x402 PaymentRequired"]
A --> C["Credential read from X-PAYMENT"]
A --> D["Receipt in X-PAYMENT-RESPONSE"]
E["Hermes + Stripe MPP expectation"] --> F["WWW-Authenticate: Payment ... method=stripe"]
E --> G["Authorization: Payment ... credential"]
E --> H["Authentication-Info receipt"]
E --> I["networkId is Stripe profile_ / profile_test_ id"]
B --> J["Compatibility pass"]
C --> J
D --> J
F --> J
G --> J
H --> J
I --> J
J --> K["Emit MPP challenge alongside x402 challenge"]
J --> L["Accept MPP Authorization credential or translate to existing SPT payload"]
J --> M["Return MPP receipt while preserving x402 receipt for existing buyers"]
J --> N["Update CLI/docs from stripenet_* examples to profile_* / profile_test_*"]
Loading

Validation

  • git diff --check
  • go test ./internal/hermes ./internal/serviceoffercontroller ./internal/agentcrd -count=1
  • docker buildx imagetools inspect nousresearch/hermes-agent:main
  • Docker Hub tag listing checked: no dated tag newer than v2026.6.5 is currently published; main/latest resolve to sha256:e9f2892b626468d2a65abeae9f94ec0a71872d7d9643906b956ab29c9bf328a9.

Follow-up

  • Replace this temporary main@sha256:... pin with the next dated Hermes release tag plus digest once available.
  • Implement the MPP wire compatibility pass described above before declaring Obol card payments interoperable with Hermes/Stripe Link.

@bussyjdbussyjd changed the title chore(hermes): use payments-enabled agent imagechore(hermes): pin payments-enabled agent imageJun 16, 2026
@bussyjdbussyjd closed this Jun 16, 2026
@bussyjd
bussyjd deleted the codex/hermes-agent-stripe-image branch June 16, 2026 17:11
@bussyjd

Copy link
Copy Markdown
ContributorAuthor

Closed after renaming the head branch off the codex/ prefix. Replacement PR with the corrected branch name and fixed Mermaid diagram: #649.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@bussyjd
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(hermes): pin payments-enabled agent image - #648

Closed
bussyjd wants to merge 2 commits into
integration/v0.11.0from
codex/hermes-agent-stripe-image
Closed

chore(hermes): pin payments-enabled agent image#648
bussyjd wants to merge 2 commits into
integration/v0.11.0from
codex/hermes-agent-stripe-image

Conversation

@bussyjd

@bussyjdbussyjd commented Jun 16, 2026

Copy link
Copy Markdown
Contributor

Summary

Bump the default Hermes agent image used by both Obol-managed Hermes runtimes to a digest-pinned upstream image that contains the new optional payments skills:

  • internal/hermes/hermes.go master agent default: nousresearch/hermes-agent:v2026.6.5 -> nousresearch/hermes-agent:main@sha256:e9f2892b626468d2a65abeae9f94ec0a71872d7d9643906b956ab29c9bf328a9
  • internal/serviceoffercontroller/agent_render.go Agent CRD/sub-agent default: same pinned image ref

Why main@sha256: the latest dated Docker tag visible on Docker Hub is still v2026.6.5, published before Hermes commit 5bfed0fe0 (feat(skills): add optional payments skills (Stripe Link, MPP, Projects)). Docker Hub shows main/latest updated after that commit, and the current multi-arch manifest digest is pinned here:

nousresearch/hermes-agent:main@sha256:e9f2892b626468d2a65abeae9f94ec0a71872d7d9643906b956ab29c9bf328a9

This keeps the train reproducible while we wait for Hermes to publish the next dated release tag containing the optional payments skills. Once that tag exists, replace this temporary digest pin with the release tag plus digest.

Compatibility Pass Map

flowchart TB
A["Hermes upstream main image pinned by digest"] --> B["Optional payments skills available in agent pod"]
B --> C["stripe-link-cli skill"]
B --> D["mpp-agent skill"]
C --> E["Stripe Link approval + Shared Payment Token"]
D --> F["MPP client probes HTTP 402 merchant"]
G["Obol seller card route"] --> H{"402 challenge wire"}
H -->|"current Obol"| I["PAYMENT-REQUIRED JSON + X-PAYMENT retry"]
H -->|"Hermes/Stripe MPP target"| J["WWW-Authenticate: Payment method=stripe"]
E --> K["Buyer retries with payment credential"]
F --> K
K --> L["x402-verifier card gate"]
L --> M["Stripe PaymentIntent authorize"]
M --> N["Proxy upstream"]
N --> O{"Upstream <400?"}
O -->|"yes"| P["Capture PaymentIntent + return receipt"]
O -->|"no"| Q["Cancel hold + return failure"]
I -.-> R["Follow-up: bridge/dual-advertise wire format"]
J -.-> R
Loading

Stripe / SPT Flow

sequenceDiagram
autonumber
participant Buyer as Hermes agent payment skill
participant StripeLink as Stripe Link CLI
participant Seller as Obol paid service
participant Verifier as x402-verifier card gate
participant Stripe as Stripe PaymentIntents
participant Upstream as Seller upstream
Buyer->>Seller: Request paid resource without credential
Seller-->>Buyer: 402 with Stripe MPP challenge
Buyer->>StripeLink: Create approved spend request for shared_payment_token
StripeLink-->>Buyer: SPT credential after user approval
Buyer->>Seller: Retry with payment credential
Seller->>Verifier: Route to card gate
Verifier->>Stripe: Authorize manual-capture PaymentIntent with SPT
Stripe-->>Verifier: requires_capture
Verifier->>Upstream: Proxy request
alt upstream succeeds
Upstream-->>Verifier: 2xx/3xx response
Verifier->>Stripe: Capture PaymentIntent
Stripe-->>Verifier: succeeded
Verifier-->>Buyer: Upstream response + payment receipt
else upstream fails
Upstream-->>Verifier: 4xx/5xx or no response
Verifier->>Stripe: Cancel PaymentIntent hold
Verifier-->>Buyer: Failure, buyer not charged
end
Loading

MPP / x402 Compatibility Work Remaining

flowchart LR
A["Current Obol card path"] --> B["Scheme card / network stripe in x402 PaymentRequired"]
A --> C["Credential read from X-PAYMENT"]
A --> D["Receipt in X-PAYMENT-RESPONSE"]
E["Hermes + Stripe MPP expectation"] --> F["WWW-Authenticate: Payment ... method=stripe"]
E --> G["Authorization: Payment ... credential"]
E --> H["Authentication-Info receipt"]
E --> I["networkId is Stripe profile_ / profile_test_ id"]
B --> J["Compatibility pass"]
C --> J
D --> J
F --> J
G --> J
H --> J
I --> J
J --> K["Emit MPP challenge alongside x402 challenge"]
J --> L["Accept MPP Authorization credential or translate to existing SPT payload"]
J --> M["Return MPP receipt while preserving x402 receipt for existing buyers"]
J --> N["Update CLI/docs from stripenet_* examples to profile_* / profile_test_*"]
Loading

Validation

  • git diff --check
  • go test ./internal/hermes ./internal/serviceoffercontroller ./internal/agentcrd -count=1
  • docker buildx imagetools inspect nousresearch/hermes-agent:main
  • Docker Hub tag listing checked: no dated tag newer than v2026.6.5 is currently published; main/latest resolve to sha256:e9f2892b626468d2a65abeae9f94ec0a71872d7d9643906b956ab29c9bf328a9.

Follow-up

  • Replace this temporary main@sha256:... pin with the next dated Hermes release tag plus digest once available.
  • Implement the MPP wire compatibility pass described above before declaring Obol card payments interoperable with Hermes/Stripe Link.

@bussyjdbussyjd changed the title chore(hermes): use payments-enabled agent imagechore(hermes): pin payments-enabled agent imageJun 16, 2026
@bussyjdbussyjd closed this Jun 16, 2026
@bussyjd
bussyjd deleted the codex/hermes-agent-stripe-image branch June 16, 2026 17:11
@bussyjd

Copy link
Copy Markdown
ContributorAuthor

Closed after renaming the head branch off the codex/ prefix. Replacement PR with the corrected branch name and fixed Mermaid diagram: #649.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@bussyjd
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

chore(hermes): pin payments-enabled agent image - #648

Closed
bussyjd wants to merge 2 commits into
integration/v0.11.0from
codex/hermes-agent-stripe-image
Closed

chore(hermes): pin payments-enabled agent image#648
bussyjd wants to merge 2 commits into
integration/v0.11.0from
codex/hermes-agent-stripe-image

Conversation

@bussyjd

@bussyjdbussyjd commented Jun 16, 2026

Copy link
Copy Markdown
Contributor

Summary

Bump the default Hermes agent image used by both Obol-managed Hermes runtimes to a digest-pinned upstream image that contains the new optional payments skills:

  • internal/hermes/hermes.go master agent default: nousresearch/hermes-agent:v2026.6.5 -> nousresearch/hermes-agent:main@sha256:e9f2892b626468d2a65abeae9f94ec0a71872d7d9643906b956ab29c9bf328a9
  • internal/serviceoffercontroller/agent_render.go Agent CRD/sub-agent default: same pinned image ref

Why main@sha256: the latest dated Docker tag visible on Docker Hub is still v2026.6.5, published before Hermes commit 5bfed0fe0 (feat(skills): add optional payments skills (Stripe Link, MPP, Projects)). Docker Hub shows main/latest updated after that commit, and the current multi-arch manifest digest is pinned here:

nousresearch/hermes-agent:main@sha256:e9f2892b626468d2a65abeae9f94ec0a71872d7d9643906b956ab29c9bf328a9

This keeps the train reproducible while we wait for Hermes to publish the next dated release tag containing the optional payments skills. Once that tag exists, replace this temporary digest pin with the release tag plus digest.

Compatibility Pass Map

flowchart TB
A["Hermes upstream main image pinned by digest"] --> B["Optional payments skills available in agent pod"]
B --> C["stripe-link-cli skill"]
B --> D["mpp-agent skill"]
C --> E["Stripe Link approval + Shared Payment Token"]
D --> F["MPP client probes HTTP 402 merchant"]
G["Obol seller card route"] --> H{"402 challenge wire"}
H -->|"current Obol"| I["PAYMENT-REQUIRED JSON + X-PAYMENT retry"]
H -->|"Hermes/Stripe MPP target"| J["WWW-Authenticate: Payment method=stripe"]
E --> K["Buyer retries with payment credential"]
F --> K
K --> L["x402-verifier card gate"]
L --> M["Stripe PaymentIntent authorize"]
M --> N["Proxy upstream"]
N --> O{"Upstream <400?"}
O -->|"yes"| P["Capture PaymentIntent + return receipt"]
O -->|"no"| Q["Cancel hold + return failure"]
I -.-> R["Follow-up: bridge/dual-advertise wire format"]
J -.-> R
Loading

Stripe / SPT Flow

sequenceDiagram
autonumber
participant Buyer as Hermes agent payment skill
participant StripeLink as Stripe Link CLI
participant Seller as Obol paid service
participant Verifier as x402-verifier card gate
participant Stripe as Stripe PaymentIntents
participant Upstream as Seller upstream
Buyer->>Seller: Request paid resource without credential
Seller-->>Buyer: 402 with Stripe MPP challenge
Buyer->>StripeLink: Create approved spend request for shared_payment_token
StripeLink-->>Buyer: SPT credential after user approval
Buyer->>Seller: Retry with payment credential
Seller->>Verifier: Route to card gate
Verifier->>Stripe: Authorize manual-capture PaymentIntent with SPT
Stripe-->>Verifier: requires_capture
Verifier->>Upstream: Proxy request
alt upstream succeeds
Upstream-->>Verifier: 2xx/3xx response
Verifier->>Stripe: Capture PaymentIntent
Stripe-->>Verifier: succeeded
Verifier-->>Buyer: Upstream response + payment receipt
else upstream fails
Upstream-->>Verifier: 4xx/5xx or no response
Verifier->>Stripe: Cancel PaymentIntent hold
Verifier-->>Buyer: Failure, buyer not charged
end
Loading

MPP / x402 Compatibility Work Remaining

flowchart LR
A["Current Obol card path"] --> B["Scheme card / network stripe in x402 PaymentRequired"]
A --> C["Credential read from X-PAYMENT"]
A --> D["Receipt in X-PAYMENT-RESPONSE"]
E["Hermes + Stripe MPP expectation"] --> F["WWW-Authenticate: Payment ... method=stripe"]
E --> G["Authorization: Payment ... credential"]
E --> H["Authentication-Info receipt"]
E --> I["networkId is Stripe profile_ / profile_test_ id"]
B --> J["Compatibility pass"]
C --> J
D --> J
F --> J
G --> J
H --> J
I --> J
J --> K["Emit MPP challenge alongside x402 challenge"]
J --> L["Accept MPP Authorization credential or translate to existing SPT payload"]
J --> M["Return MPP receipt while preserving x402 receipt for existing buyers"]
J --> N["Update CLI/docs from stripenet_* examples to profile_* / profile_test_*"]
Loading

Validation

  • git diff --check
  • go test ./internal/hermes ./internal/serviceoffercontroller ./internal/agentcrd -count=1
  • docker buildx imagetools inspect nousresearch/hermes-agent:main
  • Docker Hub tag listing checked: no dated tag newer than v2026.6.5 is currently published; main/latest resolve to sha256:e9f2892b626468d2a65abeae9f94ec0a71872d7d9643906b956ab29c9bf328a9.

Follow-up

  • Replace this temporary main@sha256:... pin with the next dated Hermes release tag plus digest once available.
  • Implement the MPP wire compatibility pass described above before declaring Obol card payments interoperable with Hermes/Stripe Link.

@bussyjdbussyjd changed the title chore(hermes): use payments-enabled agent imagechore(hermes): pin payments-enabled agent imageJun 16, 2026
@bussyjdbussyjd closed this Jun 16, 2026
@bussyjd
bussyjd deleted the codex/hermes-agent-stripe-image branch June 16, 2026 17:11
@bussyjd

Copy link
Copy Markdown
ContributorAuthor

Closed after renaming the head branch off the codex/ prefix. Replacement PR with the corrected branch name and fixed Mermaid diagram: #649.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@bussyjd