Fix claude-bot replying to Hermes's own messages, route Hermes through LiteLLM

Critical bug: claude-bot only ignored its OWN messages and text explicitly
addressed to @hermes — it did not ignore Hermes's own replies appearing in
the room. A single @hermes mention cascaded into claude-bot replying to
Hermes's thread messages ('Hermes says: ...'), which could itself cascade
further. Fixed with an OTHER_AGENT_USER_IDS allowlist of sender IDs to
always ignore, not just a text-prefix check.

Also point Hermes's model provider at the local litellm gateway
(OPENAI_BASE_URL/OPENAI_API_KEY) instead of OpenRouter directly, matching
claude-agent's own chat path — one place to hold the OpenRouter credential.
This does NOT grant Hermes access to the Claude subscription; that's an
Anthropic-side restriction unrelated to which proxy sits in front of it,
already proven earlier in this session.

Separately (not a code fix): the 'Billing or credits exhausted: HTTP 402'
error Hermes hit is real — the OpenRouter account currently has 0 credits.
This commit is contained in:
2026-08-23 16:02:15 +00:00
parent c88fdcc2ea
commit a2c00f6f8b
3 changed files with 27 additions and 4 deletions
+12 -4
View File
@@ -77,7 +77,15 @@ services:
# rooms (DMs to it would respond unprompted, per Hermes's own default behavior).
MATRIX_ALLOWED_USERS: ${MATRIX_HUMAN_USER_ID}
MATRIX_REQUIRE_MENTION: "true"
OPENROUTER_API_KEY: ${OPENROUTER_API_KEY}
# Routed through the local litellm gateway, not OpenRouter directly — same pattern
# as claude-agent's chat path, one place to hold the OpenRouter credential and swap
# models. Hermes's "main"/custom-endpoint provider is any OpenAI-compatible API
# reachable via OPENAI_BASE_URL + OPENAI_API_KEY. Note: this does NOT give Hermes
# access to the Claude Pro/Max subscription — that's blocked by Anthropic itself for
# any caller other than the real Claude Code CLI, proven earlier in this session
# (reproduced with plain curl straight to api.anthropic.com, LiteLLM or not).
OPENAI_BASE_URL: http://litellm:4000/v1
OPENAI_API_KEY: ${LITELLM_MASTER_KEY}
# Left disabled: Hermes itself warns that a network-reachable API server combined
# with the default unsandboxed ('local') terminal backend gives any caller full
# terminal/file access within the container. Matrix is the actual interface in use;
@@ -113,10 +121,10 @@ services:
MATRIX_BOT_TOKEN: ${MATRIX_BOT_TOKEN}
MATRIX_CONTROL_ROOM_ID: ${MATRIX_CONTROL_ROOM_ID}
MATRIX_BOT_USER_ID: ${MATRIX_BOT_USER_ID}
OTHER_AGENT_USER_IDS: ${OTHER_AGENT_USER_IDS}
KNOWN_REPOS: ${KNOWN_REPOS}
# All model calls now go through the local litellm service, not OpenRouter directly —
# one gateway for OpenRouter's models (incl. its auto-router) and, for the
# claude-subscription route, Anthropic itself via the forwarded OAuth token above.
# Chat replies go through the local litellm service (OpenRouter's models, incl. its
# auto-router), not OpenRouter directly.
LITELLM_BASE_URL: http://litellm:4000
LITELLM_MASTER_KEY: ${LITELLM_MASTER_KEY}
volumes: