Skip to content

Commit ed12f67

Browse files
jacobecoxclaude
andcommitted
hermes-agent 1.3.0: fix 'two ways' -> 'three' webhook-exposure count
Review caught the section lead-in still saying 'two ways to expose' above a three-row table (custom-domain path was added but the intro wasn't updated), contradicting two other spots that already said three. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
1 parent f9911fa commit ed12f67

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

‎hermes-agent/versions/1.3.0/README.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -193,7 +193,7 @@ The agent's browser tools cannot run on the Nous image alone — it ships no lau
193193

194194
## Webhooks
195195

196-
Set **`webhooks.enabled: true`** to turn on the listener on 8644 (the chart also enables the `hermes webhook subscribe` CLI for you). **Each subscription carries its OWN HMAC signing secret**: `hermes webhook subscribe` auto-generates one and prints it at creation, or you can pass `--secret "$WEBHOOK_SECRET"` to reuse the shared secret from `secret.keys.webhookSecret` (exposed to the container as `$WEBHOOK_SECRET`). Add the `webhookSecret` key to your prerequisite secret before enabling webhooks. Sign each event as HMAC-SHA256 of the body in the `X-Webhook-Signature` header (the gateway recommends the timestamped `X-Webhook-Signature-V2` form for replay protection). There are two ways to expose the listener externally:
196+
Set **`webhooks.enabled: true`** to turn on the listener on 8644 (the chart also enables the `hermes webhook subscribe` CLI for you). **Each subscription carries its OWN HMAC signing secret**: `hermes webhook subscribe` auto-generates one and prints it at creation, or you can pass `--secret "$WEBHOOK_SECRET"` to reuse the shared secret from `secret.keys.webhookSecret` (exposed to the container as `$WEBHOOK_SECRET`). Add the `webhookSecret` key to your prerequisite secret before enabling webhooks. Sign each event as HMAC-SHA256 of the body in the `X-Webhook-Signature` header (the gateway recommends the timestamped `X-Webhook-Signature-V2` form for replay protection). There are three ways to expose the listener externally:
197197

198198
| Path | How | Trade-offs |
199199
|---|---|---|

0 commit comments

Comments
 (0)