Overview
Hermes AI Agent turns an EC2 instance into a self-hosted AI assistant that customers can operate through Telegram. This is a repackaged open source software product wherein additional charges apply for independent AWS packaging, validation, security hardening, release automation, and support. Hermes Agent is developed by Nous Research and distributed under the MIT license; this product does not claim authorship of the upstream project.
The production-ready AMI includes a pinned, published Hermes Agent release, its Telegram gateway dependencies, UFW default-deny inbound firewalling, fail2ban SSH protection, SSH key-only authentication, unattended security upgrades, network sysctl hardening, gp3 root storage with encryption available at launch, and required IMDSv2. The gateway runs as a systemd service with customer configuration and state stored under /home/ubuntu/.hermes. No customer credentials are baked into the AMI.
Getting started after launch:
- Restrict TCP 22 to a trusted CIDR and connect as ubuntu with your EC2 key pair.
- Set your model-provider API key, model selection, Telegram bot token, and allowed Telegram user ID.
- Run sudo /opt/hermes/bin/provision-hermes.sh and verify systemctl status hermes-gateway.
The product is fully functional after configuration and has no product-imposed time or usage restriction. An internet connection, a supported third-party model-provider account, and a Telegram bot are required and are disclosed external dependencies. The optional five-day free trial changes only the software billing and automatically converts to the paid hourly offer; it does not enable a separate trial or evaluation edition.
The software charge is USD 0.02 per running instance-hour. EC2, EBS, data transfer, Telegram connectivity, and third-party model-provider usage are charged separately by their providers.
Highlights
- Ready to configure: Hermes Agent and its Telegram gateway dependencies are pinned and pre-installed; add your own model-provider and Telegram credentials after launch.
- Production-operated foundation: Hermes runs as a systemd service with release markers, persistent customer state, automated security updates, and daily Marketplace-copy health checks.
- Hardened from first boot: UFW, fail2ban, key-only SSH, gp3 storage with encryption available at launch, unattended security upgrades, and required IMDSv2 reduce the host attack surface.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
Free trial
Dimension | Cost/hour |
|---|---|
t3.medium Recommended | $0.02 |
t3.large | $0.02 |
t3.small | $0.02 |
t3.xlarge | $0.02 |
m6i.xlarge | $0.02 |
m6i.large | $0.02 |
Vendor refund policy
We offer a full refund of software charges for the first 48 hours billing starts if the product does not perform as described. To request a refund, email info@softwaresushi.com with your EC2 instance ID and a description of the issue. AWS infrastructure costs (EC2, EBS, data transfer) are billed by AWS and are not eligible for refund by us.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Independent AWS packaging of Nous Research Hermes Agent v2026.7.20 on hardened Ubuntu 24.04. Browser automation dependencies are not included. See https://github.com/NousResearch/hermes-agent/releases/tag/v2026.7.20
Additional details
Usage instructions
Documentation: https://softwaresushi-marketplace-branding-public.s3.amazonaws.com/docs/hermes-ai-agent/getting-started.html
- Subscribe to Hermes AI Agent, launch the current direct AMI with an EC2 key pair, and restrict inbound TCP 22 to your trusted CIDR. The AMI requires outbound HTTPS to Telegram and your selected model provider. Enable EBS encryption by default in the target AWS Region before launch if the root volume must be encrypted.
- Connect with ssh ubuntu@INSTANCE_ADDRESS, run sudo -i, and privately prompt for LLM_API_KEY, BOT_TOKEN, and CUSTOMER_TELEGRAM_ID with read -s so values do not enter shell history. Export those variables plus LLM_PROVIDER and LLM_MODEL, then run bash /opt/hermes/bin/provision-hermes.sh. For the tested OpenAI setup use LLM_PROVIDER=openai and LLM_MODEL=gpt-5.
- Verify systemctl status hermes-gateway, /var/log/deploy-ec2.log, and /home/ubuntu/.hermes/logs/gateway.log. Open the Telegram bot, select Start, and send a message. Keep DM_POLICY=allowlist unless public access is intentional.
- Customer credentials, configuration, sessions, cron jobs, and state are stored under /home/ubuntu/.hermes; .env is mode 0600. Rotate credentials by reprovisioning with new values, then revoke the old provider key and Telegram token. Back up this directory only through an approved encrypted process. No proprietary data store is used.
- For upgrades, launch the newer Marketplace version and migrate only required state after taking a protected backup. Monitor EC2 status checks, hermes-gateway, gateway logs, provider quotas, and Telegram connectivity.
Software costs USD 0.02 per running instance-hour after the five-day free software trial for one instance. EC2, EBS, data transfer, Telegram connectivity, and third-party model-provider usage are separate. Stop or terminate unused instances and monitor EC2, EBS, and provider quotas. Browser automation dependencies are not installed. No customer credentials are baked into the image.
Resources
Vendor resources
Support
Vendor support
For AMI packaging, hardening, deployment, or billing support, email info@softwaresushi.com .
For upstream Hermes Agent issues, use this issue tracker: https://github.com/NousResearch/hermes-agent/issues
Support is provided in English during US business hours. Security reports should use the subject Hermes AI Agent security.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.