Skip to content
Hermes Alternative

Self-host an open-source Hermes alternative

When a personal agent stops fitting a team, the platform underneath has to be one the team owns. Kortix is that platform: the open-source AI Operating System you self-host as one Docker Compose stack.

Start it from the command line

The manual path from the Kortix self-hosting docs.

terminal
$ curl -fsSL https://kortix.com/install | bash$ kortix self-host init --domain kortix.example.com$ kortix self-host start
Source: https://kortix.com/docs/host
terminal
$ kortix self-host configure$ kortix self-host status$ kortix self-host update --tag 0.9.84
Source: https://kortix.com/docs/host

What you actually run

Kortix self-hosting is one Docker Compose stack: the frontend, the API, the LLM gateway, and the Supabase distribution. Agent sessions run on a separate sandbox provider, so the control plane and the work stay apart. The default provider is Daytona; Platinum and E2B are also supported.

The first run asks six things and no model key. GitHub connects in the dashboard under Settings → Git, and models are BYOK in the app. Self-host is free. You pay your own model and compute bills.

Everything you configure, the agents, skills, memory, connectors and triggers, lives in one git repo you own. The instance stays reachable so the sandbox can call back, and kortix self-host start pulls its images from docker.io.

Models and keys

Any model provider with your own keys. Or the ChatGPT plan you already pay for. Or sign in with your OpenCode Console account for OpenCode Zen and Go.

Hermes makes the same promise for one person: use any model you want, switch with hermes model, no code changes. A team adds one rule to that: every member's agent uses a key the company holds and can rotate.

Isolation, per session

One isolated sandbox per session. Each session has its own isolated machine and branch. A session can install, run and break anything; only what it commits survives.

That boundary is the difference a team feels. A personal agent on a laptop shares that person's filesystem and credentials. A session here starts clean and lands nothing until a person merges.

Connector access you can scope

Agents reach 3,000+ apps in a click, plus MCP, OpenAPI, Postman, GraphQL and raw HTTP. Connector credentials are brokered server-side and never enter the machine.

You set each tool to Allow, Ask or Block, down to the arguments of each call. An Ask holds the call until a person approves it, then the agent resumes.

Review and approval gates

Approval gates you set. Off until you set them. Session work reaches main through a change request, and merge is default-deny for agents.

Around that sit per-resource permissions for people and agents, roles, groups, and an audit trail. SAML 2.0 single sign-on and SCIM 2.0 cover identity, and secrets are encrypted at rest with a key per project.

What self-hosting changes for a team

Hermes is a fine personal agent. Its learning loop creates skills from experience, and one gateway process reaches Telegram, Discord, Slack, WhatsApp and Signal. It is built for one operator on a machine that person controls.

A company needs the same freedom plus a review path and an owner. Kortix runs on Kortix Cloud, in your VPC, or on your own on-prem network. Self-host is free. Read the docs for the bootstrap script, the evaluation tunnel, and backups.

Self-hosting questions

What a team asks before it runs the stack on its own box.

Can I try a self-hosted instance without a domain?
Yes. kortix self-host init --tunnel cloudflare starts it behind a Cloudflare tunnel instead of a domain. The tunnel URL changes on every restart, so it is for evaluation, not production.
Which sandbox provider does a self-hosted Kortix use?
Sessions run on a separate sandbox provider. The default is Daytona; Platinum and E2B are also supported.
What does a self-hosted instance cost?
Self-host is free. You pay your own model and compute bills.
How do updates and backups work?
Every instance updates itself automatically; pin a version with kortix self-host update --tag <version>, or turn the updater off. There is no separate backup system: each instance keeps its data in volumes/db/data and volumes/storage under ~/.config/kortix/self-host/<instance>/, and its .env holds every secret and signing key it uses.

Self-host the platform your team owns.

One Docker Compose stack, your models, your keys.

Open source · Any model, your keys · Self-host, VPC, or on-prem