Endpoint: https://api.hermios.app/mcp (streamable HTTP, POST only, protocol version 2025-06-18). Assistants that support MCP OAuth (such as Codex and Claude) only need the URL: they discover sign-in through /.well-known/oauth-protected-resource/mcp, and the person picks a workspace and approves. Each call then runs with that person’s role. An API key also works as a bearer token for server-side agents. For Codex there is a ready-made plugin, see Hermios for Codex.

How tools are exposed

By default tools/list returns a small set of entry tools, and the assistant discovers the rest: Generated record tools behind execute_tool follow the object names: find_many_companies, find_one_company, group_by_companies, create_one_company, create_many_companies, update_one_company, update_many_companies, upsert_many_companies, delete_one_company, delete_many_companies, and so on for every object. Add ?mode=direct (https://api.hermios.app/mcp?mode=direct) to list every tool directly instead, for clients that do not do discovery.

Hermios tools

execute_tool is marked destructive in its annotations, so clients ask before running writes.

Resources

  • ui://hermios/workspace.html and ui://hermios/csv.html (text/html;profile=mcp-app): the embedded Hermios panels.
  • hermios://records/{view}/{recordId}, where view is pipeline, people, companies, tasks or vault. Each read is authorized again.

Errors

A missing or expired token gets 401 with WWW-Authenticate: Bearer resource_metadata="https://api.hermios.app/.well-known/oauth-protected-resource/mcp", which tells clients where to sign in. Methods other than POST get 405.