https://api.hermios.app/mcp (streamable HTTP, POST only, protocol version 2025-06-18).
Assistants that support MCP OAuth (such as Codex and Claude) only need the URL: they discover sign-in through /.well-known/oauth-protected-resource/mcp, and the person picks a workspace and approves. Each call then runs with that person’s role. An API key also works as a bearer token for server-side agents.
For Codex there is a ready-made plugin, see Hermios for Codex.
How tools are exposed
By defaulttools/list returns a small set of entry tools, and the assistant discovers the rest:
Generated record tools behind
execute_tool follow the object names: find_many_companies, find_one_company, group_by_companies, create_one_company, create_many_companies, update_one_company, update_many_companies, upsert_many_companies, delete_one_company, delete_many_companies, and so on for every object.
Add ?mode=direct (https://api.hermios.app/mcp?mode=direct) to list every tool directly instead, for clients that do not do discovery.
Hermios tools
execute_tool is marked destructive in its annotations, so clients ask before running writes.
Resources
ui://hermios/workspace.htmlandui://hermios/csv.html(text/html;profile=mcp-app): the embedded Hermios panels.hermios://records/{view}/{recordId}, whereviewispipeline,people,companies,tasksorvault. Each read is authorized again.
Errors
A missing or expired token gets401 with WWW-Authenticate: Bearer resource_metadata="https://api.hermios.app/.well-known/oauth-protected-resource/mcp", which tells clients where to sign in. Methods other than POST get 405.