~4m19:30
Wanderloots

One Agent, Many Devices? 🧠 Full Hermes Agentic AI + Tailscale Workflow

Jul 10, 2026

Read: ~4m · You save: 16 min

One Agent, Many Devices? Full Hermes Agentic AI + Tailscale Workflow

Unlock the power of your AI agent across multiple devices! Learn how to use Tailscale to create a unified Hermes AI workflow with shared memory and secure access.

This guide details a workflow for accessing a single instance of the Hermes AI agent from multiple devices, ensuring a unified session history, memory, and file system. The setup leverages Tailscale for secure, encrypted connections between devices, allowing a more powerful machine to act as the central processing unit for an AI agent accessible from less powerful or portable devices.

Benefits of a Unified Agent System

Utilizing a single Hermes agent across multiple devices offers several advantages over running separate instances:

  • Centralized Session History: All interactions, regardless of the access device (laptop, desktop, mobile messaging apps like Telegram, Signal, or Discord), are logged in one location. This prevents fragmented conversations and maintains a continuous context.
  • Leveraging Powerful Hardware: A more capable machine, such as a desktop with higher RAM (e.g., 32 GB), can run larger, more powerful local AI models. This processing power can then be accessed remotely from a less powerful device, such as a laptop with 24 GB of RAM, effectively using the laptop as a "window" into the desktop's capabilities.
  • Organized File System: Project files can be consolidated on a central device, such as the desktop, and accessed as needed from any connected device, eliminating the need for complex file syncing systems across multiple machines.
  • Continuous Operation: A desktop machine, typically always powered on, can host the agent, allowing it to run 24/7. Users can then access the agent from their laptop or other devices even when not actively working at the desktop, ensuring background tasks continue uninterrupted.
  • End-to-End Encryption: By using a VPN solution like Tailscale, the connection between devices is end-to-end encrypted. This ensures that data does not need to pass through cloud servers, maintaining local and private operation.

Workflow Overview

The process involves setting up Tailscale on both the primary (server) and secondary (client) devices, configuring the Hermes agent on the server with dashboard credentials for secure authentication, and then connecting the client device to this remote dashboard.

Step 1: Installing and Configuring Tailscale

Tailscale creates a secure, private network (a "tailnet") between your devices, acting as a personal VPN.

  1. Download Tailscale: Download the Tailscale application from tailscale.com. The website version is recommended over the App Store version for macOS due to potential compatibility issues.
  2. Create an Account: Sign up for a Tailscale account using GitHub, Apple, or an email address.
  3. Authorize Devices:
    • Upon first launch, authorize your first device. This adds it to your tailnet.
    • On macOS, you may need to grant network permissions and authorize the VPN.
    • Repeat this process on your second computer (e.g., your laptop).
  4. Verify Tailnet: Access the Tailscale admin panel online. You should see both your server (e.g., Mac Studio) and client (e.g., MacBook Pro) devices listed. Each device will have a unique IP address within the tailnet.

Step 2: Setting Up Hermes Dashboard Credentials on the Server

To securely access the Hermes dashboard from another device, authentication must be enabled.

  1. Modify Environment File: Edit the Hermes environment file by pasting a specific string. This string configures basic authentication for the Hermes dashboard, setting a username, password, and a randomly generated secret. The username and password can be customized.
  2. Start the Hermes Dashboard: Open a terminal on the server device and run the command:
    hermes dashboard --host 0.0.0.0
    
    This command builds the web UI and makes it available on the local network. The terminal will display the HTTP URL, typically on port 9119.

The Hermes dashboard allows for profile switching, enabling the use of different configurations, models, and settings for various tasks. For instance, one profile might be configured to use a local model like Gemma 4 via Llama, while another might use GPT 5.5.

Step 3: Connecting the Client Device to the Hermes Agent

There are two primary methods to connect your client device to the Hermes agent running on the server:

Method 1: Using the Web Dashboard (Recommended for Flexibility)

This method is generally simpler and offers more flexibility, especially for using non-default Hermes profiles.

  1. Open Browser: On your client device (e.g., laptop), open a web browser.
  2. Navigate to Server's Tailscale Address: Enter the server's Tailscale IP address followed by the port number (e.g., http://<server_tailscale_ip>:9119).
  3. Sign In: You will be prompted to sign in using the username and password configured in Step 2.
  4. Access Hermes: Once authenticated, the browser will display the Hermes dashboard, providing access to the agent running on the server.
  5. Profile Selection: The web dashboard allows you to select different Hermes profiles (e.g., "studio") to utilize specific configurations, sessions, memories, tools, skills, and model settings.

Method 2: Using the Native Hermes Desktop App (Remote Gateway)

This method uses the desktop application on the client device to connect to the remote Hermes backend.

Important Limitation: Currently, the remote gateway flow for the desktop app requires using the client device's default Hermes profile. Attempting to use a non-default profile may lead to connection issues after restarting the app.

  1. Open Hermes Desktop App on Client: Launch the Hermes desktop application on your client device.
  2. Access Settings: Press Command + , (or Control + ,) to open settings.
  3. Navigate to Gateway Tab: Select the "Gateway" tab.
  4. Toggle to Remote Gateway: Change the gateway connection from "Connected Locally" to "Remote Gateway."
  5. Enter Server's Tailscale IP and Port:
    • Obtain the server's Tailscale IP address (e.g., from the Tailscale admin panel or by right-clicking the server device in the Tailscale app and copying its "MagicDNS hostname").
    • Construct the URL: http://<server_tailscale_ip>:9119.
  6. Sign In and Reconnect: Click "Sign In" using the credentials set up in Step 2. Then, click "Save and Reconnect."
  7. Test Connection: The Hermes desktop app on the client will restart and connect to the remote gateway. You can then interact with the agent. For example, asking "Hi, what device is this?" will result in the query being processed by the Hermes agent on the server (e.g., Mac Studio) and the answer returned to the client (e.g., MacBook Pro). The session history will be updated on the server.

Step 4: Sharing Files Across Devices

To ensure file access consistency, especially when operating within Docker containers, files can be shared across the Tailscale network.

  1. Enable File Sharing on Server (macOS Example):
    • Go to System Settings > Sharing.
    • Enable "Content and Media" > "File Sharing."
    • Add the specific folder you want to share (e.g., "Hermes workspace") by clicking the "+" button. This makes the folder accessible to other devices on your network.
  2. Mount Shared Folder on Client:
    • On the client device, open Finder.
    • Go to Go > Connect to Server.
    • Enter the server's Tailscale address in the format smb://<server_magicdns_hostname>.
    • Click "Connect."
    • When prompted, select the shared folder you enabled.
    • The shared folder will appear on your client device, allowing you to read and write files that are accessible to the Hermes agent on the server. This is crucial for maintaining a consistent workspace, particularly for AI operations within Docker.

Considerations for Memory and Persistence

  • Active Connection Required: The unified memory and session history are maintained only while the client device is connected to the remote server backend via Tailscale.
  • Offline Operation: If the server backend stops running or the client disconnects, the client's Hermes desktop app may offer to run locally. This creates a separate instance with its own session history and memory, which will not automatically sync with the server's data unless a separate memory sync strategy is implemented.
  • Memory Providers: For more robust long-term memory systems, consider integrating external memory providers like Hindsight, Honcho, or Nemasean. These can write to separate database files. By running the backend on the server and connecting via a remote gateway from the client, all memories are centralized on the server's agent system.
  • LLM Wiki Integration: Tools like Obsidian can be used to build an LLM Wiki, creating a long-term memory system that Hermes can write into and pass to different agents. This approach centralizes long-term memory and can be layered with other memory providers.

This setup provides a flexible and secure way to access a single, powerful AI agent from multiple devices, ensuring a consistent and continuous user experience.

Introduction and Benefits of Multi-Device Agent Access

Introduction to accessing a Hermes AI agent from multiple devices, emphasizing the benefits of a unified session history and continuous memory system across different machines.

  • The goal is to access a single Hermes agent from multiple devices.
  • Benefits include one session history across all devices (laptop, desktop, messaging apps).
  • Allows running larger local models on more powerful hardware (e.g., desktop).
  • Provides access to a better-organized, centralized file system.
  • Enables 24/7 agent operation by leaving a desktop running.
  • Tailscale provides end-to-end encryption for local and private communication.

Setting Up Tailscale VPN

Setting up Tailscale VPN on both desktop and laptop to create a secure, private network connection between the two devices, enabling them to communicate as if on the same local network.

  • Tailscale creates a secure, private, encrypted tunnel between devices.
  • Devices are treated as separate by the router but connected by Tailscale.
  • Download Tailscale from tailscale.com (recommended over App Store).
  • Create an account using GitHub, Apple, or email.
  • Authorize devices to add them to your 'tailnet'.
  • Permissions and network authorization may be required.
  • Multiple devices connected to the same account get unique addresses within the tailnet.

Configuring Hermes Dashboard and Credentials

Configuring the Hermes agent on the desktop to enable remote dashboard access, including setting up basic authentication credentials for security.

  • The Hermes dashboard needs to run on the desktop to be accessed remotely.
  • Dashboard credentials (username, password) are required for security.
  • Modify the Hermes environment file to set basic authentication.
  • Start the dashboard using hermes dashboard --host 0.0.0.0 in the terminal.
  • The dashboard becomes available on the local network at http://<desktop_ip>:9119.
  • Hermes supports different profiles with distinct configurations and models.

Connecting Laptop to Hermes Agent

Connecting the laptop to the running Hermes dashboard on the desktop via the Tailscale network, demonstrating two methods: the web dashboard and the native desktop app.

  • Access the Hermes dashboard from the laptop's browser using the desktop's Tailscale IP address on port 9119.
  • Sign in with the configured username and password.
  • The laptop browser acts as a window to the remote dashboard.
  • The web dashboard allows switching between different Hermes profiles.
  • Alternatively, use the native Hermes desktop app on the laptop.
  • For the desktop app, connect to a remote gateway using the desktop's Tailscale IP and port.
  • A limitation exists: the desktop app remote gateway flow currently requires the laptop's default profile.

Sharing Files Between Devices via Tailscale

Demonstrates how to share files between the desktop and laptop by mounting a shared folder over the Tailscale network, crucial for workflows involving Docker or centralized data management.

  • File sharing is essential for maintaining a unified workspace.
  • Avoid cloud syncing issues (like iCloud) when using Docker.
  • Mount the Hermes workspace folder from the desktop to the laptop via Tailscale.
  • On Mac, enable File Sharing in System Settings > Sharing > Content and Media.
  • Select the specific folder to share and add it to the sharing list.
  • On the laptop, use Finder > Go > Connect to Server.
  • Connect using smb://<desktop_magic_dns_hostname> and select the shared folder.
  • This ensures the Hermes agent can always access necessary files, regardless of the device used.

Centralized Memory and Advanced Memory Providers

Discusses the importance of a centralized memory system and introduces advanced memory providers and the concept of a 'memory stack' for long-term, evolving AI memory.

  • The shared memory setup is active only while the desktop backend is running.
  • If the desktop backend stops, the laptop app might default to a local instance, losing sync.
  • Obsidian can be used to build long-term memory systems (LLM Wiki).
  • Advanced memory providers like Hindsight, Honcho, or Nemasean write to separate database files.
  • Using the gateway setup ensures all memories are written to a single agent system on the desktop.
  • This prevents the nightmare of syncing database files across devices.
  • Future videos will explore memory providers and building a 'memory stack'.