PR #53891 (cherry-picked in the three preceding commits) landed the Electron bridge, the store, the find bar overlay, and Cmd/Ctrl+F to open. It stopped short of the rest of the accelerator set and had two lifecycle leaks. This completes the surface to match the platform convention that Chrome, Safari, VS Code, and Claude Desktop's own findInPage bundle all ship. Accelerators now wired: - Cmd/Ctrl+F open the find bar (view.findInPage, from the PR) - Cmd/Ctrl+G find next (new) - Cmd/Ctrl+Shift+G find previous (new) - Enter / Shift+Enter step from the input (from the PR) - Escape close + stopFindInPage('clearSelection') (from the PR) Keyboard ownership (the substantive fix) Cmd+G was already bound to `view.toggleReview` and Escape to `composer.cancel`. The find bar's own capture-phase window listener cannot win those keys by calling stopPropagation: the keybind dispatcher's listener sits on the SAME window target in the SAME phase, and propagation control does not suppress sibling listeners on one target. Left alone, Cmd+G would step a match AND toggle the review pane, and Escape would dismiss the bar AND abort a running turn. So ownership is decided by the dispatcher, which AGENTS.md already names the single owner of combo dispatch: `findBarClaimsCombo` is consulted in use-keybinds before the registry lookup, and yields mod+g / mod+shift+g / escape to the bar only while it is open. Closing the bar hands every one of them straight back. That is the "keyboard ownership follows focus / one cancel gesture does exactly one thing" invariant. `view.findNext` / `view.findPrevious` are registered with EMPTY defaults on purpose — shipping mod+g as a second default would flag a permanent conflict in the keybinds panel against view.toggleReview. The entries document the pair and let a user bind a dedicated chord; stepping is a no-op unless the bar is open with a query, so a bound key can never search invisibly. Listener-leak fixes - The found-in-page bridge subscription is now refcounted in the store, so a remount (the connection re-home path remounts the global overlays) cannot stack duplicate subscribers that each re-dispatch the same result and outlive their component. The subscription is deliberately mount-scoped, not active-scoped: results for an in-flight search must still land if the bar just closed. - `setFindQuery` now refuses to search a closed bar. The component clears its debounce on close, but a 200ms timer that already fired would re-issue a find and re-highlight the page after the user pressed Escape. Caught by the test, fixed in the store rather than papered over in the component. - `closeFindBar` is idempotent — Escape is a shared gesture, so a second close must not reach into Electron again. Pure logic extracted for testing (no source regexing) - `src/lib/find-in-page.ts`: `formatMatchLabel` (three distinct counter states: hidden with no query, explicit 0/0, ordinal/count; clamps the ordinal and never emits NaN — Electron legitimately reports ordinal 0 on a non-final update), `findBarKeyAction` (the keybinding matcher, DOM-free), and `findBarClaimsCombo` (the ownership predicate above). Also: match counter and buttons get accessible names and the counter is aria-live, the hardcoded English "Previous"/"Next"/"Close" tooltips move to i18n (en + zh) alongside the new keybind labels, and the input gets an aria-label so the bar is reachable by role. Tests: apps/desktop/src/components/find-bar.test.tsx — 42 cases over the pure helpers, the store (open/close, next/prev dispatch shape, escape clears, refcount, double-release), and the component (focus on open, debounce coalescing, Cmd+G from outside the input, unmount releases both the bridge subscription and the window listener). cd apps/desktop && npx vitest run src/components/find-bar.test.tsx \ electron/find-in-page.test.ts -> 62 passed (42 new + 20 from the PR) Adjacent suites (src/lib/keybinds, src/i18n, src/store): 487 passed. `tsc -p tsconfig.electron.json --noEmit` clean; `tsc -p .` has 114 pre-existing errors vs 120 on the merge base (all @assistant-ui / bippy / composer), none in the touched files. eslint clean on every touched file. Co-authored-by: David Metcalfe <DavidMetcalfe@users.noreply.github.com> |
||
|---|---|---|
| .. | ||
| assets | ||
| e2e | ||
| electron | ||
| pr-assets | ||
| public | ||
| scripts | ||
| src | ||
| AGENTS.md | ||
| components.json | ||
| DESIGN.md | ||
| eslint.config.mjs | ||
| index.html | ||
| package.json | ||
| playwright.config.ts | ||
| preview-demo.html | ||
| README.md | ||
| tsconfig.e2e.json | ||
| tsconfig.electron.json | ||
| tsconfig.json | ||
| vite.config.ts | ||
| vitest.config.ts | ||
| vitest.setup.ts | ||
Hermes Desktop ☤
The native desktop app for Hermes Agent — the self-improving AI agent from Nous Research. Same agent, same skills, same memory as the CLI and gateway, in a polished native window — chat with streaming tool output, side-by-side previews, a file browser, voice, and settings, no terminal required. Available for macOS, Windows, and Linux.
| Chat with the full agent | Streaming responses, live tool activity, structured tool summaries, and the same conversation history as every other Hermes surface. |
| Side-by-side previews | Render web pages, files, and tool outputs in a right-hand pane while you keep chatting. |
| File browser | Explore and preview the working directory without leaving the app. |
| Voice | Talk to Hermes and hear it back. |
| Settings & onboarding | Manage providers, models, tools, and credentials from a real UI. First-run setup gets you to your first message in seconds. |
| Stays current | Built-in updates pull the latest agent and rebuild the app in place. |
Install
Install with Hermes (recommended)
Already have the Hermes CLI? Just run:
hermes desktop
It builds and launches the GUI against your existing install — same config, keys, sessions, and skills. If Desktop cannot find a usable runtime or saved remote connection, first launch lets you connect to an existing Hermes gateway or install Hermes locally. Local onboarding then walks you through choosing a provider and model.
Prebuilt installers
Prebuilt installers are built and distributed via the Hermes Desktop website..
Updating
The app checks for updates in the background and offers a one-click update when one is ready. You can also update any time from the CLI:
hermes update
Requirements
The installer handles everything for you (Python 3.11+, a portable Git, ripgrep).
Development
Want to hack on the app itself? Install workspace deps from the repo root once, then run the dev server from this directory:
npm install # from repo root — links apps/desktop, web, apps/shared
cd apps/desktop
npm run dev # Vite renderer + Electron, which boots the Python backend
Point the app at a specific source checkout, or sandbox it away from your real config:
# throwaway HERMES_HOME, separate Electron userData, distinct app name to avoid the single-instance lock
../scripts/dev-sandbox.sh npm run dev
HERMES_DESKTOP_HERMES_ROOT=/path/to/clone npm run dev
HERMES_HOME=/tmp/throwaway npm run dev
npm run dev:fake-boot # exercise the startup overlay with deterministic delays
Building installers
npm run dist:mac # DMG + zip
npm run dist:win # NSIS + MSI
npm run dist:linux # AppImage + deb + rpm
npm run pack # unpacked app under release/ (no installer)
Installers are built and uploaded to GitHub Releases manually. macOS/Windows signing & notarization happen automatically when the relevant credentials are present in the environment (CSC_LINK / CSC_KEY_PASSWORD / APPLE_* for macOS, WIN_CSC_* for Windows).
How it works
The packaged app ships the Electron shell and a native React chat surface. On
first launch it can install the Hermes Agent runtime into HERMES_HOME
(~/.hermes, or %LOCALAPPDATA%\hermes on Windows), using the same layout as a
CLI install.
The app has three boundaries:
- Electron resolves and validates a runnable backend, owns native filesystem/git/window capabilities, and exposes a narrow preload bridge.
- React owns the Desktop routes, panes, interaction state, and
@assistant-ui/reacttranscript. - Hermes Agent runs as a headless
hermes serveprocess and exposes thetui_gatewayJSON-RPC/WebSocket API. The renderer connects throughapps/shared, which is also used by the browser dashboard.
Backend resolution is an ordered ladder:
HERMES_DESKTOP_HERMES_ROOT- the current source checkout during development
- a completed managed install
HERMES_DESKTOP_HERMES, orhermesonPATH- a system Python that can import the Hermes runtime
- the first-launch bootstrap installer
Candidates are probed before use; an existing shim or interpreter is not enough.
A runtime that predates serve falls back to headless
dashboard --no-open. This is compatibility for the backend command only and
does not launch or embed the dashboard UI.
The Electron orchestration entry point is electron/main.ts; pure resolution,
probe, hardening, and platform policies live in focused modules beside it. The
renderer is under src/, with shared atoms in src/store and transport/native
adapters in src/lib.
Before changing the app, read:
AGENTS.md: architecture, state ownership, resolver/fallback, transport, performance, and testing rules.DESIGN.md: visual system, information architecture, motion, direct manipulation, and keyboard behavior.
Connections, projects, and switching
Desktop supports a managed local backend, explicit remote gateways, and Hermes Cloud connections. Remote and cloud modes use the same remote-capability path; authentication and discovery differ, not the renderer feature model.
When no usable local runtime or saved remote connection exists, the first-run screen offers Connect to existing Hermes before starting the local installer. Desktop probes the gateway to discover token or OAuth authentication, requires a successful HTTP and WebSocket connection test, and saves the connection using the same encrypted Desktop configuration used by Settings. A saved remote connection bypasses this choice on later launches. The regular Desktop build still includes the local-install option; this is a remote operating mode, not a separate client-only application.
In remote mode the gateway host is the execution boundary: agent tools, terminal commands, and file operations run against the remote Hermes host, not the computer displaying the Desktop UI.
Projects are the workspace abstraction. A project may own multiple folders, repositories, worktrees, and sessions; a bare new chat remains detached unless the user enters a project or configures a default project directory. Use the Projects UI rather than adding a second per-session folder-picker workflow.
Changing profiles or connection modes is a soft workspace switch, not another cold boot. The shell and current management overlay remain mounted while gateway-bound nanostores are wiped, query-backed data is invalidated, and the new connection repopulates skeletons. This prevents rows or transcripts from the previous gateway bleeding into the next one.
Verification
Run before opening a PR (lint may surface pre-existing warnings but must exit cleanly):
npm run fix
npm run typecheck
npm run lint
npm run test:ui
npm run test:desktop:platforms
Run npm run test:desktop:all for install, boot, update, packaging, or other
release-path changes.
Troubleshooting
Boot logs land in HERMES_HOME/logs/desktop.log (includes backend output and recent Python tracebacks) — check it first if the app reports a boot failure.
macOS / Linux:
# Force a clean first-launch setup
rm "$HOME/.hermes/hermes-agent/.hermes-bootstrap-complete"
# Rebuild a broken Python venv
rm -rf "$HOME/.hermes/hermes-agent/venv"
# Reset a stuck macOS microphone prompt (macOS only)
tccutil reset Microphone com.nousresearch.hermes
Windows (PowerShell):
# Force a clean first-launch setup
Remove-Item "$env:LOCALAPPDATA\hermes\hermes-agent\.hermes-bootstrap-complete"
# Rebuild a broken Python venv
Remove-Item -Recurse -Force "$env:LOCALAPPDATA\hermes\hermes-agent\venv"
The default Hermes home on Windows is
%LOCALAPPDATA%\hermes. Set theHERMES_HOMEenv var if you've relocated it.
Community
- 💬 Discord
- 📖 Documentation
- 🐛 Issues
License
MIT — see LICENSE.
Built by Nous Research.