rakit-agent/hermes
step 07

Konek ke Telegram

Agent yang sama (SOUL, skill, memory) jadi bot di HP lo. Bisa voice note, gambar, dokumen. Yang penting: siapa yang boleh ngobrol harus lo kunci.

  1. Bikin bot di @BotFather

    Buka Telegram, cari @BotFather, kirim /newbot. Dia nanya display name (bebas) dan username (harus unik, akhiran bot, misal bima_hermes_bot). Lo dapet token kayak 7123456789:AAH1bGci.... Itu rahasia.

  2. Cari user ID lo

    Chat @userinfobot, dia balikin ID numerik lo (misal 123456789). Ini yang masuk allowlist, bukan username.

  3. Taruh di .env

    ~/.hermes/.env
    TELEGRAM_BOT_TOKEN=7123456789:AAH1bGci...
    TELEGRAM_ALLOWED_USERS=123456789        # koma buat banyak: 123,456

    Atau pake wizard, yang nulis ke .env buat lo:

    bash
    $ hermes gateway setup

    Di Hermes Desktop / dashboard ada juga tombol Create with QR: scan, bot kebuat, user ID kedeteksi, .env keisi, gateway restart. Kalau lo bikin konten, jalur manual lebih enak dijelasin.

  4. Jalanin gateway

    bash
    $ hermes gateway              # foreground, enak buat liat log pas pertama
    $ hermes gateway install      # jadi user service (systemd / launchd)
    $ hermes gateway start
    $ hermes gateway status
    $ hermes gateway stop

    DM bot lo. Kalau dibales, jadi.

Kunci akses: allowlist & pairing

Cuma dua hal yang nentuin bot jawab atau nggak: user ID di allowlist, atau pairing code yang lo approve. Gak ada allowlist = deny-all. Ada TELEGRAM_ALLOW_ALL_USERS tapi itu dev-only, karena bot ini punya akses shell.

Pairing (buat nambah orang tanpa restart)

  1. Temen DM bot. Karena gak di allowlist, bot bales: 🔐 Pairing code: XKGH5N7P
  2. Temen kirim kode itu ke lo (Slack, WA, apapun).
  3. Lo approve di server:
bash
$ hermes pairing approve telegram XKGH5N7P

Langsung masuk, gak perlu restart. Kode expire 1 jam, maks 3 kode pending per platform, 1 request per user per 10 menit, 5x gagal approve = lockout 1 jam. File pairing di disk chmod 0600.

Grup & topic

Default-nya bot cuma jawab DM dari allowlist. Buat grup, set di config gateway:

~/.hermes/config.yaml
gateway:
  platforms:
    telegram:
      extra:
        group_allow_from:          # user yang boleh nge-trigger di grup
          - "123456789"
        group_allowed_chats:       # grup mana aja
          - "-1001234567890"

Boundaries khusus bot Telegram

Bot ini jalan unattended, lo gak selalu liat layarnya. Jadi:

  • TELEGRAM_ALLOWED_USERS cuma ID lo (dan orang yang lo percaya).
  • approvals.unattended_mode: deny (default) biar command berbahaya ditolak, bukan nunggu.
  • Matiin skill coding/devops di Telegram lewat hermes skills.
  • Pertimbangin terminal.backend: docker atau matiin toolset terminal.
  • memory.write_approval: true: lo review memory sebelum nempel.
  • Gateway di VM terpisah kalau bot-nya dipake orang lain.
  • Cek ~/.hermes/logs/gateway.log berkala.

Sesi Telegram nyambung terus, jadi memory snapshot-nya gak ke-refresh. Kalau mau dia "inget" hal baru, kirim /new di chat buat mulai sesi baru.

Platform lain

Wizard yang sama (hermes gateway setup) ngedukung Discord, Slack, WhatsApp, Signal, Email, Microsoft Teams, Home Assistant (plugin). Polanya sama: token di .env, allowlist user, gateway jalan.