Herm
Herm is an open-source, containerized coding agent that runs every terminal session in its own sandbox, so the agent acts without touching
Missing pricing page? Then the MIT-licensed binary is the whole cost — no license fee, which makes Herm cheap to trial and cheap to keep. What you pay for in friction is ecosystem: the vendor's own table concedes no MCP support and no IDE integration, so if your workflow leans on MCP servers or an inline editor assistant, Claude Code or OpenCode will fit better. Pick Herm when container isolation is the priority and there's room to manage API keys yourself.
Verified 20m ago · liveness 59/100 · cite: rightaichoice.com/tools/herm
- Developers who want an autonomous coding agent that cannot modify the host system
- Security-minded engineers who prefer container isolation to approval prompts
- Teams that want to swap between Anthropic, OpenAI, Gemini, Grok, and local Ollama models
- Terminal-first developers who want a lightweight Go binary instead of a heavier desktop app
- Workflows that depend on MCP servers — the vendor's comparison table lists no MCP support
- Teams expecting IDE plugins or an inline editor assistant
- Beginners who want a graphical interface rather than a CLI
We scan live Reddit threads, YouTube comments, X posts, G2 reviews and other communities — and hand you an honest verdict in under a minute.
- Honest verdict, not marketing
- Real pros & cons from real users
- Attributed quotes with receipts
3 free scans · no card needed
Skip Herm if your workflow depends on MCP servers or an IDE-integrated assistant — the vendor's comparison table lists neither, so you would be swapping ecosystem reach for container isolation.
Herm itself is free and MIT-licensed, but you bring your own API keys — Anthropic, OpenAI, Gemini, or Grok usage bills land on your provider account, not the vendor's.
Herm is MIT-licensed and free to run, so on license cost it sits below paid assistants like Claude Code, and its structure is closest to OpenCode and Pi — free, open-source terminal agents. The honest comparison is not license price but total cost: with Herm you pay your model provider directly for API usage (or supply your own GPU for Ollama), so heavy agentic use shifts spend to inference rather than a subscription.
In short
Herm — Herm is an open-source, containerized coding agent that runs every terminal session in its own sandbox, so the agent acts without touching. Best for Developers who want an autonomous coding agent that cannot modify the host system, Security-minded engineers who prefer container isolation to approval prompts, Teams that want to swap between Anthropic, OpenAI, Gemini, Grok, and local Ollama models. Free to use.
What people actually say about Herm — is it worth it?
We ran a structured research pass across product reviews, community discussions, and post-purchase forum threads to surface the patterns vendors won't publish themselves. Below: the recurring strengths, the hidden costs people mention most, and the cohort that consistently regrets adopting this tool.
19 mentions across 3 sources (Hacker News, GitHub, Lemmy) · researched Jul 3, 2026.
Average across the 3 sources that answered — each source counts once, not each post.
- +Container per session keeps host files completely safe.
- +Automatic tool extension inside containers saves manual setup.
- +Supports multiple AI providers without vendor lock-in.
- +Single Go binary with instant startup and low memory use.
- +Fully open-source system prompts under MIT license.
- −Extremely limited community feedback — almost no real user reviews.
- −Container startup may add latency for quick code suggestions.
- −No native support for GUI or cloud IDE integrations yet.
- −Learning curve for developers new to containerized workflows.
- −Unclear how well it scales for large or long-running tasks.
- • No cloud hosting; you run your own servers or local machine incurring compute and Docker costs
Viability Score
How well maintained and how widely used is Herm? Built from what the vendor actually publishes (docs, changelog, tutorials, integrations, pricing), whether the site is live, and how much real users discuss it. How we calculate this
Last calculated: October 2026
How we score →Key Features
- Runs each session in its own container, isolated from the host filesystem
- Containers auto-extend with dev tools as you prompt
- No approval prompts — the agent acts freely inside the container
- Multi-provider model support: Anthropic (Claude), OpenAI (GPT), Google (Gemini), xAI (Grok), Ollama
- Switch model providers at any time without lock-in
- Single Go binary with instant startup and low memory footprint
- Install via curl script, Homebrew tap, or `go build` from source
- Terminal-only CLI workflow — no GUI
- System prompts published under the MIT license
- Bring your own API key, configured via the CLI on first run
- /learn command to learn from arbitrary inputs
- Community Grafana Agent observability integration for monitoring runs
- Open-source project, currently at v0.8.7
About Herm
Herm is an open-source coding agent for developers who want an autonomous terminal assistant without handing it the keys to their machine. Each session runs in its own container, so Herm installs dev tools, runs commands, and edits code without stopping for approval prompts. Containers extend automatically with dev tooling as you prompt, so you rarely pre-bake an image. It ships as a single Go binary with fast startup and a small memory footprint, installable three ways: a curl script (`curl -fsSL https://hermagent.com/install.sh | sh`), a Homebrew tap (`brew tap aduermael/herm && brew install herm`), or a source build with `go build`. You pick the model at runtime from Anthropic (Claude), OpenAI (GPT), Google (Gemini), xAI (Grok), or local models through Ollama, and you can switch providers whenever you like with a key added on first run. Everything is MIT licensed, including the system prompts — useful if you have ever wanted to read the instructions a coding agent quietly follows. The current build is v0.8.7. Herm's positioning is explicit: Claude Code runs on your host and gates risky actions behind approvals; OpenCode supports MCP and IDE integration but is also host-based. Herm's bet is that containerization by default beats permission management. The tradeoff is on the vendor's own comparison table — no MCP support and no IDE integration. Independent signal cuts both ways: a third-party 10-task harness benchmark put Herm against Claude and OpenCode, and a community project added Grafana Agent observability for monitoring runs. Meanwhile, security researchers have twice shown Herm and peer agents being steered into running malware or installing unowned code inside corporate networks — container isolation protects your host, not your judgment.
Behind the Verdict
Reach for Herm when the risk you care about is the agent itself. If you have watched a coding agent wander outside the project directory, rewrite a dotfile, or ask for approval on the fortieth command of the afternoon, the container-per-session model is a real answer rather than a marketing one. The agent acts freely because it cannot reach your host, and containers growing dev tooling as you prompt means you spend your time coding, not maintaining an image. Provider flexibility is the second reason to pick it. Anthropic, OpenAI, Gemini, Grok, and local Ollama models are all switchable at runtime, so you are not repricing your whole workflow every time a model changes or an API bill spikes. That is a meaningful hedge for solo developers and small teams without a procurement process. Where it bites is the surrounding toolchain. MCP support and IDE integration are both absent from the vendor's comparison table, which puts Herm behind Claude Code and OpenCode on those two axes. If your setup pipes context through MCP servers or you live inside an editor plugin, hermes's sandbox does not compensate; OpenCode is the closer fit and Claude Code is the more integrated one, though both run on your host. Security deserves an honest read. Two separate reports in 2026 showed Herm and comparable agents being tricked into running malware or installing unowned code inside corporate networks. Container isolation protects your filesystem, not the network around it, and not your judgment about what the agent should be doing. Treat it as one layer, not the layer. On observability, a community project now wires Herm runs into an existing Grafana Agent setup, which helps teams that already watch infrastructure there. It is community tooling, not a vendor-managed product, so expect to
Researching Herm? Get your full AI stack in 60 seconds.
Free, no signup — tell us your goal and get tools matched to your budget & existing stack.
Real-world workflow fit
Concrete scenarios for the personas Herm actually fits — and what changes day-one when you adopt it.
You install the single Go binary via Homebrew, add your Anthropic API key on first run, and point it at a repo. The agent spins up a container per session, auto-installs the build tooling it needs, and edits and runs code without asking for approval each step.
Outcome: You get autonomous coding sessions with instant startup and a small memory footprint, and your host filesystem is never touched.
You clone the source, read the MIT-licensed system prompts to see exactly what the agent is instructed to do, then run risky install-and-test workflows inside the per-session container using a local Ollama model.
Outcome: You can audit the agent's instructions before trusting it and keep experimental installs isolated from your machine.
You start a feature with Gemini, switch to Grok for a second opinion on the same codebase, and fall back to a local Ollama model when you are offline or want to avoid API spend.
Outcome: Model choice stays a runtime decision with no lock-in, and the container state persists the project context across switches.
Use Cases
- Run complex coding tasks without risking your host system
- Test AI-driven scripts in isolated containers before deployment
- Switch between Anthropic, OpenAI, Gemini, Grok, and local Ollama models on one project
- Develop and debug code using local Ollama models with full sandboxing
- Automate repetitive development workflows without manual approval prompts
- Feed arbitrary knowledge into the agent with the /learn command
- Audit exactly what instructions a coding agent follows via MIT-licensed system prompts
- Monitor agent runs with community Grafana Agent observability tooling
Models Under the Hood
as of 2026-10-08
Limitations
- Herm requires familiarity with the CLI and container concepts, as it is a terminal-native coding agent with no GUI.
- Installation is manual via curl, Homebrew tap, or a source build.
- The vendor's own comparison table lists no MCP support and no IDE integration, so MCP-based context servers and editor plugins are out.
- Isolation has limits: security research in the past few months showed Herm and comparable agents being steered into running malware and installing unowned code inside corporate networks, so the container protects your host but not necessarily your network or your judgment.
as of 2026-09-23
Verification history
We have re-verified Herm 9 times since . Each pass re-reads the vendor's own pages and re-checks every listed field against that evidence; passes where nothing had changed are marked as such.
- — re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
- — re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
- — re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
- — re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
- — re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
- — re-checked, vendor evidence unchanged
Showing the 6 most recent of 9 verification passes.
Free to cite with attribution — this page re-verifies continuously.
12-month cost
Project the real annual outlay, including the implied monthly cost when only an annual tier is published.
Vendor list price only. Add-on usage, seat overages, and contract minimums are surfaced under Hidden costs & gotchas.
Plans compared
For each published Herm tier: who it actually fits, and what it adds vs. the previous tier. Cross-reference the cost calculator above for projected annual outlay.
Open Source
$0/mo
Ideal for
Solo developers, security-minded engineers, and terminal-first teams who want an autonomous coding agent without a license fee and are comfortable bringing their own model API key.
What this tier adds
Starting tier and only published tier: MIT-licensed single Go binary, container-per-session isolation, multi-provider model support, and published system prompts at $0/mo.
Where the pricing makes sense
The company stage and team size where Herm's pricing actually pencils out — and where peers do it cheaper.
Herm is MIT-licensed and free to run, so on license cost it sits below paid assistants like Claude Code, and its structure is closest to OpenCode and Pi — free, open-source terminal agents. The honest comparison is not license price but total cost: with Herm you pay your model provider directly for API usage (or supply your own GPU for Ollama), so heavy agentic use shifts spend to inference rather than a subscription.
Setup time & first value
How long it actually takes to get something useful out of Herm — broken out by persona, not the marketing-page minute.
Install-to-first-session is quick for anyone comfortable with a terminal: one curl command, a Homebrew tap, or a `go build` from source, then paste an API key on first run — expect minutes, not hours. Reading the system prompts or wiring up Grafana Agent observability for run monitoring is a separate, longer task. If you are new to containers, budget extra time to understand what the sandbox does
Switching to or from Herm
How to bring data in from common predecessors and how to get it back out — written for the switcher, not the buyer.
- →From Claude Code: install the Herm binary, add your provider API key, and re-run your coding tasks inside the per-session container instead of on your host — but MCP-based tooling will not carry over, as the vendor
- →From OpenCode: keep your terminal workflow and provider keys, then adopt Herm's container-per-session model in place of host execution; you trade IDE integration for isolation.
- →From Pi: if your setup leans on TypeScript plugins and community packages, expect to rebuild that extensibility outside Herm, which bets on sandboxing rather than a plugin ecosystem.
- →From a plain terminal + manual dev environment: let Herm's auto-extending containers install the dev tooling as you prompt instead of pre-baking an image.
- ↗To Claude Code: if you need MCP support and IDE integration and are willing to accept host execution with approval prompts, Claude Code covers both per the vendor's comparison table.
- ↗To OpenCode: move to it if you want a multi-provider, open-source terminal assistant that runs on the host and supports MCP and IDE integration.
- ↗To Pi: choose it if extensibility via TypeScript plugins and a broad community package ecosystem matters more than default sandboxing.
- ↗To a managed enterprise agent platform: move if you need vendor support contracts and managed controls rather than a free MIT project.
Integrations
Resources & Guides
Tutorials & Learning
YouTube returned 6 videos for “Herm”, and we withheld 6: 6 could not be judged, because “Herm” is a single word that other videos use for other things. We are showing none, because we could not prove any of them are about Herm.
Official links
Tools that pair well with Herm
Common stack mates teams adopt alongside Herm, with the specific reason each pairing earns its keep.
Crush
Open-source agentic coding assistant that runs inside your terminal and wires any LLM into your CLI workflow.
Cline
Open-source coding agent that reads your repo, edits files, and runs terminal commands across VS Code, JetBrains, CLI, and a desktop app.
Openclaude
Open-source terminal coding agent that runs against any model you point it at — OpenAI, Gemini, Codex, Grok, Ollama, LM Studio and 200+ more.
Featured Head-to-Head Comparisons
Herm vs Locus Robotics
Locus Robotics and Herm serve completely different domains: warehouse automation vs. AI coding. Locus is for high-volume logistics operations needing physical robots and a subscription model; Herm is a free open-source terminal agent for developers who want containerized safety and multi-provider flexibility. Choose based on your problem space — there's no direct competition.
Herm vs Presto Voice
Presto Voice and Herm serve completely different domains. Presto Voice is a specialized drive-thru voice AI for QSR chains, delivering measurable revenue lift through automation and upselling, but expensive and enterprise-only. Herm is a free, open-source terminal coding agent with sandboxed safety and multi-provider flexibility, perfect for privacy-conscious developers. Choose based on your context: if you run a QSR chain, go Presto; if you code in a terminal, pick Herm.
Herm vs Truleo
Truleo and Herm serve entirely different domains: Truleo is a paid law enforcement intelligence platform, while Herm is a free, open-source coding agent for developers. For police agencies needing to unify data from RMS, jail calls, and body cameras, Truleo is the only choice. Conversely, developers seeking a safe, terminal-native coding agent with container isolation should pick Herm.
Alternatives to Herm
View allCrush
Open-source agentic coding assistant that runs inside your terminal and wires any LLM into your CLI workflow.
Cline
Open-source coding agent that reads your repo, edits files, and runs terminal commands across VS Code, JetBrains, CLI, and a desktop app.
Openclaude
Open-source terminal coding agent that runs against any model you point it at — OpenAI, Gemini, Codex, Grok, Ollama, LM Studio and 200+ more.
Frequently Asked Questions
Used Herm? Help shape our editorial sentiment research.