Harnesses
Hermes Agent 0.21.2: the state.db release and the credential vault
After a big 0.21.0, Hermes spent its next two point releases on reliability. What broke, what the 11 September patch fixes, the new password-blind vault, and how to update safely.
- Published
- 13 Sep 2026
- Reading
- 8 min
- Class
- harnesses
half-life 45dfrom 13 Sep 2026
Two weeks after the large 0.21.0 release, Hermes Agent's 0.21.2 (11 September) is the
one to install. It is unglamorous by design: the headline is that the local session
database, state.db, stops corrupting itself.
What was going wrong
Hermes keeps conversation history in a SQLite database. With profiles, a gateway, a
dashboard and scheduled jobs all running, several processes could open it for writing at
once. The release notes identify four separate multi-writer corruption paths, including
profile gateways writing to the root database on a timer, the dashboard opening writable
handles and the doctor --fix command checkpointing while other processes
held the file. Symptoms ranged from wedged databases to a single corrupt row crashing
session listing, export or insights.
What 0.21.2 fixes
- Reliability. No second writers, healthy write-ahead-log databases no longer wedge, and search-index damage degrades gracefully instead of killing a conversation.
- Resilience. A malformed timestamp or corrupt row now shows a warning instead of crashing listing and export.
- Profile isolation. Sessions can no longer bind to another profile's database, and bots no longer inherit the default profile's allow-lists — an isolation bug that mattered for anyone running several agents.
- Speed. Opening the database no longer takes the write lock when nothing needs writing; one-shot commands against a busy gateway return in hundredths of a second instead of several seconds.
The new credential vault
The release also adds a password-blind credential vault with 1Password, Bitwarden and a local Hermes option. The point of "password-blind" is that the agent can use a credential without ever being able to read it back, which is the right shape for the accounts we recommended scoping narrowly in the small-business guide. Also new: a plugin catalogue with a CLI and pinned versions, connector tools such as Gmail, Linear and Notion that are searchable on demand, and a free Nous tier with a guided first launch.
How to update
- Stop background jobs and gateways for the profile you are updating.
- Copy the data directory, including
state.db, somewhere safe. - Run
hermes update(or rebuild the Docker image). - Start one profile, run a session listing and a search, and only then bring the rest back.
If you saw odd errors
Wedged sessions, crashing listings or a profile showing another profile's history were real bugs, not your setup. Update first; avoid running repair commands on an older version while the gateway is live, since one of the four corruption paths was exactly that.
Nothing here changes the advice about supervision: a more reliable agent is still one you should read the logs of. The Hermes spec sheet has the standing summary and our note on 0.21.0 covers the features this release stabilises.
Sources
- NousResearch/hermes-agent releases — v0.21.1 (7 September) and v0.21.2 (11 September) notes.