import type { ResolvedMcpConfig } from "../shared/types.js"; /** * GRS-018 — map the resolved MCP server set onto the ACP `mcpServers` param of * `session/new` / `session/load`, making Hermes the third non-Claude consumer * (after Codex argv `-c` overrides and Grok's project `.grok/config.toml`). * * Wire shape (ACP `McpServerStdio`, verified against the deployed Hermes * v0.17.0 venv's `acp.schema`): `{name, command, args, env}` where `env` is an * ARRAY of `{name, value}` pairs — not a map. Hermes's ACP adapter converts * these back into a config map and registers them at session start * (`acp_adapter/server.py _register_session_mcp_servers`); no `type` * discriminator is needed for the stdio variant. URL-transport servers are * skipped this slice (same boundary as codex/grok). * * TOKEN CONTRACT — why this file, uniquely, injects JINN_GATEWAY_TOKEN: * Hermes spawns MCP stdio subprocesses with a FILTERED environment * (`tools/mcp_tool.py _build_safe_env`: PATH/HOME/XDG_* + explicitly-configured * keys only; its config-file `${VAR}` interpolation does NOT run on the ACP * registration path). So the inherited-env channel that carries the bearer * token to the jinn server under codex/grok is CUT under Hermes. The only way * the token reaches the server is as an explicit env entry in the ACP message. * That is safe where argv/config-file serialization was not: the ACP channel is * an in-memory stdin pipe between the gateway and its child — the token never * touches argv (world-readable via `ps`) or any file (Hermes registers * ACP-provided servers in memory only; its save-path is dashboard/CLI-only). * The injection is restricted to the built-in `jinn` server so the secret is * never handed to third-party server processes. */ /** ACP EnvVariable — env crosses the wire as name/value PAIRS. */ export interface AcpEnvVariable { name: string; value: string; } /** ACP McpServerStdio as `session/new`/`session/load` expect it. */ export interface AcpMcpServerStdio { name: string; command: string; args: string[]; env: AcpEnvVariable[]; } /** Build the ACP `mcpServers` array from the resolved set (stdio only). */ export declare function buildAcpMcpServers(resolvedMcp: ResolvedMcpConfig | undefined): AcpMcpServerStdio[]; //# sourceMappingURL=hermes-mcp.d.ts.map