A browser window does not tell you who operates the agent behind it. Hermes Desktop can connect to a server you maintain. A self-hosted Web Dashboard can open in your phone's browser. Neither turns that server into a managed service.
Quick answer#
Choose self-hosted Hermes Agent when you need control over local files, private-network tools, model routing or the execution environment, and you can own updates, security, backups and recovery. Choose FlyHermes when you want managed browser/mobile access, supported model access and connected channels without maintaining the host and gateway yourself. Check the current FlyHermes plans and usage terms before buying; managed hosting is not unlimited inference or a promise that every integration works without authorization.
The useful question is not “does it have a dashboard?” It is “where will my work run, and who fixes each part when I am away?”
Choose the operating model, not the window#
Self-hosted Web Dashboard: you operate the installation#
The Hermes Agent Dashboard manages configuration, profiles, keys, sessions, logs, skills, tools and scheduled work. Current official documentation also describes a Chat tab that embeds the real terminal UI over a PTY/WebSocket. That is a self-hosted interface, not the FlyHermes hosted chat product. Native Windows can use the administration pages, while the PTY-backed Chat pane requires a POSIX environment such as WSL2.
A dashboard can make administration easier without taking responsibility for the machine. You still decide who can reach it, which credentials it holds, how it restarts and how state is restored. Start with the private Web UI setup guide if those are responsibilities you want.
Hermes Desktop: a client connected to a particular backend#
Desktop is the native workspace. Its selected gateway and profile determine where the session's files, memory and tools live. Connecting Desktop to a VPS does not copy your laptop's files or browser logins there. Nor does making a connection Primary necessarily switch the current Sessions workspace.
Use the remote Desktop connection guide when you want the native client but intend to maintain the remote runtime. A connection test and a harmless session on the intended profile are more useful than matching the version labels on two windows.
FlyHermes: a managed Hermes workspace#
FlyHermes advertises a hosted runtime, browser chat, supported model API access, tooling infrastructure, core channels and a monthly usage allowance. Its value is removing infrastructure assembly and day-to-day runtime maintenance, not making the software open-source in a different way.
Before subscribing, confirm the current supported channels, model access, allowance and account terms on the FlyHermes offer. Ask separately about private-network connectivity, data export, required integrations and team access. Do not infer support for a particular Desktop connection method, Bot Screen, SSO or custom deployment from the word “hosted.”
Match the choice to one real job#
A morning research brief: managed hosting is a good fit when the inputs are accessible to the hosted agent and the outcome is a report in your preferred supported channel. You still define the sources, cutoff time and what counts as a useful result. Self-hosting can be a good fit when the brief needs a private database or files that must remain inside your network.
An inbox assistant: start with draft-only work, whichever hosting model you choose. Verify the connected mailbox, authorized scope and approval step before permitting sends. The October 4 Sharbel workflow walkthrough explicitly recommends draft mode rather than automatic sending. That is a useful workflow constraint, not evidence of guaranteed sales or accuracy.
Work from your phone: a phone is the client, not proof of an always-on backend. If Hermes runs on a sleeping laptop, installing another mobile interface does not keep the runtime awake. The phone access guide separates messaging, private dashboard access and managed web chat.
Browser work requiring a login: check where the browser actually runs and how you will complete login or approval challenges. A hosted agent cannot automatically inherit the cookies from your personal computer. Require a small read-only demonstration against the intended account before giving it a consequential task.
Do not buy a larger server for the wrong failure#
“Not enough memory” can refer to host RAM, a container limit, model context or an optional remote screen. Those are different problems.
A September 30 community support thread initially described trouble connecting Desktop to a cloud instance. The discussion identified Bot Screen, not ordinary dashboard administration. The user later reported that a larger instance allowed the screen to connect. This is one support case, not a universal sizing benchmark or a FlyHermes plan recommendation.
The official Bot Screen documentation explains why: a Linux desktop and headed browser run on the owning host or supported sandbox, with a free-memory admission check. That workload is different from opening an admin page. Identify the exact pane and failing operation before buying capacity or changing a model.
For a self-hosted buying decision, record:
- The required job: text chat, a scheduled report, browser interaction or remote screen takeover.
- The machine or container that executes it, not just the device showing the interface.
- Available memory and the effective container limit during the failed attempt.
- The exact error and timestamp, with secrets and private paths removed.
- Whether the basic chat still works when the optional screen is closed.
The VPS setup guide covers the operating checks. If maintaining that inventory is not work you want to own, compare managed hosting—but still confirm that the managed offer supports the exact workflow.
What each side still has to own#
Runtime, updates and recovery#
With self-hosting, you own the server or dedicated computer, process supervision, storage, updates and rollback. Docker changes packaging; it does not supply an operator. A running container can contain a failed gateway, and a recently updated Desktop can be ahead of its backend. Use the Docker troubleshooting guide to identify the failed layer before rebuilding anything.
With managed hosting, the service operates the hosted runtime. You still need an escalation route and a way to determine whether a missed result was a platform outage, a rejected model call, a tool permission failure or an incomplete task. Ask what support and recovery the actual plan includes; do not assume a guaranteed response time or SLA.
Credentials, permissions and approval#
Self-hosters own dashboard authentication, secrets, gateway allowlists and access to connected services. Keep administrative access distinct from the channel where a teammate asks for a report. The server security checklist covers private access and public authentication boundaries.
A managed service can handle infrastructure and supported model access, but it cannot decide which business records each user should see. You own account authorization, least-privilege scopes and approval for actions such as sending email, publishing content or making payments. Ask about role separation before using one shared assistant for unrelated clients.
Usage, allowances and the bill#
Self-hosted software, infrastructure and model inference are separate cost lines. Include paid tools, storage, backup and the time spent diagnosing failures. Do not estimate the whole system from the price of the smallest VPS.
FlyHermes includes model access and a monthly usage allowance in its advertised offer. Review the current allowance, supported models and exhaustion behavior; neither “included” nor “managed” means unmetered. For variable inference spend, use the provider-cost measurement guide. Compare the same representative job and accepted result on both paths rather than assuming one is always cheaper.
State and exit options#
For self-hosting, test restoration of a protected backup before trusting it. An export is not a tested recovery, and a copied profile name is not proof that its credentials, files and schedules work on another host.
For managed hosting, confirm what can be exported, what must be reauthorized and how cancellation affects access or retention. Do not assume automatic migration of private files, browser cookies or running jobs. Keep a rollback option until one representative workflow has passed on the new runtime.
There is also a separate implementation-service purchase: paying a team to scope, integrate and launch one business workflow. The Agentra review examines that model and its contract-defined handoff. Do not compare a managed Hermes hosting fee with a deployment-pod quote as if both include workflow discovery, finance approvals, user training and acceptance testing; first write down which responsibilities you need another party to own.
Self-hosted tools can coexist with a vendor-operated agent control plane. The Claude Managed Agents review explains why local tool execution is not equivalent to local inference, zero retention or an offline agent. Draw the data-flow boundary for inputs, tool results and session history before accepting a hosting label as a privacy guarantee.
The OpenAI Agents API review provides another concrete boundary: a self-hosted sandbox does not make the managed API eligible for Zero Data Retention. Separate the location of tool execution from the location of session state and orchestration. Hosting only one layer yourself does not establish an entirely local data path.
A free coordination platform can still leave the agent running on your own machine. The Agency Label Academy review separates a free workspace from the runtime, model tooling and human approval it depends on. Map each component before outsourcing maintenance: who runs the listener, who holds credentials, who approves previews and who restores a failed site? Buying managed agent hosting does not automatically manage a separate agency platform.
Run a bounded acceptance test before moving real work#
Use one small task that reads public information and produces a local draft or private report. Do not test recovery with a payment, public post or customer email.
- Name the backend and profile that own the task. Check its actual input access.
- Run it once and inspect the output, not only the assistant's completion message.
- Close the client. For a scheduled workflow, verify a later result while that client remains closed.
- Check the intended destination and timestamp. A job row and a delivered report are separate facts.
- If a run stops unexpectedly, inspect its output and history before retrying. An uncertain completion can hide a finished external action.
- Record who will diagnose the next failure and what evidence they need.
The 24/7 setup guide expands the reliability test. This acceptance test is a proposed evaluation method, not a benchmark we claim to have run on your deployment.
Compare a working week, not a demo#
Keep a short record for each candidate setup. No invented hourly rate or monthly saving is needed:
Workflow and owner:
Backend / profile / client:
Required files, accounts and channel:
Accepted results / attempted runs:
Model and tool charges observed:
Infrastructure or subscription charge:
Operator time and incidents:
Approval and recovery steps:
Export or rollback test:
Include failed attempts and time spent on authentication, updates, browser recovery and missed delivery. A low invoice can be a poor deal if you cannot maintain the service; a managed subscription can be a poor fit if the required private integration is unavailable. Compare actual coverage before price.
Move one workflow without running it twice#
Inventory the old task, input locations, permissions, schedules and delivery destinations. Back up self-hosted state and confirm the new service's import or manual recreation path. Reauthorize only the accounts the new workflow needs; never paste credentials into a migration document.
Test on the new host with external side effects disabled. Check that the expected profile, files and channel are in use. Pause the old schedule before enabling the replacement, then verify one new run and its destination. Keep the old setup available for a time-boxed rollback without leaving both schedules active. Retire old credentials and infrastructure only after the new path is accepted.
The decision#
Choose self-hosted Hermes when control is the requirement and someone can own the operating work. Choose FlyHermes when the requirement is a managed assistant you can reach from browser or phone, with supported model access and channels, and the current offer covers your workflow.
Start with FlyHermes pricing and plan checks, or review the managed workspace. If you choose self-hosting, use the linked dashboard, security and VPS guides rather than treating a successful install as the end of setup.
Product boundaries were checked against the official Web Dashboard guide, Desktop connection guide and FlyHermes's public offer on October 5, 2026. Community and creator examples explain the questions buyers ask; they are not guarantees of compatibility, performance or financial results.