OpenClaw and Hermes Agent both let you choose the model and run the agent yourself. Hermes also offers optional Nous inference, hosted tools, and Cloud hosting.
As of September 30, 2026, the useful difference is which parts you operate and which accounts pay for them. A Nous login doesn't mean Cloud hosting is included.
We compared the documented setup and billing routes.
We haven't installed either agent, linked an account, inspected an invoice, or run the same task in both.
This decision matrix reconciles the responsibilities documented by each project. Every linked source was checked on September 30, 2026. It describes configuration choices, without scoring product quality.
| Decision | OpenClaw documented route | Hermes Agent documented route |
|---|---|---|
| Computer running the agent | Run the Gateway on your own hardware or server. The project doesn't sell a hosted service. Runtime | Run the CLI, desktop app, or messaging gateway yourself, or choose a separate hosted instance in Hermes Cloud. Installation, Cloud |
| First working conversation | Quick start can reuse an existing Claude Code or Codex CLI login, or a provider API key, and checks it with a real completion. Onboarding | Configure a provider with hermes model or hermes setup, verify a conversation, then add the messaging gateway. Quickstart |
| Remote model access | Provider plugins publish catalogs; custom endpoints have separate configuration. Providers | Direct provider keys, supported subscription logins, custom endpoints, or optional Nous Portal routing. Providers |
| Local inference | Documented Ollama, LM Studio, vLLM, SGLang, and other local routes. Local runtimes | Compatible local endpoints, with the model and served context window configured explicitly. Local endpoints |
| Inference bill | Your chosen provider bills its API or subscription account, according to that route. Usage and costs | Your direct provider account pays, or Nous Portal bills its selected route against your Nous balance. Portal |
| Tool bill | Search, media, embeddings, and other configured API tools can add charges. Cost components | Direct tool providers can be mixed with the pay-as-you-use Tool Gateway included with paid Nous plans. Tool billing |
| Hosting bill | Your hardware or hosting provider; no first-party OpenClaw hosting tier in the reviewed FAQ. Hosting scope | Your own host, or Hermes Cloud compute and storage charged separately from inference and tools. Cloud billing |
| Who can reach the agent | Channel access controls within one Gateway trust boundary. Mutually untrusted users need separate Gateways. Trust model | Messaging allowlists, DM pairing, and optional admin/regular-user distinctions for slash commands. Gateway access |
| Memory and state | Workspace and session history stay with the Gateway's host; configured remote traffic still leaves it. Data boundary | Profile memory and session storage live in the Hermes data directory; Cloud has a persistent hosted workspace. Memory, Cloud state |
| Updates and recovery | Follow the installation's update path and keep a verified state backup. Maintenance | Update through the source installer, desktop package owner, or container image as appropriate. A profile export excludes credentials. Updates, Backup scope |
Both agents can use your model provider
OpenClaw and Hermes Agent support direct model providers and local inference. Buying a Nous subscription is therefore one Hermes configuration choice, rather than a prerequisite for running the software. OpenClaw's provider plugins supply model catalogs; Hermes' provider picker also distinguishes provider keys from subscription logins. Those choices decide the account used for inference.
Bring your own key, usually shortened to BYOK, means you supply the provider credential. With an API-key route, that provider's billing and limits apply. A consumer subscription login is a different route and can have different model access, quotas, and extra-usage rules. The OpenClaw provider reference and Hermes provider reference list their supported paths. Neither list proves that your account can serve every named model.
For local inference, check the actual server and selected model before enabling tools. Hermes' quickstart requires at least 64,000 tokens of context and says smaller windows are rejected at startup. A model's advertised maximum isn't enough if your server loads it with a smaller window. OpenClaw's custom-provider guide likewise requires capability metadata to match the endpoint. An endpoint that answers a plain prompt hasn't yet demonstrated that it can use your chosen tools correctly.
Our agent-model shortlist can help choose candidates for a test. It ranks underlying models, so it cannot settle which of these products will complete your recurring workflow.
A Claude login can select a different bill
Hermes documents two distinct Claude subscription paths. Its native Anthropic OAuth route requires Claude Max and purchased extra-usage credits. The included Max allowance isn't consumed, and Claude Pro isn't supported on that native route. Native route documentation.
Anthropic's account guidance prefers API authentication for third-party tools and reserves the right to charge permitted third-party access to usage credits. That policy makes the authentication route part of the cost decision.
A separate Nous experimental Claude subscription plugin uses the installed, authenticated official Claude Code CLI for Pro or Max. It requires Hermes 0.21.4 or newer and keeps Hermes' own tools and agent loop. That plugin's documentation also says account entitlement and extra-usage settings still apply. A list-price cost estimate is not proof of an actual subscription charge.
Anthropic's Claude Code billing guidance says Pro and Max use shared subscription limits, but a configured ANTHROPIC_API_KEY instead incurs API charges. The Hermes plugin documents rejecting that conflicting API-key configuration.
OpenClaw also documents an official Claude CLI backend, separately from its Anthropic API-key route. The June 15 update on Anthropic's SDK plan page paused a proposed change to SDK and claude -p billing. That update doesn't establish how Hermes' separate native OAuth route is charged, or verify either product in an account.
Before relying on an existing plan, record the provider, selected runtime or plugin, account, and overage setting. Then confirm usage in the provider's dashboard. “Signed in with Claude” leaves too much unspecified for a budget.
Hosting puts different bills in different hands
OpenClaw's Gateway runs on infrastructure you choose. Hermes can also run on your own computer or server. Both arrangements leave someone responsible for the machine, credentials, backups, updates, and any services the agent calls. Existing hardware can avoid another hosting subscription, but its capacity and availability still matter.
OpenClaw's getting-started page currently requires Node.js 24.16+ or 26.1+, with Node 26 recommended. Its quick start runs the Gateway in the terminal. A persistent service is a later setup step. Hermes offers bundled desktop packages and a source installation. Its installation guide says current first-party installations use Python 3.14 and the macOS package supports Apple Silicon. Those are documented prerequisites, not measured installation times.
Nous Portal and Hermes Cloud solve separate parts of the setup. Portal supplies an account for inference and hosted tools. Cloud supplies the machine running your agent. A self-hosted Hermes installation can use Portal without moving its runtime to Cloud. Conversely, choosing a hosted machine doesn't remove the model and tool charges.
The Portal plan page displays Plus at $20 per month with $22 in monthly credits and a $10 rollover cap. Its public table uses a dollar symbol without identifying the currency code. Check currency and taxes at checkout. Those credits are an allowance for service usage. They cannot be converted into a fixed number of completed jobs from the plan price alone.
Hermes Cloud's billing FAQ charges running compute by uptime plus storage, and stopped instances for storage only. It explicitly adds inference and tool usage on top. For example, stopping an instance changes its hosting charge. It doesn't erase earlier inference usage or its stored workspace.
OpenClaw's usage display is also an estimate from available local session history, not the provider invoice. Compare model use, paid tools, and hosting as separate entries. The OpenClaw pricing guide builds that operating-cost estimate, while the API pricing table covers model token rates.
Access to the bot and authority to act are separate
OpenClaw's shared Gateway assumes a single operator or a team whose members trust one another. Everyone able to message a tool-enabled agent shares its delegated tool authority. Named roles and separate sessions are collaboration controls inside that boundary. They don't turn one Gateway into isolation between adversarial customers. Its trust model calls for separate Gateways for that arrangement.
Hermes separates messaging authorization from command approvals. Its gateway documentation covers allowed users and optional admin lists. The current admin/regular-user distinction gates slash commands. Plain chat is unaffected. Adding someone as a regular user therefore doesn't establish that the agent's conversational tool use has been restricted for them.
Hermes' security reference also distinguishes local and container terminal backends. The local backend supports dangerous-command checks. Specified container backends skip them because those use the container boundary. Review the approval mode, mounts, and credentials before assuming it will ask about every destructive operation. These are documented controls, not a security audit of either installation.
Self-hosting the runtime doesn't keep all task data on that machine. A remote model receives the content sent for inference. A hosted search or browser service has its own traffic, and a messaging platform carries the messages sent through it. OpenClaw states this distinction explicitly; Hermes' Portal tool routes also use Nous-managed infrastructure.
For a private-file task, list the model endpoint, enabled tools, messaging channel, and memory services before granting access. If the requirement is that the files remain on the machine, evaluate the entire route. A local model with a remote browser or extraction tool still has a remote service in the workflow. The personal AI agents hub compares these responsibilities with other product arrangements.
Record the configuration before deciding to switch
Our recommendation is to select the configuration that meets the hard requirements first, then judge its results on one job. The worksheet below turns the comparison into acceptance conditions. These are suggested checks we haven't run, so an empty result remains unknown.
| Reader constraint | Configuration worth checking | Accept it only after |
|---|---|---|
| Keep an existing server and API billing account | OpenClaw or self-hosted Hermes with that direct provider | The exact model works, the required tools are configured, and usage reaches the intended account |
| Run while a laptop is off | OpenClaw Gateway or Hermes gateway on an always-on host; Hermes Cloud is another hosting choice | A scheduled job completes with the laptop offline and its result reaches the approved destination |
| Have one account pay for hosted inference and tools | Hermes with Nous Portal, either self-hosted or in Cloud | The chosen model and tools are available, and their debits fit the budget; Cloud hosting is recorded separately |
| Use a small local inference server | Either local route, subject to its endpoint requirements | The served context window and tool support satisfy the agent; Hermes' documented context minimum is met |
| Let colleagues message a shared bot | The project's documented messaging access controls | Authorized users can reach it, unwanted users can't, and the authority available through ordinary chat is acceptable |
| Preserve preferences across sessions | The configured memory store, profile, and session settings | A saved fact appears in storage and can be retrieved in a later session; a verbal “saved” reply alone isn't evidence |
| Recover or migrate a working setup | Version-compatible backup and restore procedures | A copy restores the needed files, configuration, credentials, schedules, and state in a disposable environment |
| Decide which product costs less for your job | The same task, acceptance criteria, and recorded cost components | Completed results and actual account charges are reconciled, including retries and any intervention |
For example, a team with a working OpenClaw server and an approved API account has no documented billing reason to move solely because Hermes offers a subscription. We'd keep that setup while evaluating the specific unmet requirement. Reconsider if the current Gateway cannot meet the team's access boundary, tool needs, or maintenance constraints.
For someone willing to pay Nous for inference and tools but unwilling to maintain a server, Hermes Cloud is a route worth evaluating. The fit depends on its account access, data path, and separate hosting charge. It is the wrong configuration when the requirement is an entirely local runtime or a single flat fee covering unlimited work.
A local-model requirement leaves both products in consideration. Select the hardware and endpoint first, then check context and tools. Don't migrate a working local setup because a vendor calls its memory “self-improving.” A preference saved and retrieved across sessions is a result you can inspect. Improved task quality still requires its own test.
If neither product fits the required arrangement, the OpenClaw alternatives comparison considers a broader set of products. That is a different decision from choosing between these two configurations.
Product reliability still needs a matched task
OpenClaw's personal-agent benchmark pack uses synthetic users and a local mock-provider lane. Hermes publishes a browser component evaluation whose original per-run logs were lost and whose aggregate readouts were recovered. These materials describe repository or component testing. They don't establish a current cross-product winner for your job.
We haven't measured installation success, completed-job cost, delayed memory recall, or recovery after an interrupted recurring task. Our agent benchmark guide explains how task sets and execution conditions limit results. A higher underlying model score cannot substitute for testing the configured product.
A useful first evaluation is a contained file task: read an approved source folder, draft a change list with citations to the relevant files, and leave the source files untouched. Check the output against a written answer key. Before extending that responsibility, add a later-session recall check and an interruption-and-recovery check. Those proposed tests address different failures, so keep their results separate.
For a direct product comparison, hold the exact model version, provider, tools, machine resources, and permissions constant wherever both routes support them. Record product versions, failed attempts, usage, and human corrections. If one configuration uses Portal routing while another calls a provider directly, record that difference rather than calling the run model-controlled.
Before switching, name the requirement the new setup must meet and the evidence that will count as success. Keep the old setup and a verified backup until that result exists.
Questions
Can both agents use a local model?
OpenClaw documents local backends including Ollama, LM Studio, vLLM, and SGLang. Hermes Agent supports local compatible endpoints and documents a minimum 64,000-token context window. The selected model still needs to handle the tools you enable. Local inference alone doesn't make remote search, messaging, or other connected services local.
Does Hermes Agent require a Nous subscription?
Hermes Agent can run on your own machine with a supported model provider or local endpoint. A Nous subscription is optional for that setup. Nous Portal adds an inference and hosted-tool billing route, while Hermes Cloud adds hosting charges. Your chosen provider, tools, and computer still determine the operating bill.
Can I assume a Claude login uses my included allowance?
No. Hermes Agent's native Anthropic OAuth documentation requires Claude Max with purchased extra-usage credits and excludes the included Max allowance. Its separate experimental Claude CLI plugin documents Pro and Max subscription use. Check the exact route, account entitlement, and extra-usage settings. A successful login alone doesn't establish how a request is billed.
External sources linked in this article
24- 01Runtimedocs.openclaw.ai
- 02Installationhermes-agent.nousresearch.com
- 03Cloudportal.nousresearch.com
- 04Onboardingdocs.openclaw.ai
- 05Quickstarthermes-agent.nousresearch.com
- 06Providersdocs.openclaw.ai
- 07Providershermes-agent.nousresearch.com
- 08Local runtimesdocs.openclaw.ai
- 09Local endpointshermes-agent.nousresearch.com
- 10Usage and costsdocs.openclaw.ai
- 11Portalhermes-agent.nousresearch.com
- 12Tool billinghermes-agent.nousresearch.com
- 13Trust modeldocs.openclaw.ai
- 14Gateway accesshermes-agent.nousresearch.com
- 15Memoryhermes-agent.nousresearch.com
- 16Maintenancedocs.openclaw.ai
- 17Updateshermes-agent.nousresearch.com
- 18Native route documentationhermes-agent.nousresearch.com
- 19account guidancesupport.claude.com
- 20experimental Claude subscription plugingithub.com
- 21Claude Code billing guidancesupport.claude.com
- 22SDK plan pagesupport.claude.com
- 23Portal plan pageportal.nousresearch.com
- 24security referencehermes-agent.nousresearch.com
