diff --git a/hermes-config-template.prose.md b/hermes-config-template.prose.md index c40d298..871b018 100644 --- a/hermes-config-template.prose.md +++ b/hermes-config-template.prose.md @@ -150,6 +150,8 @@ mcp_servers: url: https://litellm.sysloggh.net/mcp headers: x-litellm-api-key: "Bearer " # Rule 15: must be a REAL key (sk-...), not an env-var name + # Note: MCP endpoint requires Accept: application/json, text/event-stream header + # This is handled by the MCP client library; don't add to config # ─── Compression ─── compression: @@ -237,6 +239,12 @@ MCP server entries in `mcp_servers:` must follow the format shown in the Templat - For template-based config generation: substitute the agent's key from the agent_keys table - For manual config updates: retrieve the key from the vault and insert the literal value +**Verification (2026-08-07):** +- Tested MCP initialize handshake against litellm.sysloggh.net/mcp with real key +- Confirmed: 200 response with `serverInfo.name: "litellm-mcp-server"` +- Confirmed: virtual keys have MCP access (tools/list returns 200, not 403) +- Key requirement: must be a valid LiteLLM virtual key (HTTP 200 on /v1/models) + ## Violation Classification When reporting findings, separate POLICY observations from FAULT findings: