1. Try the sandbox
Add this to~/.hermes/config.yaml, preserving existing entries:
/reload-mcp.
The sandbox needs no Plainrouter account or key, returns synthetic data, and never contacts Meta. Ask:
sandbox: true. This checks the connection, not production data or ad execution.
2. Create a workspace key
In Plainrouter, select your workspace and open Settings → Workspace keys. Create a Read key for analysis; use Write for Actions, including Actions record reads. Copy it once into your protected credential configuration. Each key covers one workspace. Never put keys in prompts or source control. Key permissions and replacement.3. Add Plainrouter to the client
Add a production server undermcp_servers in your private local config:
command.
4. Verify the connection
Start with this read-only request:5. Troubleshooting
- New server is missing: reload the Hermes session or gateway that actually owns the connection.
- 401 on calls: check the complete bearer header and current key. A Server secret cannot authenticate MCP.
- Tool names differ: Hermes prefixes MCP tool names with the server name. Select tools belonging to
plainrouter, not the sandbox.