SOLARYS / COMMUNICATIONS

Hermes

Authenticated site messaging and push-to-talk audio for distributed teams. Hermes runs as a desktop application on Apple Silicon Macs and connects to this service at app.solarys.ai.

Download for Mac · arm64 How to sign in

Current release: see the downloads page.

Sign in

Sign-in happens inside the Hermes desktop app, not in this browser. There is no web client and no public registration.

  1. Install Hermes and open it from Applications.
  2. Existing users: enter your organization, email and password. The production endpoint https://app.solarys.ai is prefilled in the supported release; older releases still reach the service through their original endpoint.
  3. New users: ask your Hermes administrator for a single-use invitation. Choose I have an invitation, enter the code or open the emailed link, then set your own password.
  4. Organizations with federated sign-in configured can use Check for organization sign-in; it opens your identity provider in the browser and returns to the app.

Account recovery

Forgot your password or need to verify your email? Use Forgot password or Verify email in the app. The service sends a single-use link to the address on your account when email delivery is configured for your deployment; the link opens a page on this site that hands the code to Hermes (hermes://) or lets you paste it.

If you never receive a message, contact your administrator, who can resend invitations and reset access from the app.

Verify your download

Every installer is listed with its size and SHA-256 checksum on the downloads page (SHA256SUMS.txt, release.json). Builds are ad-hoc sealed and are not Developer ID signed or notarized: macOS will ask you to confirm the first launch in System Settings → Privacy & Security. Do not disable Gatekeeper globally.

What Hermes is

Persistent messages, presence, teams and channels, authorized WebRTC/TURN voice, invitations, device enrollment and explicit transfer policies, with server-side authorization on every request. Audio stays off until an administrator permits it in site policy.

Single-host service without a production SLA, accreditation or CUI authorization. Voice requires network access to TURN on UDP/TCP 3478 or TLS 5349.