Hermes WorldKit
FreeNot checkedControls a Godot editor adapter via MCP, reporting bridge status, scene summaries, and selected nodes, with secure WebSocket authentication and scene-safe node
About
Controls a Godot editor adapter via MCP, reporting bridge status, scene summaries, and selected nodes, with secure WebSocket authentication and scene-safe node selection.
README
A separate, first-party MCP control server for WorldKit's Godot editor adapter. Hermes launches the Python process over stdio; the process also binds a localhost-only WebSocket endpoint. The optional Godot 4.6 EditorPlugin connects outbound, authenticates, and proves it opened the exact pinned project root.
Vertical-slice capabilities
- Report bridge/editor status and capabilities.
- Summarize the currently edited scene.
- List selected nodes in that scene.
- Select one existing node by an edited-scene-relative path.
There is deliberately no terminal, file writing, GDScript evaluation, generic method invocation, arbitrary property mutation, autoload, or runtime dependency.
Install
git clone https://github.com/DeployFaith/Hermes_WorldKit_MCP.git
cd Hermes_WorldKit_MCP
uv sync
Copy addons/worldkit_mcp_bridge into the target Godot project's addons/ directory, then enable WorldKit MCP Bridge in Project Settings → Plugins. The addon remains optional and must not be copied into WorldKit's base addon payload.
Required configuration
Generate a random token and make the same value available to both the MCP process and the Godot editor environment:
export WORLDKIT_MCP_TOKEN="$(python -c 'import secrets; print(secrets.token_urlsafe(32))')"
export WORLDKIT_PROJECT_ROOT="/absolute/path/to/the/godot/project"
Optional server settings:
export WORLDKIT_MCP_WS_HOST="127.0.0.1" # only loopback values are accepted
export WORLDKIT_MCP_WS_PORT="6506" # use 0 only in tests that pass the chosen URI to Godot
export WORLDKIT_MCP_REQUEST_TIMEOUT="5.0"
The Godot addon reads WORLDKIT_MCP_TOKEN and, optionally, WORLDKIT_MCP_WS_URL (default ws://127.0.0.1:6506). The URL must be exactly ws://127.0.0.1:<port> or ws://[::1]:<port> with no credentials, path, query, or fragment. Start/restart Godot from an environment containing those values after changing them. Port 0 asks the Python bridge to choose an ephemeral port; it is intended for disposable tests because the selected port must then be supplied to Godot through WORLDKIT_MCP_WS_URL.
Hermes stdio configuration example
mcp_servers:
worldkit:
command: /absolute/path/to/Hermes_WorldKit_MCP/.venv/bin/worldkit-mcp
args: []
env:
WORLDKIT_MCP_TOKEN: "replace-with-the-same-random-token-used-by-godot"
WORLDKIT_PROJECT_ROOT: "/absolute/path/to/the/godot/project"
WORLDKIT_MCP_WS_PORT: "6506"
The exact enclosing Hermes configuration keys may vary by installed Hermes version; the important stdio command and environment contract are shown above.
Wire protocol
Protocol version 2 uses mutual challenge-response authentication. Python sends a random server nonce; Godot replies with a client nonce and HMAC-SHA256 proof; Python returns its own proof before either side accepts the session. Proofs are bound to the protocol version and canonical project root, but neither the shared token nor project root is transmitted during authentication. Browser-origin WebSockets, malformed envelopes, wrong versions, mismatched roots/secrets, unsolicited response IDs, and a second simultaneous editor are rejected.
Accepted requests and responses carry a UUID request_id; responses use {ok, code, message, data}. The Python bridge turns cancellation, timeouts, protocol failures, and disconnects into stable structured errors. A timed-out selection reports SELECTION_OUTCOME_UNKNOWN because Godot may have applied it before the response was lost.
worldkit_scene_summary and worldkit_selected_nodes return a scene_token. worldkit_select_node(node_path, expected_scene_token) requires that exact token before changing selection, preventing a command inspected against one scene from affecting a newly opened scene. Paths are canonical relative paths under the edited root. Absolute paths, subnames, empty or . components, backslashes, and any .. segment are rejected before lookup. Internal nodes and nodes not owned by the current edited scene are excluded.
Scene inspection is bounded to 2,000 child-scan steps and 256 returned nodes; selected-node output is also capped at 256. The addon queues at most 64 requests and executes at most one request per editor frame.
Development checks
uv run pytest -q
uv run ruff check .
uv run python -m worldkit_mcp.schema_dump
uv run python scripts/verify_godot_editor_e2e.py
The final command first verifies the executable is Godot 4.6, then launches a disposable headless editor and loads the real optional plugin. Its hostile fixture contains 2,005 wide root children plus a nested selectable node. The check completes mutual authentication, proves the scene summary stops at 256 returned nodes and reports truncation, changes the editor selection, reads it back, and proves that escaping, stale-scene, and noncanonical paths are rejected. It uses explicit runtime checks that remain active under python -O. Set WORLDKIT_GODOT_BIN if godot is not on PATH.
This headless editor integration check proves the transport and editor API behavior. It does not prove visible UI rendering or satisfy WorldKit's eventual human manual-QA gate.
Install Hermes WorldKit in Claude Desktop, Claude Code & Cursor
unyly install hermes-worldkit-mcpInstalls into Claude Desktop, Claude Code, Cursor & VS Code — handles npx, uvx and build-from-source repos for you.
First time? Get the CLI: curl -fsSL https://unyly.org/install | sh
Or configure manually
Run in your terminal:
claude mcp add hermes-worldkit-mcp -- uvx --from git+https://github.com/DeployFaith/Hermes_WorldKit_MCP hermes-worldkit-mcpStep-by-step: how to install Hermes WorldKit
FAQ
Is Hermes WorldKit MCP free?
Yes, Hermes WorldKit MCP is free — one-click install via Unyly at no cost.
Does Hermes WorldKit need an API key?
No, Hermes WorldKit runs without API keys or environment variables.
Is Hermes WorldKit hosted or self-hosted?
Self-hosted: the server runs locally on your machine via the install command above.
How do I install Hermes WorldKit in Claude Desktop, Claude Code or Cursor?
Open Hermes WorldKit on unyly.org, pick your client tab (Claude Desktop, Claude Code, Cursor) and press Install — the config is generated automatically, no JSON editing.
Related MCPs
GitHub
PRs, issues, code search, CI status
by GitHubFilesystem
Secure file operations with configurable access controls.
Memory
Knowledge graph-based persistent memory system.
Template MCP Server
A CLI tool to create a new Model Context Protocol server project with TypeScript support, dual transport options, and an extensible structure
by mcpdotdirectCompare Hermes WorldKit with
Not sure what to pick?
Find your stack in 60 seconds
Author?
Embed badge for your README
Browse similar
All development MCPs
