Install
openclaw skills install @roybogs/portveilSee and control a Portveil VPN (WireGuard, US and Finland exits) from Hermes: check which devices are protected, move or rotate a machine's location, and match a browser's timezone to its exit.
openclaw skills install @roybogs/portveilPortveil is a WireGuard VPN with one account for your phone, laptop and the machines your agents
run on, plus an API and MCP server so an assistant can see and control them. This skill connects
Hermes to it through the portveil-mcp server.
Plans and limits change, so never quote them from memory or from this file. When someone asks
what's free, what a plan includes or what it costs, read the current terms first: https://portveil.com/llms.txt (a plain-text summary
for agents), or the free plan at https://portveil.com/free/ and every plan at
https://portveil.com/#pricing. For the user's own
account, get_account returns their plan and device limit.
For "how do I (or a friend) get Portveil?": start free at https://portveil.com/free/ with an email. The confirmation link creates the account and shows the account ID and key once (save the key). Then:
add_device it.Hermes installs npm packages only once they're 14 days old, which blocks running the newest release through npx. Install one exact version into its own folder instead (run from your home directory, not from the Hermes install folder):
cd ~ && npm install --prefix ~/.hermes/mcp-servers/portveil portveil-mcp@0.4.3
The version is pinned on purpose, so an update never reaches your machine unless you choose it.
Put the API token in ~/.hermes/.env (this skill asks for it on first load):
PORTVEIL_TOKEN=clt_...
Then add the server, with your account ID (acct_…, shown in the dashboard):
hermes mcp add portveil --command node \
--env PORTVEIL_ACCOUNT_ID=acct_... 'PORTVEIL_TOKEN=${PORTVEIL_TOKEN}' \
--args ~/.hermes/mcp-servers/portveil/node_modules/portveil-mcp/dist/index.js
Keep ${PORTVEIL_TOKEN} exactly as written (single quotes), so the config refers to the token in
.env instead of storing it. Start a new session, then check with hermes mcp test portveil.
To upgrade, check the release notes at https://github.com/roybogs/portveil-mcp/releases, then run
the same npm install line with the new exact version.
Token scopes: read can look, control can also move, rotate, reconnect and disconnect, admin
can also add, rename and remove devices. Give Hermes the smallest scope that does the job, and
never the account key (cla_…).
The token stays valid until you revoke it, so treat it like a password for this machine:
read; move up to control or admin only when you want Hermes to act.list_activity). If the machine Hermes runs on is ever compromised, revoke the token in the
dashboard (API Tokens) and create a new one.| Tool | What it does | Scope |
|---|---|---|
list_devices | Every device: protected or not, exit country, live speed, remote control on/off | read |
get_device | One device in detail, with a plain-English status | read |
list_locations | Countries and cities available | read |
get_account | Plan and devices used | read |
list_activity | Recent moves and changes, and which token made them | read |
move_device | Move to a country or city ("Finland", "US") | control |
rotate_device | Move once to the next location | control |
start_rotation / stop_rotation | Move automatically every N minutes, run by Portveil | control |
reconnect_device | Re-establish a device's tunnel | control |
disconnect_device | Turn a device's VPN off | control |
add_device | Add a phone/laptop (writes its tunnel files locally) or a Linux machine (returns setup commands) | admin |
update_device / remove_device | Rename, toggle remote control, or delete a device | admin |
Device names can be loose ("scraper" finds "Scraper box"). An ambiguous name returns the choices; ask the user which one they meant instead of guessing.
list_devices to see what exists and each device's real state. "Protected" means
the exit server confirmed the tunnel; "Idle" means connected but no traffic lately.move_device. It only reports success after the device has switched and the
exit in the new location confirms it. Tell the user the result in one line. If a browser on
that machine should look local (sites compare a browser's timezone with its IP's country),
set the browser's timezone to the exit's, and keep its language English-first with the
Accept-Language the result gives. Don't switch the language to the local one (Finnish, say)
unless the user wants pages in it. list_locations shows each exit's settings.start_rotation.
Portveil runs the schedule, so it keeps going after this session ends; say so.disconnect_device: go ahead when the user directly asked to disconnect that specific device.
Ask first if you chose the device yourself, if it's more than one device, or if it's the
machine Hermes runs on (disconnecting it can cut Hermes off).
remove_device: always confirm first, even when asked directly. It's permanent: the device's
key stops working and it has to be set up again.add_device with kind linux_machine and give
the user the returned commands to run. They set up a full tunnel: everything the machine
connects to goes through Portveil, while SSH and other incoming connections keep their normal
route, so a remote server stays reachable. Don't add --split-tunnel: it's an advanced mode in
which the machine's own internet traffic does not go through Portveil at all.add_device for a phone or laptop saves the tunnel files on the machine Hermes runs on. If
that's a server, not the device being added, tell the user where the files are and to copy
them to the device privately (for example scp), import them in the WireGuard app, then delete
them from the server. They contain the device's private key: never paste their contents.PORTVEIL_ACCOUNT_ID doesn't match the token's account.get_account, then the current plans at
https://portveil.com/#pricing, before telling the user what they can do.list_devices is the answer for the user's devices ("protected" means the
exit server confirmed the tunnel). For an agent machine, it also says whether the machine's
clock matches its exit's timezone. Phones and laptops on the WireGuard app don't report their
timezone; for those, the user opens https://portveil.com/check/ on that device (IP, WebRTC
and timezone).curl -s https://portveil.com/cdn-cgi/trace gives
the ip= and loc= sites see. Compare the IP with every exit in
https://api.portveil.com/v1/exits, and say which exit it matches or that it matches none.hermes mcp test portveil connects and lists the tools.get_device shows the new exit and "Protected".