AdPlug
Guide · LinkedIn Ads to Hermes Agent

How to Connect LinkedIn Ads to Hermes Agent

Hermes Agent is the open-source agent from Nous Research that runs on your own machine or a small server and answers from the terminal, Telegram, or Slack. Connecting AdPlug gives it a controlled way to read your LinkedIn Ads data, send reports on a schedule, and prepare changes you approve. This guide covers what you need, the five setup steps, and how to sign in when Hermes runs on a server.

Updated 2026-09-30 · 8 minute read

LinkedIn Ads MCP server URL

Pass this address to hermes mcp add. Hermes signs in with OAuth, so there is no key to paste.

https://api.adplug.app/mcp/linkedin-ads

01

How Hermes Agent reaches LinkedIn Ads

Hermes has browser tools, so it could click through Campaign Manager for you. The cleaner route is an MCP server. Hermes' MCP docs describe MCP as the way to use tools that live outside Hermes itself, and it connects to servers running on your machine and to hosted ones in the same way.

AdPlug's LinkedIn Ads MCP is a hosted one. It works through LinkedIn's official Marketing API, so Hermes gets campaign data as numbers and never has to open Campaign Manager. Nothing runs next to Hermes: there is no package to install and no API key to store. Hermes signs in to AdPlug through your browser and keeps the token on its own disk.

02

What you need

  • Hermes Agent. It is free and open source under the MIT licence, and you pay the model provider you point it at. It runs on macOS, Linux, WSL2, and Windows, from the command line or its desktop app. Hermes' install guide has the one-line installer.
  • An AdPlug account. The free plan is enough to set this up and test it: view only, 500 requests in the first month and 50 a month after that, on one ad platform.
  • Access to the ad account. A LinkedIn profile with Campaign Manager access to the ad accounts you want Hermes to work on. Viewer access is enough for reporting.
  • A browser, once. The sign-in opens a web page. If Hermes runs on a server, read Hermes on a server before step 3.

03

Setup in 5 steps

Steps 1 and 2 happen in AdPlug. Steps 3 to 5 happen in a terminal on the machine where Hermes runs. Allow about ten minutes the first time. The commands follow the documentation for Hermes Agent v0.21.5, released on 24 September 2026.

  1. Create your AdPlug account

    Go to adplug.app/signup, sign in with Google or email, and follow the short onboarding. It ends on your AdPlug dashboard.

    AdPlug Create your account screen with a Continue with Google button and name, email and password fields.
    AdPlug sign-up. One click with Google, or an email and password.
  2. Connect LinkedIn Ads to AdPlug

    On the dashboard, click Connect LinkedIn Ads and sign in with the LinkedIn profile that has Campaign Manager access to the ad accounts you want Hermes to work on. Every account that profile can manage becomes available through the one connection.

    AdPlug dashboard welcome screen with an arrow pointing to the Connect LinkedIn Ads button.
    Click Connect LinkedIn Ads to start LinkedIn's sign-in.

    Already past onboarding? The Connections page has the same button.

    AdPlug Ad Platform Connections page with an arrow pointing to the Connect LinkedIn Ads button on the LinkedIn Ads card.
    The Connections page shows the button whenever LinkedIn Ads is not linked yet.
  3. Add AdPlug to Hermes

    Hermes keeps its MCP servers in ~/.hermes/config.yaml (on native Windows the folder is %LOCALAPPDATA%\hermes) and has a command that writes the entry for you. Stay signed in to AdPlug in your browser, then run this on the machine where Hermes is installed:

    hermes mcp add adplug-linkedin-ads --url https://api.adplug.app/mcp/linkedin-ads --auth oauth

    adplug-linkedin-ads is the name Hermes will use for the server, and you can pick another. --auth oauth tells Hermes that the server signs you in through the browser, so there is no key to paste.

    Terminal running hermes mcp add adplug-linkedin-ads with the AdPlug LinkedIn Ads MCP URL and --auth oauth, then Hermes Agent asking to open a sign-in link in the browser or paste the redirect URL.
    The command, and the sign-in link Hermes prints once it reaches AdPlug.
  4. Authorise the connection

    Hermes prints a sign-in link, opens your browser when it can, and waits about 30 seconds. If you are still signed in to AdPlug from step 2, that is one click on Approve.

    AdPlug Authorize access screen asking whether an application may access your AdPlug account, with Deny and Approve buttons.
    AdPlug's authorise screen. Approve to let Hermes use your AdPlug connection.

    Back in the terminal, Hermes lists the tools it found, ten for the LinkedIn Ads server, and asks whether to enable them all. Answer Y, or type select to tick only the ones you want. Hermes then saves the server to its config and keeps the sign-in token under ~/.hermes/mcp-tokens/, so later sessions connect without asking.

    Hermes Agent reporting Connected and listing the ten tools of the AdPlug LinkedIn Ads MCP server, then asking whether to enable all of them and saving the server to config.yaml.
    Hermes lists the AdPlug tools and saves the server once you confirm.

    If Hermes says the connection timed out, 30 seconds was not enough. Answer N when it offers to save the config anyway, add the entry yourself (hermes config edit opens the file), and sign in with the command that waits five minutes:

    mcp_servers:
      adplug-linkedin-ads:
        url: "https://api.adplug.app/mcp/linkedin-ads"
        auth: oauth
    hermes mcp login adplug-linkedin-ads

    That is also the route to take when Hermes runs on a server, which the next section covers.

  5. Test the connection

    Check the connection from the shell first:

    hermes mcp test adplug-linkedin-ads

    It should report Connected and the number of tools it discovered. Then start Hermes with hermes (in a session that was already open, type /reload-mcp) and ask:

    “List my LinkedIn ad accounts.”

    Hermes calls the linkedin_ads_list_accounts tool and returns the ad accounts you can access, with currencies and statuses. If your accounts are listed, the connection works end to end.

    Hermes Agent answering 'List my LinkedIn ad accounts' through the adplug-linkedin-ads MCP server, with each account's name, type, currency and status.
    The reply to the test prompt, one row for each account Hermes can reach.

04

Hermes on a server or VPS

Hermes is built to run on a small server and be reached from Telegram. The sign-in still needs a browser once, and the browser is on your laptop while Hermes is not. Hermes finishes the sign-in by catching a redirect to 127.0.0.1 on its own machine, which your laptop cannot reach, and working round that takes longer than the 30 seconds hermes mcp add allows.

So on a server, skip that command. Add the entry from step 4 to config.yaml by hand and run hermes mcp login adplug-linkedin-ads in an SSH session. It waits five minutes, and Hermes' OAuth over SSH guide gives three ways to finish.

  • Paste the address back. Open the link on your laptop and approve. The browser then shows a connection error, which is expected. Copy the full address from the address bar and paste it at the prompt Hermes is waiting on.
  • Forward the port. Hermes prints the port it is listening on. In a second terminal on your laptop run ssh -N -L PORT:127.0.0.1:PORT user@host with that port, then open the link as normal.
  • Use the desktop app. If your Hermes desktop app is connected to the server, sign in from its MCP screen instead. The app receives the redirect on your computer and passes it on. Both the app and the server need to be up to date.

Hermes also has a device-code login for servers whose sign-in supports one. AdPlug does not offer it, so use one of the three above.

Two things catch people out. Sign in as the same system user and profile that runs the gateway, because the token is stored in that profile's Hermes folder. And a Hermes running in the background never opens a browser: if the sign-in ever stops refreshing, the server is parked with a warning in gateway.log until you run hermes mcp login adplug-linkedin-ads again.

05

Prompts and scheduled reports

LinkedIn's hierarchy is campaign group, then campaign, then creative (the ad). Name the level you mean and Hermes picks the right one. More copy-paste prompts live in the prompt playbooks.

List your LinkedIn ad accounts

“List my LinkedIn ad accounts.”

Spend by seniority

“Break my LinkedIn Ads spend down by job seniority for the last 90 days, with cost per conversion for each band. Flag anything with too little data to judge.”

Pacing check

“For each active campaign group, compare planned daily spend with actual spend over the last 7 days. Highlight anything more than 15% off.”

Lead form check

“For every Lead Gen Form campaign active in the last 30 days, list completion rate and cost per lead, and tell me which form is performing worst.”

Audience size before you commit

“Estimate the audience size for marketing directors at SaaS companies in the UK, and tell me if it is too small to run.”

Competitor research

“Search the LinkedIn Ad Library for our top competitor and list their active ads with links. Summarise what they seem to be testing.”

Hermes has a built-in scheduler, which it calls cron. The simplest way to set a job up is to ask:

“Every Monday at 8am, use the adplug-linkedin-ads tools to pull last week's spend, impressions, clicks, and leads for every active campaign group in the Acme Software account, compare them with the week before, and send me a short summary on Telegram. Read only. Do not change anything.”

The same job from the shell, delivered to Telegram (0 8 * * 1 is cron notation for 8:00 every Monday):

hermes cron create "0 8 * * 1" "Use the adplug-linkedin-ads tools to pull last week's spend, impressions, clicks, and leads for every active campaign group in the Acme Software account, and compare them with the week before. Read only. Do not change anything." --name "LinkedIn Ads weekly" --deliver telegram

A scheduled job starts a fresh session with no memory of your chat, so the prompt has to say everything: which account, which dates, what to report. A job you ask for in Telegram or Slack reports back to that chat; one created in the terminal is saved to a file unless you name a channel, which is what --deliver telegram does.

Jobs are run by the Hermes gateway, so it has to be running: hermes gateway install and then hermes gateway start set it up as a background service. Times follow the server's clock unless you set timezone in config.yaml, so check which time zone the server is on.

Run a new job once before you rely on it (hermes cron run with the job's ID) and check the summary arrives. Every run also uses AdPlug requests, and the free plan drops to 50 a month after the first, so a job that runs most days needs a paid plan.

06

Approvals and safety

AdPlug gives Hermes two tools for campaign changes: a preview tool that returns the exact change without applying it, and an execute tool that applies it. That covers campaign groups, campaigns, budgets, targeting, and ads in nine formats, including Thought Leader Ads. The free plan is view only; creating and editing campaigns needs a paid AdPlug plan.

Hermes asks before it runs a risky shell command, but an MCP server you add is trusted by default and its tools run without a prompt. For an ad account, change that. Add one line to the AdPlug entry in config.yaml, then type /reload-mcp or restart the gateway so Hermes picks it up:

mcp_servers:
  adplug-linkedin-ads:
    url: "https://api.adplug.app/mcp/linkedin-ads"
    auth: oauth
    trust: untrusted

With that line, Hermes stops and asks you before every call to a tool that can change something. It goes by the labels on AdPlug's tools: the reporting, lookup, and preview tools are marked read-only and run freely, while the execute tool and the conversion event tool are not, so those two wait for your yes. The question appears wherever the conversation is, in the terminal or in a chat such as Telegram. Untrusted is Hermes' word, described in its MCP config reference. It means ask me first, not that the server is unsafe.

A scheduled job has nobody to ask, so a change it attempts under this setting is declined instead of run. Keep scheduled work to reporting and make changes in a conversation you are in. If Hermes should never be able to change the account, run hermes mcp configure adplug-linkedin-ads and untick linkedin_ads_execute_mutation and linkedin_ads_send_conversion_event.

Hermes can take messages from several people through one gateway, and they all act through the one AdPlug sign-in, so keep the list of people allowed to message it short. For a shared Hermes that should only report, sign it in with an AdPlug seat the account owner has set to View only. On the Max and Agency plans each teammate can be set to View only or Can edit per platform, and a View only seat is refused any change, whatever Hermes is asked.

Report calls and executed changes are recorded in your AdPlug Usage and Audit Log, so you can check what Hermes did while you were away.

07

Troubleshooting

Click any item to expand the answer.

The browser shows a connection error after I approve
Either Hermes had already stopped waiting (see the next item), or it is on a different machine from your browser, so the redirect to 127.0.0.1 has nowhere to land. In the second case, copy the full address from the address bar and paste it at the prompt Hermes is waiting on, or forward the port over SSH. The section on servers has both.
The sign-in times out
hermes mcp add waits about 30 seconds for the sign-in, and so does the reload after you edit config.yaml inside a running session. Run hermes mcp login adplug-linkedin-ads from a fresh terminal instead. It waits five minutes.
The AdPlug tools do not show up in a chat
Tools load when a session starts. Type /reload-mcp in the open session or start a new one. If they are still missing, hermes mcp test adplug-linkedin-ads shows what the server answered.
A scheduled report did not arrive
Run hermes cron status to see whether the scheduler is alive, and hermes cron list to see the job and where it delivers. The gateway runs the scheduler, so hermes gateway restart brings it back if it has stopped. If the AdPlug sign-in has expired, run hermes mcp login adplug-linkedin-ads again.
The connection shows zero LinkedIn ad accounts
The LinkedIn profile you connected has no ad account access. Open Campaign Manager, confirm the profile has at least Viewer access, then disconnect and reconnect on the Connections page with the right profile.
A change is refused on the free plan
AdPlug's free plan can read but not edit, and the reply says so. Creating or changing campaigns needs a paid plan.
The numbers do not match Campaign Manager
LinkedIn finalises some metrics hours after the impression. For same-day reporting, ask for a date range ending yesterday and treat today's spend as provisional.

08

Questions people ask

Can Hermes Agent connect to LinkedIn Ads?
Yes. Hermes Agent uses outside tools through MCP servers, and AdPlug's LinkedIn Ads MCP server is a hosted one that signs in with OAuth. Run hermes mcp add adplug-linkedin-ads --url https://api.adplug.app/mcp/linkedin-ads --auth oauth, approve AdPlug's sign-in, and Hermes can pull reports from the ad accounts you have access to. With a paid AdPlug plan it can also create and change campaigns through AdPlug's preview and execute tools.
What does Hermes Agent do?
Hermes Agent is an open-source AI agent from Nous Research. It runs on your own computer or a server, works with the model provider you choose, keeps memory and skills between sessions, runs scheduled jobs, and can be reached from the terminal or from messaging apps such as Telegram, Discord, and Slack.
How much does Hermes Agent cost?
Hermes Agent is free and open source under the MIT licence. Its documentation says you pay only for the model provider you use, and that local models are free to run.
How do I add an MCP server to Hermes Agent?
For a hosted server that signs in with OAuth, run hermes mcp add with a name, --url, and --auth oauth. Hermes runs the sign-in, waiting about 30 seconds for you to approve, then lists the server's tools, asks which to enable, and saves the server under mcp_servers in ~/.hermes/config.yaml. If you need longer, add the entry to that file yourself and run hermes mcp login with the server's name, which waits five minutes. hermes mcp test checks the connection afterwards.
Does Hermes Agent support OAuth for MCP servers?
Yes. With auth: oauth on a server entry, Hermes handles discovery, client registration, the browser sign-in, and token refresh, and keeps the token under ~/.hermes/mcp-tokens. AdPlug accepts automatic client registration, so there is no client ID or secret to set up.
Does this work when Hermes Agent runs on a VPS?
Yes, with two differences. Add the server to config.yaml by hand and sign in with hermes mcp login, which waits five minutes instead of the 30 seconds hermes mcp add allows. And because Hermes waits for the browser redirect on the server's own 127.0.0.1, which your laptop cannot reach, paste the redirected address back at Hermes' prompt, forward the port over SSH, or sign in from the Hermes desktop app. AdPlug's sign-in does not offer a device code.
Can Hermes Agent change my LinkedIn Ads campaigns?
With a paid AdPlug plan, yes. AdPlug gives Hermes a preview tool that shows the exact change without applying it and an execute tool that applies it. Set trust: untrusted on the AdPlug entry in Hermes' config and Hermes asks for your approval before every call that can change the account.
Can Hermes Agent send LinkedIn Ads reports on a schedule?
Yes. Hermes has a built-in scheduler it calls cron. Ask for a job in plain language or run hermes cron create. A job you ask for in Telegram or Slack reports back to that chat, and one created in the terminal is saved to a file unless you name a channel. The Hermes gateway has to be running, and each run starts a fresh session, so the prompt must name the account and the dates.
Can Hermes Agent use Google Ads through AdPlug as well?
Yes. Add https://api.adplug.app/mcp/google-ads as a second server with the same command, or use https://api.adplug.app/mcp, which carries Google Ads and LinkedIn Ads together. AdPlug's free plan covers one ad platform, so connecting both needs a paid plan.
Is connecting Hermes Agent to LinkedIn Ads free?
AdPlug's free plan is view only, on one ad platform, with 500 requests in the first month and 50 a month after that. Campaign changes need a paid AdPlug plan, and so does a report that runs most days, because every run uses requests. Hermes Agent itself is free; you pay your model provider.