Skip to content
AGENT2AGENT PROTOCOLUPDATED 2026-09-29

The A2A protocol, governed

THE SHORT ANSWER

A2A (Agent2Agent) is an open protocol that lets AI agents built by different teams or vendors discover each other and hand work across. An agent publishes an Agent Card describing its skills; others send it tasks over JSON-RPC and follow them to completion. The protocol standardises the conversation — it does not decide whether your agent should make that call, with which credential, or how far to trust the answer.

How A2A works

  • Introduced by Google in April 2025 and contributed to the Linux Foundation as an open project.
  • Discovery: an agent publishes an Agent Card (by convention at /.well-known/agent-card.json) listing its skills, capabilities and the authentication it accepts.
  • Work: a client sends a message; the remote agent answers directly or opens a task that moves through states such as working, input-required, completed, failed or canceled.
  • Transport: JSON-RPC 2.0 over HTTP, with streaming and push notifications for long-running work.

A2A and MCP are complementary

MCP connects an agent to tools and data. A2A connects an agent to another agent that has its own reasoning and its own tools. An enterprise usually needs both — and needs the same permission, approval and evidence around each.

What the protocol leaves to you

  • Whether this person’s agent is allowed to delegate this work at all.
  • Which remote hosts may be called, and which may not.
  • Which credential goes to which partner — and that it goes nowhere else.
  • How much to trust an answer: a remote agent’s reply is untrusted content and a possible prompt injection.
  • That a retried request does not start a second remote task.
  • How large an answer you are prepared to hold.
HOW A2A MATRIX DOES IT
  • Today: agents and workflows call external A2A agents — discover the card, send a task, follow it, cancel it — through the same permission, approval and evidence path as any tool.
  • Outbound calls pass an egress guard: an allow-list of hosts, public addresses only, HTTPS outside development, no redirects followed.
  • A credential for one partner is stored under that partner’s name and sent only there; none is ever a parameter a model could see.
  • Every remote answer is marked as untrusted content, bounded in size, and a retried message reuses the same message id.
  • On the roadmap: answering A2A calls with our own Agent Card, streaming, push notifications and a catalogue of partner agents.
How it fits with what you run
QUESTIONS

Asked often.
Answered plainly.

Is A2A Matrix the A2A protocol?+

No. A2A Matrix is a governed runtime for enterprise AI agents; “A2A” in the name means agent-to-agent. It uses the open A2A protocol to call other agents, and the protocol itself is an open project hosted by the Linux Foundation.

What is the difference between A2A and MCP?+

MCP connects an agent to tools and data; A2A connects an agent to other agents. They solve different problems and are often used together.

Can a remote agent give instructions to our agents?+

No. Its answers are marked as untrusted content — information to weigh, never commands — and any action that follows still passes your permission and approval rules.

Can other agents call A2A Matrix over A2A?+

Not yet; answering A2A calls is on the roadmap. Today external AI clients reach the platform over MCP, with every action filtered to the signed-in person.