a2aproject / a2aproject/A2A

[Epic] Auth scheme declaration & credential discovery in AgentCard

Offen
#1,990 4 Kommentare 2 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
enhancement v1.1-candidate
Vorherrschende Sprache
Shell
Sterne
25.7k
Forks
2.6k
Ø Merge
3 T. 6 Std.
Gemergte PRs (30 T.)
16

Beschreibung

## Auth scheme declaration & credential discovery in AgentCard

### Problem

When an A2A server requires OAuth, a client cannot determine *from the Agent Card alone* how to obtain a usable token — today it needs out-of-band knowledge (client registration, which grant, which AS). Assertion-based grants (RFC 7521/7523) are not modeled in the declared flows, and the normative "servers MUST reject invalid/missing credentials" language leaves the SDK-compliance boundary unclear.

### Consolidated issues

- [ ] #830 — OAuth 2.1-compliant authorization for A2A (align with MCP) *(anchor)*
- [ ] #1795 — Support OAuth RFC 7521 assertion-based authorization grants
- [ ] #1770 — Why is JWT assertion (RFC 7523) not one of the declared OAuth flows?
- [ ] #1745 — When OAuth is enabled, how does the client know how to generate the token? *(discovery gap)*
- [ ] #1454 — What does the authentication requirement mean in practice for SDK compliance?

### Acceptance criteria

- The Agent Card's declared security schemes are sufficient for a client to drive token acquisition without out-of-band knowledge (or the required out-of-band steps are explicitly documented).
- Assertion-based grants (RFC 7521/7523) are representable in the declared flows.
- Alignment with MCP's OAuth 2.1 direction is stated.
- The boundary between "protocol-compliant SDK" and "application-specific auth" is clarified (#1454).
- Docs include an end-to-end client token-acquisition walkthrough.

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

This is a design epic consolidating multiple issues about OAuth and credential discovery in the AgentCard. Start by reading the linked issues (#830, #1795, #1770, #1745, #1454) to understand the scope. The work involves protocol design, aligning with MCP's OAuth 2.1 direction, and updating documentation. Look at the AgentCard specification and existing security scheme declarations. 'Done' means the acceptance criteria are met, including updated specs and an end-to-end client walkthrough.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Bereich
api, authentication, authorization, documentation
Issue-Typ
Feature
Schwierigkeit
5/5
Geschätzter Aufwand
Über eine Woche
Aktivitätsstatus
Aktiv
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
35/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.