a2aproject / a2aproject/A2A

[Epic] Auth scheme declaration & credential discovery in AgentCard

Đang mở
#1,990 4 bình luận 2 reaction 0 người được giao Xem trên GitHub
enhancement v1.1-candidate
Ngôn ngữ chính
Shell
Star
25.7k
Fork
2.6k
Merge trung bình
3 ngày 6 giờ
Pull request đã merge (30 ngày)
16

Mô tả

## Auth scheme declaration & credential discovery in AgentCard

### Problem

When an A2A server requires OAuth, a client cannot determine *from the Agent Card alone* how to obtain a usable token — today it needs out-of-band knowledge (client registration, which grant, which AS). Assertion-based grants (RFC 7521/7523) are not modeled in the declared flows, and the normative "servers MUST reject invalid/missing credentials" language leaves the SDK-compliance boundary unclear.

### Consolidated issues

- [ ] #830 — OAuth 2.1-compliant authorization for A2A (align with MCP) *(anchor)*
- [ ] #1795 — Support OAuth RFC 7521 assertion-based authorization grants
- [ ] #1770 — Why is JWT assertion (RFC 7523) not one of the declared OAuth flows?
- [ ] #1745 — When OAuth is enabled, how does the client know how to generate the token? *(discovery gap)*
- [ ] #1454 — What does the authentication requirement mean in practice for SDK compliance?

### Acceptance criteria

- The Agent Card's declared security schemes are sufficient for a client to drive token acquisition without out-of-band knowledge (or the required out-of-band steps are explicitly documented).
- Assertion-based grants (RFC 7521/7523) are representable in the declared flows.
- Alignment with MCP's OAuth 2.1 direction is stated.
- The boundary between "protocol-compliant SDK" and "application-specific auth" is clarified (#1454).
- Docs include an end-to-end client token-acquisition walkthrough.

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Hướng nghiên cứu

This is a design epic consolidating multiple issues about OAuth and credential discovery in the AgentCard. Start by reading the linked issues (#830, #1795, #1770, #1745, #1454) to understand the scope. The work involves protocol design, aligning with MCP's OAuth 2.1 direction, and updating documentation. Look at the AgentCard specification and existing security scheme declarations. 'Done' means the acceptance criteria are met, including updated specs and an end-to-end client walkthrough.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Lĩnh vực
api, authentication, authorization, documentation
Loại issue
Tính năng
Độ khó
5/5
Thời gian dự kiến
Hơn một tuần
Mức độ hoạt động
Sôi nổi
Độ rõ ràng
Khá rõ ràng
Mức phù hợp với người mới
35/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.