Glossary
Short definitions of the protocols, concepts, and standards behind agent-to-agent communication.
Protocols and standards
- A2A (Agent2Agent protocol)
- A2A is an open protocol that lets AI agents from different vendors discover each other and exchange messages, tasks and results over standard web technology.
- Agent Communication Protocol (ACP)
- IBM Research's open REST protocol for agent communication, launched in March 2025. It merged into A2A under the Linux Foundation in August 2025.
- Agent Network Protocol (ANP)
- An open-source protocol suite for agent identity, description, discovery and messaging, built on W3C decentralized identifiers and the did:wba method.
- Agent Payments Protocol (AP2)
- AP2 is an open protocol for agent-initiated payments. Signed mandates prove what a user authorized, and it can run as an extension of A2A.
- Agentic Commerce Protocol
- An open standard maintained by OpenAI and Stripe that lets a buyer's AI agent run a merchant's checkout while the merchant stays the system of record.
- Agora protocol
- A research meta-protocol for LLM agents: they agree on plain-text protocol documents identified by hash, and fall back to natural language.
- gRPC
- gRPC is an open source RPC framework that defines services in Protocol Buffers and runs them over HTTP/2. It is one of A2A's three standard bindings.
- HTTP Message Signatures (RFC 9421)
- The IETF standard for signing selected parts of an HTTP request or response and carrying the result in Signature and Signature-Input headers.
- HTTP+JSON binding
- A2A's RESTful protocol binding: resource URLs and standard HTTP methods, ProtoJSON bodies, google.rpc.Status errors, and Server-Sent Events for streams.
- JSON Canonicalization Scheme (RFC 8785)
- JCS (RFC 8785) turns JSON data into one deterministic byte sequence, so hashes and signatures over JSON verify the same way everywhere.
- JSON Web Key Set (JWKS)
- A JWKS is a JSON document that lists public keys as JSON Web Keys (RFC 7517), so a verifier can find the key that matches a signature's kid.
- JSON Web Signature (JWS)
- JWS (RFC 7515) is the IETF format for content protected by a digital signature or MAC using JSON structures. A2A uses it to sign Agent Cards.
- JSON Web Token (JWT)
- A compact, URL-safe token (RFC 7519) that carries JSON claims such as issuer, subject, audience and expiry, protected by a JWS signature or JWE encryption.
- JSON-RPC 2.0
- JSON-RPC 2.0 is a lightweight, transport-agnostic remote procedure call protocol that encodes requests, results and errors as JSON objects.
- Model Context Protocol (MCP)
- MCP is an open protocol that connects AI applications to external tools, data and prompt templates through a standard client-server interface on JSON-RPC 2.0.
- NLWeb
- An open project from Microsoft that gives a website a natural-language query endpoint answering in Schema.org JSON. Every instance is also an MCP server.
- OAuth 2.0
- The IETF authorization framework (RFC 6749) in which a client gets a scoped access token from an authorization server. A2A agents declare it in securitySchemes.
- OpenID Connect (OIDC)
- An identity layer on OAuth 2.0: the OpenID Provider issues a signed ID token, a JWT, that tells a client who the user is and how they signed in.
- ProtoJSON
- Protocol Buffers' canonical JSON encoding. A2A v1.0 uses it for all JSON: camelCase field names, enum names as strings, oneof members as keys.
- Server-Sent Events (SSE)
- Server-Sent Events is a web standard for streaming text events from server to client over one HTTP response. A2A uses it for streaming task updates.
- Session Initiation Protocol (SIP)
- The IETF signaling protocol (RFC 3261) that sets up, changes and ends voice and video sessions, such as internet phone calls, on IP networks.
- STIR/SHAKEN
- The caller ID authentication framework for IP phone networks: the originating carrier signs the calling number, and the receiving carrier verifies it.
- Universal Commerce Protocol (UCP)
- An open commerce standard, announced by Google with retail partners in January 2026, that lets agents discover a business's capabilities and check out.
- Web Bot Auth
- An IETF working group and draft protocol that let bots and AI agents sign HTTP requests to websites, so a site can verify which operator sent them.
- Well-known URI
- A well-known URI is a fixed path under /.well-known/ (RFC 8615) where a site publishes metadata. A2A agents publish their Agent Card there.
- x402
- x402 is an open payment standard built on HTTP 402 Payment Required, so a server can request payment and a client can pay within one exchange.
A2A concepts
- A2A extension
- A URI-identified addition to the A2A protocol, defined in its own spec, that an agent declares in its Agent Card and a client activates per request.
- A2A-Extensions header
- The HTTP header where an A2A client lists, comma-separated, the extension URIs it wants active. The agent's response echoes the ones it activated.
- A2A-Version header
- The HTTP header where an A2A client names the protocol version it speaks, as Major.Minor. A missing header means 0.3; an unsupported one gets -32009.
- Agent capabilities (A2A)
- The capabilities object in an A2A Agent Card: flags for streaming, push notifications and an extended card, plus the list of supported extensions.
- Agent Card
- The JSON document an A2A agent publishes to describe who it is, where to reach it, what it can do and how clients must authenticate.
- Agent skill
- An entry in an Agent Card's skills list that describes one capability an A2A agent offers: id, name, description, tags and media types.
- Artifact (A2A)
- An output an A2A agent produces for a task, such as a document, image or JSON result, made of one or more parts and identified by artifactId.
- Auth required (TASK_STATE_AUTH_REQUIRED)
- The interrupted A2A task state that asks the client to supply authorization. The spec leaves the credential's scope, format and revocation open.
- Client agent
- In A2A, the client agent is the application or agent that starts an interaction and sends messages to a remote agent on behalf of a user or system.
- contextId
- The A2A identifier that groups related tasks and messages into one conversation, so an agent can carry context from one exchange to the next.
- Data part (A2A)
- An A2A Part that carries structured JSON in its data field, such as form fields, records or machine-readable results, instead of prose.
- Extended Agent Card
- A fuller Agent Card that an A2A agent returns only to authenticated clients through GetExtendedAgentCard, often with extra skills or detail.
- File part (A2A)
- An A2A Part that carries a file, either inline as base64 bytes in raw or by reference in url, with an optional filename and mediaType.
- Input required (TASK_STATE_INPUT_REQUIRED)
- The interrupted A2A task state an agent sets when it needs more information from the client before it can continue the task.
- Message (A2A)
- One turn of communication between an A2A client and a remote agent, with a sender role, a message id and one or more content parts.
- messageId
- The required, creator-assigned unique identifier on every A2A Message. Agents may use it to spot duplicate sends, which makes client retries safer.
- Part (A2A)
- The smallest unit of content in an A2A message or artifact. Each part holds text, inline file bytes, a file URL, or structured JSON data.
- Protocol binding (A2A)
- The concrete transport and wire format for A2A's abstract operations. Version 1.0 defines JSON-RPC, gRPC and HTTP+JSON; custom bindings are named by URI.
- Push notification config (A2A)
- An A2A TaskPushNotificationConfig: the webhook URL, optional token and credentials an agent uses to POST task updates to a client.
- Remote agent
- In A2A, the remote agent is the server side: it exposes an A2A endpoint, receives messages from client agents, runs tasks and returns results.
- securitySchemes
- The A2A Agent Card map naming each way a client can authenticate: API key, HTTP auth, OAuth 2.0, OpenID Connect or mutual TLS. Used with securityRequirements.
- Signed Agent Card
- An Agent Card that carries JWS signatures over its RFC 8785 canonical form, so clients can detect tampering and see which key signed it.
- Streaming (A2A)
- A2A's real-time update mode: SendStreamingMessage or SubscribeToTask opens a stream of task, status and artifact events over SSE or gRPC.
- SubscribeToTask
- The A2A v1.0 operation that opens a stream of updates for an existing, unfinished task, starting with a snapshot of it. v0.3 called it tasks/resubscribe.
- supportedInterfaces
- The required Agent Card field that lists, in preference order, each URL where an A2A agent listens, with its protocol binding and version.
- Task (A2A)
- The stateful unit of work an A2A agent creates to track a request, with a server-generated id, a status, artifacts and message history.
- Task lifecycle (A2A)
- The path an A2A task takes from creation to an end state: submitted, working, paused for input or authorization, then completed, failed, canceled or rejected.
- Task state
- The TaskState value in an A2A task's status: submitted, working, waiting for input or authorization, or one of four terminal outcomes.
- Terminal state
- One of the four A2A task states a task can never leave: completed, failed, canceled or rejected. Follow-up work starts a new task.
- Text part (A2A)
- An A2A Part whose content is a string in its text field. It carries prompts, replies and status messages, optionally labelled with a media type.
Identity and trust
- Agent identity
- Agent identity is the verifiable answer to which software agent is making a request, which organization operates it, and on whose behalf it acts.
- Agent impersonation
- An attack where an agent poses as another agent or a trusted provider to borrow its access or reputation, via copied names, look-alike domains or stolen keys.
- Agent provider
- The organization that builds or operates an AI agent. A2A Agent Cards name it in the provider field, but only keys and domains can back that claim.
- Attestation (agents)
- Signed evidence a system produces about its own state, such as the software it runs, appraised by a verifier so a relying party can decide what to trust.
- Bot detection
- Techniques that decide whether a web request comes from a person or automated software, by scoring traffic signals or checking bots that identify themselves.
- Certificate authority
- An entity that issues digital certificates and vouches for the binding between a public key and a name. TLS and mutual TLS trust rest on CAs.
- Confused deputy problem
- A program holding authority is tricked into using it for a party that lacks it. Norm Hardy named it in 1988; agents acting for others face it daily.
- Credential revocation
- Ending a credential's validity before it expires, and the ways verifiers find out: revocation lists, status queries, token revocation and status lists.
- Decentralized identifier (DID)
- A URI such as did:web:example.com that resolves to a DID document of keys and service endpoints, whose controller can prove control (W3C DID 1.0).
- Delegation (agent authority)
- A principal granting an agent part of its authority, so the agent can act for it within set limits while staying identifiable as the agent.
- Key rotation
- Replacing a cryptographic key with a new one on a schedule or after compromise, with an overlap so verifiers keep working through the switch.
- Know Your Agent (KYA)
- Know Your Agent (KYA) is an industry term, with no single standard, for checking which AI agent is acting, who operates it, and whom it represents.
- Mandate (agent authorization)
- A signed record of what a principal authorized an agent to do, with limits, checked before acting. AP2 v0.2 defines Checkout and Payment Mandates.
- Mutual TLS (mTLS)
- TLS in which the client also presents a certificate and proves it holds the key, so both ends authenticate each other. A2A lists it as a security scheme.
- Principal (delegation)
- The person or organization an agent acts for. In delegation the principal's authority passes to the agent, which still acts under its own identity.
- Principle of least privilege
- Give each program, user and agent only the permissions its task needs, for only as long as it needs them, so mistakes and attacks do less damage.
- Prompt injection
- An attack in which text an AI model reads, typed by a user or hidden in content it processes, overrides its intended instructions. OWASP ranks it LLM01:2025.
- Reputation scoring (agents)
- Rating how far to trust an agent or its provider from observed behaviour and history. No standard defines it, so each service builds its own model.
- Scoped credential
- A credential limited to specific actions, resources, audiences or time, so a leaked or misused copy can do far less than its holder's full authority.
- Verifiable credential
- A tamper-evident set of claims signed by an issuer, kept by a holder and checked by a verifier, as defined by the W3C Verifiable Credentials Data Model 2.0.
Commerce and payments
- Agent payments
- Payments an AI agent initiates for a person or business, plus the standards that prove the agent was authorized and carry the payment itself.
- Agentic commerce
- Buying and selling in which an AI agent finds products, builds a checkout and pays for a person or business, within limits its principal sets in advance.
- Chargeback
- A card issuer's reversal of a disputed transaction back through the acquirer to the merchant, decided under card network rules.
- Checkout Mandate (AP2)
- An AP2 v0.2 credential proving to a merchant that an agent may complete one specific checkout. It replaced the Intent and Cart Mandates of AP2 v0.1.
- Dispute resolution (payments)
- The rules and steps that decide who bears the loss when a payer contests a transaction, from card network cycles to statutory error procedures.
- HTTP 402 Payment Required
- The HTTP status code that RFC 9110 reserves for future use. The x402 protocol gives it concrete meaning: pay, then retry the same request.
- Merchant of record
- The business that legally sells to the customer in a transaction: its name appears on the statement and it answers for refunds and disputes.
- Network tokenization
- Replacing a card's account number with a card-network token that works only for a given merchant, device or use, and now for specific AI agents.
- Payment Mandate (AP2)
- An AP2 v0.2 credential, secured as an SD-JWT, proving to credential providers, networks and processors that an agent may pay for one checkout.
- Reconciliation (payments)
- Matching what each system says happened to a payment (orders, processor records, payouts, on-chain transfers, books) and explaining every difference.
- Refund automation
- Deciding and issuing refunds in software under a written policy, with checks that stop duplicate, oversized or out-of-policy refunds.
- Settlement (payments)
- The step in which funds actually move between the parties to a payment, after authorization and clearing, and become final under the system's rules.
- Spend limit
- A cap on how much an agent or payment credential may spend per payment, per period or in total, checked before the payment is authorized.
- Stablecoin settlement
- Settling a payment by transferring a fiat-pegged token on a blockchain, as in x402's exact scheme, where a signed transfer authorization moves the funds.
Customer service
- Average handle time (AHT)
- The average time a contact occupies a service representative, usually talk or chat time plus hold time plus after-contact work, per handled contact.
- Callback (customer service)
- A contact center option where the customer hangs up and the business calls back later, either when an agent is free or at a scheduled time.
- Click-to-cancel
- The rule that cancelling a subscription must be as easy as signing up. The FTC's 2024 rule was vacated in 2025; ROSCA and state laws still apply.
- Contact center
- The people, systems and phone numbers a business uses to handle customer contacts across voice, chat, email and messaging, inbound and outbound.
- Contact center as a service (CCaaS)
- CCaaS is contact center software run by a provider in the cloud: channels, routing, self-service and agent tools, used over the internet and paid for by use.
- Containment rate
- The share of conversations that an automated channel, such as an IVR, chatbot or AI agent, completes without handing the customer to a person.
- Conversational AI
- Software that holds a dialogue with people in natural language, by text or voice, to answer questions or complete tasks such as bookings and refunds.
- Customer satisfaction score (CSAT)
- CSAT measures how satisfied customers were with a specific interaction, from a short rating survey sent after the conversation or ticket ends.
- Escalation (customer service)
- Moving a customer contact from an automated channel or front-line agent to someone with more authority or skill, ideally with the full context attached.
- First contact resolution (FCR)
- The share of customer issues resolved in the first interaction with no follow-up contact needed. Tools define 'first' and 'resolved' differently.
- Help desk
- The support function, and the software behind it, that receives customer or employee issues, tracks each one as a ticket and works it to resolution.
- Hold time
- Time a customer spends on hold after an agent has answered. Contact center metrics count it separately from time spent waiting in the queue.
- Interactive voice response (IVR)
- A phone system that answers calls with recorded or synthesized prompts and serves or routes callers from their keypad presses or spoken replies.
- Live agent handoff
- Moving a conversation from a bot or AI agent to a human support agent, ideally with the transcript and details so the customer does not have to repeat them.
- Omnichannel (customer service)
- Customer service that routes every channel through one engine and one agent workspace, so history and capacity carry across voice, chat, email and messaging.
- Retention offer
- A discount or other benefit a business presents when a customer tries to cancel. California requires that the customer can still cancel at once.
- Speech-to-text (STT)
- Software that converts spoken audio into written text, the first stage of most voice bots, IVRs and chained AI voice agents.
- Text-to-speech (TTS)
- Software that turns written text into spoken audio, used for IVR prompts, screen readers and the voice of AI voice agents.
- Ticketing (support)
- Recording each support issue as a ticket with an owner, priority and status, and moving it through a defined lifecycle until it is closed.
- Voice agent (AI)
- An AI system that holds spoken conversations, usually on phone calls, to answer or place calls and complete tasks for a business or a person.
Agent architecture
- Agent evaluation
- Testing an AI agent on defined tasks and grading both the outcome and the steps it took, to measure what it can do and to catch regressions.
- Agent framework
- A library or SDK that supplies the agent loop, state, memory, multi-agent patterns, approvals and tracing, so teams do not build them from scratch.
- Agent memory
- How an AI agent keeps information beyond a single model call: short-term state within a conversation, and long-term stores it can recall across sessions.
- Agentic AI
- AI systems that pursue a goal over several steps, planning and acting with tools and memory, with a degree of autonomy set by their designers.
- AI agent
- A system in which a language model decides its own next steps, calling tools and acting on the results in a loop until it reaches a goal or a stopping point.
- AutoGen
- Microsoft's open-source framework for multi-agent AI applications. It is now in maintenance mode, succeeded by Microsoft Agent Framework (1.0 in April 2026).
- Context window
- The amount of text, measured in tokens, a language model can take into account at once, including the prompt, history, tool data and its own output.
- CrewAI
- An open-source Python framework for multi-agent systems built from role-based agents in crews, with event-driven Flows, planning, memory and A2A delegation.
- Function calling (LLMs)
- A model API feature: you describe functions, the model returns a structured call to one with arguments, and your code runs it and sends back the result.
- Google Agent Development Kit (ADK)
- Google's open-source, code-first toolkit for building, evaluating and deploying agents and multi-agent systems, in Python, Java, Go, TypeScript and Kotlin.
- Guardrails (LLM)
- Checks that run around a language model or agent to block, change or flag unsafe inputs, outputs and tool calls before they cause harm.
- Human-in-the-loop (HITL)
- A design in which an AI agent pauses at defined points so a person can approve, reject, edit or add input before the agent continues.
- LangGraph
- LangChain's open-source framework for building long-running, stateful agents as graphs, with persistence, interrupts for human review, and memory.
- Multi-agent system
- A system in which several AI agents, each with its own instructions, tools and context, divide a job between them and coordinate the results.
- OpenTelemetry
- The CNCF's vendor-neutral standard and toolkit for traces, metrics and logs. Its GenAI and agent semantic conventions are still in Development status.
- Orchestrator agent
- The lead agent in a multi-agent system that breaks a request into subtasks, delegates them to other agents and combines their results.
- Planner (agents)
- The agent or component that turns a goal into an explicit plan of steps, before or during execution, for itself or for other agents to carry out.
- Sub-agent
- An agent that works on a delegated part of a larger task for a parent or orchestrator agent, usually with its own instructions, tools and context window.
- Tool use (LLMs)
- A model's ability to call external tools, such as your functions, web search, code execution or MCP servers, during a conversation and use the results.
- Tracing (agents)
- Recording each step of an agent run, such as model calls, tool calls, handoffs and guardrail checks, as linked, timed spans in one trace.
Network and discovery
- Agent directory
- A searchable listing of agents, grouped by category, capability or provider, that people and client agents browse to find an agent for a job.
- Agent discovery
- How a client agent finds a remote agent and learns how to call it. A2A defines three routes: a well-known URI, registries and direct configuration.
- Agent endpoint
- The URL or address where an agent accepts protocol requests. In A2A v1.0 each one is a supportedInterfaces entry with a URL, binding and version.
- Agent registry
- A service that keeps authoritative records about agents, such as their cards, identifiers and verified owners, and answers lookups against them.
- Capability matching
- Choosing which agent fits a task by comparing what the task needs with what agents declare: skills, media types, protocol bindings and optional features.
- Cross-Origin Resource Sharing (CORS)
- The browser protocol that lets a server allow web pages from other origins to read its responses, using Access-Control headers and preflight requests.
- Idempotency (APIs)
- An operation is idempotent when repeating it has the same effect as doing it once, which is what makes retries after timeouts and dropped connections safe.
- Rate limiting (APIs and agents)
- Capping how many requests a client can make in a time window. HTTP servers refuse the excess with status 429, often with a Retry-After header.
- Resolver (agent discovery)
- A service that turns an identifier an agent starts with, such as a domain, phone number or DID, into the endpoint and metadata needed to reach an agent.
- Server-side request forgery (SSRF)
- An attack that makes a server send requests to destinations the attacker picks, such as internal services or cloud metadata, via URLs the server fetches.
Records and compliance
- Audit trail (agent exchanges)
- A chronological record that lets you reconstruct what two agents asked, answered and did in an exchange, who was involved, and how it ended.
- Data retention
- How long an organization keeps each kind of record, the reason for that period, and how the record is deleted or anonymized when it ends.
- GDPR
- The EU's General Data Protection Regulation (EU) 2016/679, applied since 25 May 2018, which governs the processing of personal data about people in the EU.
- Hash chain
- A sequence of records in which each record includes the hash of the one before it, so changing any earlier record breaks every later link.
- Non-repudiation
- Evidence that stops a party from credibly denying it sent or received something, usually a digital signature plus trusted time and key records.
- PIPEDA
- Canada's federal private-sector privacy law, covering personal information handled in commercial activity. Bill C-36 (June 2026) proposes to replace it.
- Receipt (agent exchange)
- A signed record of one completed agent-to-agent exchange, naming the parties, the request, the outcome and the time, that either side can later verify.
- Tamper-evident log
- An append-only log built so any later change, deletion or reordering of its entries can be detected, usually with hash chains or Merkle trees.