Glossary

Short definitions of the protocols, concepts, and standards behind agent-to-agent communication.

Protocols and standards

A2A (Agent2Agent protocol)
A2A is an open protocol that lets AI agents from different vendors discover each other and exchange messages, tasks and results over standard web technology.
Agent Communication Protocol (ACP)
IBM Research's open REST protocol for agent communication, launched in March 2025. It merged into A2A under the Linux Foundation in August 2025.
Agent Network Protocol (ANP)
An open-source protocol suite for agent identity, description, discovery and messaging, built on W3C decentralized identifiers and the did:wba method.
Agent Payments Protocol (AP2)
AP2 is an open protocol for agent-initiated payments. Signed mandates prove what a user authorized, and it can run as an extension of A2A.
Agentic Commerce Protocol
An open standard maintained by OpenAI and Stripe that lets a buyer's AI agent run a merchant's checkout while the merchant stays the system of record.
Agora protocol
A research meta-protocol for LLM agents: they agree on plain-text protocol documents identified by hash, and fall back to natural language.
gRPC
gRPC is an open source RPC framework that defines services in Protocol Buffers and runs them over HTTP/2. It is one of A2A's three standard bindings.
HTTP Message Signatures (RFC 9421)
The IETF standard for signing selected parts of an HTTP request or response and carrying the result in Signature and Signature-Input headers.
HTTP+JSON binding
A2A's RESTful protocol binding: resource URLs and standard HTTP methods, ProtoJSON bodies, google.rpc.Status errors, and Server-Sent Events for streams.
JSON Canonicalization Scheme (RFC 8785)
JCS (RFC 8785) turns JSON data into one deterministic byte sequence, so hashes and signatures over JSON verify the same way everywhere.
JSON Web Key Set (JWKS)
A JWKS is a JSON document that lists public keys as JSON Web Keys (RFC 7517), so a verifier can find the key that matches a signature's kid.
JSON Web Signature (JWS)
JWS (RFC 7515) is the IETF format for content protected by a digital signature or MAC using JSON structures. A2A uses it to sign Agent Cards.
JSON Web Token (JWT)
A compact, URL-safe token (RFC 7519) that carries JSON claims such as issuer, subject, audience and expiry, protected by a JWS signature or JWE encryption.
JSON-RPC 2.0
JSON-RPC 2.0 is a lightweight, transport-agnostic remote procedure call protocol that encodes requests, results and errors as JSON objects.
Model Context Protocol (MCP)
MCP is an open protocol that connects AI applications to external tools, data and prompt templates through a standard client-server interface on JSON-RPC 2.0.
NLWeb
An open project from Microsoft that gives a website a natural-language query endpoint answering in Schema.org JSON. Every instance is also an MCP server.
OAuth 2.0
The IETF authorization framework (RFC 6749) in which a client gets a scoped access token from an authorization server. A2A agents declare it in securitySchemes.
OpenID Connect (OIDC)
An identity layer on OAuth 2.0: the OpenID Provider issues a signed ID token, a JWT, that tells a client who the user is and how they signed in.
ProtoJSON
Protocol Buffers' canonical JSON encoding. A2A v1.0 uses it for all JSON: camelCase field names, enum names as strings, oneof members as keys.
Server-Sent Events (SSE)
Server-Sent Events is a web standard for streaming text events from server to client over one HTTP response. A2A uses it for streaming task updates.
Session Initiation Protocol (SIP)
The IETF signaling protocol (RFC 3261) that sets up, changes and ends voice and video sessions, such as internet phone calls, on IP networks.
STIR/SHAKEN
The caller ID authentication framework for IP phone networks: the originating carrier signs the calling number, and the receiving carrier verifies it.
Universal Commerce Protocol (UCP)
An open commerce standard, announced by Google with retail partners in January 2026, that lets agents discover a business's capabilities and check out.
Web Bot Auth
An IETF working group and draft protocol that let bots and AI agents sign HTTP requests to websites, so a site can verify which operator sent them.
Well-known URI
A well-known URI is a fixed path under /.well-known/ (RFC 8615) where a site publishes metadata. A2A agents publish their Agent Card there.
x402
x402 is an open payment standard built on HTTP 402 Payment Required, so a server can request payment and a client can pay within one exchange.

A2A concepts

A2A extension
A URI-identified addition to the A2A protocol, defined in its own spec, that an agent declares in its Agent Card and a client activates per request.
A2A-Extensions header
The HTTP header where an A2A client lists, comma-separated, the extension URIs it wants active. The agent's response echoes the ones it activated.
A2A-Version header
The HTTP header where an A2A client names the protocol version it speaks, as Major.Minor. A missing header means 0.3; an unsupported one gets -32009.
Agent capabilities (A2A)
The capabilities object in an A2A Agent Card: flags for streaming, push notifications and an extended card, plus the list of supported extensions.
Agent Card
The JSON document an A2A agent publishes to describe who it is, where to reach it, what it can do and how clients must authenticate.
Agent skill
An entry in an Agent Card's skills list that describes one capability an A2A agent offers: id, name, description, tags and media types.
Artifact (A2A)
An output an A2A agent produces for a task, such as a document, image or JSON result, made of one or more parts and identified by artifactId.
Auth required (TASK_STATE_AUTH_REQUIRED)
The interrupted A2A task state that asks the client to supply authorization. The spec leaves the credential's scope, format and revocation open.
Client agent
In A2A, the client agent is the application or agent that starts an interaction and sends messages to a remote agent on behalf of a user or system.
contextId
The A2A identifier that groups related tasks and messages into one conversation, so an agent can carry context from one exchange to the next.
Data part (A2A)
An A2A Part that carries structured JSON in its data field, such as form fields, records or machine-readable results, instead of prose.
Extended Agent Card
A fuller Agent Card that an A2A agent returns only to authenticated clients through GetExtendedAgentCard, often with extra skills or detail.
File part (A2A)
An A2A Part that carries a file, either inline as base64 bytes in raw or by reference in url, with an optional filename and mediaType.
Input required (TASK_STATE_INPUT_REQUIRED)
The interrupted A2A task state an agent sets when it needs more information from the client before it can continue the task.
Message (A2A)
One turn of communication between an A2A client and a remote agent, with a sender role, a message id and one or more content parts.
messageId
The required, creator-assigned unique identifier on every A2A Message. Agents may use it to spot duplicate sends, which makes client retries safer.
Part (A2A)
The smallest unit of content in an A2A message or artifact. Each part holds text, inline file bytes, a file URL, or structured JSON data.
Protocol binding (A2A)
The concrete transport and wire format for A2A's abstract operations. Version 1.0 defines JSON-RPC, gRPC and HTTP+JSON; custom bindings are named by URI.
Push notification config (A2A)
An A2A TaskPushNotificationConfig: the webhook URL, optional token and credentials an agent uses to POST task updates to a client.
Remote agent
In A2A, the remote agent is the server side: it exposes an A2A endpoint, receives messages from client agents, runs tasks and returns results.
securitySchemes
The A2A Agent Card map naming each way a client can authenticate: API key, HTTP auth, OAuth 2.0, OpenID Connect or mutual TLS. Used with securityRequirements.
Signed Agent Card
An Agent Card that carries JWS signatures over its RFC 8785 canonical form, so clients can detect tampering and see which key signed it.
Streaming (A2A)
A2A's real-time update mode: SendStreamingMessage or SubscribeToTask opens a stream of task, status and artifact events over SSE or gRPC.
SubscribeToTask
The A2A v1.0 operation that opens a stream of updates for an existing, unfinished task, starting with a snapshot of it. v0.3 called it tasks/resubscribe.
supportedInterfaces
The required Agent Card field that lists, in preference order, each URL where an A2A agent listens, with its protocol binding and version.
Task (A2A)
The stateful unit of work an A2A agent creates to track a request, with a server-generated id, a status, artifacts and message history.
Task lifecycle (A2A)
The path an A2A task takes from creation to an end state: submitted, working, paused for input or authorization, then completed, failed, canceled or rejected.
Task state
The TaskState value in an A2A task's status: submitted, working, waiting for input or authorization, or one of four terminal outcomes.
Terminal state
One of the four A2A task states a task can never leave: completed, failed, canceled or rejected. Follow-up work starts a new task.
Text part (A2A)
An A2A Part whose content is a string in its text field. It carries prompts, replies and status messages, optionally labelled with a media type.

Identity and trust

Agent identity
Agent identity is the verifiable answer to which software agent is making a request, which organization operates it, and on whose behalf it acts.
Agent impersonation
An attack where an agent poses as another agent or a trusted provider to borrow its access or reputation, via copied names, look-alike domains or stolen keys.
Agent provider
The organization that builds or operates an AI agent. A2A Agent Cards name it in the provider field, but only keys and domains can back that claim.
Attestation (agents)
Signed evidence a system produces about its own state, such as the software it runs, appraised by a verifier so a relying party can decide what to trust.
Bot detection
Techniques that decide whether a web request comes from a person or automated software, by scoring traffic signals or checking bots that identify themselves.
Certificate authority
An entity that issues digital certificates and vouches for the binding between a public key and a name. TLS and mutual TLS trust rest on CAs.
Confused deputy problem
A program holding authority is tricked into using it for a party that lacks it. Norm Hardy named it in 1988; agents acting for others face it daily.
Credential revocation
Ending a credential's validity before it expires, and the ways verifiers find out: revocation lists, status queries, token revocation and status lists.
Decentralized identifier (DID)
A URI such as did:web:example.com that resolves to a DID document of keys and service endpoints, whose controller can prove control (W3C DID 1.0).
Delegation (agent authority)
A principal granting an agent part of its authority, so the agent can act for it within set limits while staying identifiable as the agent.
Key rotation
Replacing a cryptographic key with a new one on a schedule or after compromise, with an overlap so verifiers keep working through the switch.
Know Your Agent (KYA)
Know Your Agent (KYA) is an industry term, with no single standard, for checking which AI agent is acting, who operates it, and whom it represents.
Mandate (agent authorization)
A signed record of what a principal authorized an agent to do, with limits, checked before acting. AP2 v0.2 defines Checkout and Payment Mandates.
Mutual TLS (mTLS)
TLS in which the client also presents a certificate and proves it holds the key, so both ends authenticate each other. A2A lists it as a security scheme.
Principal (delegation)
The person or organization an agent acts for. In delegation the principal's authority passes to the agent, which still acts under its own identity.
Principle of least privilege
Give each program, user and agent only the permissions its task needs, for only as long as it needs them, so mistakes and attacks do less damage.
Prompt injection
An attack in which text an AI model reads, typed by a user or hidden in content it processes, overrides its intended instructions. OWASP ranks it LLM01:2025.
Reputation scoring (agents)
Rating how far to trust an agent or its provider from observed behaviour and history. No standard defines it, so each service builds its own model.
Scoped credential
A credential limited to specific actions, resources, audiences or time, so a leaked or misused copy can do far less than its holder's full authority.
Verifiable credential
A tamper-evident set of claims signed by an issuer, kept by a holder and checked by a verifier, as defined by the W3C Verifiable Credentials Data Model 2.0.

Commerce and payments

Agent payments
Payments an AI agent initiates for a person or business, plus the standards that prove the agent was authorized and carry the payment itself.
Agentic commerce
Buying and selling in which an AI agent finds products, builds a checkout and pays for a person or business, within limits its principal sets in advance.
Chargeback
A card issuer's reversal of a disputed transaction back through the acquirer to the merchant, decided under card network rules.
Checkout Mandate (AP2)
An AP2 v0.2 credential proving to a merchant that an agent may complete one specific checkout. It replaced the Intent and Cart Mandates of AP2 v0.1.
Dispute resolution (payments)
The rules and steps that decide who bears the loss when a payer contests a transaction, from card network cycles to statutory error procedures.
HTTP 402 Payment Required
The HTTP status code that RFC 9110 reserves for future use. The x402 protocol gives it concrete meaning: pay, then retry the same request.
Merchant of record
The business that legally sells to the customer in a transaction: its name appears on the statement and it answers for refunds and disputes.
Network tokenization
Replacing a card's account number with a card-network token that works only for a given merchant, device or use, and now for specific AI agents.
Payment Mandate (AP2)
An AP2 v0.2 credential, secured as an SD-JWT, proving to credential providers, networks and processors that an agent may pay for one checkout.
Reconciliation (payments)
Matching what each system says happened to a payment (orders, processor records, payouts, on-chain transfers, books) and explaining every difference.
Refund automation
Deciding and issuing refunds in software under a written policy, with checks that stop duplicate, oversized or out-of-policy refunds.
Settlement (payments)
The step in which funds actually move between the parties to a payment, after authorization and clearing, and become final under the system's rules.
Spend limit
A cap on how much an agent or payment credential may spend per payment, per period or in total, checked before the payment is authorized.
Stablecoin settlement
Settling a payment by transferring a fiat-pegged token on a blockchain, as in x402's exact scheme, where a signed transfer authorization moves the funds.

Customer service

Average handle time (AHT)
The average time a contact occupies a service representative, usually talk or chat time plus hold time plus after-contact work, per handled contact.
Callback (customer service)
A contact center option where the customer hangs up and the business calls back later, either when an agent is free or at a scheduled time.
Click-to-cancel
The rule that cancelling a subscription must be as easy as signing up. The FTC's 2024 rule was vacated in 2025; ROSCA and state laws still apply.
Contact center
The people, systems and phone numbers a business uses to handle customer contacts across voice, chat, email and messaging, inbound and outbound.
Contact center as a service (CCaaS)
CCaaS is contact center software run by a provider in the cloud: channels, routing, self-service and agent tools, used over the internet and paid for by use.
Containment rate
The share of conversations that an automated channel, such as an IVR, chatbot or AI agent, completes without handing the customer to a person.
Conversational AI
Software that holds a dialogue with people in natural language, by text or voice, to answer questions or complete tasks such as bookings and refunds.
Customer satisfaction score (CSAT)
CSAT measures how satisfied customers were with a specific interaction, from a short rating survey sent after the conversation or ticket ends.
Escalation (customer service)
Moving a customer contact from an automated channel or front-line agent to someone with more authority or skill, ideally with the full context attached.
First contact resolution (FCR)
The share of customer issues resolved in the first interaction with no follow-up contact needed. Tools define 'first' and 'resolved' differently.
Help desk
The support function, and the software behind it, that receives customer or employee issues, tracks each one as a ticket and works it to resolution.
Hold time
Time a customer spends on hold after an agent has answered. Contact center metrics count it separately from time spent waiting in the queue.
Interactive voice response (IVR)
A phone system that answers calls with recorded or synthesized prompts and serves or routes callers from their keypad presses or spoken replies.
Live agent handoff
Moving a conversation from a bot or AI agent to a human support agent, ideally with the transcript and details so the customer does not have to repeat them.
Omnichannel (customer service)
Customer service that routes every channel through one engine and one agent workspace, so history and capacity carry across voice, chat, email and messaging.
Retention offer
A discount or other benefit a business presents when a customer tries to cancel. California requires that the customer can still cancel at once.
Speech-to-text (STT)
Software that converts spoken audio into written text, the first stage of most voice bots, IVRs and chained AI voice agents.
Text-to-speech (TTS)
Software that turns written text into spoken audio, used for IVR prompts, screen readers and the voice of AI voice agents.
Ticketing (support)
Recording each support issue as a ticket with an owner, priority and status, and moving it through a defined lifecycle until it is closed.
Voice agent (AI)
An AI system that holds spoken conversations, usually on phone calls, to answer or place calls and complete tasks for a business or a person.

Agent architecture

Agent evaluation
Testing an AI agent on defined tasks and grading both the outcome and the steps it took, to measure what it can do and to catch regressions.
Agent framework
A library or SDK that supplies the agent loop, state, memory, multi-agent patterns, approvals and tracing, so teams do not build them from scratch.
Agent memory
How an AI agent keeps information beyond a single model call: short-term state within a conversation, and long-term stores it can recall across sessions.
Agentic AI
AI systems that pursue a goal over several steps, planning and acting with tools and memory, with a degree of autonomy set by their designers.
AI agent
A system in which a language model decides its own next steps, calling tools and acting on the results in a loop until it reaches a goal or a stopping point.
AutoGen
Microsoft's open-source framework for multi-agent AI applications. It is now in maintenance mode, succeeded by Microsoft Agent Framework (1.0 in April 2026).
Context window
The amount of text, measured in tokens, a language model can take into account at once, including the prompt, history, tool data and its own output.
CrewAI
An open-source Python framework for multi-agent systems built from role-based agents in crews, with event-driven Flows, planning, memory and A2A delegation.
Function calling (LLMs)
A model API feature: you describe functions, the model returns a structured call to one with arguments, and your code runs it and sends back the result.
Google Agent Development Kit (ADK)
Google's open-source, code-first toolkit for building, evaluating and deploying agents and multi-agent systems, in Python, Java, Go, TypeScript and Kotlin.
Guardrails (LLM)
Checks that run around a language model or agent to block, change or flag unsafe inputs, outputs and tool calls before they cause harm.
Human-in-the-loop (HITL)
A design in which an AI agent pauses at defined points so a person can approve, reject, edit or add input before the agent continues.
LangGraph
LangChain's open-source framework for building long-running, stateful agents as graphs, with persistence, interrupts for human review, and memory.
Multi-agent system
A system in which several AI agents, each with its own instructions, tools and context, divide a job between them and coordinate the results.
OpenTelemetry
The CNCF's vendor-neutral standard and toolkit for traces, metrics and logs. Its GenAI and agent semantic conventions are still in Development status.
Orchestrator agent
The lead agent in a multi-agent system that breaks a request into subtasks, delegates them to other agents and combines their results.
Planner (agents)
The agent or component that turns a goal into an explicit plan of steps, before or during execution, for itself or for other agents to carry out.
Sub-agent
An agent that works on a delegated part of a larger task for a parent or orchestrator agent, usually with its own instructions, tools and context window.
Tool use (LLMs)
A model's ability to call external tools, such as your functions, web search, code execution or MCP servers, during a conversation and use the results.
Tracing (agents)
Recording each step of an agent run, such as model calls, tool calls, handoffs and guardrail checks, as linked, timed spans in one trace.

Network and discovery

Agent directory
A searchable listing of agents, grouped by category, capability or provider, that people and client agents browse to find an agent for a job.
Agent discovery
How a client agent finds a remote agent and learns how to call it. A2A defines three routes: a well-known URI, registries and direct configuration.
Agent endpoint
The URL or address where an agent accepts protocol requests. In A2A v1.0 each one is a supportedInterfaces entry with a URL, binding and version.
Agent registry
A service that keeps authoritative records about agents, such as their cards, identifiers and verified owners, and answers lookups against them.
Capability matching
Choosing which agent fits a task by comparing what the task needs with what agents declare: skills, media types, protocol bindings and optional features.
Cross-Origin Resource Sharing (CORS)
The browser protocol that lets a server allow web pages from other origins to read its responses, using Access-Control headers and preflight requests.
Idempotency (APIs)
An operation is idempotent when repeating it has the same effect as doing it once, which is what makes retries after timeouts and dropped connections safe.
Rate limiting (APIs and agents)
Capping how many requests a client can make in a time window. HTTP servers refuse the excess with status 429, often with a Retry-After header.
Resolver (agent discovery)
A service that turns an identifier an agent starts with, such as a domain, phone number or DID, into the endpoint and metadata needed to reach an agent.
Server-side request forgery (SSRF)
An attack that makes a server send requests to destinations the attacker picks, such as internal services or cloud metadata, via URLs the server fetches.

Records and compliance

Audit trail (agent exchanges)
A chronological record that lets you reconstruct what two agents asked, answered and did in an exchange, who was involved, and how it ended.
Data retention
How long an organization keeps each kind of record, the reason for that period, and how the record is deleted or anonymized when it ends.
GDPR
The EU's General Data Protection Regulation (EU) 2016/679, applied since 25 May 2018, which governs the processing of personal data about people in the EU.
Hash chain
A sequence of records in which each record includes the hash of the one before it, so changing any earlier record breaks every later link.
Non-repudiation
Evidence that stops a party from credibly denying it sent or received something, usually a digital signature plus trusted time and key records.
PIPEDA
Canada's federal private-sector privacy law, covering personal information handled in commercial activity. Bill C-36 (June 2026) proposes to replace it.
Receipt (agent exchange)
A signed record of one completed agent-to-agent exchange, naming the parties, the request, the outcome and the time, that either side can later verify.
Tamper-evident log
An append-only log built so any later change, deletion or reordering of its entries can be detected, usually with hash chains or Merkle trees.