Glossary · A2A concepts

Auth required (TASK_STATE_AUTH_REQUIRED)

The interrupted A2A task state that asks the client to supply authorization. The spec leaves the credential's scope, format and revocation open.

TASK_STATE_AUTH_REQUIRED is the interrupted task state an A2A agent uses to tell the client that a task cannot continue until additional authorization is provided. The specification’s examples are an agent that needs an OAuth access token to call an API or another agent, and an action that needs human approval before it runs (section 7.6).

What the specification defines. The agent must track the work as a Task, move it to this state, and attach a status message that explains the required authorization, unless those details were agreed out of band or through an extension. Credentials must arrive out of band, unless an in-band exchange was negotiated. The agent may resume as soon as it has the credential, and should keep accepting messages so the client can negotiate, correct or refuse the request (section 7.6.1).

A client can answer itself, ask another person, agent or service, or pass the request upstream by putting its own task into the same state, which forms a chain. It should subscribe, register a webhook or poll so it does not miss the resumption (section 7.6.2). For in-band exchange, credentials should be bound to the requesting agent and encrypted when sensitive (section 7.6.3).

Illustrative task status:

{
  "state": "TASK_STATE_AUTH_REQUIRED",
  "message": {
    "messageId": "msg-a7",
    "taskId": "task-91d0",
    "contextId": "ctx-42b9",
    "role": "ROLE_AGENT",
    "parts": [{"text": "Refunds above CAD 200 need approval from the account holder."}]
  }
}

What it leaves open. Section 7.6.4 of the current specification on GitHub, added after the v1.0.1 release, says A2A does not define the scope, representation, validity or revocation of the credential or authorization decision. The state change alone must not count as authorization for any operation, and a credential obtained here must not be assumed to cover later messages on the task. Those meanings must come from the agent’s implementation, the credential issuer, or an A2A extension.

This state is separate from request authentication, which uses the schemes an Agent Card declares in securitySchemes (section 7.3). Emissar’s Mandate module proposes a scoped, revocable credential for this gap, designed to travel as an A2A extension. Its status is Spec in progress.

Questions

Does entering TASK_STATE_AUTH_REQUIRED authorize anything?
No. The current specification text says agents must not treat the state transition by itself as authorization for any operation.
How does the credential reach the agent?
Out of band by default, over a secure channel such as HTTPS. In-band exchange is allowed only when it has been negotiated out of band or through an extension.

Sources

  1. A2A Protocol Specification, section 7.6: In-Task Authorization (including 7.6.4, In-Task Authorization Scope) (accessed )
  2. A2A Protocol Specification, section 7.3: Client Authentication Process (accessed )
  3. A2A protocol definition (a2a.proto): TaskState (accessed )
  4. A2A Protocol Specification v1.0.1 (tagged release, for comparison) (accessed )
  5. Emissar: Mandate module (accessed )