Glossary · A2A concepts

Extended Agent Card

A fuller Agent Card that an A2A agent returns only to authenticated clients through GetExtendedAgentCard, often with extra skills or detail.

An extended Agent Card is a more detailed version of an agent’s Agent Card that the agent returns only to clients that have authenticated. It lets an agent keep its public card short while showing more to known callers.

How a client gets it. The public card must declare capabilities.extendedAgentCard: true. The client authenticates with one of the schemes listed in the public card’s securitySchemes, then calls the Get Extended Agent Card operation: GetExtendedAgentCard in the JSON-RPC and gRPC bindings, or GET /extendedAgentCard over HTTP+JSON (specification sections 3.1.11 and 5.3). In its simplest form, with no tenant to pass, the JSON-RPC request has no parameters:

{"jsonrpc": "2.0", "id": 6, "method": "GetExtendedAgentCard"}

The response is a complete AgentCard object. Clients should use it in place of their cached public card for the rest of the authenticated session, or until the card’s version changes.

What it can contain. Section 13.3 allows additional skills, more detailed capability information such as rate limits or quotas, and configuration specific to an organization or user. The agent may return different content depending on who authenticated, and must check that the client has permission before it returns privileged details. The extended card still should not include material that would cause harm if leaked, such as internal service URLs or unmasked credentials.

Errors. If the public card does not declare the capability, the call must fail with UnsupportedOperationError (JSON-RPC -32004). If the capability is declared but no extended card is configured, the agent returns ExtendedAgentCardNotConfiguredError (-32007).

Earlier versions. In v0.3 the flag was a top-level supportsAuthenticatedExtendedCard field and the JSON-RPC method was agent/getAuthenticatedExtendedCard. Version 1.0 moved the flag into capabilities (Appendix A.2.2) and renamed the operation.

Sources

  1. A2A Protocol Specification, section 3.1.11: Get Extended Agent Card (accessed )
  2. A2A Protocol Specification, section 13.3: Extended Agent Card Access Control (accessed )
  3. A2A Protocol Specification, Appendix A.2.2: Extended Agent Card Field Relocated (accessed )
  4. A2A Protocol Specification v0.3.0, agent/getAuthenticatedExtendedCard (accessed )