Glossary · Identity and trust

Mutual TLS (mTLS)

TLS in which the client also presents a certificate and proves it holds the key, so both ends authenticate each other. A2A lists it as a security scheme.

Mutual TLS (mTLS) is a TLS connection in which the client, as well as the server, presents a certificate and proves it holds the matching private key, so each side authenticates the other during the handshake.

How it works. In ordinary HTTPS only the server presents a certificate. In TLS 1.3 (RFC 8446), a server that authenticates with a certificate may also send a CertificateRequest. The client answers with its own certificate and a signature proving possession of the private key. The server then checks the certificate, usually by building a path to a certification authority it trusts. RFC 8705 also defines a variant for OAuth clients that skips the PKI: the client registers its self-signed certificate in advance, and the server accepts it if the presented certificate matches.

In A2A. MutualTlsSecurityScheme is one of the five security scheme types an Agent Card can declare in securitySchemes, alongside API key, HTTP authentication, OAuth 2.0 and OpenID Connect. The A2A Agent Discovery guide also lists mTLS as one way to restrict who can fetch an Agent Card that contains sensitive details.

With OAuth. RFC 8705 uses mutual TLS in two ways: to authenticate OAuth clients to the authorization server, and to bind access tokens to the client’s certificate. A bound token carries the certificate’s SHA-256 thumbprint in its cnf claim as x5t#S256. A resource server compares it with the certificate on the connection, so a stolen token is useless without the private key.

Trade-offs. mTLS suits server-to-server links between parties who already know each other. Every client needs a certificate issued, rotated and eventually revoked. When a load balancer or reverse proxy terminates TLS, the client certificate details must reach the application some other way, and RFC 8705 leaves that mechanism out of scope. mTLS also identifies the machine or organization holding the key; it carries nothing about the principal an agent is acting for.

Neighbouring terms. A certificate authority issues the certificates both sides present. A signed Agent Card is A2A’s other identity mechanism, working at the document level instead of the connection.

Sources

  1. RFC 8446: The Transport Layer Security (TLS) Protocol Version 1.3, section 4.3.2: Certificate Request (accessed )
  2. RFC 8705: OAuth 2.0 Mutual-TLS Client Authentication and Certificate-Bound Access Tokens (accessed )
  3. A2A protocol definition (a2a.proto): SecurityScheme, MutualTlsSecurityScheme (accessed )
  4. A2A documentation: Agent Discovery in A2A (accessed )