Guides to agent-to-agent communication
How the A2A protocol and the standards around it work, explained from the specifications, with sources on every page.
A2A adoption in 2026: what 274 public Agent Cards show
274 of 999,550 top websites served an A2A Agent Card in Emissar's Q3 2026 crawl, and none were signed. What the cards declare and what to fix.
Updated
A security threat model for agent-to-agent systems
Assets, actors and trust boundaries in A2A deployments, the threats at each stage from discovery to callbacks, and which spec features mitigate them.
Updated
A2A extensions: adding what the spec leaves out
How A2A extensions work: URIs, Agent Card declarations, activation with A2A-Extensions, metadata, versioning and limits, and published extensions to check.
Updated
A2A protocol bindings: JSON-RPC, gRPC, and HTTP+JSON
What an A2A protocol binding is, how JSON-RPC, gRPC and HTTP+JSON map methods and errors, how Agent Cards declare them, and how version negotiation works.
Updated
Agent identity: what "verified" should mean
A verified AI agent can mean four different things: it holds a key, a known company runs it, it acts for someone, or it behaves. What each proof shows.
Updated
Agent payments: AP2 and x402 compared
AP2 proves what a user authorized an agent to buy. x402 puts a payment inside an HTTP or A2A exchange. How each works, how each meets A2A, and when to use both.
Updated
Delegated authority: how an agent proves it may act for you
How an AI agent proves a person authorized it: A2A's auth-required state, OAuth token exchange, scoped tokens, verifiable credentials and AP2 mandates.
Updated
Detecting AI agents on your website
How to recognize AI crawlers and agents on your site, from user agents and IP ranges to robots.txt and signed requests (RFC 9421, Web Bot Auth).
Updated
Making your customer service agent-ready: a checklist
An ordered checklist for letting customers' AI agents reach your service directly: Agent Card, skills, inputs, auth, handoff, records, limits, testing.
Updated
Moving from A2A 0.3 to 1.0
Every breaking change between A2A 0.3 and 1.0, a before and after example, a step-by-step migration checklist, and how one endpoint can serve both versions.
Updated
Multi-turn tasks: input-required and auth-required
How A2A tasks pause for input or authorization, how to continue them on the same taskId, which ID mismatches agents must reject, and what the spec leaves open.
Updated
Prompt injection between agents
How injected instructions travel through A2A messages, parts, artifacts and fetched content, why agent-to-agent raises the stakes, and which defenses work.
Updated
Streaming and push notifications in A2A
How A2A streams task updates over SSE, which events arrive in what order, how to reconnect, how push webhooks work and are secured, and when to poll instead.
Updated
Tutorial: build an A2A server on Cloudflare Workers
Build a minimal A2A v1.0 agent on Cloudflare Workers: Agent Card, JSON-RPC SendMessage and GetTask, a multi-turn task and correct error codes, tested with curl.
Updated
Tutorial: publish your first Agent Card
Write a minimal A2A v1.0 Agent Card, serve it at /.well-known/agent-card.json with the right headers, and check it with the Emissar validator.
Updated
When two voice agents meet on a phone call
Why AI agents now phone businesses that answer with AI, what breaks when both ends are machines, what Gibberlink showed, and a structured alternative.
Updated
A2A vs MCP: which one do you need?
MCP connects an agent to tools and data. A2A connects an agent to other agents. How each works, how they fit together, and a table for choosing.
Updated
Agent Cards explained: fields, discovery, and caching
What each field in an A2A 1.0 Agent Card means, how clients find cards, how to cache them, what changed from 0.3, and a checklist for publishing your own.
Updated
Signed Agent Cards: how JWS and RFC 8785 prove who published a card
What A2A signs in an Agent Card, how RFC 8785 and JWS fit together, how to verify a signature step by step, and what a valid one proves.
Updated
The A2A task lifecycle, state by state
Every A2A v1.0 task state, which ones are final, how multi-turn input works, how to follow a task, and the errors you hit, with a live exchange.
Updated
What is the A2A protocol? A plain-language guide
A2A is an open protocol for AI agents from different vendors to find each other and exchange tasks. What it covers, what it leaves out, and a live example.
Updated