State of Agent-to-Agent

State of Agent-to-Agent: Q3 2026

How many of the top one million websites publish an A2A Agent Card, and what those cards declare.

Crawl
September 26, 2026 to September 27, 2026
Crawl ID
full-20260926-39db43
Seed list
Tranco list L5PZ4, top 1,000,000 domains, created September 25, 2026
Data
Aggregate CSV · Methodology

Key figures

Domains checked
999,550
of 1,000,000 in the list
Served an Agent Card
274
0.027% of domains checked
Use the v1.0 shape
200
73.0% of cards
Signed
0
0% of cards

Adoption

Agent Cards by site popularity

Share of domains in each Tranco rank range that served an Agent Card

Agent Cards by site popularityShare of domains in each Tranco rank range that served an Agent Card. 1 to 1,000: 0%; 1,001 to 10,000: 0.033%; 10,001 to 100,000: 0.038%; 100,001 to 1,000,000: 0.026%.1 to 1,000: 0%1 to 1,0000%1,001 to 10,000: 0.033%1,001 to 10,0000.033%10,001 to 100,000: 0.038%10,001 to 100,0000.038%100,001 to 1,000,000: 0.026%100,001 to 1,000,0000.026%
274 of 999,550 domains checked served an Agent Card (0.027%). The highest share was in the 10,001 to 100,000 range: 34 of 89,900 domains.
Show as table
Agent Cards by site popularity
Tranco rankDomains checkedAgent CardsShare
1 to 1,0001,00000%
1,001 to 10,0009,00030.033%
10,001 to 100,00089,900340.038%
100,001 to 1,000,000899,6502370.026%

What each domain returned

Share of domains checked, by outcome

What each domain returnedShare of domains checked, by outcome. Agent Card, v1.0 shape: 0.020%; Agent Card, v0.3 shape: 0.007%; JSON, not an Agent Card: 0.12%; Not JSON: 8.7%; HTTP error status: 57.5%; Blocked by robots.txt: 17.6%; Timed out: 6.0%; Connection failed: 9.5%; Redirect not followed: 0.49%; Invalid domain name: 0.022%.Agent Card, v1.0 shape: 0.020%Agent Card, v1.0 shape0.020%Agent Card, v0.3 shape: 0.007%Agent Card, v0.3 shape0.007%JSON, not an Agent Card: 0.12%JSON, not an Agent Card0.12%Not JSON: 8.7%Not JSON8.7%HTTP error status: 57.5%HTTP error status57.5%Blocked by robots.txt: 17.6%Blocked by robots.txt17.6%Timed out: 6.0%Timed out6.0%Connection failed: 9.5%Connection failed9.5%Redirect not followed: 0.49%Redirect not followed0.49%Invalid domain name: 0.022%Invalid domain name0.022%
Each domain counts once. When robots.txt could not be read, that is the outcome. Otherwise, when neither card path returned a card, the domain counts under the most informative path result, in this order: JSON, not JSON, HTTP error, redirect, timeout, connection failure, robots.txt rules.
Show as table
What each domain returned
Outcome1 to 1,0001,001 to 10,00010,001 to 100,000100,001 to 1,000,000AllShare
Agent Card, v1.0 shape02191792000.020%
Agent Card, v0.3 shape011558740.007%
JSON, not an Agent Card4131141,0561,1870.12%
Not JSON907668,07277,83686,7648.7%
HTTP error status5115,51453,859515,045574,92957.5%
Blocked by robots.txt11181210,650164,283175,85617.6%
Timed out524185,11854,88060,4686.0%
Connection failed2221,40811,47081,87794,9779.5%
Redirect not followed8554734,3424,8780.49%
Invalid domain name211110942170.022%

What the cards declare

Shares below are of the 274 cards found. They count what each card declares; the crawl did not call any agent.

Card shape and location

Share of cards, by shape and the path that served them

Card shape and locationShare of cards, by shape and the path that served them. v1.0 shape at agent-card.json: 72.6%; v0.3 shape at agent-card.json: 24.8%; v0.3 shape at agent.json: 2.2%; v1.0 shape at agent.json: 0.36%.v1.0 shape at agent-card.json: 72.6%v1.0 shape at agent-card.json72.6%v0.3 shape at agent-card.json: 24.8%v0.3 shape at agent-card.json24.8%v0.3 shape at agent.json: 2.2%v0.3 shape at agent.json2.2%v1.0 shape at agent.json: 0.36%v1.0 shape at agent.json0.36%
200 of 274 cards list their endpoints in supportedInterfaces (v1.0). The rest use the v0.3 fields url with protocolVersion or preferredTransport.
Show as table
Card shape and location
Shape and pathCardsShare
v1.0 shape at agent-card.json19972.6%
v0.3 shape at agent-card.json6824.8%
v0.3 shape at agent.json62.2%
v1.0 shape at agent.json10.36%

Declared capabilities

Share of cards that set each capability to true

Declared capabilitiesShare of cards that set each capability to true. Streaming: 22.6%; Push notifications: 13.5%; At least one extension: 6.6%; Extended card: 0%.Streaming: 22.6%Streaming22.6%Push notifications: 13.5%Push notifications13.5%At least one extension: 6.6%At least one extension6.6%Extended card: 0%Extended card0%
Streaming, push notifications and the extended card are optional A2A features. Extensions counts cards that list at least one extension URI.
Show as table
Declared capabilities
CapabilityCardsShare
Streaming6222.6%
Push notifications3713.5%
At least one extension186.6%
Extended card00%

Protocol bindings

Share of cards declaring each binding (a card can declare several)

Protocol bindingsShare of cards declaring each binding (a card can declare several). JSON-RPC (JSONRPC): 32.1%; HTTP+JSON/REST (HTTP+JSON): 37.2%; gRPC (GRPC): 0%; Another value: 45.6%; None declared: 16.4%.JSON-RPC (JSONRPC): 32.1%JSON-RPC (JSONRPC)32.1%HTTP+JSON/REST (HTTP+JSON): 37.2%HTTP+JSON/REST (HTTP+JSON)37.2%gRPC (GRPC): 0%gRPC (GRPC)0%Another value: 45.6%Another value45.6%None declared: 16.4%None declared16.4%
The A2A specification defines three standard bindings: JSONRPC, GRPC and HTTP+JSON. 113 of the 200 v1.0-shape cards name the binding with transport, the v0.3 field name, instead of protocolBinding; they are counted by that value.
Show as table
Protocol bindings
BindingCardsShare
JSON-RPC (JSONRPC)8832.1%
HTTP+JSON/REST (HTTP+JSON)10237.2%
gRPC (GRPC)00%
Another value12545.6%
None declared4516.4%

Authentication schemes

Share of cards declaring each security scheme type (a card can declare several)

Authentication schemesShare of cards declaring each security scheme type (a card can declare several). OAuth 2.0: 20.8%; HTTP, other scheme: 10.9%; API key: 8.4%; HTTP Bearer: 5.8%; Other (non-standard type): 1.8%; OpenID Connect: 0.73%; None declared: 70.8%.OAuth 2.0: 20.8%OAuth 2.020.8%HTTP, other scheme: 10.9%HTTP, other scheme10.9%API key: 8.4%API key8.4%HTTP Bearer: 5.8%HTTP Bearer5.8%Other (non-standard type): 1.8%Other (non-standard type)1.8%OpenID Connect: 0.73%OpenID Connect0.73%None declared: 70.8%None declared70.8%
194 of 274 cards declare no security scheme. Types outside the A2A list count as other.
Show as table
Authentication schemes
Scheme typeCardsShare
OAuth 2.05720.8%
HTTP, other scheme3010.9%
API key238.4%
HTTP Bearer165.8%
Other (non-standard type)51.8%
OpenID Connect20.73%
None declared19470.8%

Skills per card

Share of cards, by number of skills listed

Skills per cardShare of cards, by number of skills listed. 0 skills: 1.8%; 1 skill: 13.9%; 2 to 4 skills: 47.8%; 5 to 9 skills: 34.3%; 10 to 19 skills: 1.5%; 20+ skills: 0.73%.0 skills: 1.8%0 skills1.8%1 skill: 13.9%1 skill13.9%2 to 4 skills: 47.8%2 to 4 skills47.8%5 to 9 skills: 34.3%5 to 9 skills34.3%10 to 19 skills: 1.5%10 to 19 skills1.5%20+ skills: 0.73%20+ skills0.73%
A skill is one capability the agent advertises in the card's skills list.
Show as table
Skills per card
SkillsCardsShare
0 skills51.8%
1 skill3813.9%
2 to 4 skills13147.8%
5 to 9 skills9434.3%
10 to 19 skills41.5%
20+ skills20.73%

Signing and HTTP caching

Share of cards with each property

Signing and HTTP cachingShare of cards with each property. Signed (signatures present): 0%; Content-Type: application/json: 98.5%; Cache-Control header: 84.7%; Cache-Control max-age above 0: 58.8%; ETag header: 43.8%; max-age above 0 and ETag: 27.0%.Signed (signatures present): 0%Signed (signatures present)0%Content-Type: application/json: 98.5%Content-Type: application/json98.5%Cache-Control header: 84.7%Cache-Control header84.7%Cache-Control max-age above 0: 58.8%Cache-Control max-age above 058.8%ETag header: 43.8%ETag header43.8%max-age above 0 and ETag: 27.0%max-age above 0 and ETag27.0%
The A2A specification says servers should send Cache-Control with max-age and an ETag for the card. Signed means the card has a non-empty signatures array; the crawl did not verify the signatures.
Show as table
Signing and HTTP caching
PropertyCardsShare
Signed (signatures present)00%
Content-Type: application/json27098.5%
Cache-Control header23284.7%
Cache-Control max-age above 016158.8%
ETag header12043.8%
max-age above 0 and ETag7427.0%
application/a2a+json20.73%
other10.36%
text/html10.36%

Provider organizations

Cards naming a provider organization
175
63.9% of cards
Distinct organization names
141
Names on more than one domain
7
covering 41 cards
Distinct card documents
262
by SHA-256 of the body

Counts only. This report does not name organizations or domains. Names are compared case-insensitively.

Why the other domains returned no card

999,276 domains returned no card. The detail recorded for each outcome, largest first:

Outcome and detailDomainsShare of checked
HTTP error status574,92957.5%
404 or 410 (not found)473,88747.4%
401 or 403 (refused)85,3988.5%
Other 4xx status7,0010.70%
5xx (server error)6,8300.68%
429 (rate limited)9350.094%
3xx that could not be followed8780.088%
Blocked by robots.txt175,85617.6%
robots.txt returned 429 or 5xx (full disallow)106,47010.7%
robots.txt rules disallow the paths53,0675.3%
robots.txt redirect not followed16,3191.6%
Connection failed94,9779.5%
Host did not resolve (530)94,9019.5%
Other network error760.008%
Not JSON86,7648.7%
HTML instead of JSON71,8107.2%
Body larger than 256 KiB12,9571.3%
Other non-JSON body1,9970.20%
Timed out60,4686.0%
robots.txt took over 5 s56,2015.6%
Card path took over 5 s4,2670.43%
Redirect not followed4,8780.49%
Redirect to a non-HTTPS URL3,5200.35%
More than 3 redirects1,2790.13%
Redirect to a blocked host or port790.008%
JSON, not an Agent Card1,1870.12%
JSON without Agent Card fields1,1870.12%
Invalid domain name2170.022%
Invalid or reserved name2170.022%

Data and reproducibility

The aggregate CSV has every figure on this page, one row per figure, with its count and base. It has no per-domain rows and no copies of cards.

Every number comes from one export of the crawl database, taken September 27, 2026. The methodology explains what was requested and how each outcome is classified. These are the queries the export ran:

Show the 10 SQL queries
  1. Crawl run: Tranco list, start and finish times, domains queued and checked, status.

    SELECT id, list_id, source, started_at, finished_at, domains_total, domains_done, status FROM crawls WHERE id = 'full-20260926-39db43'
  2. Domains per rank bucket and outcome class (crawl_stats holds totals only, no per-domain rows).

    SELECT bucket, classification, SUM(count) AS domains FROM crawl_stats WHERE crawl_id = 'full-20260926-39db43' GROUP BY bucket, classification ORDER BY bucket, classification
  3. Domains without a card, grouped into reasons from the stored detail (HTTP status, robots.txt result, network error kind).

    SELECT classification, CASE WHEN classification = 'http-error' AND detail IN ('404', '410') THEN 'not-found' WHEN classification = 'http-error' AND detail IN ('401', '403') THEN 'forbidden' WHEN classification = 'http-error' AND detail = '429' THEN 'rate-limited' WHEN classification = 'http-error' AND detail LIKE '5__' THEN 'server-error' WHEN classification = 'http-error' AND detail LIKE '3__' THEN 'redirect-status' WHEN classification = 'http-error' THEN 'other-status' WHEN classification = 'robots-disallowed' AND detail = 'rules' THEN 'robots-rules' WHEN classification = 'robots-disallowed' AND (detail = 'robots.txt 429' OR detail LIKE 'robots.txt 5__') THEN 'robots-unavailable' WHEN classification = 'robots-disallowed' THEN 'robots-redirect' WHEN classification = 'network-error' AND detail LIKE '%530' THEN 'unresolved' WHEN classification = 'network-error' AND detail LIKE '%dns' THEN 'dns' WHEN classification = 'network-error' AND detail LIKE '%tls' THEN 'tls' WHEN classification = 'network-error' AND (detail LIKE '%refused' OR detail LIKE '%reset') THEN 'connection' WHEN classification = 'network-error' THEN 'other-network' WHEN classification = 'timeout' AND detail = 'robots.txt' THEN 'robots-timeout' WHEN classification = 'timeout' THEN 'card-timeout' WHEN classification = 'not-json' AND detail = 'text/html' THEN 'html' WHEN classification = 'not-json' AND detail = 'oversize' THEN 'oversize' WHEN classification = 'not-json' THEN 'other-body' WHEN classification = 'redirect-error' AND detail = 'blocked-not-https' THEN 'redirect-not-https' WHEN classification = 'redirect-error' AND detail = 'too-many-redirects' THEN 'redirect-too-many' WHEN classification = 'redirect-error' THEN 'redirect-blocked' ELSE classification END AS reason, SUM(count) AS domains FROM crawl_stats WHERE crawl_id = 'full-20260926-39db43' AND classification NOT IN ('card-v1', 'card-v0.3') GROUP BY classification, reason ORDER BY domains DESC, classification, reason
  4. Cards by shape (1.0 = supportedInterfaces, 0.3 = url plus protocolVersion or preferredTransport) and by the path that served them.

    SELECT version, path, COUNT(*) AS cards FROM cards WHERE crawl_id = 'full-20260926-39db43' GROUP BY version, path ORDER BY cards DESC, version, path
  5. Card totals: distinct documents, signatures present, HTTP caching headers, declared capabilities, security schemes, provider organization present.

    SELECT COUNT(*) AS cards, COUNT(DISTINCT raw_sha256) AS distinct_documents, COALESCE(SUM(signed), 0) AS signed, COALESCE(SUM(CASE WHEN cache_control IS NOT NULL AND trim(cache_control) <> '' THEN 1 ELSE 0 END), 0) AS cache_control_present, COALESCE(SUM(CASE WHEN (instr(lower(cache_control), 'max-age=') > 0 AND CAST(substr(lower(cache_control), instr(lower(cache_control), 'max-age=') + 8) AS INTEGER) > 0) THEN 1 ELSE 0 END), 0) AS max_age_positive, COALESCE(SUM(CASE WHEN lower(cache_control) LIKE '%no-store%' THEN 1 ELSE 0 END), 0) AS no_store, COALESCE(SUM(etag_present), 0) AS etag, COALESCE(SUM(CASE WHEN etag_present = 1 AND (instr(lower(cache_control), 'max-age=') > 0 AND CAST(substr(lower(cache_control), instr(lower(cache_control), 'max-age=') + 8) AS INTEGER) > 0) THEN 1 ELSE 0 END), 0) AS max_age_and_etag, COALESCE(SUM(CASE WHEN json_extract(capabilities_json, '$.streaming') = 1 THEN 1 ELSE 0 END), 0) AS streaming, COALESCE(SUM(CASE WHEN json_extract(capabilities_json, '$.pushNotifications') = 1 THEN 1 ELSE 0 END), 0) AS push_notifications, COALESCE(SUM(CASE WHEN json_array_length(capabilities_json, '$.extensions') > 0 THEN 1 ELSE 0 END), 0) AS extensions, COALESCE(SUM(CASE WHEN json_extract(capabilities_json, '$.extendedAgentCard') = 1 THEN 1 ELSE 0 END), 0) AS extended_agent_card, COALESCE(SUM(CASE WHEN json_array_length(security_schemes) = 0 THEN 1 ELSE 0 END), 0) AS no_security_schemes, COALESCE(SUM(CASE WHEN provider_org IS NOT NULL AND trim(provider_org) <> '' THEN 1 ELSE 0 END), 0) AS with_provider_org FROM cards WHERE crawl_id = 'full-20260926-39db43'
  6. Cards by response media type (Content-Type without parameters); uncommon values fold into 'other'.

    SELECT CASE WHEN mt = '' THEN 'none' WHEN mt IN ('application/json', 'application/a2a+json', 'text/plain', 'text/html', 'application/octet-stream') THEN mt ELSE 'other' END AS media_type, COUNT(*) AS cards FROM (SELECT lower(trim(CASE WHEN instr(COALESCE(content_type, ''), ';') > 0 THEN substr(content_type, 1, instr(content_type, ';') - 1) ELSE COALESCE(content_type, '') END)) AS mt FROM cards WHERE crawl_id = 'full-20260926-39db43') GROUP BY media_type ORDER BY cards DESC, media_type
  7. Cards declaring each security scheme type (a card can declare several); non-standard types fold into 'other'.

    SELECT CASE WHEN j.value IN ('apiKey', 'oauth2', 'openIdConnect', 'mutualTLS', 'http:bearer', 'http:basic') THEN j.value WHEN j.value LIKE 'http:%' THEN 'http:other' ELSE 'other' END AS scheme, COUNT(DISTINCT c.domain) AS cards FROM cards AS c, json_each(c.security_schemes) AS j WHERE c.crawl_id = 'full-20260926-39db43' GROUP BY scheme ORDER BY cards DESC, scheme
  8. Cards by number of skills.

    SELECT CASE WHEN skills_count = 0 THEN '0' WHEN skills_count = 1 THEN '1' WHEN skills_count <= 4 THEN '2-4' WHEN skills_count <= 9 THEN '5-9' WHEN skills_count <= 19 THEN '10-19' ELSE '20+' END AS skills, COUNT(*) AS cards FROM cards WHERE crawl_id = 'full-20260926-39db43' GROUP BY skills
  9. Provider organizations as counts only: how many distinct names (case-insensitive), how many appear on more than one domain.

    SELECT COUNT(*) AS organizations, COALESCE(SUM(CASE WHEN n > 1 THEN 1 ELSE 0 END), 0) AS organizations_on_several_domains, COALESCE(SUM(CASE WHEN n > 1 THEN n ELSE 0 END), 0) AS cards_from_those, COALESCE(MAX(n), 0) AS most_domains_for_one FROM (SELECT lower(trim(provider_org)) AS org, COUNT(*) AS n FROM cards WHERE crawl_id = 'full-20260926-39db43' AND provider_org IS NOT NULL AND trim(provider_org) <> '' GROUP BY org)
  10. Internal: the domains with a card and their shape, used only to read the stored raw cards in R2. Never exported.

    SELECT domain, version FROM cards WHERE crawl_id = 'full-20260926-39db43' ORDER BY domain

Read from the stored raw cards (R2 emissar-crawl, key cards/full-20260926-39db43/<domain>.json (npx wrangler r2 object get ... --remote --pipe)):

  • Protocol bindings: v1.0 cards, supportedInterfaces[].protocolBinding, or that entry's transport field (the v0.3 name) when protocolBinding is absent; v0.3 cards, preferredTransport and additionalInterfaces[].transport. Compared case-insensitively with JSONRPC, GRPC and HTTP+JSON; any other value counts as 'other'. A card counts once per binding.
  • v1TransportField: v1.0 cards with at least one supportedInterfaces entry that has transport but no protocolBinding.
  • Extended card: v1.0 cards with capabilities.extendedAgentCard = true; v0.3 cards with supportsAuthenticatedExtendedCard = true.

How to cite

Emissar team. "State of Agent-to-Agent: Q3 2026." Emissar, published September 27, 2026. https://emissar.ai/research/state-of-a2a/2026-q3. Data: crawl full-20260926-39db43 of Tranco list L5PZ4 (2026-09-25).

Sources

  1. A2A protocol specification: Agent Card, discovery, caching and signatures
  2. Tranco list L5PZ4; Le Pochat et al., "Tranco: A Research-Oriented Top Sites Ranking Hardened Against Manipulation," NDSS 2019
  3. RFC 9309: Robots Exclusion Protocol