A2A endpoint tester
Call an A2A agent the way a client would, once, and see whether its replies match the specification.
By Emissar. Updated .
Result
- Card
- Endpoint
- Protocol
- Summary
- Checked at
- Shareable link
What it checks
Five steps, in order. A failed check breaks a MUST or a required field; a warning breaks a SHOULD or is likely to trip up clients. A step is skipped when an earlier one leaves nothing to test.
| Step | Check | Source |
|---|---|---|
| Fetch the Agent Card | Reads the card the same way the Agent Card validator does: /.well-known/agent-card.json, then the legacy /.well-known/agent.json, or the exact card URL you enter. Runs the validator's rules and reports how many checks fail. | A2A v1.0 §8.2, §4.4.1 |
| Pick the JSON-RPC interface | v1.0 cards: the first supportedInterfaces entry with protocolBinding JSONRPC and a protocolVersion the tester speaks (1.0 or 0.3), plus its tenant. v0.3 cards: url when preferredTransport is JSONRPC, else a JSONRPC entry in additionalInterfaces. The endpoint URL must pass the same fetch rules as the card and be on the card's own domain, and a tenant must be a plain identifier; otherwise the endpoint isn't called (see How it works). | §8.3.2; v0.3 §5.6.3 |
| SendMessage | Sends one message with a single text part: "Emissar endpoint test: please describe your skills." v1.0 endpoints get method SendMessage with the header A2A-Version: 1.0; v0.3 endpoints get message/send. Checks the HTTP status and Content-Type, the JSON-RPC envelope, and that the result is a Task or a Message with its required fields, valid states and roles, camelCase names and UTC timestamps. | §9.4.1, §4.1, §5.5, §5.6.1; v0.3 §7.1, §6 |
| GetTask | If SendMessage returned a task, fetches it once by id with historyLength 0. Checks that the same task comes back, that no history is returned, and that a terminal state hasn't changed. | §9.4.3, §3.2.4; v0.3 §7.3 |
| Unknown method | Calls a method that doesn't exist and expects error -32601 (Method not found) with an integer code and a message. For v1.0, any error details must be objects with an @type. | JSON-RPC 2.0 §5.1; A2A §9.5 |
How it works
- Requests come from Emissar's servers on Cloudflare, not from your browser, with the user agent
EmissarTools/0.1 (+https://emissar.ai/tools). Requests aren't signed with Emissar's key: anyone can point this tool at any site, so only our crawler signs (how EmissarBot's signatures work). - The agent only ever receives payloads the tester builds itself: the test message above, a GetTask for the task id the agent returned, and a call to a method that doesn't exist. Nothing you enter is sent to the agent, and nothing the agent says is acted on.
- Only an endpoint on the card's own domain is called: the host you enter, its
www.form or name withoutwww., or one of its subdomains. A card that names an endpoint on another site gets a warning and isn't tested, so a card can't point the tester at someone else's agent. - A tenant from the card is sent, as A2A requires, only when it is a plain identifier: letters, digits and
. _ ~ -, at most 100 characters. Otherwise the endpoint isn't called. - At most 4 requests per test: the card (one, or two when it falls back to the legacy path) and then the JSON-RPC calls. If the card needed two requests, the unknown-method call is skipped.
- Only public domain names over https on port 443 are contacted, for the card and for the endpoint. IP addresses,
localhost,.local,.internaland single-label names are refused. Each request times out after 5 seconds, and a response over 256 KB is dropped. - Card redirects are followed by hand, at most 3, and every hop goes through the same checks. A redirect from the endpoint is reported, not followed: clients post to the URL in the card.
- In each reply, the first 50 entries of any list (history, artifacts, parts) are checked, and at most 100 findings about its shape are listed, then a count of the rest.
- Each host, card and endpoint alike, is tested at most once every 30 seconds. Asking again sooner returns the previous result. If another test contacted the endpoint's host in the last 30 seconds, the endpoint isn't called this time, it is reported as not tested rather than failed, and the trace isn't stored.
- For emissar.ai, the card is read from this site's own route and the calls go to Emissar's agent inside the same Worker, not over the network.
API
The page uses a public endpoint you can call directly. It is rate limited per IP address (per calling zone for requests from other Cloudflare Workers, which share one address), and the response is the same JSON as the downloadable report.
curl -s https://emissar.ai/api/tools/test-endpoint \
-H 'Content-Type: application/json' \
-d '{"input":"example.com"}'
# Open a stored trace (kept for 24 hours)
curl -s https://emissar.ai/api/tools/test-endpoint/RESULT_IDLimitations
- It speaks only the JSON-RPC binding. gRPC and HTTP+JSON interfaces aren't tested.
- It sends no credentials. An agent that requires authentication answers with HTTP 401 or 403, and the test stops there.
- An agent whose card and endpoint are on different sites can't be tested here, because the tester only calls the card's own domain.
- It doesn't stream, subscribe, cancel, list tasks or register push notifications, and it doesn't wait for a working task to finish.
- It checks the shape of each reply, not whether the answer is right. Two replies can both pass and say very different things.
- One run is one sample: latency varies from call to call, and the timings include Emissar's own network path.
- Your test creates a task on the agent you test, like any client call would.
- The per-host limit is stored in Cloudflare Workers KV, which is eventually consistent, so two tests at the same moment in different regions can both go through.
Privacy
We keep the host names of the card and the endpoint for about a minute to enforce the per-host limit. Every complete trace is stored under a random id for 24 hours so the link works, then deleted automatically. A trace holds the card URL, the endpoint URL, timings and the check results. It doesn't hold the agent's replies: the tester reports their shape, not their content.
Anyone with a result link can open it until it expires. Responses from the agents we test aren't written to logs. As with any request to this site, Cloudflare processes your IP address to deliver and protect it. Details are in the trust center and the privacy policy.
Related
- Agent Card validator, for the full list of card checks and signature verification.
- The A2A task lifecycle, state by state, for what each task state means.
- Emissar's own agent, which this tester can call.