A2A protocol, agent to agent authentication
The agent to agent protocol deliberately keeps identity out of its messages. Its own documentation states that A2A payloads do not carry user or client identity directly, and pushes authentication down to the transport. Authorization is left to each agent, which must enforce it before performing sensitive actions.
The verdict
Verified
The document exists. The ledger fetched it at its publisher and quotes it.
Key facts
What the sources say
- Record ID
- AAL-2026-0017
- Kind
- Standard or protocol
- Jurisdiction
- Global
- Last verified
- Added
- The documentation states that A2A protocol payloads, such as JSON-RPC messages, do not carry user or client identity information directly.
- Identity is handled at the HTTP layer with standard web authentication rather than inside the protocol.
- Agents that interact with backend systems, databases or tools must enforce appropriate authorization before performing sensitive actions.
- Because identity is not in the payload, an agent receiving a delegated task cannot read the original principal out of the message itself.
Dimension by dimension
3 dimensions, each one stated, silent or open
Identity, Authorization, Delegation. Stated means the document you can open below says it; silent means the ledger read the document and it does not.
- IdentityStated
- The protocol carries no identity claim; the calling agent is whoever the transport authenticated.A2A Protocol documentation, Enterprise Ready, primary source, 15 September 2026.
- AuthorizationStated
- Each agent is told to enforce authorization itself before any sensitive action, so the protocol sets a duty rather than a mechanism.A2A Protocol documentation, Enterprise Ready, primary source, 15 September 2026.
- DelegationSilent
- Nothing in the payload records that one agent is acting for another agent's principal, so a delegation chain has to be carried outside A2A.A2A Protocol documentation, Enterprise Ready, primary source, 15 September 2026.
What it changes
For a team deploying an agent
If you connect agents with A2A, you own the identity problem. The protocol will not tell a receiving agent whose authority is behind a request, so decide now whether you carry that in a token audience, a token exchange actor claim, or an out of band record, and write it down before the second agent is added.
Sources
What this record was verified against
- A2A Protocol documentation, Enterprise ReadyPrimary · 15 September 2026
Related
Records that sit beside this one
RFC 8693, OAuth 2.0 token exchange
Global · verified 15 September 2026
The specification defines how to request and obtain security tokens from OAuth 2.0 authorization servers, including tokens employing impersonation and delegation.
How does a sub agent's authority attenuate
Global · verified 15 September 2026
RFC 8693 lets a token record that one party is acting for another, but does not require the exchanged token to be narrower.
Does a spending limit belong to the agent or to the principal
Global · verified 15 September 2026
The Visa Trusted Agent Protocol addresses recognising an approved agent and its intent, and does not itself carry a spending ceiling.
Can an agent hold a credential of its own
Global · verified 15 September 2026
NIST SP 800-63-4 states that for that publication, person refers only to natural persons.
Who is liable when a delegated agent exceeds its mandate
Global · verified 15 September 2026
The EU AI Act allocates duties to providers and deployers, and does not address an agent acting beyond its instructions.
No international standard governs revoking an agent's authority
Global · verified 15 September 2026
The Model Context Protocol relies on short lived access tokens and audience validation rather than on any revocation mechanism for an agent.
Cite this record
Free to reuse under CC BY 4.0, with attribution. The record ID AAL-2026-0017 is permanent and is never reused.
- In a sentence
- According to the GAGE Agent Authority Ledger (as of 15 September 2026), a2a protocol, agent to agent authentication.
- APA
- GAGE (Global Academy of Generative-AI Education). (2026). A2A protocol, agent to agent authentication. Agent Authority Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0017-a2a-protocol-enterprise-authentication
- MLA
- "A2A protocol, agent to agent authentication." Agent Authority Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0017-a2a-protocol-enterprise-authentication.
- Chicago
- GAGE (Global Academy of Generative-AI Education). "A2A protocol, agent to agent authentication." Agent Authority Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0017-a2a-protocol-enterprise-authentication.
- Permalink
- https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0017-a2a-protocol-enterprise-authentication
Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any NIST, IETF or MCP publication.
Back to the full ledger, or every record for Global and every standard or protocol record.
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.