Skip to main content

A2A protocol, agent to agent authentication

The agent to agent protocol deliberately keeps identity out of its messages. Its own documentation states that A2A payloads do not carry user or client identity directly, and pushes authentication down to the transport. Authorization is left to each agent, which must enforce it before performing sensitive actions.

The verdict

Verified

The document exists. The ledger fetched it at its publisher and quotes it.

Key facts

What the sources say

Record ID
AAL-2026-0017
Kind
Standard or protocol
Jurisdiction
Global
Last verified
Added
  • The documentation states that A2A protocol payloads, such as JSON-RPC messages, do not carry user or client identity information directly.
  • Identity is handled at the HTTP layer with standard web authentication rather than inside the protocol.
  • Agents that interact with backend systems, databases or tools must enforce appropriate authorization before performing sensitive actions.
  • Because identity is not in the payload, an agent receiving a delegated task cannot read the original principal out of the message itself.

Dimension by dimension

3 dimensions, each one stated, silent or open

Identity, Authorization, Delegation. Stated means the document you can open below says it; silent means the ledger read the document and it does not.

IdentityStated
The protocol carries no identity claim; the calling agent is whoever the transport authenticated.A2A Protocol documentation, Enterprise Ready, primary source, 15 September 2026.
AuthorizationStated
Each agent is told to enforce authorization itself before any sensitive action, so the protocol sets a duty rather than a mechanism.A2A Protocol documentation, Enterprise Ready, primary source, 15 September 2026.
DelegationSilent
Nothing in the payload records that one agent is acting for another agent's principal, so a delegation chain has to be carried outside A2A.A2A Protocol documentation, Enterprise Ready, primary source, 15 September 2026.

What it changes

For a team deploying an agent

If you connect agents with A2A, you own the identity problem. The protocol will not tell a receiving agent whose authority is behind a request, so decide now whether you carry that in a token audience, a token exchange actor claim, or an out of band record, and write it down before the second agent is added.

Sources

What this record was verified against

  1. A2A Protocol documentation, Enterprise ReadyPrimary · 15 September 2026

Related

Cite this record

Free to reuse under CC BY 4.0, with attribution. The record ID AAL-2026-0017 is permanent and is never reused.

In a sentence
According to the GAGE Agent Authority Ledger (as of 15 September 2026), a2a protocol, agent to agent authentication.
APA
GAGE (Global Academy of Generative-AI Education). (2026). A2A protocol, agent to agent authentication. Agent Authority Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0017-a2a-protocol-enterprise-authentication
MLA
"A2A protocol, agent to agent authentication." Agent Authority Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0017-a2a-protocol-enterprise-authentication.
Chicago
GAGE (Global Academy of Generative-AI Education). "A2A protocol, agent to agent authentication." Agent Authority Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0017-a2a-protocol-enterprise-authentication.
Permalink
https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0017-a2a-protocol-enterprise-authentication

Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any NIST, IETF or MCP publication.

Back to the full ledger, or every record for Global and every standard or protocol record.

GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.