-
-
Notifications
You must be signed in to change notification settings - Fork 2
[Story] A2A protocol v2 handshake with JWT-SVID #149
Copy link
Copy link
Open
Labels
P2Nice to have — could slipNice to have — could slipapiAPI design or breaking changesAPI design or breaking changesfederationCross-cluster federationCross-cluster federationsecuritySecurity hardening and vulnerabilitiesSecurity hardening and vulnerabilitiestrustIdentity, certificates, mTLS (Phase 2)Identity, certificates, mTLS (Phase 2)
Description
Activity
Metadata
Metadata
Assignees
Labels
P2Nice to have — could slipNice to have — could slipapiAPI design or breaking changesAPI design or breaking changesfederationCross-cluster federationCross-cluster federationsecuritySecurity hardening and vulnerabilitiesSecurity hardening and vulnerabilitiestrustIdentity, certificates, mTLS (Phase 2)Identity, certificates, mTLS (Phase 2)
Parent
Part of #146 (Cross-Cluster Agent Identity Federation epic).
Status
Blocked by validation gate. Coordinated with Workload API integration.
Goal
Extend the A2A protocol handshake with a v2 variant carrying JWT-SVIDs across trust domains, while remaining backward-compatible with v1 (operator-issued JWT).
Scope
X-A2A-Version: 2triggers SVID code path; absence = v1X-A2A-TrustDomaincarries the claimer's trust domain403 untrusted_domainif bundle missingagents/a2a/protocol.pywith v2 schemaagents/a2a/server.pyto route on version headeragents/a2a/client.pyto advertise v2 whenspiffe.enabled=trueReference
RFC-0001 § 4.3
agents/a2a/protocol.pyAcceptance
docs/a2a-architecture.md