a2a-sdk.
When to use A2A
- Mibyan ↔ Mibyan across machines — let your desktop agent hand tasks to a Mibyan on a server, or vice versa, each with its own memory, tools, and credentials.
- Delegating to specialist agents — a peer that advertises
web_search/research/codingskills on its Agent Card can be discovered and called mid-conversation. - Being a callable service — expose your Mibyan so other frameworks’ agents can send it tasks.
Enable
~/.mibyan/config.yaml:
a2a toolset, off by default — enable it per platform:
Outbound: calling other agents
With thea2a toolset enabled, the agent gets:
Configure known peers in
config.yaml:
a2a_call accepts any A2A endpoint.
Inbound: being callable
With the platform enabled, Mibyan serves:- Agent Card at
GET /.well-known/agent-card.json(canonical v1.0 path; the legacyagent.jsonalso answers) — advertises your agent’s name, skills (derived from enabled toolsets), and auth requirements. - JSON-RPC 2.0 at
POST /— canonical v1.0 methods (SendMessage,SendStreamingMessage,GetTask,ListTasks,CancelTask,SubscribeToTask, push-notification config CRUD) plus the pre-1.0 path-style aliases (message/send, …). - SSE streaming for
SendStreamingMessage, with spec-correct JSON-RPC-enveloped frames. - Push notifications (webhooks) for long-running tasks, HMAC-SHA256 signed.
contextId, so a peer can hold a multi-turn exchange.
Interoperability is verified against the official Python a2a-sdk (card resolution, SendMessage, streaming).
Security model
Secure by default; every widening step is explicit:- No token ⇒ localhost only. The server binds
127.0.0.1. Remote exposure requires a bearer token and an explicitA2A_HOST. - Per-peer tokens —
A2A_PEER_TOKENS="alice:tok1,bob:tok2"gives each peer its own credential; the authenticated name drives rate limiting, trust, and audit. - Prompt-injection filtering — inbound text is filtered and framed as untrusted peer input. Remote peers cannot invoke operator slash commands.
- Outbound redaction — credential-shaped strings (API keys, JWTs, tokens) are scrubbed from replies.
- Audit log — every exchange appends to
~/.mibyan/a2a_audit.jsonl. - Anti-loop — per-context turn caps stop two agents ping-ponging forever.
Configuration reference
Behind a reverse proxy or Kubernetes Service, set
A2A_PUBLIC_URL (or rely on X-Forwarded-Host/X-Forwarded-Proto) so the Agent Card advertises a URL peers can actually call back.
Quick test
Troubleshooting
- Peers can’t reach the card URL — the card was advertising your bind address; set
A2A_PUBLIC_URLto the externally routable URL. 401 Unauthorized— token mismatch; checkA2A_PEER_TOKENS/A2A_BEARER_TOKENon the server and the peer’sauth:block.- Server won’t bind non-localhost — by design: set a bearer token first, then
A2A_HOST=0.0.0.0. - Replies time out on long tasks — raise
A2A_REPLY_TIMEOUT(the orphan sweep follows it, so a late reply is stored, not discarded), or have the caller register a push-notification config and pollGetTask.

