STANDARD · §2.6 · DISCOVER · ACT · LAST REVIEWED SEPTEMBER 2026
What is A2A, the Agent2Agent protocol?
How one agent finds another, reads what it can do, and hands it a task.
Agent Readiness Compare editors · Spec status checked September 2026
Answer
A2A is an open standard for communication between AI agents. It was developed at Google and donated to the Linux Foundation, where a Technical Steering Committee maintains it. Agents describe themselves in an Agent Card published at a well-known URI, and exchange tasks over JSON-RPC 2.0, gRPC or HTTP+JSON. A website needs A2A only if it offers an agent of its own.
- Maintainer:
- Linux Foundation (Technical Steering Committee)
- Status:
- version 1.0.0
- Spec:
- a2a-protocol.org
1.What is A2A?
A2A (Agent2Agent) lets agents built on different frameworks interact without exposing their internal systems. The Technical Steering Committee includes representatives from AWS, Cisco, Google, IBM Research, Microsoft, Salesforce, SAP and ServiceNow. The protocol is licensed under Apache 2.0. The current released version is 1.0.0; versions 0.3.0, 0.2.6 and 0.1.0 remain available.
2.What is an Agent Card?
An Agent Card is a JSON document in which an agent describes its identity, capabilities and how to reach it. The specification registers a well-known URI for discovering Agent Cards (section 14.3 of the specification), so another agent can find it at a predictable path on the host. Publish one only if you run an agent that other agents should call.
3.Which transports does A2A use?
- JSON-RPC 2.0 over HTTP (specification section 9)
- gRPC (section 10)
- HTTP+JSON/REST (section 11)
Custom bindings are allowed if they keep the same data model and operations (section 12).
4.What does A2A not do?
- It does not connect an agent to tools and data; that is MCP. The A2A project describes the two as 'designed to work together'.
- It does not make a website readable to an agent that visits it.
- It does not handle payment.
5.Does my website need A2A?
Only if your business runs an agent that other agents should be able to call, for example a support or booking agent. Most sites start with readable pages, llms.txt and an MCP server, and add an Agent Card when they have an agent to publish.
6.Where does it sit in the readiness stack?
Layers 1 and 3: the Agent Card is a discovery signal, and the protocol carries tasks.
The readiness stack: five layers (Discover, Read, Act, Pay, Trust), the standards that address each, and the tools that document support.
Can an agent find you, and is it allowed in?
Can it read and understand what you offer?
Can it complete a task on your site or API?
Can it pay you?
Can you tell which agent it is, and on whose behalf it acts?
L1 DISCOVER
Can an agent find you, and is it allowed in?
Cloudflare AI Crawl Control (controls crawler access); ora.ai Scan (checks it); Cloudflare Is It Agent Ready (checks it)
L2 READ
Can it read and understand what you offer?
Cloudflare Markdown for Agents (serves markdown); ora.ai Scan (checks it)
L3 ACT
Can it complete a task on your site or API?
Cloudflare (hosts MCP servers); Vercel (hosts MCP servers); nekuda (builds WebMCP tools); ora.ai Journey and WebMCP audit (test it)
L4 PAY
Can it pay you?
Cloudflare Pay per crawl (private beta, for crawlers); ora.ai Scan payments layer (checks it)
L5 TRUST
Can you tell which agent it is, and on whose behalf it acts?
Cloudflare (verifies signed bots); Vercel (verifies signed bots); Forter (links agentic shoppers to verified customer identities)
| Layer | Question | Standards | Tools that document support |
|---|---|---|---|
| L1 DISCOVER | Can an agent find you, and is it allowed in? | robots.txt (RFC 9309); Sitemaps; llms.txt; A2A Agent Card | Cloudflare AI Crawl Control (controls crawler access); ora.ai Scan (checks it); Cloudflare Is It Agent Ready (checks it) |
| L2 READ | Can it read and understand what you offer? | llms.txt; Markdown negotiation (Accept: text/markdown); JSON-LD | Cloudflare Markdown for Agents (serves markdown); ora.ai Scan (checks it) |
| L3 ACT | Can it complete a task on your site or API? | MCP; WebMCP; agents.json; OpenAPI | Cloudflare (hosts MCP servers); Vercel (hosts MCP servers); nekuda (builds WebMCP tools); ora.ai Journey and WebMCP audit (test it) |
| L4 PAY | Can it pay you? | x402; ACP; UCP; MPP | Cloudflare Pay per crawl (private beta, for crawlers); ora.ai Scan payments layer (checks it) |
| L5 TRUST | Can you tell which agent it is, and on whose behalf it acts? | Web Bot Auth; OAuth 2.0 | Cloudflare (verifies signed bots); Vercel (verifies signed bots); Forter (links agentic shoppers to verified customer identities) |
Text version of the diagram
| Layer | Question | Standards | Tools that document support |
|---|---|---|---|
| L1 DISCOVER | Can an agent find you, and is it allowed in? | robots.txt (RFC 9309); Sitemaps; llms.txt; A2A Agent Card | Cloudflare AI Crawl Control (controls crawler access); ora.ai Scan (checks it); Cloudflare Is It Agent Ready (checks it) |
| L2 READ | Can it read and understand what you offer? | llms.txt; Markdown negotiation (Accept: text/markdown); JSON-LD | Cloudflare Markdown for Agents (serves markdown); ora.ai Scan (checks it) |
| L3 ACT | Can it complete a task on your site or API? | MCP; WebMCP; agents.json; OpenAPI | Cloudflare (hosts MCP servers); Vercel (hosts MCP servers); nekuda (builds WebMCP tools); ora.ai Journey and WebMCP audit (test it) |
| L4 PAY | Can it pay you? | x402; ACP; UCP; MPP | Cloudflare Pay per crawl (private beta, for crawlers); ora.ai Scan payments layer (checks it) |
| L5 TRUST | Can you tell which agent it is, and on whose behalf it acts? | Web Bot Auth; OAuth 2.0 | Cloudflare (verifies signed bots); Vercel (verifies signed bots); Forter (links agentic shoppers to verified customer identities) |
Frequently asked questions
What is the difference between A2A and MCP?
MCP connects an agent to tools and data. A2A connects an agent to other agents. They are complementary.
Who maintains A2A?
The Linux Foundation, through a Technical Steering Committee. Google originally developed the protocol.
Source: a2a-protocol.org · A2A specification · Reviewed Sep 2026