3.2 The agent-to-agent protocol

Book 3 · The Orchestrated OrganizationChapter 3 · section 2 of 6

There is an agent-to-agent protocol, and it is useful to know its actual shape, because its gaps are the point. A2A, originally from Google and now governed by the Linux Foundation, lets one agent discover another through an advertised capability card and delegate tasks to it over ordinary web standards — JSON-RPC over HTTPS — even when the two agents share no memory, no tools, and no vendor. As of this writing it has reached version 1.0 and defines transport authentication, signed Agent Cards, and in-task authorization states. Deployments can apply authorization policies around those exchanges, including skill-specific rules. What the core protocol does not standardize is a portable delegation object that says which principal authorized this task, which subset of authority may flow downstream, what budget and duration apply, how that authority can be revoked, and which evidence must return with the result — the specification explicitly leaves the scope, validity, and revocation semantics of authorization decisions to implementations and extensions, and task-bound delegated authorization sits in the project’s issue tracker as an open question.7 Two independent systems do not inherit the same task-bound authority semantics merely because they both speak A2A.

Read that open issue rather than only citing it, because it shows the missing object being worked out in public. It was filed in June 2026 by a contributor, not a maintainer, and it asks a narrow question: should A2A define an optional profile that binds a delegation to a specific acting agent, task, target, scope, and validity window, so that a grant issued for one task cannot be replayed into another? The commenters — practitioners, not the project’s owners — converged on a minimum tuple: caller, delegate, task or session scope, allowed skills or tools, validity window, and the state the delegation was based on, with the rule that the delegate can accept or refuse the tuple and can never widen it. As of this writing the issue is open, has five comments, and has no response from the maintainers; an older issue asking A2A to account for the confused-deputy problem has been open since April 2025, assigned and unresolved.8

The identity standards bodies are further along. Chapter 7 pointed at RFC 8693, OAuth 2.0 Token Exchange, whose act claim already lets a token carry a nested chain of who acted on whose behalf. In June 2026 the IETF’s OAuth working group approved a charter with a work item it calls complex delegation: “authorization of automated agents working on behalf of users, including addressing scenarios where automated agents act across multiple administrative domains.” That last clause is the cross-system case exactly. The individual drafts arriving under it are not yet working-group documents, and Internet-Drafts expire after six months, so nothing here should be built to; but they agree on a property worth designing for now. An attenuated-delegation profile submitted in September 2026 carries a chain of delegation links in which every link may only narrow the scope, tighten the conditions, or shorten the expiry of its parent, and a verifier must check every link rather than trusting the last hop; other drafts — one already expired, one revised in August — propose claims for task context, delegation chain, and human oversight, or a grant profile that attenuates authority through token exchange and pushes budgets, audit stores, and policy engines outside the interoperable core.9 Monotonic narrowing, whole-chain verification, an expiry on every link: the same tuple the A2A commenters reached independently, which is some evidence that the shape is real and not one community’s taste.

Governance has consolidated, and an orchestrator should know where. In December 2025 the Linux Foundation formed the Agentic AI Foundation, with Anthropic donating the Model Context Protocol, Block donating goose, and OpenAI donating AGENTS.md; A2A already lived under the Linux Foundation.10 A separate Linux Foundation project, AGNTCY, is building the discovery, identity, and messaging layer that lets agents from different vendors find and verify each other.11 None of this solves the problem. It names the fora — the AAIF for agent protocols, the IETF for delegation tokens, FIDO for payment mandates — so that when the delegation object arrives it will arrive from one of them, in a shape you can already see. A system that records the tuple today will have something to hand the protocol. A system that records a task ID and a bearer token will not.


  1. Agent2Agent protocol, https://a2a-protocol.org/latest/specification/ (v1.0.0, verified September 9, 2026). The specification defines authentication, Agent Card security schemes, signed cards, cancellation, and an authorization-required task state. It leaves the scope, validity, and revocation of authorization to implementations, and payload identity is established at the transport layer; enterprise guidance, https://a2a-protocol.org/latest/topics/enterprise-ready/. Task-bound delegation remains an open issue: https://github.com/a2aproject/A2A/issues/1937.↩︎

  2. a2aproject/A2A issue #1937, “[Feat]: Optional context-binding profile for delegated authority,” opened June 15, 2026, https://github.com/a2aproject/A2A/issues/1937 — “the goal is to define what needs to be bound and verified, not a new token format”; five comments, June 16 to August 14, 2026, including “the delegate cannot widen the tuple; it can only accept or refuse it”. Issue and comments are from contributors without a maintainer role (GitHub author_association: NONE); no maintainer response as of September 9, 2026, when the issue was retrieved via the GitHub API. Issue #153, “A2A should account for the confused deputy problem,” opened April 14, 2025, https://github.com/a2aproject/A2A/issues/153 — open, assigned, last updated June 9, 2025. Issue discussions are not specification text.↩︎

  3. IETF Web Authorization Protocol working-group charter, June 4, 2026, https://datatracker.ietf.org/doc/charter-ietf-oauth/, work item “Complex Delegation”; A. Hassan, “An Attenuated Delegation Profile for Automated Agents,” September 2, 2026, https://datatracker.ietf.org/doc/draft-hamr-oauth-agent-delegation/; and S. Kumar, “OAuth Profile for Delegated AI Agent Authorization,” August 30, 2026, https://datatracker.ietf.org/doc/draft-mishra-oauth-agent-grants/. These are individual works in progress, not adopted standards.↩︎

  4. The Linux Foundation, “Linux Foundation Announces the Formation of the Agentic AI Foundation (AAIF),” press release, December 9, 2025, https://www.linuxfoundation.org/press/linux-foundation-announces-the-formation-of-the-agentic-ai-foundation — founding contributions from Anthropic (MCP), Block (goose), and OpenAI (AGENTS.md); platinum members include AWS, Anthropic, Block, Bloomberg, Cloudflare, Google, Microsoft, and OpenAI. Verified September 9, 2026. Adoption figures in the release are the foundation’s own.↩︎

  5. AGNTCY, https://agntcy.org/ — “an open-source stack enabling AI agents to collaborate across vendors and frameworks through discovery, identity, messaging, and observability”; the site identifies the project as “a Series of LF Projects, LLC,” the Linux Foundation’s project-hosting entity. Verified September 9, 2026. Cited for what the project says it is building; maturity and adoption are not established by the site.↩︎