Agents delegating work to other agents create new trust relationships. A2A relies on standard web security, applied carefully.
Authentication
Agent Cards declare which authentication schemes an agent accepts, such as API keys, OAuth 2.0 or OpenID Connect. Credentials are obtained outside the protocol and sent with HTTP requests.
Transport Security
Use HTTPS for all production traffic.
Authorisation
The remote agent decides what each client is allowed to do, based on identity and scopes. Consider which user a request is on behalf of, and apply that user's permissions.
Risks
- Malicious or compromised agents returning manipulative content that hijacks the client agent.
- Over-sharing: sending sensitive data to agents that don't need it.
- Impersonation: fake agents claiming to be trusted services.
- Webhook abuse: push notification URLs pointed at internal systems.
Defences
- Allow-list trusted agents.
- Treat all remote output as untrusted data.
- Minimise data shared per task.
- Log delegations and results for audit.
- Require human approval before acting on high-stakes results.