A2A 1.0 is out: signed Agent Cards and a path from version 0.3
The Agent2Agent protocol has reached version 1.0, with signed Agent Cards, multi-tenancy and three protocol bindings. What changes for teams already on version 0.3.
On 12 March, the Agent2Agent protocol (A2A) reached version 1.0. A2A is the open protocol that lets AI agents from different vendors find each other and hand over tasks. Version 1.0 is the first release the project calls production-ready, and it contains changes that matter for anyone who connects agents across platforms.
What is new
- Signed Agent Cards. An Agent Card describes what an agent can do and how to reach it. In 1.0 the card can be signed cryptographically, so the receiver can check that it really comes from the agent it claims to be, and that the content has not been changed. This is the most important security change in the release.
- Multi-tenancy. One endpoint can host several agents safely. That makes it easier for a platform to offer agents to many customers or departments from the same installation.
- Three protocol bindings. A2A 1.0 standardises on JSON over HTTP, gRPC and JSON-RPC. Clients can use polling, streaming or webhooks, depending on what fits the task.
- Version negotiation. Client and agent can agree on which version to use, so one side does not have to upgrade at the same moment as the other.
- SDKs in six languages: Python, Go, Java, JavaScript, .NET and Rust.
The project is run under the Linux Foundation with an Apache 2.0 licence. Its technical steering committee has members from AWS, Cisco, Google, IBM Research, Microsoft, Salesforce, SAP and ServiceNow.
Breaking changes, but a soft transition
The interaction protocol itself has changes that break compatibility with version 0.3. The Agent Card, on the other hand, has been extended in a backward-compatible way, and an agent can announce that it supports both 0.3 and 1.0 at the same time. That means you can migrate gradually, agent by agent, instead of switching everything over in one go.
What it means for integration teams
A stable 1.0 version is the signal many have been waiting for before building on A2A in production. At the same time, the release shows that agent-to-agent traffic needs the same things as other integration: identity, versions, security and monitoring.
Some practical points:
- Take inventory. Find out which agents and platforms in your company already speak A2A, and which version they use.
- Require signed Agent Cards. Once the platforms support it, agents from outside your own organisation should not be trusted without a verified signature.
- Plan the migration. Use the option to run 0.3 and 1.0 in parallel, and set a date for when 0.3 is switched off.
- Put a gateway in front. Traffic between agents should go through a point where you can log, limit and stop it, just like API traffic.
- Ask your iPaaS vendor when it supports A2A 1.0, and whether the platform can act as both client and agent.
Sources
This post was written with AI assistance and reviewed by the editor before publishing.