Connect a generic A2A agent¶
For a team with an agent that speaks A2A but does not run on kagent: at the end, Agent Kourier sends a Binding's turns
to that agent through the generic a2a dialect.
Before you start¶
The agent must:
- serve an A2A 1.0 or 0.3 agent card whose capabilities advertise streaming. Agent Kourier rejects an agent whose card does not;
- offer a JSON-RPC interface. A card that lists only gRPC or REST is refused;
- serve its card at the endpoint URL plus
/.well-known/agent-card.json, with a trailing slash on the URL trimmed.
Declare the backend¶
config:
agentBackends:
my-agent:
spec:
dialect: a2a
url: https://my-agent.example.internal/a2a/ # (1)!
headers: # (2)!
- name: X-Tenant
value: payments
allowedNamespaces: [payments]
- The exact JSON-RPC endpoint, used as written. Keep a trailing slash if the agent's route has one: Agent Kourier follows no redirects, because a redirect could carry the Binding's token to another host.
- Optional static headers, sent on every request. A value can come from a Secret with
valueSecretRef. Headers that carry or select identity are refused:Authorization,Proxy-Authorization,Cookie,X-User-Id,X-Agent-Name,X-Share-TokenandX-Kagent-Insecure-Runtime-Identity.
Choose how the Binding identifies itself¶
In the Binding's identity:
tokenSecretRefsends the Secret's value asAuthorization: Bearer. Something must verify it: the agent itself, or a proxy in front of it. If the Secret cannot be read, the turn fails; it never falls back touserId.userIdalone is sent asX-User-Id, for an agent that trusts its network.
What works on this dialect¶
- Chat and alert investigations, with streamed answers.
- An agent's question, when it pauses with
input-requiredand text, if the Binding setsinteractions.askUser: true. A single question with no choices also takes a typed reply in the thread. - Not: structured choices, tool approvals, or tool calls as step cards. Those come from kagent's extension, which only
the
kagent-v1dialect speaks. - An A2A 0.3 agent has no task list, so after a restart a turn may be sent, and run, twice.
Check it¶
Mention the bot in a bound channel and watch the pod log for session turn started and session turn ended. A card
problem shows in session turn failed; see Troubleshoot an install.