A2A Gateway API
Use the A2A Gateway API when one agent needs to delegate work to a registered peer under workspace policy, approval, loop, identity, and audit controls.
Not included in DVARA Open Source.
Choose an operation
| Endpoint | Purpose |
|---|---|
GET /a2a/{agentId}/.well-known/agent-card.json | Read the governed Agent Card |
POST /a2a/{agentId}/message:send | Send a message and wait for the result |
POST /a2a/{agentId}/message:stream | Send a message and stream task updates |
POST /a2a/{agentId}/tasks:get | Read one task |
POST /a2a/{agentId}/tasks:list | List tasks |
POST /a2a/{agentId}/tasks:cancel | Cancel a task |
POST /a2a/{agentId}/tasks:resubscribe | Resume task event streaming |
POST /a2a/{agentId}/pushConfig:set | Create or replace push configuration |
POST /a2a/{agentId}/pushConfig:get | Read push configuration |
POST /a2a/{agentId}/pushConfig:list | List push configurations |
POST /a2a/{agentId}/pushConfig:delete | Remove push configuration |
Every request uses the target's registered agentId. DVARA resolves the
workspace from the bearer API key before it looks up the target.
Send a governed message
Replace the host, target agent ID, and workspace API key:
curl --silent https://<dvara-host>/a2a/<agent-id>/message:send \
--header 'Authorization: Bearer <your-api-key>' \
--header 'Content-Type: application/json' \
--data '{
"jsonrpc": "2.0",
"id": "hop-1042",
"method": "message/send",
"params": {
"metadata": {"skill": "summarize"},
"message": {
"role": "user",
"parts": [
{"kind": "text", "text": "Summarize claim CLM-1042 for review."}
]
}
}
}'
A completed peer call returns an A2A message or task inside the JSON-RPC envelope:
{
"jsonrpc": "2.0",
"id": "hop-1042",
"result": {
"task": {
"id": "task-7f12"
}
}
}
If policy denies the hop, DVARA returns 403 and does not call the peer.
Open Agents → A2A Hops to inspect the source, target, decision, status, and latency. The same hop writes intent and result or denial evidence to Governance → Audit, joined by its trace information.
Diagnose a failed call
A missing, expired, or revoked workspace key returns 401. A key without the
required A2A scope returns 403. A target outside the caller's workspace is
not exposed. Peer discovery, signature, credential, policy, approval, and loop
failures use distinct error codes so you can separate configuration failures
from governed denials.
For delegation chains, approval behavior, streaming, push callbacks, and Agent Card trust, continue with Govern agent-to-agent calls with the A2A Gateway.