Blog

The Agent2Agent (A2A) Protocol: Standardizing Multi-Agent Coordination and Hand-Offs

Connecting autonomous agents across frameworks requires an open wire format, but turning peer handoffs into working software still demands state that survives a crash.

Quick Answer

The Agent2Agent (A2A) Protocol is an open standard stewarded by the Linux Foundation's Agentic AI Foundation that governs how autonomous agents discover peers, negotiate capabilities, and delegate work across heterogeneous frameworks like LangChain, CrewAI, AutoGen, and custom runtimes. Created by Google in April 2025, and since joined by IBM's competing Agent Communication Protocol, A2A forms the horizontal coordination layer of modern AI architecture, complementing Model Context Protocol (MCP) for downward tool access and Agent Client Protocol (ACP) for upward user interfaces. The standard defines message schemas for task delegation, streaming lifecycle events over Server-Sent Events, typed artifact exchange, and delegated authorization scopes over standard web transports. Even with standard message passing, multi-agent squads fail if peer handoffs remain ephemeral: preventing duplicate work and hallucinated completion requires durable task storage, lease-based claiming, and human-anchored verification gates.

Origins: from framework silos to the Linux Foundation

In 2024 and 2025, multi-agent development hit an artificial ceiling created by framework fragmentation. An orchestrator built on CrewAI could not hand a subtask to a LangGraph coding specialist or an AutoGen research cluster without custom glue code. Every team wrote its own HTTP wrappers, agreed on ad-hoc JSON payloads, and re-implemented session tracking from scratch.

Google announced the Agent2Agent Protocol in April 2025 at Cloud Next, with more than 50 launch partners, and donated it to the Linux Foundation in June 2025. Separately, IBM's BeeAI project had built its own Agent Communication Protocol for agent messaging. In August 2025, rather than maintain two competing standards, IBM folded that work into A2A. That ACP is unrelated to the Agent Client Protocol discussed below, which happens to share the acronym.

In August 2026 A2A was accepted as a Growth Stage project at the Linux Foundation's Agentic AI Foundation (AAIF), alongside MCP and AGENTS.md. Neutral governance means cross-agent interoperability is not owned by a single model vendor or framework creator.

The problem A2A solves: horizontal interoperability

Single-runtime agent teams are easy to build because one orchestrator holds global state in memory. Real-world systems break when coordination crosses process boundaries, different tech stacks, or corporate firewalls. A team writing code in a Python framework frequently needs to invoke a specialized database agent maintained by another team in Go or TypeScript.

A2A provides the horizontal wire layer that lets independent agents collaborate without sharing an execution engine. It standardizes four operational primitives that previously required custom integration:

  • Agent discovery: publishing standardized manifests that describe an agent's skills, supported schemas, and operational boundaries.
  • Capability negotiation: verifying model context capacities, input schemas, and expected output formats before sending a payload.
  • Task delegation: dispatching structured task requests with explicit constraints, execution budgets, and dependencies.
  • Lifecycle tracking: monitoring progress through standardized task states: submitted, working, input-required, auth-required, completed, canceled, failed and rejected.

Wire protocol and message semantics

A2A is built on standard web transports, primarily HTTP/REST and JSON-RPC with Server-Sent Events (SSE) for streaming updates. Using established protocols ensures that agent communication passes through standard corporate proxies, load balancers, and security inspection layers without special networking hardware.

A delegation begins with a task request. The calling agent submits an intent payload containing prompt instructions, structured parameters, and deadline constraints. In response, the receiving agent validates the request and issues an execution handle. Real-time updates flow back over an SSE connection, providing token streams, tool invocation notifications, and intermediate thought summaries so the caller can detect stalls immediately.

Artifact exchange is handled by reference rather than raw context injection. Instead of stuffing megabytes of file diffs, test outputs, or database snapshots into conversation tokens, agents exchange typed artifact URIs. This separation keeps conversational context windows clean while preserving access to full binary and textual outputs.

Security is enforced through scoped authorization tokens. A2A messages carry delegated access claims, often using mutual TLS and scoped OAuth tokens. A delegating agent can grant access to a specific repository branch or database table without exposing its own master credentials to the receiving agent.

The protocol triad: MCP, ACP, and A2A

Understanding where A2A fits requires looking at the modern three-tier agent protocol stack. Each protocol handles one specific axis of communication, and confusing them leads to poor system design.

MCP handles the downward vertical axis. Built by Anthropic, Model Context Protocol connects an agent to passive tools, local files, and database connections. A tool answers queries; it does not make decisions or delegate work.

ACP handles the upward vertical axis. The Agent Client Protocol connects an agent to user-facing applications, desktop shells, and code editors. It governs how a human interacts with a primary assistant.

A2A handles the horizontal axis. It connects autonomous agents to other autonomous agents. Both parties possess reasoning loops and can accept, reject, or negotiate work as peers.

  • Vertical Down (MCP): agent to tools and resources. Passive execution, no autonomy on the server side.
  • Vertical Up (ACP): agent to client and editor. Interactive control, human-in-the-loop oversight.
  • Horizontal (A2A): agent to agent. Autonomous peer delegation, capability exchange, and cross-framework handoffs.

Multi-agent squad realities: why wire protocols are not enough

A clean wire protocol solves network interoperability, but it does not solve operational reliability. Coding agents run as subprocesses in terminals and cloud containers. They run out of memory, hit model rate limits, encounter network timeouts, and crash without sending a disconnect signal.

Treating peer handoffs as ephemeral RPC calls causes immediate failures in production squads. If an agent delegates a subtask over an A2A stream and either process dies mid-execution, the reasoning, progress notes, and partial work vanish. Without durable state outside the connection, the delegating agent hangs or restarts from scratch.

The second failure is the abandoned lock. When an agent accepts an assignment and silently hangs on a stalled command, a naive system leaves that task locked forever. Solving this requires lease-based claiming. A task claim must be a temporary lease that expires automatically unless renewed by an active heartbeat. When an agent crashes, its lease lapses and the task returns to the pool with its log and blockers intact.

The most dangerous failure is hallucinated completion. Large language models possess a strong bias toward declaring success. An agent asked to implement a feature will often assert that all requirements were met even when tests failed or build steps were skipped. If peer agents can mark work completed and close tickets unilaterally, hallucinated successes propagate unchecked through the dependency graph.

This is why robust multi-agent systems anchor verification authority in humans. In Forkbench, every agent starts at a contributor tier with the ability to report completion, but never the authority to accept it. Verification authority cannot be granted by any agent tool call; it requires an explicit human action. An agent can do the work, but it cannot grade its own homework.

Related: The client layer: Agent Client Protocol (ACP) for editors, The tool layer: Model Context Protocol (MCP) for tools, Tracing distributed agent handoffs with OpenTelemetry, Surviving crashed agents: lease claiming and task boards, Sealed credentials and authorization boundaries in Forkbench

Frequently asked

Keep reading

Sources