Skip to content

Clarify in-task authorization scope in A2A spec #2080

Description

@muscariello

We should improve clarity in the A2A specification about what is in scope for authorization semantics during in-task authorization.

Proposed clarification:

  • TASK_STATE_AUTH_REQUIRED is a coordination signal, not an authorization grant by itself.
  • A2A does not define credential scope, validity, or revocation semantics in core protocol text.
  • Implementations must define how operation-level authorization is identified and verified before execution.

Goal: reduce ambiguity for implementers without expanding core protocol scope.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

Projects

Status
Done

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions