Docs: cover the A2A HTTP and JSON-RPC transport for kagent 1.x
维护者通常 1 天内回复
还没有人认领这个 Issue。
评估
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 新手友好度
- 45/100
- Issue 类型
- 文档
- 描述清晰度
- 基本清楚
- 活跃度
- 活跃
- 技术栈
- grpc
- 领域
- api, documentation
调研方向
Read docs/architecture/a2a-transports.md and substrate-runtime/identity.md, then run examples/a2a-agents.md as written. Fetch an Agent Card, exercise JSON-RPC streaming and share-token permissions, and verify ingress behavior against a live instance. Done means the guide documents both transports, routing and naming changes, ingress requirements, and a resolved exposure policy.
由索引模型根据 Issue 内容生成。
描述
[!IMPORTANT]
Rewritten for 1.0.0-alpha5 on 2026-09-29. This issue was filed against alpha4 and described a per-AgentInstance endpoint. alpha5 changed the URL shape, the resource it addresses, and the gRPC routing field. The original scoping is superseded; what follows is verified against thev1.0.0-alpha5tag. Part of #549.
examples/a2a-agents.md uses grpcurl throughout and documents no HTTP path. kagent serves A2A over HTTP/JSON-RPC alongside gRPC, with a discoverable Agent Card, and a reader who wants an ordinary HTTP client has nothing to follow.
Upstream's docs/architecture/a2a-transports.md is the endpoint contract and the right source. It is an architecture document rather than a task guide.
The endpoint surface
Both transports are served on the controller's API listener, port 8083 by default, and share the same Session authorization, durable tasks, history, and runtime lifecycle.
| Operation | Path |
|---|---|
| Read the Agent Card | GET /agents/{namespace}/{name}/.well-known/agent-card.json |
| Call JSON-RPC, including streaming | POST /agents/{namespace}/{name} |
The URL addresses an Agent, not an AgentInstance. This is the alpha5 change: alpha4 served /agents/{instance-id}, and the resource that a conversation belongs to is now a Session.
- HTTP requests need no
tenant. gRPC requests use the standard A2Atenantfield asnamespace/name, advertised only on the card's gRPC interface. An HTTP request that does supply a tenant must have it match the URL. Session.idis the messagecontextId. Omitting both context and task IDs creates a new conversation; retrying that first message with the same message ID reuses it. A task-only request resolves the conversation from the globally unique task ID.- There is no deployment-wide Agent Card, because the gateway serves many agents.
JSON-RPC uses the pinned upstream A2A v1 SDK: SendMessage, SendStreamingMessage, GetTask, ListTasks, CancelTask, SubscribeToTask, and GetExtendedAgentCard. Those are the v1 names for what older clients called message/send, message/stream, tasks/get, tasks/list, tasks/cancel, and tasks/resubscribe, which is worth stating for anyone arriving with a pre-v1 client.
Behavior the API does not announce
controller.a2aGatewayUrlchanged meaning in alpha4 and still holds. It was the public gRPC URL advertised by Agent Cards; it is now the gateway base URL for both transports, and HTTP interfaces append the agent path to it, preserving any deployment prefix. Its default is the controller's cluster Service URL.- An ingress with a prefix must strip it before forwarding to the core listener, and must forward streaming responses without buffering. Neither is enforced by a chart value.
- The card advertises JSON-RPC first, then gRPC. It comes from the Agent's latest successful revision, or from a shared session's pinned revision, and retains runtime extensions while reporting the gateway's streaming capabilities.
- Share tokens grade by permission. A validated
X-Share-Tokensupplements the authenticated user's access to its session: a read-only share permits card and task reads and subscriptions, and a read-write share also permits messages and cancellation. Cards are not publicly cached.
The conflict to resolve before writing
substrate-runtime/identity.md warns against exposing port 8083 outside the cluster, because the open source build's authenticator admits every request. The HTTP transport is served on that same listener, and the architecture document describes setting a2aGatewayUrl and putting an ingress in front precisely so agents can be reached from outside.
alpha5 changes this picture and it must be re-checked before writing. kagent#2971 restored controller.auth.mode and controller.auth.userIdClaim, so the permissive posture is no longer the only option. Establish what the authenticated configuration actually allows, then say which argument won. This is the main open question in this issue.
What to check before starting
- Read
docs/architecture/a2a-transports.mdat the release being documented. - Run the existing
examples/a2a-agents.mdguide as written, so the gRPC path is known to work before an HTTP path joins it. Note that the page is written around AgentInstance and needs the Session rename from #549 regardless. - Fetch a card over HTTP and confirm the interface ordering and retained extensions.
- Exercise streaming over JSON-RPC, and confirm what a client sees when an ingress buffers.
- Confirm the share-token grading through both transports rather than inferring it.
Done when
- Both endpoint paths are documented in their alpha5 form, with a working
curlexample for the card and for a JSON-RPC call. - The page states that the URL addresses an Agent, and that
Session.idis thecontextId. - The v1 method names are listed against their pre-v1 equivalents.
- The
a2aGatewayUrlmeaning is covered wherever that value is documented. - The ingress requirements, prefix stripping and unbuffered streaming, are stated.
- The exposure question against
identity.mdis resolved against alpha5 authentication rather than left for the reader. - Every command was run against a live Agent.
- 主要语言
- TypeScript
- 星标
- 20
- 派生
- 66
- 平均合并
- 1 天 3 小时
- 30 天内合并 PR
- 52
环境准备
这个项目没有提供开发容器、Dockerfile 或贡献指南,环境需要你自己搭建:先看它的 README,通用步骤见我们的新手贡献指南。
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
kagent-dev/website 的其他 Issue
-
Hold until GA: repoint kagent.dev navigation from 0.x to 1.x可能已有人在做 @Rachael-Graham 于 9 天前认领。 未关闭
难度 2/5 1-3 小时 新手友好度 75/100
kagent-dev/website#521 · 已指派 1 人 ·
维护者通常 1 天内回复
-
documentation kagent
难度 4/5 3-5 天 新手友好度 60/100
kagent-dev/website#562 ·
维护者通常 1 天内回复
-
help wanted
难度 3/5 1-2 天 新手友好度 72/100
kagent-dev/website#539 ·
维护者通常 1 天内回复
-
Docs: cover microvm sandbox support for kagent 1.x可能已有人在做 @boxcee-interview 于 1 天前认领。 未关闭help wanted
难度 4/5 3-5 天 新手友好度 45/100
kagent-dev/website#537 ·
维护者通常 1 天内回复
-
Docs: add Codex and Claude Harness examples, and a codex runtime-image conref可能已有人在做 @chinmaychahar 于 2 天前认领。 未关闭help wanted
难度 3/5 1-2 天 新手友好度 65/100
kagent-dev/website#530 · 7 条评论 · 已指派 1 人 ·
维护者通常 1 天内回复
查看 kagent-dev/website 的全部 Issue
相似的 Issue
-
Mondriaan
难度 1/5 1 小时以内 新手友好度 88/100
knaw-huc/textannoviz#709 ·
维护者通常 1 天内回复
-
streams:add
难度 1/5 1 小时以内 新手友好度 62/100
维护者通常 1 天内回复
-
About page content is also published as an unstyled duplicate at /about/about/可能已有人在做 关联的 PR 仍在进行中或已合并。 未关闭
难度 2/5 1-3 小时 新手友好度 78/100
walletbeat/walletbeat#1558 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 82/100
hawk-digital-environments/HAWKI#438 ·
维护者通常 1 天内回复
-
good first issue
难度 2/5 1-3 小时 新手友好度 78/100
OktoLabsAI/okto-pulse#114 ·
维护者通常 1 天内回复