# The Agent Card: Discovery — MCP & Agent-to-Agent Protocols

Source: https://www.geekswithgeeks.com/en/mcp-a2a/a-card

> Describe an agent's identity, skills, endpoint and security needs.

## A business card for an agent

An **Agent Card** is a JSON document in which a remote agent describes itself: **name and description**, **version**, the **URL/endpoint** where it accepts requests, supported **capabilities** (such as streaming and push notifications), accepted **input and output modes**, the **skills** it offers (each with an id, name and description, sometimes examples) and the **authentication schemes** a client must use. It is typically published at a **well-known URL** on the agent's domain (the exact path has varied by spec version, so check the current one) so clients can fetch and read it. Client agents, or the humans who configure them, use cards to decide **whether and how** to delegate. Treat card contents as **untrusted input**: descriptions are text a model may read, and an unverified card can lie about its skills.

## An example Agent Card, checked

I ran this with plain Python 3 (standard library only). This card is an illustrative sample whose field names follow the general shape of A2A cards; the exact schema depends on the spec version. The script checks that required fields are present and reads the skills and authentication.

```python
import json

card = {
    "name": "Refund Agent",
    "description": "Looks up invoices and proposes refunds. Cannot issue payments.",
    "url": "https://agents.example.com/refunds",
    "version": "1.2.0",
    "capabilities": {"streaming": True},
    "skills": [{"id": "propose-refund", "name": "Propose refund",
                "description": "Check an invoice and propose a refund amount."}],
    "authentication": {"schemes": ["bearer"]},
}
REQUIRED = ["name", "description", "url", "version", "skills"]
missing = [k for k in REQUIRED if k not in card]
print("missing fields:", missing)
print("skills:", [s["id"] for s in card["skills"]])
print("needs auth:", bool(card["authentication"]["schemes"]))
print(json.dumps(card)[:80] + "...")

```

Output:

```
missing fields: []
skills: ['propose-refund']
needs auth: True
{"name": "Refund Agent", "description": "Looks up invoices and proposes refunds....
```

**Quiz:** Why treat an Agent Card as untrusted?

- [ ] It cannot contain text
- [ ] It is always encrypted
- [ ] It is signed by the model
- [x] It can misstate skills and contains text a model may read

*Answer:* It can misstate skills and contains text a model may read. Verify the publisher and sanitise card text like any external input.
