Lesson 25 / 31

Streaming, Push Notifications and Security in A2A

Handle long tasks and protect cross-organisation calls.

Long tasks and trust boundaries

For short work the client can wait for a response. For longer work A2A offers streaming (the client receives incremental status and artifact updates, typically over Server-Sent Events) and push notifications (the remote agent calls a webhook the client supplied when the task changes state, so the client need not keep a connection open). Messages travel over standard web transports such as JSON-RPC over HTTPS, and later spec versions also describe other bindings. Because calls cross organisational boundaries, use TLS, authenticate with the schemes the Agent Card declares (for example OAuth 2.0 bearer tokens or API keys), authorise per skill and per data type, validate webhook calls (signatures or tokens), rate-limit, and log every delegation. Treat remote-agent output like tool output: untrusted data that may contain injected instructions.

Share the minimum

Send a remote agent a redacted summary, not your whole customer record. It is outside your trust boundary.

Quick check: What is the purpose of push notifications in A2A?

  • Encrypt cards
  • Send ads to users
  • Notify the client of task updates without holding a connection open
  • Replace the task id
Answer

Notify the client of task updates without holding a connection open — A webhook callback suits tasks that take minutes or longer.