Skip to content

get_a2a_agent_card does not send auth headers when fetching the agent card #179

Description

@Diogo-Damasceno

Description

In rogue/run_cli.py, get_a2a_agent_card fetches the A2A AgentCard with:

response = requests.get(f"{agent_url}/.well-known/agent.json", timeout=5, headers=headers)

but headers is only populated from agent_auth_type.get_auth_header(...) in ping_agent, and for NO_AUTH it is None. For agents that require authentication to read /.well-known/agent.json, the card fetch sends no Authorization header and fails (or returns 401), so authenticated A2A agents cannot be pinged/validated at CLI startup.

Impact

  • A2A agents protected by API key / bearer auth can't be evaluated via the CLI even when credentials are provided, because the card GET is unauthenticated.

Suggestion

Pass the resolved headers through to get_a2a_agent_card for all transports (HTTP/STREAMABLE_HTTP/SSE) so authenticated agents return their card. This pairs with the #150 fix (Streamable HTTP/SSE support).

Related: #150 (transport support), #113 (startup ping).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions