Description
In rogue/run_cli.py, get_a2a_agent_card fetches the A2A AgentCard with:
response = requests.get(f"{agent_url}/.well-known/agent.json", timeout=5, headers=headers)
but headers is only populated from agent_auth_type.get_auth_header(...) in ping_agent, and for NO_AUTH it is None. For agents that require authentication to read /.well-known/agent.json, the card fetch sends no Authorization header and fails (or returns 401), so authenticated A2A agents cannot be pinged/validated at CLI startup.
Impact
- A2A agents protected by API key / bearer auth can't be evaluated via the CLI even when credentials are provided, because the card GET is unauthenticated.
Suggestion
Pass the resolved headers through to get_a2a_agent_card for all transports (HTTP/STREAMABLE_HTTP/SSE) so authenticated agents return their card. This pairs with the #150 fix (Streamable HTTP/SSE support).
Related: #150 (transport support), #113 (startup ping).
Description
In
rogue/run_cli.py,get_a2a_agent_cardfetches the A2A AgentCard with:but
headersis only populated fromagent_auth_type.get_auth_header(...)inping_agent, and forNO_AUTHit isNone. For agents that require authentication to read/.well-known/agent.json, the card fetch sends no Authorization header and fails (or returns 401), so authenticated A2A agents cannot be pinged/validated at CLI startup.Impact
Suggestion
Pass the resolved
headersthrough toget_a2a_agent_cardfor all transports (HTTP/STREAMABLE_HTTP/SSE) so authenticated agents return their card. This pairs with the #150 fix (Streamable HTTP/SSE support).Related: #150 (transport support), #113 (startup ping).