Skip to content

feat(a2a): read agent credentials from a file or a command - #1550

Merged
edenreich merged 1 commit into
mainfrom
feat/a2a-token-file-command
Oct 6, 2026
Merged

edenreich merged 1 commit into
mainfrom
feat/a2a-token-file-command

Conversation

@edenreich

@edenreich edenreich commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Two new credential sources in the auth block of agents.yaml, next to token_env and oidc, plus an optional scopes list on oidc, and three examples that put an agent behind Google, Microsoft Entra ID and Amazon Cognito.

auth:
  token_file: /var/run/secrets/kubernetes.io/serviceaccount/token
auth:
  token_command: [gcloud, auth, print-identity-token, --audiences=https://billing.example.com]
  • token_file is re-read on every request, so a token rotated in place by the kubelet, spiffe-helper or Vault Agent is picked up. It is the shape a workload gets from its platform, with no provisioned secret. This is also how kagent carries its workload credential.
  • token_command runs a cloud CLI or a broker without a shell and reuses its stdout until the token expires (the exp claim when it is a JWT, five minutes otherwise). It is honoured from ~/.infer/agents.yaml only: a project file arrives with a clone and the agent card fetch runs without approval. A failing command is reported by name and exit status, never by its output.
  • oidc.scopes is requested on top of the card's scopes. Entra requires api://<app>/.default on client credentials and the ADK card declares none.

Why

The existing OIDC handling is spec-correct and ahead of the official A2A SDKs, which only attach a pre-acquired token. What it lacked is a way to use the token a platform or cloud already mints: Google issues ID tokens from the metadata server (no client-credentials grant), Azure managed identity and Entra Agent ID mint tokens by token exchange, Kubernetes and SPIRE hand workloads a token file. Both additions are a few lines in auth.go and add no dependency.

Examples

examples/a2a-auth-gcp, examples/a2a-auth-entraid and examples/a2a-auth-aws mirror the gateway repository's auth-gcp, auth-entra and auth-cognito examples: a mock agent trusts the provider as its issuer, get-token.sh fetches the provider's token, and a tokenless mock model drives the delegation. GCP and AWS use token_file, Entra runs the client-credentials grant from the oidc block.

Verification

  • task precommit:run passes, go test ./... passes.
  • examples/a2a-auth: all five scenarios pass with this build.
  • examples/a2a-auth-gcp wiring against a static-token mock agent with a hand-written .token: the task completes, a wrong token is reported as an authentication failure.
  • token_command from ~/.infer/agents.yaml authenticates infer agents status, the same block in a project .infer/agents.yaml is refused with token_command is only read from ~/.infer/agents.yaml.
  • The cloud examples themselves need the provider's account and were not run against a real issuer.

Docs

docs/agents-configuration.md, docs/a2a-connections.md and docs/examples.md are updated here.

Docs ticket: inference-gateway/docs#992

Follow-up, not in this PR: native auth.spiffe via the SPIFFE Workload API, and switching examples/a2a-gateway-auth from a pasted token to auth.oidc.

Two new credential sources in the auth block of agents.yaml, next to
token_env and oidc:

- token_file is re-read on every request, so a token rotated in place by
  the kubelet, spiffe-helper or Vault Agent is picked up. This is the shape
  a workload gets from its platform and needs no provisioned secret.
- token_command runs a cloud CLI or a broker and reuses its stdout until
  the token expires: the exp claim when it is a JWT, five minutes
  otherwise. It is honoured from ~/.infer/agents.yaml only, since a
  project file arrives with a clone and the agent card fetch runs without
  approval. A failed command is reported by name and exit status, never by
  its output.

oidc gains an optional scopes list, requested on top of the card's.
Microsoft Entra ID requires api://<app>/.default on client credentials and
the ADK card declares no scopes.

Three examples put a mock agent behind Google, Microsoft Entra ID and
Amazon Cognito, mirroring the gateway repository's auth-gcp, auth-entra
and auth-cognito examples: a2a-auth-gcp and a2a-auth-aws write the
provider's token to a file, a2a-auth-entraid runs the client-credentials
grant from the oidc block.
@edenreich
edenreich requested a review from a team as a code owner October 6, 2026 19:23
@edenreich
edenreich merged commit 4a32144 into main Oct 6, 2026
12 checks passed
@edenreich
edenreich deleted the feat/a2a-token-file-command branch October 6, 2026 19:47
@inference-gateway-releaser

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 0.227.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

1 participant