---
title: "Agent Card"
description: "The JSON document an A2A agent publishes, usually at /.well-known/agent-card.json, describing its identity, skills, service endpoint and the authentication schemes it accepts."
canonical: https://aigovernanceengineer.com/glossary/agent-card
author: "Jorge García Aibar"
license: "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)"
doi: https://doi.org/10.5281/zenodo.22956197
version: "0.5.0"
updated: 2026-09-25
---

# Agent Card

The JSON document an A2A agent publishes, usually at /.well-known/agent-card.json, describing its identity, skills, service endpoint and the authentication schemes it accepts. It can be signed with JWS over a canonicalised form, so a client can check that the card is untampered and comes from the claimed provider [1]. A peer allow-list admits only registered agents with verified cards.

- Developed in: [ch. 23, Multi-agent systems and delegation chains](https://aigovernanceengineer.com/bok/governing-agents#multi-agent-systems-and-delegation-chains)
- Chapters: [ch. 23, AI Agents](https://aigovernanceengineer.com/bok/governing-agents)
- In the glossary chapter: https://aigovernanceengineer.com/bok/glossary#t-agent-card

## Sources

[1] Agent2Agent (A2A) Protocol Specification, v1.0 (v1.0.0 released 2026-03-12 and v1.0.1 on 2026-05-28 in github.com/a2aproject/A2A; Agent Card at /.well-known/agent-card.json, signed with JWS over JCS-canonicalised JSON; servers authenticate every request; authorisation implementation-specific; scope and revocation of in-task authorisation not defined). A2A Project (Linux Foundation). 2026-05-28. https://a2a-protocol.org/latest/specification/ (verified: primary)
