A2A & Agent Networks
GaaS as the governance control plane for multi-agent systems — covering the A2A Protocol v1.0, Agent Trust Registry, and AP2 Agentic Payment Governance.
When AI agents talk to each other, delegate tasks, or execute financial transactions autonomously, governance becomes non-negotiable. GaaS is an A2A v1.0 agent: every message another agent sends it passes through the same 5-stage governance pipeline as a human-facing action. It is built on the official A2A SDK and tested on every change with the official A2A conformance suite (TCK) at the MUST level, over JSON-RPC — the binding its Agent Card declares.
Agent Card
GaaS publishes its Agent Card at the spec's well-known path, without authentication:
GET /.well-known/agent-card.json. (/.well-known/agent.json, the pre-v1.0 path,
redirects there.) version is GaaS's own version; the A2A protocol version is on each entry of
supportedInterfaces.
{
"name": "GaaS Governance Agent",
"version": "0.2.17",
"supportedInterfaces": [
{
"url": "https://api.gaas.is/a2a/v1",
"protocolBinding": "JSONRPC",
"protocolVersion": "1.0"
}
],
"capabilities": {
"streaming": true,
"pushNotifications": false,
"extendedAgentCard": false
},
"securitySchemes": {
"apiKey": {
"apiKeySecurityScheme": {
"description": "Your GaaS API key (the same key as the rest of the API).",
"location": "header",
"name": "X-API-Key"
}
}
},
"securityRequirements": [
{
"schemes": {
"apiKey": {}
}
}
],
"skills": [
{
"id": "governance-check",
"name": "Governance Check",
"tags": [
"governance",
"compliance",
"risk",
"audit",
"policy"
]
},
{
"id": "risk-assessment",
"name": "Risk Assessment",
"tags": [
"risk",
"scoring",
"assessment",
"dimensions"
]
},
…
]
}
Abridged: the live card also carries a description, provider, documentation link, input and output modes, and all 8 skills.
A2A Gateway
The A2A endpoint is JSON-RPC 2.0 at POST /a2a/v1. Every request must carry
A2A-Version: 1.0; a request without it (which the spec reads as 0.3) or with another version gets
error -32009 (VersionNotSupportedError). Authenticate with your GaaS API key in
X-API-Key.
Methods
| Method | What it does |
|---|---|
SendMessage | Govern an action; returns the task with the decision |
SendStreamingMessage | The same, as server-sent events |
GetTask | One of your tasks |
ListTasks | Your tasks, newest first, paged (pageSize, pageToken) |
CancelTask | Cancel one of your tasks that has not finished |
SubscribeToTask | Stream a running task's updates |
| Push notification methods | Not available: -32003 (see below) |
GetExtendedAgentCard | Not offered: -32004; the public card is complete |
Tasks belong to the organization whose key created them. Another organization's task id gets
-32001 (TaskNotFoundError), the same as an id that does not exist.
Example: govern an action
POST /a2a/v1
X-API-Key: gsk_...
A2A-Version: 1.0
Content-Type: application/json
{
"jsonrpc": "2.0",
"id": 1,
"method": "SendMessage",
"params": {
"message": {
"messageId": "msg-0001",
"role": "ROLE_USER",
"parts": [{"text": "Send the quarterly revenue report to the external auditor by email"}]
}
}
}
The result is a task. Its governance-decision artifact holds GaaS's decision as a
data part (verdict, risk_score, reasoning,
audit_id, blocking_policies, …), the status message carries the reasoning, and
the task metadata carries gaas_audit_id, gaas_intent_id and gaas_verdict.
To pick a skill, put "skill": "<id>" in the message metadata or in a data part. Set
"gaas.pipelineMode": "shadow" in the message metadata to evaluate without enforcing.
Decisions as task states
| GaaS verdict | Task state |
|---|---|
| approve, approve with modifications | TASK_STATE_COMPLETED |
| block | TASK_STATE_REJECTED |
| escalate (a person must decide) | TASK_STATE_INPUT_REQUIRED |
| evaluation error | TASK_STATE_FAILED |
An escalated action becomes a review item in your dashboard, and GaaS emails your organization. The task's
metadata carries gaas_escalation_id. Send another message on the same task (with its
taskId and contextId) to get the outcome: approved or modified →
COMPLETED, denied → REJECTED, timed out → per your timeout rule, still waiting
→ INPUT_REQUIRED again.
Agent Trust Registry
The Agent Trust Registry is GaaS's decentralized reputation system for autonomous agents. Every agent that interacts with the platform accumulates a trust score based on governance outcomes, policy violations, and human review results.
Register a new agent in the trust registry
Retrieve an agent's profile, trust score, and interaction history
List all governance decisions for a specific agent
Re-fetch the agent card from its URL and recompute trust score
Suspend an agent with a reason (blocks further governance participation)
Restore a suspended agent to active status
Overview of all registered agents with current trust scores
Trust Score
Trust scores range from 0.0 (untrusted) to 1.0 (fully trusted).
New agents start at 0.5 and build reputation through approved actions and positive human review outcomes.
Violations, blocks, and escalations reduce the score.
| Score Range | Trust Level | Effect |
|---|---|---|
| 0.85 – 1.0 | High | Fast-path approval for low-risk actions |
| 0.65 – 0.84 | Standard | Normal governance pipeline |
| 0.40 – 0.64 | Elevated scrutiny | Additional deliberation rounds required |
| 0.0 – 0.39 | Low / Suspended | All actions require human review or are blocked |
A2A Authentication
POST /a2a/v1 accepts:
- GaaS API Key: the standard
X-API-Keyheader — the same key as the rest of the API. This is what the hosted service accepts. - Bearer JWT: an
Authorization: Bearertoken signed with the deployment's A2A secret (GAAS_A2A_JWT_SECRET), carryingorg_idand optionallyagent_id. Only when that secret is configured; the hosted service does not configure it today.
The Agent Card lists exactly the schemes the deployment accepts. OAuth 2.0 client credentials and mutual TLS are not supported.
Governance Proxy
Send an A2A message to POST /a2a/proxy/messages with the target_agent_url it is meant for.
GaaS runs it through the five-stage governance pipeline and returns the result as an A2A task.
Forwarding approved messages to the target agent is built, not yet switched on: today your
orchestrator forwards an approved message itself, and does not forward a blocked or escalated one.
POST /a2a/proxy/messages/shadow runs the same evaluation in shadow mode.
POST /a2a/proxy/messages
X-API-Key: gsk_...
Content-Type: application/json
{
"role": "user",
"parts": [
{"type": "text", "text": "Ship order 1042 to the customer's address on file"}
],
"target_agent_url": "https://fulfillment.example.com/a2a"
}
The target agent's URL must be HTTPS on a public host name: GaaS refuses private, loopback and cloud-metadata addresses, and does not follow redirects, whenever it contacts another agent.
Cross-Org Policy Federation
Built, not yet enabled. Federation lets GaaS negotiate governance requirements and check mutual compliance before agents in two organizations work together. The hosted service does not run it yet, so a cross-organization request is governed only by the receiving organization's own policies.
Push Notifications
Not available yet. The Agent Card says "pushNotifications": false, and the push
configuration methods return -32003 (PushNotificationNotSupportedError). Poll with
GetTask, or stream with SendStreamingMessage / SubscribeToTask.
AP2 Payment Governance
The Agentic Payment Protocol (AP2) extends GaaS with seven payment-specific policies that govern autonomous agent transactions. AP2 is designed around the emerging reality that AI agents will execute payments autonomously on behalf of users — and those payments require the same compliance safeguards as human-initiated transactions.
Tier 1 AP2 Policies (Fast-Fail)
These four policies run first and immediately block invalid or out-of-scope payment requests:
Mandate Validity
Verifies that a valid payment mandate exists for the agent, the target merchant, and the requested amount. No mandate = immediate block.
Mandate Conditions
Checks that all conditions attached to the mandate are satisfied — validity window, allowed merchant categories, and geographic restrictions.
HNP Threshold
High Net Payment threshold check. Transactions above the mandate's HNP limit require explicit human approval regardless of trust score.
Cumulative Spend Limit
Tracks total spend against the mandate's rolling limit (daily / monthly). Rejects transactions that would exceed the limit.
Tier 2 AP2 Policies (Regulatory)
These three policies enforce payment regulation compliance:
PCI-DSS Compliance
Verifies that cardholder data is handled in-scope, encryption is enforced, and the transaction channel meets PCI-DSS requirements.
PSD2 Strong Customer Authentication
Enforces SCA requirements for EU/EEA transactions. Determines whether SCA exemption applies (low-value, trusted beneficiary, low-risk TRA).
AML Velocity
Anti-money laundering velocity check. Flags unusual transaction frequency, amount clustering, or structuring patterns within the rolling window.
Submitting an AP2-governed Payment Intent
POST /v1/intents
X-API-Key: your_api_key
{
"intent": {
"agent": {
"id": "procurement_agent_v1",
"framework": "custom"
},
"action": {
"type": "TRANSACT",
"verb": "initiate_payment",
"target": {
"type": "ACCOUNT",
"identifier": "vendor_account_V9912",
"sensitivity": "REGULATED"
}
},
"payload": {
"summary": "Pay vendor invoice INV-2026-0044 for SaaS services",
"content": {
"amount_usd": 2500.00,
"currency": "USD",
"merchant_category": "7372",
"mandate_id": "mnd_vendor_9912"
}
},
"estimated_impact": {
"reversible": false,
"financial_exposure_usd": 2500.00,
"regulatory_domains": ["PCI-DSS", "PSD2", "AML"]
}
}
}
AP2 Mandate Management
Mandates define the authorized scope for agent payments. A mandate specifies which agent may transact, on whose behalf, with which merchants, up to what limits, and for what period.
Create a new payment mandate authorizing an agent to transact
Retrieve mandate details, remaining budget, and validity status
List all mandates for the organization, with optional status filter
Revoke a mandate — any in-flight transactions using this mandate are blocked
List all governed transactions executed under a mandate
Mandate Schema
{
"mandate_id": "mnd_vendor_9912",
"agent_id": "procurement_agent_v1",
"authorized_by": "user_cfo_01",
"scope": {
"merchant_categories": ["7372", "7371"],
"max_single_transaction_usd": 5000.00,
"daily_limit_usd": 10000.00,
"monthly_limit_usd": 50000.00,
"hnp_threshold_usd": 10000.00,
"currency": "USD",
"geographic_scope": ["US", "EU"]
},
"valid_from": "2026-01-01T00:00:00Z",
"valid_until": "2026-12-31T23:59:59Z",
"status": "active",
"cumulative_spend_usd": 2500.00,
"remaining_daily_budget_usd": 7500.00
}
POST /v1/ap2/mandates/{mandate_id}/revoke.
Related Pages
- Connectors — A2A Registry and AP2 Mandate connectors
- Intent Declaration API — The core governance entry point
- Policy Library — Full policy catalog including AP2 and Tier 4 AI safety policies
- Webhooks — Event-driven notifications for governance decisions
- Authentication — API keys and A2A auth schemes