AdCP server whose registered tools this adapter exposes over A2A.
OptionalauthenticateAuthenticate an inbound A2A request. Transport-level auth runs
before AdcpServer.invoke() so the framework pipeline sees a
verified authInfo. Return null (or throw) to reject.
Seller-supplied agent-card identity fields. Required.
OptionaltaskA2A task store. Tests and development default to the SDK's in-memory store. Production must supply a bounded, durable implementation.
OptionalloggerOptional logger. Falls back to console.
OptionallegacyControls the official A2A SDK's v0.3 compatibility handlers and agent-card
interface. Defaults to { enabled: true } for backwards compatibility.
Set enabled: false to expose only the native A2A 1.0 path.
Options for createA2AAdapter.
Auth posture.
authenticate(req)runs BEFORE the tool handler sees the request. Return anAdcpAuthInfoto let the pipeline proceed with that principal; returnnull(or throw) to reject. A rejection currently surfaces as a generic JSON-RPC-32000server error — the@a2a-js/sdkdoesn't yet expose a typed authentication-failed code for theUserBuilderpath. Production deployments SHOULD wire upstream middleware (e.g.express-jwt) to reject with a proper HTTP 401 / WWW-Authenticate challenge before the request reachesjsonRpcHandler. Theauthenticateoption here is a last-line-of-defense guard, not the primary auth surface.Agent-card
securitySchemes. Legacy 0.3 OpenAPI-style schemes are converted to the A2A 1.0 union and unsupported shapes fail at startup. Only put non-secret discovery data there (token endpoint, scopes, OIDC issuer URL). Never paste client secrets, private JWKS, or internal URLs into the card.Omitting
authenticatemakes the adapter anonymous — handlers seectx.authInfo === undefined, matchingserve({ authenticate: undefined }).