personal-assistant in the personal workspace hand
documentation work to docs-writer in the aadocs workspace.
Prerequisites
- Someone who is a member of
aadocsissues the key. It acts as them, so a delegated task inaadocsis started by them. - You administer the calling workspace. Pointing a secret at an address sends the secret there, so only an admin may add or change that binding.
Steps
Issue a key for the target agent
In The key reaches
aadocs, open docs-writer → Settings → A2A access. Copy the
agent’s Address, then select Issue key, name it after the caller,
for example personal, and copy the key; it is shown once. Or:docs-writer over A2A and nothing else: no other agent, no
data in aadocs, no REST route. Revoke it in the same section to cut the
caller off.Store the key as a secret in the calling workspace
In The agent keeps only the secret’s name. The value is read when the agent
delegates, so rotating the key means updating this secret, not the agent.
personal, open Secrets and create a secret named aadocs-key with
the key as its value, or:Add the delegate to the calling agent
Open
personal-assistant → Settings → Delegation → Agent, and
fill in External agent (A2A):Select Add external agent, then Save changes. Through the API, the
same delegate is one entry in the agent’s
tools; the update replaces the
whole list, so send every tool the agent should keep:Verify
Start a task onpersonal-assistant that needs the delegate, for example “Write
a one-sentence doc for add(a, b) and delegate it to docs-writer”. The task’s
activity shows a delegate_to_docs_writer call, and a new task for
docs-writer appears in the aadocs workspace, started by whoever issued the
key.
Troubleshooting
Reading the card fails, or the call fails naming the agent card
Reading the card fails, or the call fails naming the agent card
Nothing at the address serves
/.well-known/agent-card.json. Use the
address from A2A access, not the JSON-RPC URL. For another A2A server,
use the origin or base URL its card is published under.The call fails with HTTP 401
The call fails with HTTP 401
No valid key reached the target. Check that Token names a secret, and
that the secret holds a key that has not been revoked and whose issuer is
still a member of the target workspace.
The call fails with HTTP 403
The call fails with HTTP 403
The key is bound to a different agent, or it is a key for another
workspace. Issue one from the target agent’s A2A access.
The call fails: the card names no endpoint on the address
The call fails: the card names no endpoint on the address
The remote card points its endpoint at another host. The token is sent only
to the address you configured, so the delegate refuses. Configure the host
the card names as the address instead.
Saving fails: only a workspace admin may send a workspace secret
Saving fails: only a workspace admin may send a workspace secret
Adding a delegate with a Token, or changing its address or token, needs
a workspace admin in the calling workspace. Ask one to add the delegate.
Saving fails with invalid_delegate
Saving fails with invalid_delegate
The detail names the delegate and the problem: a secret that does not exist
or is managed by a connection, an address that is not http(s), or two
delegates whose names become the same tool name.
The call fails naming a secret that was not found
The call fails naming a secret that was not found
The secret was renamed or deleted after the delegate was added. Recreate it
under the same name, or pick another one on the delegate.
The error says the host resolves to a non-public address
The error says the host resolves to a non-public address
The outbound guard refused the address. Use the public one. A self-hosted
deployment that must reach an internal host names it in
OUTBOUND_PRIVATE_ALLOWLIST on the worker and the API.The delegate reports it is still working
The delegate reports it is still working
The target did not finish within the 110-second A2A delegation budget. The
task keeps running in the target workspace; its result does not come back
to the caller.
Related
Agent-to-agent communication
Delegation, the A2A binding, and its limits
Issue access tokens
Create, scope, rotate, and revoke API keys
Create and configure an agent
Create an agent and give it a model, instructions and tools