Skip to content

Add "AAuth and the agent protocols" — A2A, ACP, MCP positioning has no written answer #9

Description

@dickhardt

The question we keep not answering

From the Center for AI Safety event at Stanford (academics, industry, frontier lab representatives, tort lawyers), reported in the August 2026 office hours:

  • The room's top conclusion was that every agent must operate on behalf of a principal — a legal or natural person.
  • AAuth came up organically, several times, as a candidate answer.
  • The open question the group put back was: how does AAuth align with A2A, ACP, and the other agent protocols?

Nothing on the site answers that, and it is the first question anyone asks who is already tracking the agent protocol space.

The answer is short

They are different layers. A2A, ACP, and MCP are how agents talk — transport, discovery, tool invocation, agent-to-agent messaging. AAuth is who an agent acts for and what it is allowed to do. An agent speaking any of them still has to answer "on whose behalf, and who said you could" — and none of them answers it.

That is a paragraph. It does not exist in writing anywhere, so every time it is asked, it gets answered live and inconsistently.

What to add

A page — "AAuth and the agent protocols" — with:

  • The layering, stated plainly and up front. One diagram if it helps: transport and tool-calling on one layer, authorization underneath, and what each answers.
  • Per protocol, one honest paragraph:
    • MCP — the closest and most concrete. AAuth authorizes the calls an MCP server serves. Worth naming the existing work rather than speaking hypothetically.
    • A2A — agent-to-agent messaging. Where AAuth's call chaining and sub-agent authorization apply, and where they do not.
    • ACP — same treatment.
    • AP2 / x402 / Ramp agent cards — payments-adjacent, already cited as prior art in the Budgets draft. These are the ones people confuse with budgets, so the distinction is worth drawing directly.
  • A "not competing with" statement. Some of this is read as territorial when it is not. Saying explicitly that AAuth composes with these, rather than replacing them, defuses it before it starts.

Why it is worth doing well

"Every agent must operate on behalf of a principal" is the framing that made AAuth come up on its own in a room of people who had no reason to be thinking about it. That framing is stronger than "an OAuth extension for agents," and this page is the natural place for it: start from the principal problem, then show that the other protocols leave it open.

Metadata

Metadata

Assignees

No one assigned

    Labels

    documentationImprovements or additions to documentation

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions