Files
hermes-agent/plugins/platforms/a2a
Teknium 199c66f70f fix(gateway): adapter settings resolve per profile under multiplex, not from the default's env
Under gateway.multiplex_profiles a served secondary profile's adapter is built and
connected inside _profile_runtime_scope while os.environ still holds the DEFAULT
profile's .env. Credentials and allowlists were already read through the profile
scope (get_scoped_secret / _platform_gate_env), but the non-credential SETTINGS the
adapters read with bare os.getenv were not, so a served profile silently ran with the
default profile's values: webhook listener host/port/URL (SMS, Teams, LINE, Feishu,
BlueBubbles), Signal's connect URL/account gate, mention gating and reactions (Slack,
Matrix, Signal, Feishu, BlueBubbles, Discord), Matrix thread/session/E2EE policy and
message-length limits, Discord backfill/command-sync/attachment caps, Buzz reply mode
and env enablement seed, A2A agent name/port/description/toolsets, and the
api_server model alias.

Every such read now goes through the existing scoped reader (get_scoped_secret, or the
adapter's own scope-aware helper): under a secondary's scope the profile's own .env is
authoritative and a miss yields the default -- never another profile's value; the
default profile and single-profile gateways keep reading os.environ exactly as before.
Buzz and A2A previously short-circuited to "extra only / built-in default" under a
scope, which also dropped the profile's OWN .env; they now read the scope so a served
profile matches its standalone gateway.

The parity harness (temp HERMES_HOME, default + 2 secondaries with distinct values for
every env var each adapter reads, real load_gateway_config + adapter factory in both
topologies) went from 70 raw process-env bypass sites across 14 adapters to only the
HERMES_<PLATFORM>_* perf knobs and the api_server listener vars, which are process-
global by design (agent.secret_scope._GLOBAL_ENV_*).
2026-09-11 19:37:59 -07:00
..
…
…
…

A2A — Agent-to-Agent protocol for Hermes

Talk to other agents, and let other agents talk to you, over the open A2A protocol v1.0. Works with any A2A-compliant peer (another Hermes, LangChain, CrewAI, Google ADK, OpenClaw, …). Stdlib only — no a2a-sdk dependency.

Enable

hermes gateway setup      # pick A2A, or:
# ~/.hermes/config.yaml
gateway:
  platforms:
    a2a:
      enabled: true
      extra:
        port: 9900

# peers you want to call (outbound):
a2a_agents:
  researcher:
    url: "http://localhost:9999"
    auth: { type: bearer, token: "sk-..." }
    timeout: 120
    capabilities: [web_search, research]

Outbound — call other agents

The agent gets five tools:

  • a2a_discover(url) — what can this agent do?
  • a2a_call(agent, message, context_id?) — send it a task, get the reply.
  • a2a_list() — configured peers, saved conversations, metrics.
  • a2a_history(context_id) — recall a saved A2A conversation.
  • a2a_orchestrate(capability, message, mode?) — fan-out a task to every peer advertising a capability (all / first / best).

Inbound — be callable

When the a2a platform is enabled, Hermes serves a v1.0 Agent Card at http://<host>:<port>/.well-known/agent-card.json (the legacy /.well-known/agent.json path is also answered for pre-1.0 clients) and accepts JSON-RPC message/send, message/stream (SSE), tasks/get|list|cancel|subscribe, and push notification configs (inline or via tasks/pushNotificationConfig/create). Incoming tasks are injected into your live agent session — the same agent that's talking to you, with full memory — and the reply is returned over A2A. Completed tasks stay queryable via tasks/get.

Security

  • No token ⇒ localhost only. The server binds 127.0.0.1 and refuses to widen unless you configure a token and set A2A_HOST.
  • Per-peer tokens: A2A_PEER_TOKENS="alice:tok1,bob:tok2" gives each remote agent its own credential; that authenticated name (never anything in the request body) drives rate limiting, trust, and audit.
  • Inbound text — including /-prefixed text — is run through prompt-injection filters and framed as untrusted peer input; remote peers cannot invoke operator slash commands.
  • Outbound text is scrubbed of credential-shaped strings.
  • Push callbacks are SSRF-guarded and HMAC-SHA256 signed (X-A2A-Signature).
  • Every exchange is logged to ~/.hermes/a2a_audit.jsonl.
  • Conversations persist to ~/.hermes/a2a_conversations/ — they survive context compaction and restarts (a2a_history recalls them).

Env vars

Var Default Meaning
A2A_PEER_TOKENS (unset) Per-peer credentials name:token,… (preferred).
A2A_BEARER_TOKEN (unset) Shared token; identity falls back to caller IP.
A2A_HOST 127.0.0.1 Bind host. Only widens with a token set.
A2A_PORT 9900 Inbound port.
A2A_AGENT_NAME hostname-derived Name on the Agent Card.
A2A_PUBLIC_URL (unset) Routable URL advertised on the card (reverse proxies).
A2A_TRUSTED_PEERS (unset) Allow-list of authenticated identities.
A2A_ALLOW_ALL_USERS false Allow any authed peer (dev only).
A2A_RATE_LIMIT 60 Requests/minute per identity.
A2A_MAX_PINGPONG_TURNS 5 Anti-loop turn cap per context (max 20).
A2A_REPLY_TIMEOUT 300 Seconds to wait for the agent's reply.
A2A_PUSH_SECRET bearer token HMAC secret for push signing.
A2A_ADVERTISED_TOOLSETS all registered Restrict skills on the Agent Card.

See DESIGN.md for architecture and the requirement-tracing table.