Same class as the Bot Chat drain wedge already on this branch: every JSON-file scan guarded "did it parse?" and then assumed the value was a dict. A file holding `42`, `"oops"` or `[1,2,3]` (corruption, truncated write, foreign tool) passed the guard and raised AttributeError/TypeError at the first `.get()`, usually before a single healthy sibling was processed. Each site now treats a non-object payload like a corrupt file under that subsystem's existing policy: - tools/bot_relay.py::_expire_if_stale / claim_pending_envelopes — the envelope is skipped by the sweep and not claimed (same as unparseable). - tools/browser_lightpanda.py::reap_orphaned_lightpanda — record unlinked, scan continues. - tools/write_approval.py::list_pending / get_pending — record skipped with the existing "unreadable pending record" warning / None. - tui_gateway/methods_session.py::_legacy_spawn_tree_entry / spawn_tree.load — scalar snapshot reads as empty / returns the existing 5000 error instead of violating the SpawnTreeLoadResult contract. - hermes_cli/local_runtime/binaries.py::manifest_verified — False. - plugins/platforms/a2a/protocol.py::load_conversation — non-dict lines are dropped, keeping the declared list[dict] return. - batch_runner.py::_load_dataset / _scan_completed_prompts_by_content / _combine_batch_files — line skipped and counted as filtered. - trajectory_compressor.py::process_entry_async — scalar entry passed through unchanged. Ported from the source hunks of PR #114241; its gateway/shutdown_flush.py drain_transcript_spool hunk is left to open PR #84785, and its recover_pending_to_db / cron / bot_live_delivery / bot_mode_dm hunks are already on this branch or on main. (cherry picked from commit d4b54568887e69b3ee3d363ebe4dcd657ccf64f9)
A2A — Agent-to-Agent protocol for Hermes
Talk to other agents, and let other agents talk to you, over the open
A2A protocol v1.0. Works with any A2A-compliant
peer (another Hermes, LangChain, CrewAI, Google ADK, OpenClaw, …). Stdlib only —
no a2a-sdk dependency.
Enable
hermes gateway setup # pick A2A, or:
# ~/.hermes/config.yaml
gateway:
platforms:
a2a:
enabled: true
extra:
port: 9900
# peers you want to call (outbound):
a2a_agents:
researcher:
url: "http://localhost:9999"
auth: { type: bearer, token: "sk-..." }
timeout: 120
capabilities: [web_search, research]
Outbound — call other agents
The agent gets five tools:
a2a_discover(url)— what can this agent do?a2a_call(agent, message, context_id?)— send it a task, get the reply.a2a_list()— configured peers, saved conversations, metrics.a2a_history(context_id)— recall a saved A2A conversation.a2a_orchestrate(capability, message, mode?)— fan-out a task to every peer advertising a capability (all/first/best).
Inbound — be callable
When the a2a platform is enabled, Hermes serves a v1.0 Agent Card at
http://<host>:<port>/.well-known/agent-card.json (the legacy
/.well-known/agent.json path is also answered for pre-1.0 clients) and
accepts JSON-RPC
message/send, message/stream (SSE), tasks/get|list|cancel|subscribe,
and push notification configs (inline or via
tasks/pushNotificationConfig/create). Incoming tasks are injected into your
live agent session — the same agent that's talking to you, with full
memory — and the reply is returned over A2A. Completed tasks stay queryable
via tasks/get.
Security
- No token ⇒ localhost only. The server binds
127.0.0.1and refuses to widen unless you configure a token and setA2A_HOST. - Per-peer tokens:
A2A_PEER_TOKENS="alice:tok1,bob:tok2"gives each remote agent its own credential; that authenticated name (never anything in the request body) drives rate limiting, trust, and audit. - Inbound text — including
/-prefixed text — is run through prompt-injection filters and framed as untrusted peer input; remote peers cannot invoke operator slash commands. - Outbound text is scrubbed of credential-shaped strings.
- Push callbacks are SSRF-guarded and HMAC-SHA256 signed (
X-A2A-Signature). - Every exchange is logged to
~/.hermes/a2a_audit.jsonl. - Conversations persist to
~/.hermes/a2a_conversations/— they survive context compaction and restarts (a2a_historyrecalls them).
Env vars
| Var | Default | Meaning |
|---|---|---|
A2A_PEER_TOKENS |
(unset) | Per-peer credentials name:token,… (preferred). |
A2A_BEARER_TOKEN |
(unset) | Shared token; identity falls back to caller IP. |
A2A_HOST |
127.0.0.1 |
Bind host. Only widens with a token set. |
A2A_PORT |
9900 |
Inbound port. |
A2A_AGENT_NAME |
hostname-derived | Name on the Agent Card. |
A2A_PUBLIC_URL |
(unset) | Routable URL advertised on the card (reverse proxies). |
A2A_TRUSTED_PEERS |
(unset) | Allow-list of authenticated identities. |
A2A_ALLOW_ALL_USERS |
false |
Allow any authed peer (dev only). |
A2A_RATE_LIMIT |
60 |
Requests/minute per identity. |
A2A_MAX_PINGPONG_TURNS |
5 |
Anti-loop turn cap per context (max 20). |
A2A_REPLY_TIMEOUT |
300 |
Seconds to wait for the agent's reply; the orphan sweep never fails a task before this window (floor 300s) or while a request still waits on it. |
A2A_PUSH_SECRET |
bearer token | HMAC secret for push signing. |
A2A_ADVERTISED_TOOLSETS |
all registered | Restrict skills on the Agent Card. |
See DESIGN.md for architecture and the requirement-tracing table.