Does your A2A Agent Card declare real authentication?

Grade an A2A Agent Card's securitySchemes and security requirement against the A2A specification and OpenAPI security-scheme conventions — every finding cited, results shareable by permalink.

We fetch only the public Agent Card over HTTPS — the URL itself, then /.well-known/agent-card.json, then /.well-known/agent.json. Nothing is stored unless a report is created.

a2ascan

Grade an A2A Agent Card's declared authentication

by IntegrAuth