Connectivity

Agents that you build in Neptune DXP - Open Edition can call each other and can be called by other systems through the A2A protocol. The Connectivity tab of an agent holds both directions:

  • A2A Peers: other agents this agent may delegate to.

  • Agent-to-Agent (A2A) Settings and Skills Configuration: how this agent is published to callers.

The Connectivity tab is not shown for external agents and for agents that have Agentic Apps enabled.

Exposing an agent

Enable Expose agent via A2A to publish the agent as an A2A endpoint. The endpoint URLs are not displayed in the Cockpit. They are built from the host of your instance and the agent ID:

Purpose URL

Agent endpoint (JSON-RPC)

[PROTOCOL]://[HOST]/api/AIBuildersKit/AIAgent/[AGENT-ID]

Agent card

[PROTOCOL]://[HOST]/api/AIBuildersKit/AIAgent/[AGENT-ID]/.well-known/agent.json

Instance signing keys (JWKS)

[PROTOCOL]://[HOST]/.well-known/jwks.json

Token endpoint for OAuth clients

[PROTOCOL]://[HOST]/api/oauth/token

Calling the agent always requires authentication. The agent card advertises the methods the instance accepts:

  • An API key or JWT in the Authorization header.

  • HTTP Basic authentication with local, LDAP, or SAP Edition credentials.

  • A Bearer token (JWT or Microsoft Entra ID access token).

  • OAuth 2.0 client credentials, exchanged for a Bearer token at /api/oauth/token. Create the credentials in OAuth Clients.

Access to the agent follows the roles assigned on the agent’s Role tab. A caller authenticated as a user without one of those roles cannot fetch the card or send messages.

Public Discovery

Serves the agent card at its .well-known URL without authentication, so external systems can discover the agent before they have credentials. Calling the agent still requires authentication. The public card is cached for five minutes and rate-limited to 120 requests per minute per client address. Off by default.

Organization

The name of the organization operating this agent, included in the agent card.

Provider URL

Written into the provider.url field of the agent card. It is informational and does not change where the card is served.

The instance signs every served card with its own key (ES256). Callers can verify the signature against /.well-known/jwks.json. The key is created on first use; there is no Cockpit tool for it.

Configuration of the agent card

With Skills Configuration you describe what the agent can do to any caller.

Expose Agent Tools as Skills

Advertises each of the agent’s tools as an individual skill in the agent card.

Skills

Manually defined skills. Each skill has an ID and a Name (both required), a Description, Tags, and Examples. If you define no skills and do not expose tools, the card contains one skill built from the agent’s name and description.

Skills and provider information are only there to inform external agents/users. They do not change what the agent can do. The agent uses tools, vector sources, etc., independent of how you configure the skills.

A2A peers

In the A2A Peers panel you select the agents this agent may delegate to. The picker lists both standard agents on this instance and external agents you have registered. To remove a peer, open the picker again and deselect it.

When an agent has at least one peer, it receives two extra tools:

discover_agents

Lists the peers with their descriptions and skills, so the model can choose the right one.

sendMessageToAgent

Sends a message to a peer and returns the peer’s reply. If the peer is still working after the timeout, the model gets a status note instead of a reply.

Every peer call uses one agent step. Keep Maximum agent steps high enough for the delegation chain you expect.

Each delegation runs on a child thread of the current conversation. In the chatbox, the peer’s intermediate steps appear as a nested panel while the call runs. In Agent Trace, the call shows up as a sendMessageToAgent step and the peer’s own run is logged on the child thread.

A peer call waits for up to 10 minutes in total and gives up after one minute without any activity from the peer. For work that takes longer, switch on Run tasks in background for that peer. See Background tasks.

Serving long-running requests

When another system calls this agent and disconnects before the agent is done, the agent normally stops. Switch on Continue tasks after disconnect to let it finish. The result is stored and the caller can read it later with tasks/get. The agent keeps working for at most 30 minutes after the disconnect.

Limits

  • Outbound calls to peers are blocked when the target resolves to a private, loopback, or link-local address. This applies to card URLs and to the service URL inside the card. For local testing outside production, the configuration key ai.a2a.outboundAllowlist (environment variable A2A_OUTBOUND_ALLOWLIST) lists bare hostnames or IP addresses that bypass the check. Entries are matched without port or scheme. The allowlist is ignored in production.

  • The check resolves the hostname once and does not pin the address for the connection that follows.

  • Cached cards of external agents are refreshed after one hour.