Platform

A2A Agents

The Application-to-Application agent protocol enables workloads to authenticate to CoreLink and retrieve secrets without human intervention. Each A2A agent is issued a rotating token bound to a specific workspace and permission set. Authentication uses mutual TLS with automatic certificate renewal.

A2A agents are tracked in the NHI registry with the same ownership, expiry, and risk scoring as other non-human identities. Token rotation happens automatically with zero downtime using a dual-token overlap window.

A2A Agents screenshot

Key Configuration

  • Agent token rotation interval
  • Workspace and permission scope
  • mTLS certificate authority
  • Dual-token overlap window
All documentation Question about this? Talk to us