Description
A2AExecutor receives the inbound A2A RequestContext, including context.metadata (SendMessageRequest.metadata), but ignores it. run_kwargs is fixed when the executor is constructed, so runtime context a caller passes as function_invocation_kwargs and client_kwargs cannot reach the hosted agent. Middleware and tools on a hosted agent therefore see different context.kwargs than they would if the agent ran locally in the same workflow.
function_invocation_kwargs and client_kwargs are the only run-time inputs in the SupportsAgentRun.run contract besides messages, session and stream, so they are the natural thing to rehydrate on the server.
Proposal
Let A2AExecutor opt in to accepting selected keys of the kwargs a client forwards in SendMessageRequest.metadata["agent_framework"] (client side: #7973), and pass them to agent.run(function_invocation_kwargs=..., client_kwargs=...):
- Opt-in via a key allowlist (
A2AExecutor(agent, accepted_kwargs=[...])). Nothing is accepted by default, because the values are chosen by a remote caller and client_kwargs can reach a provider client.
run_kwargs configured on the executor win on conflict.
- Framework-owned names (
stream, messages, options, session, middleware and similar, plus underscore-prefixed names) are rejected with ValueError at construction, so a remote caller cannot cause duplicate keyword errors.
- Missing or malformed metadata is ignored.
Code Sample
executor = A2AExecutor(agent, accepted_kwargs=["tenant"])
A caller that forwards function_invocation_kwargs={"tenant": "acme"} then gets context.kwargs["tenant"] == "acme" in function middleware and tools on the hosted agent.
Language/SDK
Python
Description
A2AExecutorreceives the inbound A2ARequestContext, includingcontext.metadata(SendMessageRequest.metadata), but ignores it.run_kwargsis fixed when the executor is constructed, so runtime context a caller passes asfunction_invocation_kwargsandclient_kwargscannot reach the hosted agent. Middleware and tools on a hosted agent therefore see differentcontext.kwargsthan they would if the agent ran locally in the same workflow.function_invocation_kwargsandclient_kwargsare the only run-time inputs in theSupportsAgentRun.runcontract besidesmessages,sessionandstream, so they are the natural thing to rehydrate on the server.Proposal
Let
A2AExecutoropt in to accepting selected keys of the kwargs a client forwards inSendMessageRequest.metadata["agent_framework"](client side: #7973), and pass them toagent.run(function_invocation_kwargs=..., client_kwargs=...):A2AExecutor(agent, accepted_kwargs=[...])). Nothing is accepted by default, because the values are chosen by a remote caller andclient_kwargscan reach a provider client.run_kwargsconfigured on the executor win on conflict.stream,messages,options,session,middlewareand similar, plus underscore-prefixed names) are rejected withValueErrorat construction, so a remote caller cannot cause duplicate keyword errors.Code Sample
A caller that forwards
function_invocation_kwargs={"tenant": "acme"}then getscontext.kwargs["tenant"] == "acme"in function middleware and tools on the hosted agent.Language/SDK
Python