Builds an A2aUserBuilder that authenticates A2A requests against a
shared bearer token.
Callers must send Authorization: Bearer <token>; the credential is
compared against token in constant time, and a request with a missing,
malformed or incorrect one is rejected before the agent or any of its tools
is invoked. Serve the surface over HTTPS, or the secret travels in clear
text on every call.
consttoken = process.env.MY_TOKEN; if (!token) { thrownewError('MY_TOKEN is not set'); } toA2a(agent, {authentication:bearerTokenUserBuilder(token)});
A rejected request surfaces as whatever the @a2a-js/sdk handler produces
for a failing UserBuilder, which is an HTTP 500 rather than a 401. The
guarantee here is that the agent is never reached, not that the caller gets
a particular status code.
Parameters
token: string
The shared secret callers must present; surrounding whitespace
is trimmed, because HTTP strips it from header values anyway.
Builds an A2aUserBuilder that authenticates A2A requests against a shared bearer token.
Callers must send
Authorization: Bearer <token>; the credential is compared againsttokenin constant time, and a request with a missing, malformed or incorrect one is rejected before the agent or any of its tools is invoked. Serve the surface over HTTPS, or the secret travels in clear text on every call.A rejected request surfaces as whatever the
@a2a-js/sdkhandler produces for a failingUserBuilder, which is an HTTP 500 rather than a 401. The guarantee here is that the agent is never reached, not that the caller gets a particular status code.