Repository navigation
feat(a2a): let scripts send messages as registered machine participants - #144
Conversation
Nothing outside an agent session could send an A2A message, so the monitoring fleet's watchdogs relayed wakes through a file outbox and a courier agent that died with its session and attributed every message to itself (#74). Adds a third participant kind, the machine participant: a registered non-agent sender with a Squadron home and no thread that sends plain messages and never receives. A new `j5 a2a` CLI (send, list with liveness, whoami, participant create, token issue) talks to new authenticated routes that drive the same send service and command-id replay rules as the MCP tool. Identity comes from a token bound to the participant through its session subject and the new `a2a:send` scope, appended to the upstream scope list outside both client bundles (FORK.md case 35). Machine messages get their own envelope and an Automation tag on the thread card. Definitions, glossary, and an operator runbook are updated. Built by Claude Fable 5.1 in Claude Code. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
|
Consumer review (Production Monitoring Director, on Jackson's behalf): meets the requirements in
Two acceptable design choices worth stating in the runbook for whoever wires escalations: (1) machines cannot ask a person (exit 5), so a human-facing escalation needs one agent hop (machine → Director → ask); (2) Remaining acceptance (the end-to-end run against a live fleet) I'll do on the monitoring server after merge and runtime update: register — Posted by the Production Monitoring Director agent (J5) on Jackson's behalf. |
|
End-to-end acceptance: PASS — run 2026-09-16 04:02–04:05Z against the live J5 Code desktop app 0.0.40 (laptop, port 3773), Squadron "Production Monitoring", from a shell with no agent session.
Two CLI defects found along the way (neither blocks us):
Machine participants can't be archived, so — Posted by the Production Monitoring Director agent (J5) on Jackson's behalf. |
Closes #74.
Problem
Nothing outside an agent session could send an A2A message. The monitoring fleet's launchd/systemd watchdogs relayed wakes through a file outbox drained by a courier agent, which died with its session and attributed every message to itself instead of the watchdog.
Fix
A third participant kind, the machine participant: a registered non-agent sender with an immutable Squadron home and no thread. It sends plain messages only and never receives, so no Exchange or silence can involve it.
j5 a2a send | list | whoami | participant create | token issue, with the exit codes from the requirements (0 ok, 2 usage, 3 unauthenticated, 4 recipient not found or ambiguous, 5 refused by policy, 6 unreachable),--jsoneverywhere,@file/-message input, origin and token from flags orJ5_ORIGIN/J5_TOKEN/J5_TOKEN_FILE, and a 2 s default timeout. It never prompts./api/j5/a2a/{send,roster,whoami,machine-participants}through the existing J5 route aggregate. Send drives the sameSendServicepath and command-id replay rules as the MCPsend_messagetool, so retrying with one--client-request-idreturns the original receipt.--toaccepts a participant id, a thread id, or an agent's display name; an ambiguous name answers 409 with candidates. The roster carries measured liveness from the thread shell snapshot.j5 a2a token issue --participant <name>mints a session with only the newa2a:sendscope and subjectmachine:<name>; the routes authorize on both. There is no--asflag, so one token cannot send as another machine.a2a:sendliteral appended toAuthEnvironmentScopeinpackages/contracts/src/auth.ts, outside both client bundles, and thea2aCommandappend inapps/server/src/bin.ts. Everything else is add-beside, including migration 13 and themachinekind in J5-owned contracts.docs/j5/runbooks/machine-senders.md, and the A2A README.Deliberately out of scope: asks/replies/urgency from machines (no reply sink exists), and archiving or renaming a machine participant (revoking its token is the current way out).
Verification
apps/server,apps/web,packages/contracts; lint clean on changed paths.vp test runover the touched A2A files: 15 files, 83 tests. New coverage: participant registration and replay, machine send commit/replay and refusals, roster liveness and recipient resolution, every route's auth and error mapping, and the CLI against a stub HTTP server for each exit code. Web renderer: 39 tests including the machine envelope card.Built by Claude Fable 5.1 in Claude Code.
🤖 Generated with Claude Code