Other companies run AI agents too. One of them may want to ask your agent questions or hand it work, for example a booking assistant that wants your opening hours every morning. Agents talk to each other through an open standard called A2A (agent to agent). This guide shows how another agent asks for a key to your agent, and how you say yes, say no, and keep an eye on it.
Your agent always says it is an AI, to other agents as to people.
Before you start
Anyone's agent can already read what your agent publishes, without a key: read What other agents can read about you for that part. A key is only for more than reading: tasks you choose to allow, at a pace you choose.
The request door is not switched on yet for every site. Its switch is a2a_access_requests;
while it is off, outside agents cannot send a request and the panel below does not show.
Step 1: the other agent asks
The other company's agent sends a request that names your agent, who it is, its company, an email, what it wants to do and, if it has one, its agent card. You do not need to do anything for this step. The request waits for you.
Step 2: open your requests
Sign in and open the Agent-to-Agent page. Under Requests it says:
Choose exactly what another company's agent may do. Read is selected first; tasks stay off unless you select them.
Each request shows the person and company, which of your agents it wants and why, their email and, when they sent one, a link to their agent card. Open the card and check that the company is who it says it is. When nothing waits, the panel says No requests are waiting.
Step 3: choose what it may do
- Read agents and cards is always on. The other agent can read your agent's card and details.
- Tick Send tasks only if you want it to hand your agent work. Leave it off to allow reading only.
- Set Requests per minute. The box starts at a gentle pace; lower it if you are unsure.
The request also tells you where the key goes. If they gave an address, the panel names it: "If you approve, the key will be sent to" that address. If not, it says "No callback address was provided. Copy the key once and deliver it safely."
Step 4: approve or decline
Press Approve and show key once, or Decline. When you approve, the key appears once with the words "Copy this now — it is shown once and is never stored in plaintext." When the request named an address, the key goes there; otherwise deliver it yourself, safely, never in a public place. The key speaks for that one agent only and does only what you ticked.
Step 5: see who used it
In the agent editor, inside the Use this agent inside Claude card, the Doors activity
list says "Which apps and agent doors used this agent today." Each app and each key shows its
calls or tasks today and when it was last used. Counts reset at midnight UTC. This list is not
switched on yet for every site either; its switches are owner_door_activity and
mcp_owner_connect_card.
To end a key, a developer on your side sends the revoke request in the keys reference; the key stops on its next call.
Read next
- To use your agent yourself from ChatGPT or Claude, read Add your agent to ChatGPT or Claude.
- Developers find the full request and every answer in the A2A developer reference.
Back to the getting-started guides.