# Agent 2 Agent authentication

> Connect Integration Service to a remote Agent2Agent (A2A) agent by entering its service URL and the credentials for the authentication type the agent requires.

Each Agent 2 Agent connection points to one remote agent. Create a connection for every agent you want to call from Maestro.

## Prerequisites

- The remote agent meets the [remote agent requirements](uipath-google-agent2agent.md#remote-agent-requirements).
- The base URL of the agent, used as the **Service URL**. Enter the base URL only, without a path or a trailing slash. The connector adds the A2A paths, such as `/.well-known/agent-card.json`, itself.
- The credentials for the authentication type that the agent requires. The agent declares its supported security schemes in its Agent Card.

## Authentication types

All authentication types require the **Service URL**. The other fields depend on the authentication type.

| Authentication type | Fields |
| --- | --- |
| Basic Authentication | **Username**, **Password** (optional), **Authentication validation API** (optional) |
| API Key | **Parameter name**, **Value**, **Add to** (**Header** or **Query**, default **Header**), **Authentication validation API** (optional) |
| Personal Access Token | **Token prefix** (default `Bearer`), **Token**, **Authentication validation API** (optional) |
| OAuth 2.0 Authorization code | **Client ID**, **Client secret**, **Authorization URL**, **Token URL**, **Scope** (optional) |
| OAuth 2.0 Client credentials | **Client ID**, **Client secret**, **Token URL**, **Scope** (optional) |
| OAuth 2.0 Password | **Client ID**, **Client secret**, **Authorization URL**, **Token URL**, **Username**, **Password** (optional), **Scope** (optional) |
| OAuth 2.0 JWT Bearer | **Client ID**, **Client secret**, **Authorization URL**, **Token URL**, **JWT base64 encoded key**, **Scope** (optional) |

The following fields need more context:

- **Parameter name**: the exact name of the header or query parameter that carries the API key, for example `X-API-Key`.
- **Token prefix**: the prefix added before the token in the `Authorization` header. Leave it empty if the agent expects the token without a prefix.
- **Authentication validation API**: a relative path that returns a successful response when the credentials are valid, for example `/api/v1/me`.
- **Scope**: the OAuth scopes requested from the authorization server of the agent, as declared in its Agent Card. Separate multiple scopes with spaces or commas. Leave it empty to use the default scopes of the authorization server.
- **JWT base64 encoded key**: the Base64-encoded private key used to sign the JWT. Follow the instructions of your identity provider to generate and encode it.

## Add the Agent 2 Agent connection

1. Select **Orchestrator** from the product launcher.
2. Select a folder, and then navigate to the **Connections** tab.
3. Select **Add connection**.
4. To open the connection creation page, select the **Agent 2 Agent** connector from the list. You can use the search bar to find the connector.
5. In **Service URL**, enter the base URL of the agent.
6. Select the **Authentication Type**.
7. Enter the fields required for the selected authentication type.

   Where available, select the menu next to a field and choose **Use credential asset** or **Use Orchestrator asset** to reference an Orchestrator asset instead of entering the value directly. For more information, see [Use credential assets for connections](credential-store-connections.md).
8. Select **Connect**.

The connection is created and named after the agent, as declared in the `name` field of its Agent Card.
