<!-- Source: https://docs.paxeer.app/a2a/ -->

# Agent-to-Agent Payments

Discover a payment agent, submit structured tasks and reconcile each outcome with Paxeer X protocol evidence.

## A payment agent with explicit boundaries

The A2A transport exposes a JSON-RPC payment agent bound to one hosted environment, one local signing key and a specific source account and asset. Its agent card declares served skills and enforced gateway scopes. Task delivery coordinates work; canonical activities and verified receipts establish monetary authority.

## Install the runtime

```
layerx environment use beta
layerx auth set --environment beta
layerx install a2a --environment beta --key operator   --source-account <64-hex-source-account>   --asset <64-hex-asset-id>
layerx a2a start
layerx a2a status
```

The identity session is read from stdin by `auth set`. Installation provisions a gateway key and stores its secret in credential storage. Payment mode grants `activity:write` and `receipt:read`. Both source and asset are required and bind the runtime's payment authority. The default listener is `127.0.0.1:9433`.

### Read-only and credential rotation

```
layerx install a2a --environment beta --read-only
layerx a2a stop
# Rotate the installed credentials while preserving the intended payment binding.
layerx install a2a --environment beta --key operator --rotate   --source-account <64-hex-source-account> --asset <64-hex-asset-id>
```

Read-only installation grants `receipt:read` and accepts neither source account nor asset. A separate installation-local Bearer credential protects incoming task requests. It lives in the owner-only authorization file; the hosted gateway credential remains in secure credential storage. Agent-card discovery is public on the loopback listener.

## Discover the agent card

```
GET /.well-known/agent-card.json
# Compatibility discovery path:
GET /.well-known/agent.json
```

The card uses A2A protocol version `0.3.0` and preferred transport `JSONRPC`. It includes URL, software version, JSON input/output modes, skill descriptors, the `layerxLocalBearer` security scheme and an environment extension containing environment, deployment mode and scopes. Read this card before choosing a skill.

| Skill | Inputs | Authority and evidence |
| --- | --- | --- |
| `receipt.get` | `activity_id`, a 64-hex identifier. | Requires receipt read scope; returns gateway-verified receipt material. |
| `activity.submit` | Destination, decimal amount, account sequence, validity times, fee limit and 64-hex idempotency key. | Requires activity write scope; constructs a canonical native asset SEND with the installed source and asset. |
| `faucet.request` | DID and public key. | Uses the approved beta allocation policy and the served deployment's permissions. |

## Send a structured task

```
POST / HTTP/1.1
Authorization: Bearer <installation-local-a2a-credential>
Content-Type: application/json

{"jsonrpc":"2.0","id":1,"method":"message/send","params":{
  "message":{
    "kind":"message","role":"user","messageId":"receipt-check-01",
    "contextId":"treasury-reconciliation",
    "parts":[{"kind":"data","data":{
      "skill":"receipt.get","arguments":{"activity_id":"<64-hex-activity-id>"}
    }}]
  }
}}
```

HTTP requests carry an explicit Content-Length and one JSON body. A data part contains `skill` and `arguments`; a text part may contain the same object serialized as JSON. The server admits only skills in its card. It generates task and artifact IDs and retains the submitted message in task history.

### Payment arguments

```
{"skill":"activity.submit","arguments":{
  "destination":"<64-hex-destination-account>",
  "amount":"1000","account_sequence":"<current-sequence>",
  "not_before_ms":"<current-unix-ms>","expires_at_ms":"<expiry-unix-ms>",
  "fee_limit":"<integer-fee-limit>","idempotency_key":"<64-hex-stable-key>"
}}
```

All numeric arguments are decimal strings. Amount must be positive; the validity window must be nonempty and no wider than 300,000 milliseconds. The caller cannot replace the runtime's source account or asset through task arguments. The runtime constructs and signs canonical bytes and submits them through the hosted gateway.

## Track task state and protocol state

```
{"jsonrpc":"2.0","id":2,"method":"tasks/get","params":{"id":"<task-id>"}}
{"jsonrpc":"2.0","id":3,"method":"tasks/cancel","params":{"id":"<task-id>"}}
```

| Task state | Meaning | Next step |
| --- | --- | --- |
| `completed` | The skill returned its result. | Inspect the artifact and verify the monetary outcome evidence. |
| `submitted` | Gateway state is acknowledged or pending. | Retain the existing activity and reconcile its receipt. |
| `unknown` | The gateway outcome is uncertain. | Look up the original activity before retrying a write. |
| `rejected` | The gateway refused the operation or skill execution failed. | Read the task status message and resolve its cause. |

The task artifact carries the skill result as a data part. A completed transport task does not independently establish final settlement. Submitted protocol activities cannot be canceled by this transport; terminal tasks also cannot be canceled. Preserve activity IDs, stable idempotency keys and receipt evidence outside the bounded runtime task ledger.

## Capabilities, errors and policy

The card declares streaming, push notifications and transition-history capabilities as false for this JSON-RPC runtime. Use `tasks/get` and receipt reads. Unsupported streaming/resubscription/push-configuration requests return `-32004`; unknown methods or unserved skills return `-32601`; invalid arguments return `-32602`; missing tasks return `-32001`. Missing or incorrect incoming Bearer credentials return HTTP 401.

Use owner policy, capability scope and [budget and approval controls](https://docs.paxeer.app/agent-budgets) to bound agent spending. MCP routes tool calls through an enrolled daemon binding; this A2A runtime uses its installed gateway and signing bindings. See [API authority and commitment levels](https://docs.paxeer.app/platform-api), [identity](https://docs.paxeer.app/identity) and [CLI workflows](https://docs.paxeer.app/cli).
