Repository navigation
Releases: kleinmatic/a2a-bridge
Release list
v0.2.0
Config validation, a security fix, and a documentation pass. Upgrade if you are on 0.1.x.
Fixed
Authentication could be bypassed with a blank API key. Present in 0.1.0 and 0.1.1. Inline api_keys were read from YAML without stripping or dropping empty entries. A blank entry matched the empty token of a request carrying no Authorization header, so the bridge answered it. api_keys: ["${MY_KEY}"] with the variable unset renders exactly that shape. Blank entries are now dropped when the config loads, and an empty token can never match a key. Only affects configs using inline api_keys; the api_keys_env path always filtered correctly.
docker build -t a2a-bridge . failed in 0.1.1. The version is derived from the git tag, and the image does not copy .git, so the build raised LookupError. Building now works, and --build-arg VERSION=0.2.0 stamps a real version into the image.
Added
Config mistakes now produce messages that name the file, the agent and what to write instead, rather than a Python traceback about dataclass constructor arguments:
agents.yml: agent 'publisher': unknown option: card_urls.
Valid: artifact_join, caller, card_url, conversation_id_header, endpoint_url, id, ...
Also caught now: typos in top-level options (api_key_env: used to load a bridge with no keys, in silence), duplicate agent ids, malformed caller blocks, and YAML that is the wrong shape. The bridge warns at startup when no API keys are configured and it is open to anyone who can reach it.
Documentation
A correction worth reading if you rely on the session fallback. The docs said that without conversation_id_header the bridge hashes the first user message, and that sessions break only when someone edits it. It hashes the newest message, which is different on every turn, so the fallback starts a new session every turn. Set conversation_id_header.
The README, both example configs and the LibreChat guide were rewritten in plainer language. Every configuration option is now documented, which the previous release claimed but did not do.
pip install a2a-bridge==0.2.0
v0.1.1
Packaging and documentation only. No code changed — src/ is byte-for-byte identical to v0.1.0, so there is nothing to gain by upgrading unless you want the corrected project page.
- The version now comes from the git tag (
setuptools-scm) instead of being written inpyproject.toml. Publishing a release taggedvX.Y.Zis the whole procedure; there is no number to edit and no way for the two to drift apart. - The PyPI project page gets the README that knows the package is published, a version badge, and Repository / Issues / Changelog links.
Versioning, going forward: semver on 0.x — the middle number for a breaking change or a new feature, the last for a fix. Pin the minor version; agents.yml will move before 1.0.
pip install a2a-bridge==0.1.1
v0.1.0
First release.
Connects LibreChat, or any OpenAI-compatible chat client, to any A2A agent, with no model in the path — the user's text goes to the agent, and the agent's text is what renders. Adding an agent is a config block, not a code change.
- Blocking
message/send, optionalmessage/stream, agent-card discovery - Each configured agent appears as a selectable model on
/v1/models - Session continuity via a server-minted
contextIdkeyed to the client's conversation id - In-memory, SQLite or MongoDB context store
- Optional HMAC-signed per-caller identity forwarding, so an agent that rate-limits by IP doesn't see every user of a server-side bridge as one caller
Early and deliberately small: no Task lifecycle management, no polling, no push notifications. Expect the agents.yml schema to move before 1.0 — pin the minor version.
pip install a2a-bridge==0.1.0