A2A.PushNotificationSender.HTTP (A2A v0.3.0)

Copy Markdown View Source

Default A2A.PushNotificationSender, POSTing payloads with Req.

Available only when the optional :req dependency is present, and used automatically when it is.

Options

  • :timeout — per-attempt receive timeout in ms (default: 15_000). The spec recommends 10-30s.
  • :attempts — total delivery attempts including the first (default: 3). Retries back off exponentially from 200ms.
  • :require_https — reject http:// webhook URLs (default: false).
  • :block_private_ips — reject loopback, link-local and RFC 1918 hosts (default: false).

Why the hardening is off by default

The spec makes SSRF protection and HTTPS a SHOULD for the agent, not a MUST, and both break ordinary local development — a webhook receiver on localhost is how the A2A compliance suite itself tests delivery. Turn them on for an agent that accepts webhook URLs from untrusted callers:

MyAgent.start_link(
  push_sender: {A2A.PushNotificationSender.HTTP,
                require_https: true, block_private_ips: true}
)