Default A2A.PushNotificationSender, POSTing payloads with Req.
Available only when the optional :req dependency is present, and used
automatically when it is.
Options
:timeout— per-attempt receive timeout in ms (default:15_000). The spec recommends 10-30s.:attempts— total delivery attempts including the first (default:3). Retries back off exponentially from 200ms.:require_https— rejecthttp://webhook URLs (default:false).:block_private_ips— reject loopback, link-local and RFC 1918 hosts (default:false).
Why the hardening is off by default
The spec makes SSRF protection and HTTPS a SHOULD for the agent, not a
MUST, and both break ordinary local development — a webhook receiver on
localhost is how the A2A compliance suite itself tests delivery. Turn
them on for an agent that accepts webhook URLs from untrusted callers:
MyAgent.start_link(
push_sender: {A2A.PushNotificationSender.HTTP,
require_https: true, block_private_ips: true}
)