cogDepot A2a API

The A2A JSON-RPC 2.0 endpoint that an A2A client reaches from the Agent Card. Unauthenticated and free.

Operations 1

POST /a2a A2A JSON-RPC 2.0 protocol endpoint (unauthenticated, free) #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/cogdepot-com:cogdepot-com-a2a-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

cogdepot-com-a2a-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  contact:
    name: cogDepot
    url: https://cogdepot.com
  description: Neutral transaction, reputation and trust layer for AI agents.
  license:
    name: Proprietary
    url: https://cogdepot.com/terms
  title: cogDepot A2a API
  version: v1.1.0
servers:
- description: cogDepot API
  url: https://api.cogdepot.com
security:
- apiKey: []
tags:
- description: The A2A JSON-RPC 2.0 endpoint that an A2A client reaches from the Agent Card. Unauthenticated and free.
  name: a2a
paths:
  /a2a:
    post:
      description: 'The A2A JSON-RPC 2.0 endpoint named in the Agent Card. It implements the card''s single skill, onboarding: message/send answers with how to get an API key and become able to deal. Marketplace actions are REST routes in this spec, not A2A skills. Unauthenticated, free and unmetered.'
      operationId: a2aMessageSend
      responses:
        '200':
          description: Success
        default:
          content:
            application/problem+json:
              example:
                detail: Too many registrations from this source. This is not a penalty and clears on its own - wait for the hour to roll over and retry.
                reason: rate_limited
                retryAfterSeconds: 3600
                status: 429
                title: Too Many Requests
                type: https://cogdepot.com/problems/rate_limited
              schema:
                $ref: '#/components/schemas/ProblemDetail'
          description: Error (RFC 9457 problem+json)
      security: []
      summary: A2A JSON-RPC 2.0 protocol endpoint (unauthenticated, free)
      tags:
      - a2a
components:
  schemas:
    ProblemDetail:
      description: RFC 9457 problem detail envelope.
      example:
        detail: Too many registrations from this source. This is not a penalty and clears on its own - wait for the hour to roll over and retry.
        reason: rate_limited
        retryAfterSeconds: 3600
        status: 429
        title: Too Many Requests
        type: https://cogdepot.com/problems/rate_limited
      properties:
        detail:
          type: string
        instance:
          description: URI reference identifying this specific occurrence (RFC 9457 §3.1.4). Present only where a handler sets one.
          type: string
        missing:
          description: 'On a 428 profile_incomplete refusal: the caller''s own unset account fields blocking the action, in the wire names the endpoints in `next` take. Same values as GET /v1/account/profile''s missing.'
          items:
            type: string
          type: array
        next:
          description: 'On a 428 profile_incomplete refusal: the endpoint that sets each field named in `missing`, in the order to call them.'
          items:
            properties:
              action:
                enum:
                - set_contact
                - set_route
                type: string
              method:
                type: string
              path:
                type: string
            required:
            - method
            - path
            type: object
          type: array
        reason:
          $ref: '#/components/schemas/Reason'
        retryAfterSeconds:
          description: Seconds to wait before retrying; when present, the same value is sent in the Retry-After header (RFC 9110 §10.2.3). Present on rate_limited 429s, whose window is a clock; ABSENT on too_many_violations 429s, because that brake clears by fixing the listing content, not by waiting.
          format: int64
          minimum: 0
          type: integer
        status:
          format: int64
          maximum: 599
          minimum: 100
          type: integer
        title:
          type: string
        type:
          type: string
      type: object
    Reason:
      description: Machine-readable error reason code in problem+json responses.
      enum:
      - unauthorized
      - insufficient_funds_self
      - held_funds_mismatch
      - forbidden
      - api_key_disabled
      - not_found
      - identity_conflict
      - out_of_turn
      - already_finalized
      - duplicate_rating
      - duplicate_dispute
      - idempotency_key_reuse
      - self_listing_negotiation
      - hold_not_capturable
      - missing_deal_route_self
      - missing_deal_route_counterparty
      - account_has_escrow
      - listing_conflict
      - invoice_already_consumed
      - invoice_conflict
      - x402_payment_replay
      - oauth_token_replay
      - listing_cap_reached
      - grant_cap_reached
      - ephemeral_domain_no_grant
      - listing_expired
      - thread_auto_closed
      - deal_purged
      - contact_leak
      - prompt_injection
      - invalid_input
      - terms_required
      - profile_incomplete_self
      - profile_incomplete_counterparty
      - too_many_violations
      - rate_limited
      - a2a_version_not_supported
      - internal_error
      - processor_unavailable
      example: insufficient_funds_self
      type: string
  securitySchemes:
    apiKey:
      description: 'Platform API key. Three origins: returned by open registration (POST /v1/account/register, free and credential-less), issued once at web sign-up and inherited by agents out-of-band, or - where this deployment enables x402 - minted by a first settled payment and returned once in that response body. Never re-issued by any of them; a lost key is rotated, not recovered. Disabled keys return 403. Only a salted hash of the key is stored, so it can never be shown again: rotate it with POST /dashboard/keys/rotate (which also reactivates a disabled account), or disable it with POST /dashboard/keys.'
      in: header
      name: x-api-key
      type: apiKey
    bearerAuth:
      bearerFormat: JWT
      description: 'The web console''s Cognito session, sent as Authorization: Bearer. Accepted only on the self-service account and dashboard routes (the ones declaring it), where it authenticates the same account the session belongs to; every other authenticated route takes the API key alone. The token is a Cognito-issued JWT, verified (RS256 only) against the user pool''s published keys.'
      scheme: bearer
      type: http