Summary
With 9.0's shared Host/Origin policy (#1301), a request for /.well-known/agent-card.json that carries an Origin outside allowed_origins gets 403. On 8.0.0 the same request got 200. A request without Origin still gets 200. http_policy.py says the policy deliberately covers "protocol, discovery and operational HTTP paths".
Why it matters
The agent card is public metadata. Browser-based tools fetch it cross-origin: agent directories, registry UIs, playgrounds, a buyer's web console probing a seller. With Origin enforcement on discovery, a seller that sets allowed_origins to protect its protocol endpoints also hides its card from every browser tool it didn't list. MCP and A2A requests need the Origin check (DNS rebinding, CSRF against a local agent). A read of public metadata doesn't seem to.
Observed on the Embedded Sales Agent (scope3data/embedded-sales-agent) running 9.0.0b1 with ADCP_DNS_REBINDING_PROTECTION=false and an explicit allowed_origins:
| request |
8.0.0 |
9.0.0b1 |
GET /.well-known/agent-card.json, no Origin |
200 |
200 |
same, Origin: https://other.example |
200 |
403 |
| MCP / A2A POST, foreign Origin |
403 |
403 |
Ask
Either exempt the discovery documents (agent card, adagents.json if served) from Origin enforcement, or add a knob such as public_discovery_origins="*". Either way, document the decision in the 9.0 migration notes. If 403 is the intended behavior, a sentence in the 9.0 notes saying so would be enough.
Summary
With 9.0's shared Host/Origin policy (#1301), a request for
/.well-known/agent-card.jsonthat carries anOriginoutsideallowed_originsgets 403. On 8.0.0 the same request got 200. A request withoutOriginstill gets 200.http_policy.pysays the policy deliberately covers "protocol, discovery and operational HTTP paths".Why it matters
The agent card is public metadata. Browser-based tools fetch it cross-origin: agent directories, registry UIs, playgrounds, a buyer's web console probing a seller. With Origin enforcement on discovery, a seller that sets
allowed_originsto protect its protocol endpoints also hides its card from every browser tool it didn't list. MCP and A2A requests need the Origin check (DNS rebinding, CSRF against a local agent). A read of public metadata doesn't seem to.Observed on the Embedded Sales Agent (scope3data/embedded-sales-agent) running 9.0.0b1 with
ADCP_DNS_REBINDING_PROTECTION=falseand an explicitallowed_origins:GET /.well-known/agent-card.json, no OriginOrigin: https://other.exampleAsk
Either exempt the discovery documents (agent card,
adagents.jsonif served) from Origin enforcement, or add a knob such aspublic_discovery_origins="*". Either way, document the decision in the 9.0 migration notes. If 403 is the intended behavior, a sentence in the 9.0 notes saying so would be enough.