Skip to content

server: agent-card discovery returns 403 to cross-origin browser fetches when allowed_origins is set #1436

Description

@bokelley

Summary

With 9.0's shared Host/Origin policy (#1301), a request for /.well-known/agent-card.json that carries an Origin outside allowed_origins gets 403. On 8.0.0 the same request got 200. A request without Origin still gets 200. http_policy.py says the policy deliberately covers "protocol, discovery and operational HTTP paths".

Why it matters

The agent card is public metadata. Browser-based tools fetch it cross-origin: agent directories, registry UIs, playgrounds, a buyer's web console probing a seller. With Origin enforcement on discovery, a seller that sets allowed_origins to protect its protocol endpoints also hides its card from every browser tool it didn't list. MCP and A2A requests need the Origin check (DNS rebinding, CSRF against a local agent). A read of public metadata doesn't seem to.

Observed on the Embedded Sales Agent (scope3data/embedded-sales-agent) running 9.0.0b1 with ADCP_DNS_REBINDING_PROTECTION=false and an explicit allowed_origins:

request 8.0.0 9.0.0b1
GET /.well-known/agent-card.json, no Origin 200 200
same, Origin: https://other.example 200 403
MCP / A2A POST, foreign Origin 403 403

Ask

Either exempt the discovery documents (agent card, adagents.json if served) from Origin enforcement, or add a knob such as public_discovery_origins="*". Either way, document the decision in the 9.0 migration notes. If 403 is the intended behavior, a sentence in the 9.0 notes saying so would be enough.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions