Describe the bug
My setup:
- A2A Main service
- A2A Subagent
- MCP server (exposed as tool of A2A Subagent) The MCP service is defined via @cap_js/mcp annotation and is refered to as:
cds.requires. "mcp-bpread": {"kind": "mcp", "credentials": { "destination": "mymcp_bpread","path": "/bpread"} },
I am using IAS as authentication against the A2A main service. All of the 3 components are created as separate services in a single CAP 10 project and bound to the same IAS app.
Then I ask a question that invokes the subagent that invokes the MCP server.
I get a 401 of the MCP server as JWT seems to not flow down all the way to the MCP server invokation.
To Reproduce
Steps to reproduce the behavior:
as described above. I did create a trimmed down version of my use case that can be found here:
https://github.com/franksgit/cap_js_agent_subagent_2_mcp_jwt_issue_demo/tree/main
Expected behavior
The JWT injected in the main A2A agent should be propagated down to the A2A subagent and its MCP server tools, even when using destinations.
Quick explaination why I did this setup. (as said it is a trimmed down version of my wider testing):
I wanted to have PoC capabilities where I deploy from a single CAP project a multi agent setup. The split between subagent and the actions implemented in separate service is needed to be compliant with the API policy of SAP to actually expose calls that happen to the S/4 backend via the MCP gateway. In my demo repo linked above, I am simulating the MCP gateway by having a separate MCP enabled service. In reality it would be a service that exposes the API as rest actions that are then consumed/exposed in the MCP gateway. As the URL of the MCP sever from the MCP gateway is different than the URLs of the CAP service, I need MCP destination in between.
[ ] is it a regression issue?
Screenshots
If applicable, add screenshots to help explain your problem.
Customer Info
Company: xyz.
Describe the bug
My setup:
cds.requires. "mcp-bpread": {"kind": "mcp", "credentials": { "destination": "mymcp_bpread","path": "/bpread"} },
I am using IAS as authentication against the A2A main service. All of the 3 components are created as separate services in a single CAP 10 project and bound to the same IAS app.
Then I ask a question that invokes the subagent that invokes the MCP server.
I get a 401 of the MCP server as JWT seems to not flow down all the way to the MCP server invokation.
To Reproduce
Steps to reproduce the behavior:
as described above. I did create a trimmed down version of my use case that can be found here:
https://github.com/franksgit/cap_js_agent_subagent_2_mcp_jwt_issue_demo/tree/main
Expected behavior
The JWT injected in the main A2A agent should be propagated down to the A2A subagent and its MCP server tools, even when using destinations.
Quick explaination why I did this setup. (as said it is a trimmed down version of my wider testing):
I wanted to have PoC capabilities where I deploy from a single CAP project a multi agent setup. The split between subagent and the actions implemented in separate service is needed to be compliant with the API policy of SAP to actually expose calls that happen to the S/4 backend via the MCP gateway. In my demo repo linked above, I am simulating the MCP gateway by having a separate MCP enabled service. In reality it would be a service that exposes the API as rest actions that are then consumed/exposed in the MCP gateway. As the URL of the MCP sever from the MCP gateway is different than the URLs of the CAP service, I need MCP destination in between.
[ ] is it a regression issue?
Screenshots
If applicable, add screenshots to help explain your problem.
Customer Info
Company: xyz.