Foundry A2A tool returns 404 "Failed to fetch agent card" when one Foundry agent calls another

Manikanta Ravi Teja 0 Reputation points
2026-10-01T14:11:09.1433333+00:00

I'm trying to connect two agents in the same project (new Foundry portal) over the A2A protocol, and every call fails.

Setup

Target agent (<target-agent>): a prompt agent with a Fabric IQ (OneLake Catalog) tool. The A2A protocol is set up and shows Active. Endpoint: https://<resource>.services.ai.azure.com/api/projects/<project>/agents/<target-agent>/endpoint/protocols/a2a

Calling agent (<master-agent>): a prompt agent with an Agent2agent (A2A) tool pointing to the endpoint above. Authentication: Microsoft Entra → Agent Identity, audience https://ai.azure.com.

Roles: the calling agent's identity has Foundry Agent Consumer and Foundry User on the Foundry resource.

The tool's endpoint shows as an APIM gateway URL (https://<gateway>.azure-api.net/tool-...), and the agent YAML shows a2a_version: "1.0".

Error (any prompt in the playground)

Failed to fetch agent card: Response status code does not indicate success: 404 (Resource Not Found). The target A2A agent card was not found or is not accessible to the configured identity.

What I've tried

Three different target agents, all freshly created with A2A Active.

Both "Connect from Foundry" and "Connect via endpoint".

New connections and new calling agents.

Waiting for the role assignment to take effect.

From Python (a2a SDK, token from DefaultAzureCredential for https://ai.azure.com/.default), the card loads fine from <a2a endpoint>/agentCard/v0.3. So the agent and the permissions work, but the tool seems to request a different card path or version.

Other issues in the portal

In "Connect via endpoint", the Agent Card Path field rejects every value, including its own example agentCard/v1.0 ("Enter a valid agent card path…"). The Connect button stays disabled.

With the default card path, the connection saves, but the first call fails with "Connection '…' does not have a valid target URL specified". Editing it later only offers the "Connect from Foundry" tab.

Remove on an A2A tool (Tools → ⋮ → Remove) has no effect.

Questions

What is the supported way to connect one Foundry agent to another over A2A: the card path, the A2A version (0.3 or 1.0), and the audience?

How can I set the agent card path (or a2a_version) on the tool when the form won't accept it?

If a Fabric IQ tool on the target agent uses OAuth Identity Passthrough, does it work when the agent is called over A2A by another agent?

Thanks!

Artifact Signing
Artifact Signing

A fully managed end-to-end service for digitally signing code, documents, and applications. (formerly Trusted Signing)

0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.