On a laptop an agent is a loop in one process. In production it connects to tools owned by other teams, hands work to other agents, survives restarts mid-task, and leaves a trace explaining its choices.

Two protocols: tools and neighbours

Tools are functions you call and wait for; other agents receive tasks you track by status. MCP is the standard for the first, A2A for the second.

MCP: tools by standard

A team exposes an MCP server once and any agent can connect. The server is a regular service with its own authentication; tool descriptions are part of the prompt and change carefully; the agent gets only the tools its task needs.

A2A: an agent talks to an agent

An agent publishes a card with its skills and address; work flows through tasks with statuses. Reasoning and execution stay with their owners: the support agent asks the logistics agent instead of receiving logistics tools.

{
  "name": "logistics-agent",
  "description": "Reschedules delivery, changes pickup point, reports parcel status",
  "skills": ["reschedule_delivery", "change_pickup_point"],
  "url": "https://logistics.internal/a2a"
}

How to deploy an agent

An agent version is code plus model plus instruction plus tool descriptions, released together. Long runs keep state outside the process. New versions pass evaluation and roll out gradually.

Tracing a run

One root span per user request, child spans for each model step and tool call, with model, tokens, chosen tool, duration and status. Prompts and replies are stored separately with short retention. The trace id travels into MCP servers and A2A tasks.

Limits and stopping

Per-step timeouts are not enough: cap steps, tokens, money and total time per run, and hand the task to a human when a limit fires. Add per-user and system-wide caps as with any resilience limiter.

In short

  • MCP for tools, A2A for other agents.
  • Version = code, model, instruction and tool descriptions together.
  • Durable state, gradual rollout after evaluation.
  • One trace per request, propagated through MCP and A2A.
  • Run limits on steps, tokens, money and time.