Build the common vocabulary
Prerequisite: Basic web or API familiarity.
Purpose: Read requirements, HTTP, JSON, OAuth, and privacy without mixing their boundaries.
These questions test five situations that regularly appear in implementation and design review. They do not ask you to memorize RFC numbers; each answer explains the governing decision and what to study next.
Prerequisite: Basic web or API familiarity.
Purpose: Read requirements, HTTP, JSON, OAuth, and privacy without mixing their boundaries.
Prerequisite: Foundation course or API security experience.
Purpose: Review JWT, metadata, TLS, proof-of-possession, and current OAuth security guidance.
Prerequisite: Authentication, cryptography, or protocol-review experience.
Purpose: Keep channel binding, signatures, attestation, identity, and authorization as separate proofs.
Open a course to choose quizzes by topic. RFC numbers remain visible as the supporting references, not as the starting point.
Keep the roles of HTTP, JSON, OAuth, TLS, and privacy distinct.
Review JWT, metadata, TLS, proof-of-possession, and current OAuth security.
Treat channels, signatures, attestation, identity, and authorization as distinct evidence.
A2A (Agent-to-Agent) defines how AI agents exchange requests, progress, and results. An implementation also needs sound decisions about HTTP, authentication and authorization, peer verification, replay, and privacy. This page organizes the supporting RFCs into an eight-stage learning path.
This page is not a replacement for the A2A specification. It teaches the RFC-based design decisions needed during implementation and review.
Pick a quiz (English or Japanese). Use search to filter by RFC number, title, or keyword.