A2UI Agent implementation
The python/a2ui_agent/src/a2ui directory contains the Python implementation of
the A2UI agent SDK.
Core Components
The following directories contain the base protocol logic, parsing, and schema operations directly under src/a2ui/:
Schema Management (src/a2ui/schema)
manager.py: TheA2uiSchemaManagerhandles loading specification schemas, managing catalogs, and generating system prompts for LLMs.catalog.py: DefinesA2uiCatalogandCatalogConfigfor handling component libraries.A2uiCatalog.validate_componentschecks components against the catalog schema with thea2ui-corePayloadValidator.
Parser (src/a2ui/parser)
parser.py: Implementation ofparse_responsefor synchronous parsing.streaming.py: Incremental streaming parsers with automatic JSON healing and validation.payload_fixer.py: Utilities to automatically correct common LLM output issues in A2UI payloads.
Basic Catalog (src/a2ui/basic_catalog)
provider.py: Implementation ofBasicCatalogfor handling the basic A2UI components.
A2A (src/a2ui/a2a)
extension.py: Utilities for managing the A2UI extension URI and activation logic.parts.py: Utilities for creating A2A Parts with A2UI data and helpers for response parsing.
ADK Extensions (src/a2ui/adk)
Support for the Agent Development Kit (ADK) and A2A protocol.
send_a2ui_to_client_toolset.py: Implementation ofSendA2uiToClientToolsetto enable agents to send UI to clients via tool calls.
Running tests
-
Navigate to the package directory:
cd python/a2ui_agent
-
Run the tests
uv run pytest
Building the SDK
Building from source regenerates the Express parser from
specification/inference_formats/express/Express.g4. That step runs ANTLR, which
requires a Java runtime (JRE 11 or newer) on the PATH.
To build the SDK, run the following command from the python/a2ui_agent
directory:
uv build
Formatting code
To format the code, run the following command from the python
directory:
uv run pyink .
Releasing the SDK
See internal guidance at go/a2ui-release-pipy.
Disclaimer
Important: The sample code provided is for demonstration purposes and illustrates the mechanics of A2UI and the Agent-to-Agent (A2A) protocol. When building production applications, it is critical to treat any agent operating outside of your direct control as a potentially untrusted entity.
All operational data received from an external agent—including its AgentCard, messages, artifacts, and task statuses—should be handled as untrusted input. For example, a malicious agent could provide crafted data in its fields (e.g., name, skills.description) that, if used without sanitization to construct prompts for a Large Language Model (LLM), could expose your application to prompt injection attacks.
Similarly, any UI definition or data stream received must be treated as untrusted. Malicious agents could attempt to spoof legitimate interfaces to deceive users (phishing), inject malicious scripts via property values (XSS), or generate excessive layout complexity to degrade client performance (DoS). If your application supports optional embedded content (such as iframes or web views), additional care must be taken to prevent exposure to malicious external sites.
Developer Responsibility: Failure to properly validate data and strictly sandbox rendered content can introduce severe vulnerabilities. Developers are responsible for implementing appropriate security measures—such as input sanitization, Content Security Policies (CSP), strict isolation for optional embedded content, and secure credential handling—to protect their systems and users.
Release files for a2ui-agent-sdk 0.7.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| a2ui_agent_sdk-0.7.0.tar.gz | 256.9 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| a2ui_agent_sdk-0.7.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 501.0 kB
Release files / a2ui_agent_sdk-0.7.0.tar.gz
| Download URL | a2ui_agent_sdk-0.7.0.tar.gz |
|---|---|
| Size | 256.9 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
db2a028779bf9961825125ea2cdb4c188db0b5721fd2d51ffa5e7ac0a7125b30
|
|
BLAKE2b-256 checksum How to use checksums |
1c5a99417fcc47103ecadd70a2b17c89698c20d217d68d39fed11531c762726f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.2.0 CPython/3.11.2
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by Google Cloud, verified by PyPI on Sep 28, 2026.
Transparency logRelease files / a2ui_agent_sdk-0.7.0-py3-none-any.whl
| Download URL | a2ui_agent_sdk-0.7.0-py3-none-any.whl |
|---|---|
| Size | 244.1 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
f4ab1a3bcbda226698497fe646123a1c87b5c31dcdae129f68a470afb50de1e1
|
|
BLAKE2b-256 checksum How to use checksums |
c4ecf062d7af989a34d85ec9dd47b1f550c691ffdfd7fbbd16f75f0e7df13f28
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.2.0 CPython/3.11.2
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by Google Cloud, verified by PyPI on Sep 28, 2026.
Transparency log