Skip to main content

A2UI Agent implementation

The python/a2ui_agent/src/a2ui directory contains the Python implementation of the A2UI agent SDK.

Core Components

The following directories contain the base protocol logic, parsing, and schema operations directly under src/a2ui/:

Schema Management (src/a2ui/schema)

  • catalog.py: Defines CatalogConfig, which loads a component catalog as an a2ui.core.Catalog, and load_examples, which reads few-shot examples and can validate them against the catalogs.

Catalog transformers (src/a2ui/catalog_transformers)

  • pruning.py: ComponentPruningTransformer and FunctionPruningTransformer return a copy of a catalog that keeps only the allowed components or functions. Pass them to CatalogConfig as transformers.

Utilities (src/a2ui/utils)

  • catalog_resolver.py: resolve_catalogs returns the catalogs that are active for the capabilities that a renderer sent.
  • schema_pruning.py: prune_messages_schema and prune_common_types_schema reduce the protocol schemas to the allowed messages and the common types that are referenced.
  • validation.py: validate_payload checks a payload the way a renderer holding the catalogs would, and raises A2uiValidationError if the renderer would reject it.

Parser (src/a2ui/parser)

  • parser.py: Implementation of parse_response for synchronous parsing.
  • streaming.py: Incremental streaming parsers with automatic JSON healing and validation.
  • payload_fixer.py: Utilities to automatically correct common LLM output issues in A2UI payloads.

A2A (src/a2ui/a2a)

  • extension.py: Utilities for managing the A2UI extension URI and activation logic.
  • parts.py: Utilities for creating A2A Parts with A2UI data and helpers for response parsing.

ADK Extensions (src/a2ui/adk)

Support for the Agent Development Kit (ADK) and A2A protocol.

  • send_a2ui_to_client_toolset.py: Implementation of SendA2uiToClientToolset to enable agents to send UI to clients via tool calls.

Running tests

  1. Navigate to the package directory:

    cd python/a2ui_agent
    
  2. Run the tests

    uv run pytest
    

Building the SDK

To build the SDK, run the following command from the python/a2ui_agent directory:

uv build

The build doesn't need Java. The Express lexer, parser, and visitor in src/a2ui/inference_formats/experimental/express/generated/ are generated from specification/inference_formats/express/Express.g4 and committed to the repository.

Regenerating the Express parser

After changing Express.g4, regenerate the parser from the python/a2ui_agent directory and commit the result:

uv run python scripts/generate_express_parser.py

The script runs ANTLR 4.13.2 through antlr4-tools from the dev dependency group. ANTLR needs a Java runtime (JRE 11 or newer) on the PATH, and antlr4-tools downloads the ANTLR jar on first use. Add --check to compare the committed files with the grammar without changing them. CI runs this check.

Formatting code

To format the code, run the following command from the python directory:

uv run pyink .

Releasing the SDK

See internal guidance at go/a2ui-release-pipy.

Disclaimer

Important: The sample code provided is for demonstration purposes and illustrates the mechanics of A2UI and the Agent-to-Agent (A2A) protocol. When building production applications, it is critical to treat any agent operating outside of your direct control as a potentially untrusted entity.

All operational data received from an external agent—including its AgentCard, messages, artifacts, and task statuses—should be handled as untrusted input. For example, a malicious agent could provide crafted data in its fields (e.g., name, skills.description) that, if used without sanitization to construct prompts for a Large Language Model (LLM), could expose your application to prompt injection attacks.

Similarly, any UI definition or data stream received must be treated as untrusted. Malicious agents could attempt to spoof legitimate interfaces to deceive users (phishing), inject malicious scripts via property values (XSS), or generate excessive layout complexity to degrade client performance (DoS). If your application supports optional embedded content (such as iframes or web views), additional care must be taken to prevent exposure to malicious external sites.

Developer Responsibility: Failure to properly validate data and strictly sandbox rendered content can introduce severe vulnerabilities. Developers are responsible for implementing appropriate security measures—such as input sanitization, Content Security Policies (CSP), strict isolation for optional embedded content, and secure credential handling—to protect their systems and users.

Metadata

Release files for a2ui-agent-sdk 0.8.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for a2ui-agent-sdk 0.8.0
File Size Uploaded
a2ui_agent_sdk-0.8.0.tar.gz 276.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for a2ui-agent-sdk 0.8.0
File Interpreter ABI Platform
a2ui_agent_sdk-0.8.0-py3-none-any.whl Python 3 none any Details

Total release size: 518.1 kB

Release files / a2ui_agent_sdk-0.8.0.tar.gz

Download URL a2ui_agent_sdk-0.8.0.tar.gz
Size 276.2 kB
Tags Source
SHA-256 checksum
How to use checksums
dc036d6094147dd7be3f817243e71b49d8f472ce1fe8414c3b2a84acc2d34a31
BLAKE2b-256 checksum
How to use checksums
1d7c571c04830b74b7faf1c057b41c7e4358906f2f385fb074862da66e6755dd
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.2.0 CPython/3.11.2

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by Google Cloud, verified by PyPI on Oct 8, 2026.

Transparency log

Release files / a2ui_agent_sdk-0.8.0-py3-none-any.whl

Download URL a2ui_agent_sdk-0.8.0-py3-none-any.whl
Size 241.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
bc8708fcb40a589bb9e71845054daaab7b1f86641d91e8a34e78a42ea6df1e5a
BLAKE2b-256 checksum
How to use checksums
19894e03430b0be6530f8e7c0589c47b6b8c88ebaaf341d8c82e6af18b549b06
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.2.0 CPython/3.11.2

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by Google Cloud, verified by PyPI on Oct 8, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.8.0 This release

2 release files

0.7.0

2 release files

0.6.0

2 release files

0.5.0

2 release files

0.4.0

2 release files

0.3.0

2 release files

0.2.4

2 release files

0.2.3

2 release files

0.2.2

2 release files

0.2.1

2 release files

0.2.0

2 release files

0.1.2

2 release files

0.1.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page