Connect Custom Agents to External Agents using A2A
- Register External Agents.Ensure that you include a body payload containing the target 3P agent metadata, platform ID, and the Self-Service Agent tool skill configuration (ssa-agent-as-a-tool / resource ID 6bfadd7c014610000dffae8d77c00000).
You can connect Custom Agents to external agents, such as Google Gemini Enterprise, using the industry Agent2Agent (A2A) protocol. When you register a third-party client in Workday's Agent System of Record (ASOR), you can enable that agent to discover and call the Custom Agent on behalf of an authorized user.
For detailed instructions for how to connect Workday to Gemini Enterprise, see Set Up Sana From Workday for Gemini Enterprise.
This functionality is for Extend Professionals only.
- Create a Custom Agent (3P) Agent Definition in ASOR that references your Custom Agent as tools. Workday recommends creating a new agent definition per client system you integrate with, not per Custom Agent.
- Access theAgent Management Hub.
- In Agent Registry, select from the related action of the Custom Agent.
- Copy the Workday ID.
- Access the Workday Development Site.
- Connect to the relevant tenant and selectCopy Token.
- Call the ASOR REST API and create a new request to register your agent using an external API Client, Example: Bruno.As you create the request, consider:
- Endpoint: https://us.agent.workday.com/asor/v1/agentDefinition
- Operation: POST
- Body: Refer to ASOR v1.2 API documentation on Github and ASOR JSON Swagger documentation sample.
- Headers:
- Authorization: Bearer <token>
- wd-agent-tenant-alias: <your tenant name>
Example:curl --request post \ --url https://us.agent.workday.com/asor/v1/agentDefinition \ --header 'Authorization: {{bearer token}}' \ --header 'Content-Type: application/json' \ --header 'wd-agent-tenant-alias: {{tenant-alias}}' --data' "name": "Custom Agent via A2A", "description": "3P Agent Definition to enable connectivity between Custom Agents and a 3P System", "provider": { }, "id": "Provider=SELF-BUILT" "url": "https://us.agent.workday.com", "platform": { }, "id": "Platform=OTHER" "skills": [ { "description": "This skill enables connectivity to Custom Agents.", "id": "custom-agent-as-a-tool", "inputModes": [ { "type": "text/plain" } ], "name": "Custom Agent", "outputModes": [ { "type": "text/plain" }, "type": "application/json" } ] } , "workdayConfig": [ { "workdayResources":[ { } ], "description": "Custom Agent as a tool", "tool name": "Custom Agent as Tool", "agent resource": { "id": "{{Custom Agent wid}}" } } ], "executionMode": { "id": "Mode=Delegate" }, "skillId": "custom-agent-as-a-tool" }' "capabilities": { }, "stateTransitionHistory": false, "streaming": false, "pushNotifications": false "supportsAuthenticatedExtendedCard": false, "version": "v1"
- Configure and activate 3P agent in App Registry:
- Access theAgent Management Hub.
- InAgent Registry, select the 3P agent just created.
- From the agent's profile view, clickConfigure Agent.
- In theStatuscolumn, make each relevant skill available by enabling the toggle slider.
- For each available delegate execution mode skill, populate theAvailable Toprompt and determine the security groups that you want to add for that specific skill for the agent.The security groups you select in theAvailable Toprompt must also have permissions to the domain or business process security policies that secure the agents' tools. You can use theView Security for Agent Skillreport to assist with your agent security configurations. This report shows you detailed information about the agent's Tools APIs and the respective domain or business process security policies and permissions. At agent runtime, Workday evaluates both user access to the agent and the user access to the APIs the agent is executing as tools.
- Click theConfirmcheck box, and then clickOK.
- For delegate skills, add the relevant redirect url for the client system you are connecting to.
- ClickOK.
- When you configure the agent for the first time, we display the OAuth client details for the agent.
- Copy and save the Client ID and Client Secret values. This page won't display again and you won't be able to access this information again.SelectAgent Registry, and click the agent you want to activate.
- From the agent's profile view, clickActivate Agent. On theActivate Agentwindow, select theConfirmcheck box, and thenOKto complete the activation.
- Create or reuse an ISU OAuth client:
- Log in to Workday asSystem Admin.
- Access theCreate Integration System Usertask (if you don't have a suitable ISU already).
- Access theRegister API Client for Integrationstask and:
- SelectAgent System of Recordfrom theFunctional Areaprompt.
- Check theInclude Workday Owned Scopescheck box.
- Save Client ID and Client secret.
- On the client:
- Click .
- Select the ISU that you created.
- Generate a new refresh token.
- Record the new refresh token.
- You now have:
- CLIENT_ID / CLIENT_SECRET (integration client)
- REFRESH_TOKEN (ISU)
- Generate an ISU bearer token.
- Send a POST using POST ISU Bearer Token.yaml in your preferred API client.Example:curl --request POST --url https://us.agent.workday.com/auth/oauth2/TENANT ALIAS/toke n --header 'Content-Type: application/x-www-form-urlencoded' --data 'grant_type=refresh_token' --data 'refresh token={{refresh token}}' --data 'client id={{client id}}' --data 'client_secret={{client secret}}'
- Save the returned ISU Bearer Token.
- Retrieve the Agent Card JSON using the GET Agent Card.yaml in your preferred API Client:curl --request GET --url https://us.agent.workday.com/v1/a2a/TENANT ALIAS/AGENT ID/ .well-known/agent-card.ison --header 'Authorization: Bearer {{bearer token}}' --header 'Accept-Encoding: identity' --header 'Content-Type: application/json'
- Save the JSON response. This is your Agent Card.
- Configure the external platform.
- Import/paste the Agent Card JSON into your external Al platform.
- Configure these OAuth settings in the external platform, referencing the details provided in the Connectivity Tab of the Agent you configured:
- Client IDandClient Secret.
- PKCE: Enable PKCE.
- Auth URL: https://<region-code>.agent.workday.com/auth/authorize/<tenant-alias>?response_type=code.
- Token URL: https://<region-code>.agent.workday.com/auth/oauth2/<tenant-alias>/token.
- Redirect URL: Ensure it matches the Redirect URI from theConfigure activate 3P agent in App Registrystep above.
Your external platform can now use the 3P agent.