Class JdkA2AHttpClient

java.lang.Object
org.a2aproject.sdk.client.http.JdkA2AHttpClient
All Implemented Interfaces:
A2AHttpClient

public class JdkA2AHttpClient extends Object implements A2AHttpClient
Default HTTP client implementation using JDK 11+ HttpClient.

This is the fallback implementation used when no higher-priority A2AHttpClientProvider is available. It provides full support for:

  • HTTP/2 with automatic fallback to HTTP/1.1
  • Synchronous GET, POST, and DELETE requests
  • Asynchronous Server-Sent Events (SSE) streaming

Security Note: The default client does not follow HTTP redirects automatically to prevent credential leakage to third-party origins. To enable redirect following for a POST request, supply a redirect-capable HttpClient via JdkA2AHttpClient(HttpClient) and call followRedirects(true) on the builder. Both steps are required.

Host header limitation: the underlying JDK HttpClient rejects addHeader("Host", ...) with an IllegalArgumentException ("restricted header name") unless the JVM is started with -Djdk.httpclient.allowRestrictedHeaders=host. This is a JDK-wide restriction that cannot be worked around per-client-instance. Applications that need to send an explicit Host header (for example, connecting directly to an instance while presenting the hostname a load balancer normally supplies) should either set that system property or use an A2AHttpClient implementation that does not build on java.net.http.HttpClient, such as org.a2aproject.sdk.client.http.vertx.VertxA2AHttpClient (the a2a-java-sdk-http-client-vertx extra), which has no such restriction.

Provider Priority: 0 (lowest - used as fallback)

This implementation is registered via JdkA2AHttpClientProvider in the ServiceLoader system and is automatically used by A2AHttpClientFactory when no other provider is available.

See Also:
  • Constructor Details

    • JdkA2AHttpClient

      public JdkA2AHttpClient()
      Creates a new JDK-based HTTP client with secure defaults.

      Configures the client with:

      • HTTP/2 preferred (with HTTP/1.1 fallback)
      • No automatic redirect following (security hardening to prevent credential leakage)

      To enable redirect following for POST requests, use JdkA2AHttpClient(HttpClient) with a redirect-capable HttpClient and call followRedirects(true) on each A2AHttpClient.PostBuilder. Both steps are required: the builder flag selects which underlying client is used; supplying a redirect-capable client alone has no effect if the flag is not set.

    • JdkA2AHttpClient

      public JdkA2AHttpClient(HttpClient httpClient)
      Creates a new JDK-based HTTP client using a caller-provided JDK HttpClient.

      This constructor allows full control over the HttpClient configuration. The caller is responsible for ensuring the client is configured securely.

      POST redirect opt-in requires two steps: this client is only used for a POST request when followRedirects(true) is also called on the builder. If the flag is not set the builder uses an internal no-redirect client regardless of the policy configured on the httpClient supplied here.

      Parameters:
      httpClient - the JDK HTTP client to delegate requests to
      Throws:
      IllegalArgumentException - if httpClient is null
    • JdkA2AHttpClient

      public JdkA2AHttpClient(HttpClient httpClient, SSEParserConfig sseParserConfig)
      Creates a new JDK-based HTTP client using a caller-provided JDK HttpClient and custom SSE parser limits.
      Parameters:
      httpClient - the JDK HTTP client to delegate requests to
      sseParserConfig - the SSE parser configuration to use for streaming responses
      Throws:
      IllegalArgumentException - if httpClient or sseParserConfig is null
  • Method Details