# Setup — connect an agent to A2A Grocery

MCP door: https://mcp.a2a-grocery.ai/mcp (streamable-http, protocol 2025-06-18, server name a2a-grocery). Agent Card: https://a2a-grocery.ai/.well-known/agent-card.json (ES256, kid a2ag-2026-10); keyring https://a2a-grocery.ai/.well-known/jwks.json. Registry name io.github.greencore-solutions/a2a-grocery.

## Connect

Any MCP client: { "url": "https://mcp.a2a-grocery.ai/mcp", "transport": "streamable-http" }

First three calls: resolve_jurisdiction → resolve_actor → gate_transaction. No availability, price, documents, order or handoff tool answers before an allow decision exists.

## Credentials by actor class

- Reads: no authentication
- Maker / brand owner / private label / distributor / importer / broker / retail buyer: register at https://a2a-registry.ai/oauth/register with hub grocery, take a client-credentials Bearer and present it on the write tools (see /auth.md)
- Agent: inherits the class of the credential it presents; none → DENY_UNLICENSED_AGENT
- Auditor: read-only, issued by the operator
- Settlement: x402, USDC on Base, after the gate; receipts signed; front door https://a2a-pay.ai/

## Claim

A maker claims its listed records at https://a2a-grocery.ai/claim; verification lands before trade.
