Workday A2A Tester Run locally ← Apps

Workday A2A Tester

Prove the Workday side works before you blame Copilot Studio.

A local test harness that validates your Workday Agent2Agent (A2A) connection to the Self-Service Agent end‑to‑end — ISU token, Agent Card discovery, delegated OAuth (PKCE), and a live message/send chat — before you wire it into Copilot Studio or Gemini.

It runs on your own machine and talks only to your own Workday Agent Gateway. Credentials are typed into the interface at runtime and held in memory for the life of the process; nothing is written to disk and nothing is sent anywhere else.

Download the bundle Read the usage guide

Free to use, copy and modify, with attribution retained. Python 3.9+. Independent tool — not affiliated with, endorsed by, or supported by Workday, Inc.

Why it exists

When an external agent cannot reach the Self-Service Agent, the failure surfaces inside Copilot Studio or Gemini — a platform that tells you very little about which half is broken. Four separate things have to be right first: the ISU client and its scope, the agent registration in ASOR, the delegate OAuth client and its redirect URI, and the A2A endpoint itself.

This walks those four in order, with the raw request and response visible at every step, so the answer to “is it Workday or is it my platform?” takes minutes rather than a support ticket.

What it checks

  1. ISU bearer token — refresh_token grant against /auth/oauth2/<tenant>/token. Proves the Integration System User client exists and carries the Agent System of Record scope.
  2. Agent Card — a GET of /.well-known/agent-card.json for your tenant and resource ID. Proves the SSA is A2A‑enabled and reachable, and yields the discovery document you paste into your external platform. There is a button to save it as JSON.
  3. Delegate OAuth — Authorization Code + PKCE (S256) in a pop‑up against your registered delegate client. Proves the redirect URI matches, the secret is current, and the signing‑in user is permitted. A Refresh Delegate Token button mints a new access token without a fresh login.
  4. A live chat — JSON‑RPC message/send to the URL the Agent Card advertises, using the delegate token. Ask “what is my remaining time off balance?” and read the answer. That is the whole path working.

The ISU token and the delegate token are independent and used at different moments: the ISU token only fetches the card; the delegate token is the signed‑in user’s, and is what the chat calls carry.

Reading what happened

Live Verbose Logs in the left panel show every request and response as it happens. Raw API Response Payload on the right holds the JSON from the most recent call, with a Download JSON button — useful for attaching to a Workday support ticket.

What is in the bundle

Or take the files individually: workday_a2a_tester.py · usage guide · RegisterAgent.sample.json

Running it

pip install fastapi uvicorn requests

The OAuth redirect is HTTPS, so it needs a certificate for localhost. Generate a self‑signed pair in the same folder as the script:

openssl req -x509 -newkey rsa:2048 -nodes -keyout key.pem -out cert.pem \
  -days 365 -subj "/CN=localhost" \
  -addext "subjectAltName=DNS:localhost,IP:127.0.0.1"
python workday_a2a_tester.py

Then open https://localhost:8080 and accept the certificate warning — and accept it again on the OAuth callback pop‑up.

What you need from Workday

Tenant alias & regionregion is one of US, EU, UK, SIN, IND, JPN — the gateway host that fronts your tenant
ISU OAuth clientscoped to Agent System of Record, with a refresh token
A registered delegate agentAuthorization Code client with a client ID, a client secret, and redirect URI https://localhost:8080/callback — matching character for character
Your own Workday loginthe person the agent acts on behalf of, in a security group assigned to the SSA

Not registered the external agent yet? Section 3 of the usage guide covers it — ASOR defines and registers in a single POST, then you activate the agent in the Agent Registry and Workday creates the agent system user and security group for you. Note that Workday matches on name + version + provider: repost the same three and it updates the existing registration; change any of them and you get a second agent.

Common failures

SymptomUsually
invalid_client on token exchangestale client secret, or the redirect URI does not match
redirect_uri_mismatch at authorizescheme, host, port, path or trailing slash differs from what is registered
401 on the Agent Cardthe ISU client is missing the Agent System of Record scope, or its refresh token has expired
Refresh Delegate Token failsthe delegate refresh token expired — run the full OAuth flow again
Port 8080 in usean earlier instance is still running

Delegate access tokens last about four hours and refresh tokens about a day, so a long testing session will need a refresh at some point.

Before you run it

This is a testing aid, not a production service. Run it on a machine you control, with credentials for a sandbox tenant where you can. Do not commit real credentials, cert.pem or key.pem to source control.

Once all four pass

Hand the same values to your external platform: the downloaded Agent Card, the authorize and token endpoint URLs from the agent’s profile, the delegate client ID and secret, and PKCE with S256. If the harness can hold a conversation with the Self-Service Agent and Copilot Studio cannot, the remaining problem is on that side — which is a much shorter list to work through.