Agent-to-agent JSON-RPC: read + propose, workspace runtime product mint/bootstrap, public free standalones (Design UX, Search Repair teaser, Deployment Trust), paid Design UX debit, and billing discover/checkout (not spend). Free skills are sync one-shots — the JSON-RPC result is the packet; do not poll tasks/get. Public discovery is not authority. Raw secrets rejected. No publish, deploy, or approve. A2A taskStore is in-process non-durable memory (not a durable task DB). Durable mission work lives in mission_sessions. Calling convention: JSON-RPC 2.0 over HTTP POST to /api/a2a. message/send needs params.skill (a skill id from this card) — a standard A2A Message without params.skill is rejected, so this is not a drop-in standard A2A Message client.