A2A scope mappings now live on the interface itself, with proper support for custom mount prefixes. Routes served under a non-default prefix get the scope checks they're supposed to, so authorization holds up no matter how you mount your A2A interface.
Learn more in the A2A docs.