Personal Agent Protocol draft 0.1 was published on 9 Oct 2026 · What goes in poppy.json →
Personal Agent Protocol checker

What can a personal agent do with your company?

Your poppy.json sets what a personal agent can do with you: how it finds you, how your customers sign in, what it may view or change, and which APIs, pages and company agent it can use. Check it against the published draft.

Free · read-only · no sign-up · what we check

13 domains checked· 2 publishing poppy.json· rules from draft 0.1 (9 Oct 2026)
How it works

One request, from your agent to a done change

What happens when a personal agent works with a company over the Personal Agent Protocol. Steps 2 and 3 are what we check from outside; the rest happens inside a live session. A fictional company, with the draft's section for each step.

  1. “Move my grocery delivery to Saturday morning and add oat milk.”
  2. GET /.well-known/poppy.json
  3. POST /oauth/token · signed-out session
  4. delivery_slots → Sat 9–11 open
  5. change_order needs poppy:write
  6. Sign in on the company’s own page?
  7. Proposed: order #4821 → Sat 9–11, + oat milk, +$3.49
  8. Approve
  9. confirm revision 1 → changed, once
Directory

Who publishes poppy.json

Every domain we have found with a Personal Agent Protocol discovery file, and the day we first saw it. We recheck them weekly.

SiteOrganizationSign-inRoutesFirst seen
poppy-receiver.roundtrip.workers.dev Northstar Outfitters demo direct company agentAPIswebsite 11 Oct 2026
withpoppyseed.dev Poppy Travel demo directdevicemediated company agentAPIswebsite 11 Oct 2026
View every site →
The report

Every rule, with the section it comes from

No score. Each line says which rule of the draft it checks and whether it holds: a problem, a warning, or a note.

yourcompany.com1 problem · 1 warning · 4 passed
OK
poppy.json published
Served over HTTPS at /.well-known/poppy.json
§3
OK
organization.domain matches
yourcompany.com, ignoring a leading www.
§3.1
Problem
poppy_domains does not list yourcompany.com
Agents must refuse a document whose issuer doesn't confirm the domain
§3.2
OK
Sign-in types: direct, device
Scopes poppy:read, poppy:write
§4.4
Warning
apis[1]: no description
A short description helps the agent pick the right API
§3.1
OK
apis[0]: OpenAPI 3.1 description
Reachable, and a version the draft allows
§6
What we check

Everything an agent reads before it starts

GET requests for public documents only, the way a personal agent reads them.

Discovery

HTTPS at the well-known path, redirects that stay on HTTPS, a version agents can read, and an organization.domain that matches.

Sign-in

The OAuth issuer, the sign-in types offered (direct, device, mediated), their scopes, and custom scope names.

Sign-in server

OAuth metadata at the issuer, an exact issuer match, poppy_domains listing the domain, and the endpoints each type needs.

Routes

The company agent's conversation endpoint, the website session endpoint, and each API's type, URL and description.

APIs

OpenAPI descriptions reachable and 3.0 or 3.1. MCP servers whose resource metadata names the company's issuer.

Extensions

operations and other extensions carry a version and endpoint; custom ones use a domain prefix.

Questions

Frequently asked

What is the Personal Agent Protocol?

An open protocol for how a person's AI agent works with a company on their behalf: how the agent finds the company, signs the user in, what it may do, and how it reaches the company's APIs, website or own agent. Meta and Sierra lead it; draft 0.1 was published on 9 October 2026. It is also called Poppy.

What is poppy.json?

The discovery document a company publishes at /.well-known/poppy.json. It names the organization, its OAuth issuer and sign-in types, and the APIs, website session endpoint and company agent it offers. Read the guide.

Does the check sign in or call my APIs?

No. It makes ordinary GET requests for public documents: poppy.json, the issuer's OAuth metadata, OpenAPI descriptions and MCP resource metadata. It never starts a session, signs in or sends data to your endpoints.

Is there a score?

No. Each result says which rule of the draft it checks and whether it holds: a problem (a MUST that isn't met), a warning (a SHOULD or a recommendation), or a note.

Is this the official checker?

No. PAP Checker is independent and not affiliated with the protocol's authors. The draft can change at any point before a stable version, and we update the rules when it does.

How does it relate to UCP?

The Universal Commerce Protocol covers shopping (catalog, cart, checkout, orders); the Personal Agent Protocol covers how a personal agent identifies itself, gets permission and works with any company. A store can run both: the two protocols don't reference each other.