Your poppy.json sets what a personal agent can do with you: how it finds you, how your customers sign in, what it may view or change, and which APIs, pages and company agent it can use. Check it against the published draft.
Free · read-only · no sign-up · what we check
What happens when a personal agent works with a company over the Personal Agent Protocol. Steps 2 and 3 are what we check from outside; the rest happens inside a live session. A fictional company, with the draft's section for each step.
Every domain we have found with a Personal Agent Protocol discovery file, and the day we first saw it. We recheck them weekly.
| Site | Organization | Sign-in | Routes | First seen |
|---|---|---|---|---|
| poppy-receiver.roundtrip.workers.dev | Northstar Outfitters demo | direct | company agentAPIswebsite | 11 Oct 2026 |
| withpoppyseed.dev | Poppy Travel demo | directdevicemediated | company agentAPIswebsite | 11 Oct 2026 |
No score. Each line says which rule of the draft it checks and whether it holds: a problem, a warning, or a note.
GET requests for public documents only, the way a personal agent reads them.
HTTPS at the well-known path, redirects that stay on HTTPS, a version agents can read, and an organization.domain that matches.
The OAuth issuer, the sign-in types offered (direct, device, mediated), their scopes, and custom scope names.
OAuth metadata at the issuer, an exact issuer match, poppy_domains listing the domain, and the endpoints each type needs.
The company agent's conversation endpoint, the website session endpoint, and each API's type, URL and description.
OpenAPI descriptions reachable and 3.0 or 3.1. MCP servers whose resource metadata names the company's issuer.
operations and other extensions carry a version and endpoint; custom ones use a domain prefix.
An open protocol for how a person's AI agent works with a company on their behalf: how the agent finds the company, signs the user in, what it may do, and how it reaches the company's APIs, website or own agent. Meta and Sierra lead it; draft 0.1 was published on 9 October 2026. It is also called Poppy.
The discovery document a company publishes at /.well-known/poppy.json. It names the organization, its OAuth issuer and sign-in types, and the APIs, website session endpoint and company agent it offers. Read the guide.
No. It makes ordinary GET requests for public documents: poppy.json, the issuer's OAuth metadata, OpenAPI descriptions and MCP resource metadata. It never starts a session, signs in or sends data to your endpoints.
No. Each result says which rule of the draft it checks and whether it holds: a problem (a MUST that isn't met), a warning (a SHOULD or a recommendation), or a note.
No. PAP Checker is independent and not affiliated with the protocol's authors. The draft can change at any point before a stable version, and we update the rules when it does.
The Universal Commerce Protocol covers shopping (catalog, cart, checkout, orders); the Personal Agent Protocol covers how a personal agent identifies itself, gets permission and works with any company. A store can run both: the two protocols don't reference each other.