Personal Agent Protocol draft 0.1 was published on 9 Oct 2026 · What goes in poppy.json →
PAP Checker/Sites/poppy-receiver.roundtrip.workers.dev
PAP discovery report

poppy-receiver.roundtrip.workers.dev

Publishes a poppy.json with no problems found. Organization: Northstar Outfitters.

Publishes poppy.json
0problems
HTTP 200 Version 0.1 Sign-in direct Routes agent, APIs, web Checked 1 hour ago First seen 11 Oct 2026
Open poppy.json ↗
Findings14 passed · 1 note
Discovery
OK
poppy.json published
Served over HTTPS at /.well-known/poppy.json.
§3
OK
Protocol version 0.1
A major.minor version this checker reads.
§3.1
OK
organization.domain matches the domain checked
It must match the host the agent requested, ignoring a leading www.
§3.1
Sign-in
OK
OAuth issuer: https://poppy-receiver.roundtrip.workers.dev
An HTTPS issuer identifier.
§3.1
OK
Sign-in types: direct
How a user can sign in through a personal agent.
§4.4
Sign-in server
OK
OAuth server metadata published
Found at the issuer (RFC 8414).
§3.2
OK
issuer matches auth.issuer
Exact match, as agents must check.
§3.2
OK
poppy_domains lists poppy-receiver.roundtrip.workers.dev
The issuer confirms this domain may use it.
§3.2
OK
token_endpoint published
Issues Session and Account Tokens.
§3.2
OK
revocation_endpoint published
Revokes Account Tokens (sign-out).
§3.2
OK
authorization_endpoint published
Starts Direct Sign-In.
§3.2
Routes
OK
Offers: company agent, APIs, website
At least one of agent, apis or web is listed.
§3.1
OK
Company agent reachable over Personal Agent Protocol conversations
A conversation endpoint of type poppy is listed.
§7.1
Note
Website: signed-out browsing
No browser_session_endpoint, so personal agents browse the site as ordinary signed-out visitors.
§5
APIs
OK
apis[0]: OpenAPI 3.1.0 description
Reachable, and a version the draft allows (3.0 or 3.1).
§6

poppy.json as served

0.5 KB
{
    "protocol_version": "0.1",
    "organization": {
        "name": "Northstar Outfitters",
        "domain": "poppy-receiver.roundtrip.workers.dev"
    },
    "auth": {
        "issuer": "https://poppy-receiver.roundtrip.workers.dev",
        "direct": {
            "scopes": [
                "poppy:read",
                "poppy:write"
            ]
        }
    },
    "agent": {
        "protocols": [
            {
                "type": "poppy",
                "endpoint": "https://poppy-receiver.roundtrip.workers.dev/poppy/conversations"
            }
        ]
    },
    "apis": [
        {
            "type": "openapi",
            "url": "https://poppy-receiver.roundtrip.workers.dev/openapi.json",
            "description": "Orders and jacket exchanges"
        }
    ],
    "web": {}
}

OAuth server metadata as served

0.7 KB
{
    "issuer": "https://poppy-receiver.roundtrip.workers.dev",
    "poppy_domains": [
        "poppy-receiver.roundtrip.workers.dev"
    ],
    "authorization_endpoint": "https://poppy-receiver.roundtrip.workers.dev/oauth/authorize",
    "token_endpoint": "https://poppy-receiver.roundtrip.workers.dev/oauth/token",
    "revocation_endpoint": "https://poppy-receiver.roundtrip.workers.dev/oauth/revoke",
    "grant_types_supported": [
        "urn:ietf:params:oauth:grant-type:jwt-bearer",
        "authorization_code",
        "refresh_token"
    ],
    "response_types_supported": [
        "code"
    ],
    "token_endpoint_auth_methods_supported": [
        "private_key_jwt"
    ],
    "token_endpoint_auth_signing_alg_values_supported": [
        "ES256"
    ],
    "code_challenge_methods_supported": [
        "S256"
    ],
    "dpop_signing_alg_values_supported": [
        "ES256"
    ],
    "scopes_supported": [
        "poppy:read",
        "poppy:write"
    ]
}

Rules from Personal Agent Protocol draft 0.1 (updated 9 Oct 2026). Section numbers refer to the specification. The draft can change before a stable version.