Publishes a poppy.json with no problems found. Organization: Poppy Travel.
{
"protocol_version": "0.1",
"organization": {
"name": "Poppy Travel",
"domain": "withpoppyseed.dev"
},
"auth": {
"issuer": "https://withpoppyseed.dev",
"direct": {
"scopes": [
"poppy:read",
"poppy:write",
"travel:loyalty"
]
},
"device": {
"scopes": [
"poppy:read",
"poppy:write",
"travel:loyalty"
]
},
"mediated": {
"endpoint": "https://withpoppyseed.dev/poppy/sign-in",
"fields": [
{
"name": "email",
"label": "Email",
"secret": false
},
{
"name": "password",
"label": "Password",
"secret": true
}
],
"scopes": [
"poppy:read"
]
},
"custom_scopes": {
"travel:loyalty": "See your Poppy Miles balance"
}
},
"agent": {
"protocols": [
{
"type": "poppy",
"endpoint": "https://withpoppyseed.dev/poppy/conversations"
}
]
},
"apis": [
{
"type": "mcp",
"url": "https://withpoppyseed.dev/mcp",
"description": "Search flights and hotels, read fare rules, see your trips and book with your approval"
},
{
"type": "openapi",
"url": "https://withpoppyseed.dev/poppy/openapi.json",
"description": "Search flights and hotels, read fare rules, see your trips and book with your approval"
}
],
"web": {
"browser_session_endpoint": "https://withpoppyseed.dev/poppy/browser-session"
},
"extensions": {
"operations": {
"version": "1",
"endpoint": "https://withpoppyseed.dev/poppy/operations"
}
}
}
{
"issuer": "https://withpoppyseed.dev",
"token_endpoint": "https://withpoppyseed.dev/oauth/token",
"revocation_endpoint": "https://withpoppyseed.dev/oauth/revoke",
"poppy_domains": [
"withpoppyseed.dev"
],
"token_endpoint_auth_methods_supported": [
"private_key_jwt"
],
"token_endpoint_auth_signing_alg_values_supported": [
"ES256",
"RS256"
],
"revocation_endpoint_auth_methods_supported": [
"private_key_jwt"
],
"dpop_signing_alg_values_supported": [
"ES256",
"RS256"
],
"scopes_supported": [
"poppy:read",
"poppy:write",
"travel:loyalty"
],
"authorization_response_iss_parameter_supported": true,
"authorization_endpoint": "https://withpoppyseed.dev/oauth/authorize",
"response_types_supported": [
"code"
],
"code_challenge_methods_supported": [
"S256"
],
"device_authorization_endpoint": "https://withpoppyseed.dev/oauth/device",
"grant_types_supported": [
"urn:ietf:params:oauth:grant-type:jwt-bearer",
"refresh_token",
"authorization_code",
"urn:ietf:params:oauth:grant-type:device_code"
]
}
Rules from Personal Agent Protocol draft 0.1 (updated 9 Oct 2026). Section numbers refer to the specification. The draft can change before a stable version.