Personal Agent Protocol draft 0.1 was published on 9 Oct 2026 · What goes in poppy.json →
PAP Checker/Sites/withpoppyseed.dev
PAP discovery report

withpoppyseed.dev

Publishes a poppy.json with no problems found. Organization: Poppy Travel.

Publishes poppy.json
0problems
HTTP 200 Version 0.1 Sign-in direct, device, mediated Routes agent, APIs, web Checked 1 hour ago First seen 11 Oct 2026
Open poppy.json ↗
Findings18 passed · 2 notes
Discovery
OK
poppy.json published
Served over HTTPS at /.well-known/poppy.json.
§3
Note
Served after 1 redirect
Allowed: every hop is HTTPS, and the document still speaks for the domain requested. Final URL: https://www.withpoppyseed.dev/.well-known/poppy.json
§3
OK
Protocol version 0.1
A major.minor version this checker reads.
§3.1
OK
organization.domain matches the domain checked
It must match the host the agent requested, ignoring a leading www.
§3.1
Sign-in
OK
OAuth issuer: https://withpoppyseed.dev
An HTTPS issuer identifier.
§3.1
OK
Sign-in types: direct, device, mediated
How a user can sign in through a personal agent.
§4.4
Note
Accepts credentials from personal agents (mediated)
A company offering Mediated Sign-In must rate-limit attempts and should require a one-time code when a sign-in looks unusual.
§4.7
Sign-in server
OK
OAuth server metadata published
Found at the issuer (RFC 8414).
§3.2
OK
issuer matches auth.issuer
Exact match, as agents must check.
§3.2
OK
poppy_domains lists withpoppyseed.dev
The issuer confirms this domain may use it.
§3.2
OK
token_endpoint published
Issues Session and Account Tokens.
§3.2
OK
revocation_endpoint published
Revokes Account Tokens (sign-out).
§3.2
OK
authorization_endpoint published
Starts Direct Sign-In.
§3.2
OK
device_authorization_endpoint published
Starts Device Sign-In.
§3.2
Routes
OK
Offers: company agent, APIs, website
At least one of agent, apis or web is listed.
§3.1
OK
Company agent reachable over Personal Agent Protocol conversations
A conversation endpoint of type poppy is listed.
§7.1
OK
Website joins the agent's session
A browser_session_endpoint is listed, so web pages apply the session's sign-in and scopes.
§5
APIs
OK
apis[0]: MCP server names the company's issuer
Its protected resource metadata lists auth.issuer in authorization_servers, so MCP clients can sign in.
§6
OK
apis[1]: OpenAPI 3.1.0 description
Reachable, and a version the draft allows (3.0 or 3.1).
§6
Extensions
OK
Supports the operations extension
§3.3

poppy.json as served

1.1 KB
{
    "protocol_version": "0.1",
    "organization": {
        "name": "Poppy Travel",
        "domain": "withpoppyseed.dev"
    },
    "auth": {
        "issuer": "https://withpoppyseed.dev",
        "direct": {
            "scopes": [
                "poppy:read",
                "poppy:write",
                "travel:loyalty"
            ]
        },
        "device": {
            "scopes": [
                "poppy:read",
                "poppy:write",
                "travel:loyalty"
            ]
        },
        "mediated": {
            "endpoint": "https://withpoppyseed.dev/poppy/sign-in",
            "fields": [
                {
                    "name": "email",
                    "label": "Email",
                    "secret": false
                },
                {
                    "name": "password",
                    "label": "Password",
                    "secret": true
                }
            ],
            "scopes": [
                "poppy:read"
            ]
        },
        "custom_scopes": {
            "travel:loyalty": "See your Poppy Miles balance"
        }
    },
    "agent": {
        "protocols": [
            {
                "type": "poppy",
                "endpoint": "https://withpoppyseed.dev/poppy/conversations"
            }
        ]
    },
    "apis": [
        {
            "type": "mcp",
            "url": "https://withpoppyseed.dev/mcp",
            "description": "Search flights and hotels, read fare rules, see your trips and book with your approval"
        },
        {
            "type": "openapi",
            "url": "https://withpoppyseed.dev/poppy/openapi.json",
            "description": "Search flights and hotels, read fare rules, see your trips and book with your approval"
        }
    ],
    "web": {
        "browser_session_endpoint": "https://withpoppyseed.dev/poppy/browser-session"
    },
    "extensions": {
        "operations": {
            "version": "1",
            "endpoint": "https://withpoppyseed.dev/poppy/operations"
        }
    }
}

OAuth server metadata as served

0.9 KB
{
    "issuer": "https://withpoppyseed.dev",
    "token_endpoint": "https://withpoppyseed.dev/oauth/token",
    "revocation_endpoint": "https://withpoppyseed.dev/oauth/revoke",
    "poppy_domains": [
        "withpoppyseed.dev"
    ],
    "token_endpoint_auth_methods_supported": [
        "private_key_jwt"
    ],
    "token_endpoint_auth_signing_alg_values_supported": [
        "ES256",
        "RS256"
    ],
    "revocation_endpoint_auth_methods_supported": [
        "private_key_jwt"
    ],
    "dpop_signing_alg_values_supported": [
        "ES256",
        "RS256"
    ],
    "scopes_supported": [
        "poppy:read",
        "poppy:write",
        "travel:loyalty"
    ],
    "authorization_response_iss_parameter_supported": true,
    "authorization_endpoint": "https://withpoppyseed.dev/oauth/authorize",
    "response_types_supported": [
        "code"
    ],
    "code_challenge_methods_supported": [
        "S256"
    ],
    "device_authorization_endpoint": "https://withpoppyseed.dev/oauth/device",
    "grant_types_supported": [
        "urn:ietf:params:oauth:grant-type:jwt-bearer",
        "refresh_token",
        "authorization_code",
        "urn:ietf:params:oauth:grant-type:device_code"
    ]
}

Rules from Personal Agent Protocol draft 0.1 (updated 9 Oct 2026). Section numbers refer to the specification. The draft can change before a stable version.