PAP Sandbox
Pick a store
Reference stores for personal agents

Three test stores your agent can sign in to.

Each store speaks the Personal Agent Protocol. Point your agent at one, start a session, sign in as the test customer, and change an order or a booking. You approve every change on the store's own page.

Reference test stores for personal agents. Nothing here is for sale: no charges, nothing ships.
Session · Kettle Street NoodlesSAMPLE
“Move my delivery to Saturday and add a side of gyoza.”
§3  discover  poppy.json, issuer metadata §4.2 session  started signed out, DPoP-bound §4.5 authorize  user approved poppy:read poppy:write §6   act  my_orders, delivery_slots, menu ops  propose  change_order: Saturday, + gyoza ops  confirm  user approved revision 1
Every store keeps a trace like this for each session, with the spec section each step meets.
1DiscoverYour agent reads the store's /.well-known/poppy.json and starts a session with its own keys.
2Sign inThe store's own page shows which agent is asking. Continue as the test customer and choose what it may do.
3Approve the changeThe agent reads the order or booking, proposes a change with exact terms, and goes ahead only after you approve.

Reference stores

How an agent connects

Every store is its own company with its own issuer. Replace {store} with a store's host.
WhatWhereSpec
Discoveryhttps://{store}/.well-known/poppy.json§3
Issuer metadatahttps://{store}/.well-known/oauth-authorization-server§3.2
Sessions and tokensPOST https://{store}/oauth/token§4.2, §4.3
Sign-in (code + PKCE)https://{store}/oauth/authorize§4.5
Sign-outPOST https://{store}/oauth/revoke§4.9
Tools (OpenAPI 3.1)https://{store}/poppy/openapi.json§6
Changes the user approveshttps://{store}/poppy/operations/{id}operations v1

Any agent can try: we accept any client ID that checks out (an HTTPS metadata document, keys, redirect URIs on the same domain), with rate limits. Each store's For agents page lists its tools and scopes.