Reference stores for personal agents
Three test stores your agent can sign in to.
Each store speaks the Personal Agent Protocol. Point your agent at one, start a session, sign in as the test customer, and change an order or a booking. You approve every change on the store's own page.
Reference test stores for personal agents. Nothing here is for sale: no charges, nothing ships.Session · Kettle Street NoodlesSAMPLE
“Move my delivery to Saturday and add a side of gyoza.”
§3 discover poppy.json, issuer metadata
§4.2 session started signed out, DPoP-bound
§4.5 authorize user approved poppy:read poppy:write
§6 act my_orders, delivery_slots, menu
ops propose change_order: Saturday, + gyoza
ops confirm user approved revision 1
Every store keeps a trace like this for each session, with the spec section each step meets.
1DiscoverYour agent reads the store's
/.well-known/poppy.json and starts a session with its own keys.2Sign inThe store's own page shows which agent is asking. Continue as the test customer and choose what it may do.
3Approve the changeThe agent reads the order or booking, proposes a change with exact terms, and goes ahead only after you approve.
Reference stores
Northlight Flowers
Bouquets and plants. Find a bouquet, check delivery dates, then change a booked delivery.
Try: “Change Friday’s bouquet to the peonies and add a card.”
flowers.papsandbox.com
Harbour Row Stays
A guesthouse on the harbour. Check availability and rates, then move a booked stay.
Try: “Move my stay to the weekend after and add breakfast.”
stays.papsandbox.com
Kettle Street Noodles
Ramen, bowls and gyoza. Read the menu and delivery slots, then change a scheduled delivery.
Try: “Move my delivery to Saturday and add a side of gyoza.”
food.papsandbox.com
How an agent connects
Every store is its own company with its own issuer. Replace{store} with a store's host.| What | Where | Spec |
|---|---|---|
| Discovery | https://{store}/.well-known/poppy.json | §3 |
| Issuer metadata | https://{store}/.well-known/oauth-authorization-server | §3.2 |
| Sessions and tokens | POST https://{store}/oauth/token | §4.2, §4.3 |
| Sign-in (code + PKCE) | https://{store}/oauth/authorize | §4.5 |
| Sign-out | POST https://{store}/oauth/revoke | §4.9 |
| Tools (OpenAPI 3.1) | https://{store}/poppy/openapi.json | §6 |
| Changes the user approves | https://{store}/poppy/operations/{id} | operations v1 |
Any agent can try: we accept any client ID that checks out (an HTTPS metadata document, keys, redirect URIs on the same domain), with rate limits. Each store's For agents page lists its tools and scopes.