Free tool · No sign-up required
Poppy Inspector —
check any poppy.json in seconds.
Enter any domain and fetch its Personal Agent Protocol (Poppy) discovery file from /.well-known/poppy.json. See the OAuth issuer, sign-in methods, scopesand APIs a personal agent would find, and whether the issuer's RFC 8414 metadata agrees with it.
Specs and standards covered
What it shows you
Discovery document check
Fetches /.well-known/poppy.json and reads it the way a personal agent would: protocol_version, organization, auth, agent, apis, web and extensions. A file that is JSON but missing protocol_version or organization is flagged as indicated, not confirmed.
Issuer cross-check
Agents must fetch the OAuth authorization server metadata and confirm its issuer equals auth.issuer exactly and that poppy_domains lists the organization's domain. The inspector runs the same check and reports the required endpoints each sign-in method needs.
Plain-language lint
Domain that does not match the host, auth missing while apis are listed, http URLs, an api type other than openapi or mcp, an unknown extension name. Each warning names the field and the rule from the draft.
Sign-in and scopes at a glance
See which of direct, device and mediated sign-in a company offers, and the scopes it declares: poppy:read, poppy:write, and any custom scopes. Scopes appear in the IGA review packet's authentication context.
APIs and company agent
Lists the OpenAPI and MCP APIs a company advertises, its browser-session endpoint and its conversation endpoint. Paste a listed MCP server's URL into the same tool to see what an agent finds there.
Draft-aware and honest about scope
The specification is Draft 0.1 and the project says it can still change. The inspector reads the published document and metadata only. It does not sign in, test DPoP, or call the listed APIs, and it is not a conformance test. Compare two scans and download a report. Pro feature.
poppy.json fields parsed
Based on the Draft 0.1 specification. Learn more: what poppy.json is and what the Personal Agent Protocol is. See what a scan can and cannot see.
Who uses it
Platform and API teams preparing for personal agents
You plan to publish a poppy.json. Check the file and the OAuth metadata behind it before an agent does, and see exactly which rule each warning comes from.
Identity and security engineers
The draft ties a domain to an issuer from both sides. Confirm your issuer, your poppy_domains list and the endpoints each sign-in method needs line up, and see which scopes the file declares.
Agent developers
Before relying on a company's poppy.json, run the same checks the draft asks agents to make and see what the company says about its APIs, sign-in methods and extensions.