Trango ComputeContextIQ

Free tool · No sign-up required

Poppy Inspector —
check any poppy.json in seconds.

Enter any domain and fetch its Personal Agent Protocol (Poppy) discovery file from /.well-known/poppy.json. See the OAuth issuer, sign-in methods, scopesand APIs a personal agent would find, and whether the issuer's RFC 8414 metadata agrees with it.

Specs and standards covered

Personal Agent Protocol (Poppy)poppy.jsonOAuth 2.0RFC 8414 metadataRFC 7523 JWT bearerDPoP (RFC 9449)MCPOpenAPI

What it shows you

Discovery document check

Fetches /.well-known/poppy.json and reads it the way a personal agent would: protocol_version, organization, auth, agent, apis, web and extensions. A file that is JSON but missing protocol_version or organization is flagged as indicated, not confirmed.

Issuer cross-check

Agents must fetch the OAuth authorization server metadata and confirm its issuer equals auth.issuer exactly and that poppy_domains lists the organization's domain. The inspector runs the same check and reports the required endpoints each sign-in method needs.

Plain-language lint

Domain that does not match the host, auth missing while apis are listed, http URLs, an api type other than openapi or mcp, an unknown extension name. Each warning names the field and the rule from the draft.

Sign-in and scopes at a glance

See which of direct, device and mediated sign-in a company offers, and the scopes it declares: poppy:read, poppy:write, and any custom scopes. Scopes appear in the IGA review packet's authentication context.

APIs and company agent

Lists the OpenAPI and MCP APIs a company advertises, its browser-session endpoint and its conversation endpoint. Paste a listed MCP server's URL into the same tool to see what an agent finds there.

Draft-aware and honest about scope

The specification is Draft 0.1 and the project says it can still change. The inspector reads the published document and metadata only. It does not sign in, test DPoP, or call the listed APIs, and it is not a conformance test. Compare two scans and download a report. Pro feature.

poppy.json fields parsed

protocol_versionorganization.nameorganization.domainauth.issuerauth.directauth.deviceauth.mediatedauth.custom_scopesagent.protocolsapis[].typeapis[].urlweb.browser_session_endpointextensions

Based on the Draft 0.1 specification. Learn more: what poppy.json is and what the Personal Agent Protocol is. See what a scan can and cannot see.

Who uses it

Platform and API teams preparing for personal agents

You plan to publish a poppy.json. Check the file and the OAuth metadata behind it before an agent does, and see exactly which rule each warning comes from.

Identity and security engineers

The draft ties a domain to an issuer from both sides. Confirm your issuer, your poppy_domains list and the endpoints each sign-in method needs line up, and see which scopes the file declares.

Agent developers

Before relying on a company's poppy.json, run the same checks the draft asks agents to make and see what the company says about its APIs, sign-in methods and extensions.