Test storeBrowse here; your agent changes your order. No food is cooked.All PAP Sandbox stores
Kettle Street Noodles
For agents
Personal Agent Protocol draft 0.1

For agents

Ramen, bowls and gyoza. Read the menu and delivery slots, then change a scheduled delivery. Nothing is charged and nothing ships. Start from poppy.json; everything else is linked from there.

The showcase task. Ask your agent:“Move my delivery to Saturday and add a side of gyoza.”

Endpoints

Discovery
https://food.papsandbox.com/.well-known/poppy.json
Issuer
https://food.papsandbox.com
Issuer metadata
https://food.papsandbox.com/.well-known/oauth-authorization-server
Token
POST https://food.papsandbox.com/oauth/token
Sign-in
https://food.papsandbox.com/oauth/authorize
Direct Sign-In: authorization code with PKCE (S256), iss in the redirect.
Sign-out
POST https://food.papsandbox.com/oauth/revoke
API
https://food.papsandbox.com/poppy/openapi.json
OpenAPI 3.1. DPoP-bound Session Tokens on every call.
Extensions
operations v1 at https://food.papsandbox.com/poppy/operations

Tools

ToolNeedsWhat it does
menu
GET /poppy/products
Signed out is fine Search the catalogue by name, category or tag. Prices in cents.
delivery_slots
GET /poppy/delivery-slots
Signed out is fine The delivery slots open for the next week or two.
my_orders
GET /poppy/orders
poppy:read The signed-in customer's open orders.
change_order
POST /poppy/orders/{order_id}/changes
poppy:write Propose a change to an order: move the delivery, add, swap or remove items. Returns HTTP 202 with an operation (operations extension v1); nothing changes until it is confirmed.

poppy.json

Open
{
    "protocol_version": "0.1",
    "organization": {
        "name": "Kettle Street Noodles",
        "domain": "food.papsandbox.com"
    },
    "auth": {
        "issuer": "https://food.papsandbox.com",
        "direct": {
            "scopes": [
                "poppy:read",
                "poppy:write"
            ]
        }
    },
    "apis": [
        {
            "type": "openapi",
            "url": "https://food.papsandbox.com/poppy/openapi.json",
            "description": "Menu, delivery slots, the customer's orders, and changes to a scheduled delivery"
        }
    ],
    "web": {},
    "extensions": {
        "operations": {
            "version": "1",
            "endpoint": "https://food.papsandbox.com/poppy/operations"
        }
    }
}

Issuer metadata

Open
{
    "issuer": "https://food.papsandbox.com",
    "token_endpoint": "https://food.papsandbox.com/oauth/token",
    "revocation_endpoint": "https://food.papsandbox.com/oauth/revoke",
    "authorization_endpoint": "https://food.papsandbox.com/oauth/authorize",
    "poppy_domains": [
        "food.papsandbox.com"
    ],
    "response_types_supported": [
        "code"
    ],
    "grant_types_supported": [
        "authorization_code",
        "refresh_token",
        "urn:ietf:params:oauth:grant-type:jwt-bearer"
    ],
    "code_challenge_methods_supported": [
        "S256"
    ],
    "token_endpoint_auth_methods_supported": [
        "private_key_jwt"
    ],
    "token_endpoint_auth_signing_alg_values_supported": [
        "ES256",
        "RS256",
        "EdDSA"
    ],
    "revocation_endpoint_auth_methods_supported": [
        "private_key_jwt"
    ],
    "dpop_signing_alg_values_supported": [
        "ES256",
        "RS256",
        "EdDSA"
    ],
    "authorization_response_iss_parameter_supported": true,
    "client_id_metadata_document_supported": true,
    "scopes_supported": [
        "poppy:read",
        "poppy:write"
    ]
}