Test storeBrowse here; your agent changes your booking. Nobody is expecting you.All PAP Sandbox stores
Harbour RowStays
Your bookingsFor agents
Personal Agent Protocol draft 0.1

For agents

A guesthouse on the harbour. Check availability and rates, then move a booked stay. Nothing is charged and nothing ships. Start from poppy.json; everything else is linked from there.

The showcase task. Ask your agent:“Move my stay to the weekend after and add breakfast.”

Endpoints

Discovery
https://stays.papsandbox.com/.well-known/poppy.json
Issuer
https://stays.papsandbox.com
Issuer metadata
https://stays.papsandbox.com/.well-known/oauth-authorization-server
Token
POST https://stays.papsandbox.com/oauth/token
Sign-in
https://stays.papsandbox.com/oauth/authorize
Direct Sign-In: authorization code with PKCE (S256), iss in the redirect.
Sign-out
POST https://stays.papsandbox.com/oauth/revoke
API
https://stays.papsandbox.com/poppy/openapi.json
OpenAPI 3.1. DPoP-bound Session Tokens on every call.
Extensions
operations v1 at https://stays.papsandbox.com/poppy/operations

Tools

ToolNeedsWhat it does
availability
GET /poppy/availability
Signed out is fine Rooms free for the dates, with the lowest total for each.
rates
GET /poppy/rates
Signed out is fine Every rate plan for a room and dates, with totals and cancellation terms.
my_bookings
GET /poppy/bookings
poppy:read The signed-in guest's upcoming bookings.
change_booking
POST /poppy/bookings/{booking_id}/changes
poppy:write Propose a change to a booking: new dates, room or rate plan (add breakfast with rp_flex_bb). Returns HTTP 202 with an operation (operations extension v1); nothing changes until it is confirmed.

poppy.json

Open
{
    "protocol_version": "0.1",
    "organization": {
        "name": "Harbour Row Stays",
        "domain": "stays.papsandbox.com"
    },
    "auth": {
        "issuer": "https://stays.papsandbox.com",
        "direct": {
            "scopes": [
                "poppy:read",
                "poppy:write"
            ]
        }
    },
    "apis": [
        {
            "type": "openapi",
            "url": "https://stays.papsandbox.com/poppy/openapi.json",
            "description": "Room availability and rates, the guest's bookings, and changes to a booking"
        }
    ],
    "web": {},
    "extensions": {
        "operations": {
            "version": "1",
            "endpoint": "https://stays.papsandbox.com/poppy/operations"
        }
    }
}

Issuer metadata

Open
{
    "issuer": "https://stays.papsandbox.com",
    "token_endpoint": "https://stays.papsandbox.com/oauth/token",
    "revocation_endpoint": "https://stays.papsandbox.com/oauth/revoke",
    "authorization_endpoint": "https://stays.papsandbox.com/oauth/authorize",
    "poppy_domains": [
        "stays.papsandbox.com"
    ],
    "response_types_supported": [
        "code"
    ],
    "grant_types_supported": [
        "authorization_code",
        "refresh_token",
        "urn:ietf:params:oauth:grant-type:jwt-bearer"
    ],
    "code_challenge_methods_supported": [
        "S256"
    ],
    "token_endpoint_auth_methods_supported": [
        "private_key_jwt"
    ],
    "token_endpoint_auth_signing_alg_values_supported": [
        "ES256",
        "RS256",
        "EdDSA"
    ],
    "revocation_endpoint_auth_methods_supported": [
        "private_key_jwt"
    ],
    "dpop_signing_alg_values_supported": [
        "ES256",
        "RS256",
        "EdDSA"
    ],
    "authorization_response_iss_parameter_supported": true,
    "client_id_metadata_document_supported": true,
    "scopes_supported": [
        "poppy:read",
        "poppy:write"
    ]
}