The showcase task. Ask your agent:“Move my stay to the weekend after and add breakfast.”
Endpoints
- Discovery
https://stays.papsandbox.com/.well-known/poppy.json- Issuer
https://stays.papsandbox.com- Issuer metadata
https://stays.papsandbox.com/.well-known/oauth-authorization-server- Token
POST https://stays.papsandbox.com/oauth/token- Sign-in
https://stays.papsandbox.com/oauth/authorize
Direct Sign-In: authorization code with PKCE (S256),issin the redirect.- Sign-out
POST https://stays.papsandbox.com/oauth/revoke- API
https://stays.papsandbox.com/poppy/openapi.json
OpenAPI 3.1. DPoP-bound Session Tokens on every call.- Extensions
operationsv1 athttps://stays.papsandbox.com/poppy/operations
Tools
| Tool | Needs | What it does |
|---|---|---|
availabilityGET /poppy/availability |
Signed out is fine | Rooms free for the dates, with the lowest total for each. |
ratesGET /poppy/rates |
Signed out is fine | Every rate plan for a room and dates, with totals and cancellation terms. |
my_bookingsGET /poppy/bookings |
poppy:read | The signed-in guest's upcoming bookings. |
change_bookingPOST /poppy/bookings/{booking_id}/changes |
poppy:write | Propose a change to a booking: new dates, room or rate plan (add breakfast with rp_flex_bb). Returns HTTP 202 with an operation (operations extension v1); nothing changes until it is confirmed. |
poppy.json
Open{
"protocol_version": "0.1",
"organization": {
"name": "Harbour Row Stays",
"domain": "stays.papsandbox.com"
},
"auth": {
"issuer": "https://stays.papsandbox.com",
"direct": {
"scopes": [
"poppy:read",
"poppy:write"
]
}
},
"apis": [
{
"type": "openapi",
"url": "https://stays.papsandbox.com/poppy/openapi.json",
"description": "Room availability and rates, the guest's bookings, and changes to a booking"
}
],
"web": {},
"extensions": {
"operations": {
"version": "1",
"endpoint": "https://stays.papsandbox.com/poppy/operations"
}
}
}
Issuer metadata
Open{
"issuer": "https://stays.papsandbox.com",
"token_endpoint": "https://stays.papsandbox.com/oauth/token",
"revocation_endpoint": "https://stays.papsandbox.com/oauth/revoke",
"authorization_endpoint": "https://stays.papsandbox.com/oauth/authorize",
"poppy_domains": [
"stays.papsandbox.com"
],
"response_types_supported": [
"code"
],
"grant_types_supported": [
"authorization_code",
"refresh_token",
"urn:ietf:params:oauth:grant-type:jwt-bearer"
],
"code_challenge_methods_supported": [
"S256"
],
"token_endpoint_auth_methods_supported": [
"private_key_jwt"
],
"token_endpoint_auth_signing_alg_values_supported": [
"ES256",
"RS256",
"EdDSA"
],
"revocation_endpoint_auth_methods_supported": [
"private_key_jwt"
],
"dpop_signing_alg_values_supported": [
"ES256",
"RS256",
"EdDSA"
],
"authorization_response_iss_parameter_supported": true,
"client_id_metadata_document_supported": true,
"scopes_supported": [
"poppy:read",
"poppy:write"
]
}