Personal Agent Protocol report
emorahealth.com
emorahealth.com publishes a poppy.json, and no P0 or P1 check fails.- Verdict
- Working
- Profile
- pap-0.1@2026-10-09PAP Draft 0.1 (published 2026-10-09; may change)
- Last run
- Tier 1 probed
Tier 0: the public files
Plain reads of poppy.json and the documents it points to. None of these requests carries a credential.15 pass, 2 fail, 13 N/A- T0-01Document existsserved at https://www.emorahealth.com/.well-known/poppy.json
- T0-02Redirects safe1 redirect(s), all HTTPS
- T0-03Valid JSON objecta JSON object
- T0-04Supported protocol_versionprotocol_version 0.1
- T0-05Organization matches the requested hostorganization.domain emorahealth.com
- T0-06Has an interfaceinterfaces: agent
- T0-07auth.issuer when neededauth.issuer https://www.emorahealth.com/poppy
- T0-08All URLs HTTPSevery URL is https
- T0-SIBPublished on the requested hostpublished on emorahealth.com
- T0-09Issuer metadata reachablehttps://www.emorahealth.com/.well-known/oauth-authorization-server/poppy
- T0-10Issuer matchissuer https://www.emorahealth.com/poppy
- T0-11Domain bindingpoppy_domains includes emorahealth.com
- T0-12Required endpointstoken_endpoint, revocation_endpoint
- T0-21Cache headersCache-Control: private, max-age=300
- ADV-PKCENo plain PKCEcode_challenge_methods_supported not listed
- T0-13Scopes definedno sign-in type or custom scope
- T0-14Mediated sign-in well formedno mediated sign-in
- T0-19Extensions named correctlyno extensions
- T0-20Operations advertised fullyoperations extension not advertised
- T0-15Conversation entries1 agent protocol(s)
- T0-16API entriesno apis
- T0-17OpenAPI parsesno openapi entries
- T0-18MCP resource metadatano mcp entries
- X-01Same MCP server everywherepoppy.json lists no MCP server
- X-02Same organizationno ARD catalog host to compare
- X-04Domains coveredpoppy_domains lists no other domain
- X-07One issuerthe site's protected resource metadata lists https://www.emorahealth.com, not the PAP issuer https://www.emorahealth.com/poppy
- X-08One metadata documentthe site also serves authorization server metadata for https://www.emorahealth.com; poppy.json names https://www.emorahealth.com/poppy
- X-10Shared token endpoint lists both protocols' grantsno other protocol shares the PAP issuer's token endpoint
- X-12Consistent 401sno recorded 401 challenge from a PAP MCP server
Tier 1: junk requests to the listed endpoints
Requests with no valid credential, which a correct site refuses. They run only when the scan asks for them, at most once per domain every 6 hours.Tier 1 last probed .4 pass, 3 N/A- T1-01Token endpoint rejects a junk JWT bearer requesthttps://www.emorahealth.com/poppy/oauth/token answered HTTP 401 invalid_client
- T1-02Error bodies leak nothingno stack traces in error bodies
- T1-03Conversation endpoint requires DPoPhttps://www.emorahealth.com/poppy/conversations answered HTTP 401 with WWW-Authenticate: DPoP
- T1-05MCP server challenges unauthenticated initializeno MCP server listed
- T1-07Browser endpoint rejects a junk assertionno web.browser_session_endpoint
- T1-09Operations endpoint requires a tokenoperations extension not advertised
- ADV-REDIRECTEndpoint answers without a redirectevery probed endpoint answered without a redirect
Tier 2a: coming soon
Valid requests with a real client, once Ora publishes its own client metadata and signs real requests. Not measured yet.10 not measuredShow the 10 planned checks
- T2-M1Call each read-only OpenAPI GET with no token, then with a valid signed-out token
- T2-M5Load the consent page for Ora's real client_id from a valid S256 request and inspect headers; never sign in
- T2-01Start a Session for U1
- T2-02Token lifetime
- T2-05Renew with session_id
- T2-14Nonce challenge
- T2-16Bearer token request for an MCP server (no DPoP, resource = MCP url)
- T2-18Token accepted without cookies
- T2-19Valid browser assertion, form POST
- T2-25Cookie scope
Tier 2b: requires opt-in
Checks that run only for a verified owner who opts in. Not measured yet.36 not measuredShow the 36 planned checks
- T2-M2Send a valid Session Token in ?access_token= instead of the header
- T2-M3Send a valid browser assertion in the URL instead of the form body
- T2-M4Start Direct Sign-In with code_challenge_method=plain and Ora's real client_id; stop at the authorization endpoint
- T1-12Mediated endpoint, only if the company opts in: two bad-credential attempts
- T2-03Replay the same assertion jti
- T2-04Assertion with aud as an array or another endpoint
- T2-06Renew U1's Session with a U2 assertion
- T2-07Assertion signed with a key not in Ora's JWKS
- T2-08alg: none or HS256 assertion
- T2-09Valid token, reused proof jti
- T2-10Proof with wrong htu or htm
- T2-11Proof with wrong ath
- T2-12Proof signed by a different key than the token's binding
- T2-13Stale iat (beyond ~1 min)
- T2-15Token sent as Authorization: Bearer to a non-MCP endpoint
- T2-17That Bearer token at another MCP server or an OpenAPI endpoint
- T2-20Replay the same browser assertion
- T2-21exp more than 60 s after iat
- T2-22return_to on a foreign domain
- T2-23Session assertion (wrong typ) at the browser endpoint
- T2-24Browser assertion at the token endpoint
- T2-26Start with a general question
- T2-27Retry the same message id and content
- T2-28Same id, different content
- T2-29Read events with and without wait
- T2-30POST …/messages?wait=10
- T2-31Junk cursor
- T2-32U2 reads U1's conversation
- T2-33Stream with Accept: text/event-stream
- T2-34Ask about the account while signed out
- T2-35Message with only context
- T2-36Close, then send a message
- T2-37Handoff (opt-in only; may page staff)
- T2-38Ora client metadata without extensions.operations, trigger a proposing endpoint
- T2-39U2 reads U1's signed-out operation
- T2-40Confirm an old revision (if revisions can be triggered)
Tier 3: needs a test account and a person
Checks that need a test account from the company and a person at the keyboard. Ora does not run these on its own.17 not measuredShow the 17 planned checks
- T3-01Direct sign-in
- T3-02Redirect URI not in Ora's redirect_uris
- T3-03User declines
- T3-04Device sign-in
- T3-05Mediated sign-in (if offered)
- T3-06Partial scope approval
- T3-07Request an unlisted scope
- T3-08Scope enforcement across channels
- T3-09Account Token from another client_id or at an API
- T3-10Account Token with narrower and wider scope
- T3-11Sign a Session into account B after account A
- T3-12Revoke the Account Token
- T3-13Signed-out token on an account-using conversation
- T3-14Direct Conversation
- T3-15Operation end to end (sandbox action)
- T3-16standing_permission on a user_approval_required operation
- T3-17Account settings