Personal Agent Protocol report

emorahealth.com

emorahealth.com publishes a poppy.json, and no P0 or P1 check fails.
Verdict
Working
Profile
pap-0.1@2026-10-09PAP Draft 0.1 (published 2026-10-09; may change)
Last run
Tier 1 probed
Each row is one check from the PAP spec, with its outcome, its severity (P0 blocks every agent or is a security MUST, P1 is a MUST that breaks one feature, P2 is a SHOULD or one of Ora's own consistency checks, Advisory never counts against a site) and the section it tests. The full list is in the check catalog, and what Ora's scanner sends is on its own page.

Tier 0: the public files

Plain reads of poppy.json and the documents it points to. None of these requests carries a credential.15 pass, 2 fail, 13 N/A
  1. T0-01Document exists
    Outcome: PassSeverity: P0§3
    served at https://www.emorahealth.com/.well-known/poppy.json
  2. T0-02Redirects safe
    Outcome: PassSeverity: P0§3
    1 redirect(s), all HTTPS
  3. T0-03Valid JSON object
    Outcome: PassSeverity: P0§3
    a JSON object
  4. T0-04Supported protocol_version
    Outcome: PassSeverity: P0§3.1
    protocol_version 0.1
  5. T0-05Organization matches the requested host
    Outcome: PassSeverity: P0§3.1
    organization.domain emorahealth.com
  6. T0-06Has an interface
    Outcome: PassSeverity: P0§3.1
    interfaces: agent
  7. T0-07auth.issuer when needed
    Outcome: PassSeverity: P0§3.1
    auth.issuer https://www.emorahealth.com/poppy
  8. T0-08All URLs HTTPS
    Outcome: PassSeverity: P0§3
    every URL is https
  9. T0-SIBPublished on the requested host
    Outcome: PassSeverity: P2§3.1
    published on emorahealth.com
  10. T0-09Issuer metadata reachable
    Outcome: PassSeverity: P0§3.2
    https://www.emorahealth.com/.well-known/oauth-authorization-server/poppy
  11. T0-10Issuer match
    Outcome: PassSeverity: P0§3.2
    issuer https://www.emorahealth.com/poppy
  12. T0-11Domain binding
    Outcome: PassSeverity: P0§3.2
    poppy_domains includes emorahealth.com
  13. T0-12Required endpoints
    Outcome: PassSeverity: P0§3.2
    token_endpoint, revocation_endpoint
  14. T0-21Cache headers
    Outcome: PassSeverity: P2§3.2
    Cache-Control: private, max-age=300
  15. ADV-PKCENo plain PKCE
    Outcome: N/ASeverity: Advisoryguides
    code_challenge_methods_supported not listed
  16. T0-13Scopes defined
    Outcome: N/ASeverity: P1§3.1
    no sign-in type or custom scope
  17. T0-14Mediated sign-in well formed
    Outcome: N/ASeverity: P1§4.7
    no mediated sign-in
  18. T0-19Extensions named correctly
    Outcome: N/ASeverity: P1§3.3
    no extensions
  19. T0-20Operations advertised fully
    Outcome: N/ASeverity: P1Ops §2
    operations extension not advertised
  20. T0-15Conversation entries
    Outcome: PassSeverity: P1§3.1
    1 agent protocol(s)
  21. T0-16API entries
    Outcome: N/ASeverity: P1§3.1
    no apis
  22. T0-17OpenAPI parses
    Outcome: N/ASeverity: P1§6
    no openapi entries
  23. T0-18MCP resource metadata
    Outcome: N/ASeverity: P1§6
    no mcp entries
  24. X-01Same MCP server everywhere
    Outcome: N/ASeverity: P2§6
    poppy.json lists no MCP server
  25. X-02Same organization
    Outcome: N/ASeverity: P2§3.1
    no ARD catalog host to compare
  26. X-04Domains covered
    Outcome: N/ASeverity: P2§3.2
    poppy_domains lists no other domain
  27. X-07One issuer
    Outcome: FailSeverity: P2§3.2
    the site's protected resource metadata lists https://www.emorahealth.com, not the PAP issuer https://www.emorahealth.com/poppy
  28. X-08One metadata document
    Outcome: FailSeverity: Advisory§3.2
    the site also serves authorization server metadata for https://www.emorahealth.com; poppy.json names https://www.emorahealth.com/poppy
  29. X-10Shared token endpoint lists both protocols' grants
    Outcome: N/ASeverity: P2§3.2
    no other protocol shares the PAP issuer's token endpoint
  30. X-12Consistent 401s
    Outcome: N/ASeverity: P2§6
    no recorded 401 challenge from a PAP MCP server

Tier 1: junk requests to the listed endpoints

Requests with no valid credential, which a correct site refuses. They run only when the scan asks for them, at most once per domain every 6 hours.Tier 1 last probed .4 pass, 3 N/A
  1. T1-01Token endpoint rejects a junk JWT bearer request
    Outcome: PassSeverity: P1§4.2
    https://www.emorahealth.com/poppy/oauth/token answered HTTP 401 invalid_client
  2. T1-02Error bodies leak nothing
    Outcome: PassSeverity: Advisoryguides
    no stack traces in error bodies
  3. T1-03Conversation endpoint requires DPoP
    Outcome: PassSeverity: P0§4.3
    https://www.emorahealth.com/poppy/conversations answered HTTP 401 with WWW-Authenticate: DPoP
  4. T1-05MCP server challenges unauthenticated initialize
    Outcome: N/ASeverity: P1§6
    no MCP server listed
  5. T1-07Browser endpoint rejects a junk assertion
    Outcome: N/ASeverity: P0§5
    no web.browser_session_endpoint
  6. T1-09Operations endpoint requires a token
    Outcome: N/ASeverity: P2Ops §2
    operations extension not advertised
  7. ADV-REDIRECTEndpoint answers without a redirect
    Outcome: PassSeverity: Advisoryguides
    every probed endpoint answered without a redirect

Tier 2a: coming soon

Valid requests with a real client, once Ora publishes its own client metadata and signs real requests. Not measured yet.10 not measured
Show the 10 planned checks
  1. T2-M1Call each read-only OpenAPI GET with no token, then with a valid signed-out token
    Outcome: Not measuredSeverity: P1coming soon§6
  2. T2-M5Load the consent page for Ora's real client_id from a valid S256 request and inspect headers; never sign in
    Outcome: Not measuredSeverity: Advisorycoming soonguides
  3. T2-01Start a Session for U1
    Outcome: Not measuredSeverity: P0coming soon§4.2
  4. T2-02Token lifetime
    Outcome: Not measuredSeverity: P2coming soon§4.2
  5. T2-05Renew with session_id
    Outcome: Not measuredSeverity: P1coming soon§4.2
  6. T2-14Nonce challenge
    Outcome: Not measuredSeverity: P1coming soon§4.3
  7. T2-16Bearer token request for an MCP server (no DPoP, resource = MCP url)
    Outcome: Not measuredSeverity: P1coming soon§4.3, §6
  8. T2-18Token accepted without cookies
    Outcome: Not measuredSeverity: P1coming soon§4.3
  9. T2-19Valid browser assertion, form POST
    Outcome: Not measuredSeverity: P0coming soon§5
  10. T2-25Cookie scope
    Outcome: Not measuredSeverity: Advisorycoming soonguides

Tier 2b: requires opt-in

Checks that run only for a verified owner who opts in. Not measured yet.36 not measured
Show the 36 planned checks
  1. T2-M2Send a valid Session Token in ?access_token= instead of the header
    Outcome: Not measuredSeverity: P0requires opt-in§4.3
  2. T2-M3Send a valid browser assertion in the URL instead of the form body
    Outcome: Not measuredSeverity: P1requires opt-in§5
  3. T2-M4Start Direct Sign-In with code_challenge_method=plain and Ora's real client_id; stop at the authorization endpoint
    Outcome: Not measuredSeverity: Advisoryrequires opt-inguides
  4. T1-12Mediated endpoint, only if the company opts in: two bad-credential attempts
    Outcome: Not measuredSeverity: P1requires opt-in§4.7, guides
  5. T2-03Replay the same assertion jti
    Outcome: Not measuredSeverity: P0requires opt-in§4.2
  6. T2-04Assertion with aud as an array or another endpoint
    Outcome: Not measuredSeverity: P1requires opt-in§4.2
  7. T2-06Renew U1's Session with a U2 assertion
    Outcome: Not measuredSeverity: P0requires opt-in§4.2
  8. T2-07Assertion signed with a key not in Ora's JWKS
    Outcome: Not measuredSeverity: P0requires opt-in§4.1
  9. T2-08alg: none or HS256 assertion
    Outcome: Not measuredSeverity: Advisoryrequires opt-inguides
  10. T2-09Valid token, reused proof jti
    Outcome: Not measuredSeverity: P0requires opt-in§4.3
  11. T2-10Proof with wrong htu or htm
    Outcome: Not measuredSeverity: P0requires opt-in§4.3
  12. T2-11Proof with wrong ath
    Outcome: Not measuredSeverity: P0requires opt-in§4.3
  13. T2-12Proof signed by a different key than the token's binding
    Outcome: Not measuredSeverity: P0requires opt-in§4.3
  14. T2-13Stale iat (beyond ~1 min)
    Outcome: Not measuredSeverity: P1requires opt-in§4.3
  15. T2-15Token sent as Authorization: Bearer to a non-MCP endpoint
    Outcome: Not measuredSeverity: P0requires opt-in§4.3
  16. T2-17That Bearer token at another MCP server or an OpenAPI endpoint
    Outcome: Not measuredSeverity: P0requires opt-in§4.3
  17. T2-20Replay the same browser assertion
    Outcome: Not measuredSeverity: P0requires opt-in§5
  18. T2-21exp more than 60 s after iat
    Outcome: Not measuredSeverity: P1requires opt-in§5
  19. T2-22return_to on a foreign domain
    Outcome: Not measuredSeverity: P0requires opt-in§5
  20. T2-23Session assertion (wrong typ) at the browser endpoint
    Outcome: Not measuredSeverity: P1requires opt-in§5
  21. T2-24Browser assertion at the token endpoint
    Outcome: Not measuredSeverity: P1requires opt-in§5
  22. T2-26Start with a general question
    Outcome: Not measuredSeverity: P0requires opt-in§7.3
  23. T2-27Retry the same message id and content
    Outcome: Not measuredSeverity: P1requires opt-in§7.3
  24. T2-28Same id, different content
    Outcome: Not measuredSeverity: P1requires opt-in§7.3
  25. T2-29Read events with and without wait
    Outcome: Not measuredSeverity: P1requires opt-in§7.5, §7.7
  26. T2-30POST …/messages?wait=10
    Outcome: Not measuredSeverity: P2requires opt-in§7.3
  27. T2-31Junk cursor
    Outcome: Not measuredSeverity: P1requires opt-in§7.13
  28. T2-32U2 reads U1's conversation
    Outcome: Not measuredSeverity: P0requires opt-in§7.2
  29. T2-33Stream with Accept: text/event-stream
    Outcome: Not measuredSeverity: P2requires opt-in§7.6
  30. T2-34Ask about the account while signed out
    Outcome: Not measuredSeverity: P1requires opt-in§7.11
  31. T2-35Message with only context
    Outcome: Not measuredSeverity: P2requires opt-in§7.4
  32. T2-36Close, then send a message
    Outcome: Not measuredSeverity: P1requires opt-in§7.12
  33. T2-37Handoff (opt-in only; may page staff)
    Outcome: Not measuredSeverity: P2requires opt-in§7.9
  34. T2-38Ora client metadata without extensions.operations, trigger a proposing endpoint
    Outcome: Not measuredSeverity: P1requires opt-inOps §2
  35. T2-39U2 reads U1's signed-out operation
    Outcome: Not measuredSeverity: P0requires opt-inOps §3.2
  36. T2-40Confirm an old revision (if revisions can be triggered)
    Outcome: Not measuredSeverity: P1requires opt-inOps §5.2

Tier 3: needs a test account and a person

Checks that need a test account from the company and a person at the keyboard. Ora does not run these on its own.17 not measured
Show the 17 planned checks
  1. T3-01Direct sign-in
    Outcome: Not measuredSeverity: P0needs a test account and a person§4.5
  2. T3-02Redirect URI not in Ora's redirect_uris
    Outcome: Not measuredSeverity: P0needs a test account and a person§4.5
  3. T3-03User declines
    Outcome: Not measuredSeverity: P1needs a test account and a person§4.5
  4. T3-04Device sign-in
    Outcome: Not measuredSeverity: P1needs a test account and a person§4.6
  5. T3-05Mediated sign-in (if offered)
    Outcome: Not measuredSeverity: P1needs a test account and a person§4.7
  6. T3-06Partial scope approval
    Outcome: Not measuredSeverity: P1needs a test account and a person§4.4
  7. T3-07Request an unlisted scope
    Outcome: Not measuredSeverity: P1needs a test account and a person§4.4
  8. T3-08Scope enforcement across channels
    Outcome: Not measuredSeverity: P0needs a test account and a person§4.4, guides
  9. T3-09Account Token from another client_id or at an API
    Outcome: Not measuredSeverity: P0needs a test account and a person§4.8
  10. T3-10Account Token with narrower and wider scope
    Outcome: Not measuredSeverity: P1needs a test account and a person§4.8
  11. T3-11Sign a Session into account B after account A
    Outcome: Not measuredSeverity: P1needs a test account and a person§4.4
  12. T3-12Revoke the Account Token
    Outcome: Not measuredSeverity: P0needs a test account and a person§4.9
  13. T3-13Signed-out token on an account-using conversation
    Outcome: Not measuredSeverity: P1needs a test account and a person§7.11
  14. T3-14Direct Conversation
    Outcome: Not measuredSeverity: P1needs a test account and a person§7.10
  15. T3-15Operation end to end (sandbox action)
    Outcome: Not measuredSeverity: P0needs a test account and a personOps §3, Ops §6
  16. T3-16standing_permission on a user_approval_required operation
    Outcome: Not measuredSeverity: P1needs a test account and a personOps §5.2
  17. T3-17Account settings
    Outcome: Not measuredSeverity: Advisoryneeds a test account and a personguides