The user guide
Every screen you'll meet, from download to your first running poppy. The app is free, the one-time AWS setup takes about three minutes, and nothing below ever asks for — or uses — admin access to your cloud.
Building apps instead? That path lives in the developer hub.
Download AgentsPoppy for macOS, Windows, or Linux — it's free, with no account to create. The first launch introduces the one idea everything else rests on: AgentsPoppy is the gatekeeper between your apps and your own AWS. Apps never hold your keys; they get scoped, short-lived credentials that expire within the hour, and you can switch any of it off whenever you like.
Poppies run in your cloud account, so setup begins by choosing one. Today that is Amazon Web Services — Google Cloud and Azure are marked coming soon — and the screen is built for people who have never opened a cloud console: one choice, full screen, nothing else to parse. No AWS account yet? Press the AWS mark and the app opens Amazon's own signup; creating an account is free, new accounts get free credits, and plenty of the Free Tier stays free permanently. You'll enter a card for identity verification; Free-Tier usage isn't charged.
Two minutes in the AWS console: you make one dedicated, least-privilege user — never your account root. One action per card, in order: a button that opens the right console page, and a button that copies the scoped policy. That policy lets the one-time setup create AgentsPoppy's own role and operator, and nothing else, and you can revoke it any time. Stuck on any card? A small Stuck? link under it explains that step in plain words — the help is there when needed and invisible when not.
Create that user's access key and paste both values in — the only thing you type, and the last console work you'll ever do here. The wizard walks you to AWS's own Done button on purpose: the secret is shown only once, and leaving that screen half-finished is how people lose it. If your company signs in through SSO and can't create access keys, an advanced path is offered right on this screen, exactly where you'd need it.
Last question: which region of the world should hold everything AgentsPoppy sets up? The closest one to you is suggested from your timezone — closest is fastest, and your data stays in that part of the world. Choosing a flag arms the finish button, and pressing it does the rest on its own: AgentsPoppy creates the broker role and a non-admin operator in your account, links the account, and verifies the connection actually works before saying so. This is the part that makes AgentsPoppy different — the role lives in your account, AgentsPoppy only ever assumes it, and it never receives a key of its own. Safe to walk away from: if it's interrupted nothing elevated is saved, and running setup again picks up wherever AWS actually got to.
eu-west-1, with the closest suggested — and the finish button is
the confirm, so the choice can never be skipped.
The Poppies tab is the app store — except every listing links its open repository, so you (or your AI agent) can read exactly what a poppy does before it ever touches your cloud. Pick one, press Install, done.
The first time a poppy wants to use its connection, AgentsPoppy stops and asks you — Approve or Deny, in plain language, with every requested power rated green, amber, or red. Nothing runs until you say yes, and you can pause or revoke a poppy's access at any time.
A running poppy is just an app — inbox, dashboard, buttons — with one difference you can see in its title bar: Sandboxed · own resources only. Its backend lives in your account, its data stays in your account, and where costs exist they're counted in front of you.
Open any poppy on the Dashboard and you get the view no ordinary app store can give you: a live map of what it actually built in your cloud, service by service, plus every power it holds — each one labelled “Its own” (scoped to resources it created) or “Broad” (and then read-only). Done with it? “Tear down everything it built” removes the lot. No zombie servers, no surprise bill.
This is the part no other app platform does. When an update ships, AgentsPoppy doesn't auto-install it — it shows you Review and update. Reviewing reads the open source; nothing is downloaded to your computer until you choose to install.
One click on “Verify this update with your AI agent” copies a prompt — written by AgentsPoppy, not by the app being audited — that has your own AI read the source and report anything undeclared or risky: new external calls, credential access, broader AWS powers.
Every other store asks you to trust an update because someone else reviewed it. Here the reviewer works for you, reads the actual source, and answers to nobody else — and if the verdict is bad, the update simply never touches your machine or your cloud.
Install → connect your own cloud → approve in plain language → watch what it builds → audit what changes. The app is free; your cloud stays yours.