Poppy:
what's announced,
what's still missing.
Poppy (Personal Agent Protocol) is an open standard Sierra and Meta announced on October 6, 2026. It sets out how your AI agent signs in to a business and acts for you. You choose what access to grant. The business chooses the route. Draft 0.1 is public and still evolving.
poppy.md is an independent tracker, not affiliated with Sierra, Meta or the partners. We log every partner, date and claim with its source, and we'll annotate v0.1 the day it ships.
The customer picks access
Read-only or write. That’s the whole menu for now; finer limits are on the "later" list.
Sessions run on OAuth
Sign in on the company’s own page, or use credentials already set up with the agent. A guest visit is fine for stock checks.
The business picks the route
Its website, an API such as MCP or OpenAPI, or its own agent when the job needs a conversation.
Poppy in ten lines
Everything here comes from Sierra's post or named coverage. If it isn't sourced, it isn't on the list. Checked Oct 10, 2026.
How we got here: the timeline- Name
- Poppy (Personal Agent Protocol)
- Announced
- October 6, 2026, at Sierra Summit, San Francisco
- Created by
- Sierra (Bret Taylor, Clay Bavor) and Meta
- What it covers
- How a personal AI agent signs in to a business and what it may do there
- Auth
- OAuth sessions; guest or signed in
- Access levels
- Read-only or write, chosen by the customer
- Routes
- Company website, APIs (MCP, OpenAPI), or the company’s own agent
- Spec
- Draft 0.1 published October 9, 2026 · Apache 2.0
- Not covered yet
- Payments, push notifications, finer permissions
- Not named as partners
- Anthropic, Google, Amazon
How the Personal Agent Protocol works
You, your agent and the company share one visit. The draft now defines discovery, sign-in, sessions and the routes companies can offer.
Discover on the site
The agent finds what the company offers and how to reach it. A guest session can check stock or a returns policy.
You choose access
If the task needs your account, you sign in. You decide read-only or write. The visit stays the same.
The company picks a route
Website pages, an API such as MCP or OpenAPI, or the company’s own agent.
Draft 0.1 defines the details
Draft 0.1 specifies discovery at /.well-known/poppy.json, OAuth sign-in, session tokens and the API and conversation routes. It can still change before a stable release.
Where Poppy fits next to MCP, A2A, UCP, ACP, TAP and PACT
Agents already have a protocol for tools, one for talking to each other, two for shopping and one for proving who they are. Poppy adds the customer's permission. Here's where each one ends.
Poppy vs MCP
Low overlapModel Context Protocol · Anthropic
Tools and data an AI app can call
Read the comparisonPoppy vs A2A
Some overlapAgent2Agent · Google, now a Linux Foundation project
How two agents talk to each other
Read the comparisonPoppy vs UCP
Some overlapUniversal Commerce Protocol · Google, with Shopify and retailers
The shopping flow: discovery, checkout, after-sale
Read the comparisonPoppy vs ACP
Some overlapAgentic Commerce Protocol · OpenAI and Stripe
In-agent checkout and payment tokens
Read the comparisonPoppy vs TAP
High overlapTrusted Agent Protocol · Visa and Cloudflare
Proving an agent’s identity on each request
Read the comparisonPoppy vs PACT
High overlapPersonal Agent Consent & Trust Protocol · Decagon and Instinct
Agent identity and customer authority, agent-to-agent
Read the comparisonTwo announcements, two partner lists
Sierra and Meta didn't publish the same names. Seven appear on both. Instinct is only on Sierra's list; NiCE and Decagon are only on Meta's.
| Company | Role | Sierra post | Meta post |
|---|---|---|---|
| Sierra | Co-creator | ||
| Meta | Co-creator | ||
| Genesys | Launch partner | ||
| Rocket Companies | Launch partner | ||
| Shopify | Launch partner | ||
| Stripe | Launch partner | ||
| Walmart | Launch partner | ||
| Instinct | Launch partner | ||
| NiCE | Partner | ||
| Decagon | Working group |
Not named on the October 6 lists: Anthropic, Google, Amazon. Meta's list as reported by CMSWire.
Questions people keep asking
Is the Poppy specification published?+
Yes. Draft 0.1 was published on October 9, 2026 under Apache 2.0. It is subject to change before a stable release.
Are OpenAI, Anthropic, Google or Amazon part of Poppy?+
OpenAI joined as a design partner on October 9, 2026. Anthropic, Google and Amazon are not named in the partner announcements.
Does Poppy handle payments?+
Not in the announced first version. Payment extensions, letting an agent buy without sharing card details, are listed as a possible later step.
Does Poppy replace MCP?+
No. The announcement names MCP and OpenAPI as API routes a company can offer inside a Poppy session.
Building for agents before the spec lands?
Don't code against guessed endpoints. Start with what's actually been announced, and check the tracker. We'll publish an annotated read of v0.1 the day it goes live.