How the Personal Agent Protocol works
A Poppy visit starts on the company's website. The agent can stay a guest or the customer signs in through OAuth and picks read-only or write. Then the company decides how the agent finishes the job: its website, its APIs or its own agent.
One visit
Three parties share the visit: the customer, their personal agent, and the company. The session is built on OAuth.
1. Discover
The agent fetches /.well-known/poppy.json. The document lists the company's sign-in methods and whichever web, API, and company-agent routes it offers.
2. Start a session
The agent begins a session for the user. It can start as a guest. That can be enough to check product availability or ask about a returns policy.
When the task needs the customer's account, the customer signs in on the company's page or uses credentials already set up with the personal agent.
3. Choose access
The customer stays in control and decides whether the agent has:
- Read-only access
- Write access
The draft defines broad poppy:read and poppy:write scopes. Companies choose which operations each scope permits and may define narrower scopes of their own.
4. Keep one visit
The OAuth session carries across channels. A question asked before sign-in and an order change made afterward are part of the same visit.
Three routes
After the session exists, the agent uses whichever route the company believes will offer the best customer experience. The company decides what it makes available.
Website
The agent navigates the company's regular web pages.
APIs
The agent connects through interfaces built on standards such as MCP andOpenAPI. Those are the two standards the announcement names.
Company agent
The agent works through the company's own agent when the task needs conversation. The announcement's example is a warranty claim.
What each party gets
| Party | Decides | Gets |
|---|---|---|
| Customer | What access the agent receives | A faster way to finish the task |
| Company | Parameters and which routes exist | Visibility into an agent acting for a customer |
| Agent builder | How the agent uses the offered routes | One consistent way to connect |
Planned, not in the first cut
Sierra and Meta described these as possible next steps, alongside the v0.1 spec, design workshops, and a reference implementation:
- More detailed permissions — customers and companies set limits on specific actions
- Push notifications — a company tells the agent when a flight is delayed or an order ships
- Payment extensions — the agent completes a purchase without sharing credit card information
Next
Glossary →
Terms used on this site, kept to what the announcement actually says.
Partners →
Who's named, by whom, and what they said.
Sources
- Sharing a draft of Personal Agent Protocol · Sierra (Bret Taylor, Clay Bavor), Oct 9, 2026 · primary source
- Personal Agent Protocol overview (Draft 0.1) · Personal Agent Protocol, Oct 9, 2026 · primary source
- Personal Agent Protocol specification (Draft 0.1) · Personal Agent Protocol, Oct 9, 2026 · primary source
poppy.md is independent and not affiliated with Sierra, Meta or any Poppy partner. Facts here come from the sources listed on each page.