Last checked against sources:

How the Personal Agent Protocol works

A Poppy visit starts on the company's website. The agent can stay a guest or the customer signs in through OAuth and picks read-only or write. Then the company decides how the agent finishes the job: its website, its APIs or its own agent.

Draft 0.1 · October 9, 2026. The specification is public under Apache 2.0 and may change before a stable release. Read it →

One visit

Three parties share the visit: the customer, their personal agent, and the company. The session is built on OAuth.

Poppy protocol architecture The Personal Agent Protocol draft 0.1 system map. A User sets a task and approves account access when needed. Their Personal Agent fetches the Company discovery document at /.well-known/poppy.json, then starts a Session with the Company OAuth server. Sessions begin signed out. The User may sign in directly, by device, or through the Personal Agent; the Company enforces approved scopes. The same Session context can reach the Company website through a browser assertion and Company cookie, APIs through Session Tokens (DPoP for OpenAPI, Bearer for MCP), or the Company Agent through Poppy conversations. The Account Token is an OAuth refresh token used only at the token endpoint. Source: official draft 0.1, sections 3–7. How a Poppy Session works Discovery, scoped access, then a route the Company offers. User Sets the task and approves account access when the task needs it. Personal Agent Finds the Company, starts a Session, and acts through supported routes. task COMPANY Discovery The agent fetches /.well-known/poppy.json for the OAuth issuer, sign-in methods, and offered web, API, and Company Agent routes. OAuth server Starts Sessions signed out. If needed, the User signs in directly, by device, or through the agent. The Company enforces scopes. GET discovery start Session One Company Session One User, one Company, one Personal Agent. Activity stays linked across the offered channels. Session context Choose an offered route Website Browser assertion joins the Session; the Company sets its scoped cookie. APIs OpenAPI uses DPoP. MCP uses a server-scoped Bearer Session Token. Company Agent Poppy conversations use DPoP. Events can stream and hand off to a person. The two tokens have different jobs Session Token: short-lived; used for APIs and conversations. Account Token: OAuth refresh token; used only at the token endpoint to get later signed-in Sessions. Source: Personal Agent Protocol draft 0.1, sections 3–7 · personalagentprotocol.org/docs/spec
Poppy draft 0.1: discovery, authorization, and three company routes. PNG

1. Discover

The agent fetches /.well-known/poppy.json. The document lists the company's sign-in methods and whichever web, API, and company-agent routes it offers.

2. Start a session

The agent begins a session for the user. It can start as a guest. That can be enough to check product availability or ask about a returns policy.

When the task needs the customer's account, the customer signs in on the company's page or uses credentials already set up with the personal agent.

3. Choose access

The customer stays in control and decides whether the agent has:

  • Read-only access
  • Write access

The draft defines broad poppy:read and poppy:write scopes. Companies choose which operations each scope permits and may define narrower scopes of their own.

4. Keep one visit

The OAuth session carries across channels. A question asked before sign-in and an order change made afterward are part of the same visit.

Three routes

After the session exists, the agent uses whichever route the company believes will offer the best customer experience. The company decides what it makes available.

Website

The agent navigates the company's regular web pages.

APIs

The agent connects through interfaces built on standards such as MCP andOpenAPI. Those are the two standards the announcement names.

Company agent

The agent works through the company's own agent when the task needs conversation. The announcement's example is a warranty claim.

What each party gets

PartyDecidesGets
CustomerWhat access the agent receivesA faster way to finish the task
CompanyParameters and which routes existVisibility into an agent acting for a customer
Agent builderHow the agent uses the offered routesOne consistent way to connect

Identity has a boundary

Draft 0.1 identifies the personal agent with its HTTPS client_id. The user ID is stable for that agent at one company, opaque, and different at every company. A company can require agent registration, keep allowlists or blocklists, and revoke an agent ID. The draft does not define a universal user identity or a trust claim from an agent operator that follows a customer across companies.

That distinction responds to a question raised by Colin at Clerk: could services rely on an agent operator to identify the signed-in user? Poppy v0.1 puts account identity through the company's own sign-in flow instead. The tradeoff is worth watching: it limits cross-company identity sharing, while leaving operator-level trust and recognition outside this draft.Read Colin's post →

Explore Poppy implementations

Community projects now include SDKs, clients, pre-draft samples and partner demos. Each listing describes the draft version and flows it covers, along with known limitations.Browse Poppy implementations →

Planned, not in the first cut

Sierra and Meta described these as possible next steps, alongside the v0.1 spec, design workshops, and a reference implementation:

  • More detailed permissions — customers and companies set limits on specific actions
  • Push notifications — a company tells the agent when a flight is delayed or an order ships
  • Payment extensions — the agent completes a purchase without sharing credit card information

Next

Sources

  1. Sharing a draft of Personal Agent Protocol · Sierra (Bret Taylor, Clay Bavor), Oct 9, 2026 · primary source
  2. Personal Agent Protocol overview (Draft 0.1) · Personal Agent Protocol, Oct 9, 2026 · primary source
  3. Personal Agent Protocol specification (Draft 0.1) · Personal Agent Protocol, Oct 9, 2026 · primary source
  4. Community feedback on agent and user identity in Poppy · Colin (Clerk) on X, Oct 10, 2026

poppy.md is independent and not affiliated with Sierra, Meta or any Poppy partner. Facts here come from the sources listed on each page.