Last checked against sources:

Glossary

Definitions follow draft 0.1, published October 9, 2026. The draft may change before a stable release.

Core concepts

Poppy (Personal Agent Protocol)

An open standard Sierra and Meta are developing with industry partners. It defines how personal agents and companies work together across discovery, sign-in, sessions, web browsing, APIs, and conversations. Anyone can implement the draft under Apache 2.0.

Personal agent

An AI agent that acts for a person. The announcement's examples of tasks include scheduling appointments, booking flights, and shopping for insurance. Meta's Muse is the consumer agent discussed alongside the launch.

Muse

Meta's personal agent, launched September 8, 2026. Amazon blocked it from Amazon.com on September 20. It's the agent most of the Poppy coverage is really about.

Company agent

An agent operated by the company. A personal agent can use it for tasks that need conversation, such as a warranty claim.

Session and access

Discovery

A company publishes discovery at /.well-known/poppy.json, listing its sign-in methods and supported interfaces.

Guest

A session that has not signed in to the customer account. It may be enough to check product availability or ask about a returns policy.

OAuth

The established standard Poppy uses to authorize access. The customer signs in on the company's page or uses credentials already set up with the personal agent.

Read-only access

The draft defines the poppy:read scope for viewing account information.

Write access

The draft defines the poppy:write scope for making account changes.

Session

The OAuth visit between the agent and the company. It carries across channels, so a question before sign-in and a change afterward belong to the same visit.

Routes

Route

A way the company lets the personal agent finish the task. The company chooses the route it believes is best for the customer.

  • Website: the company's regular web pages
  • APIs: interfaces on standards such as MCP and OpenAPI
  • Company agent: conversational tasks, such as a warranty claim

OpenAPI

A standard way to describe an HTTP API. The other API standard the announcement names.

Related protocols

MCP (Model Context Protocol)

Anthropic's protocol for AI apps to call tools and read data through servers. Poppy names it as one of the API routes a company can offer, so it doesn't replace MCP.Poppy vs MCP →

A2A (Agent2Agent)

A protocol for agents from different vendors to exchange tasks, started by Google. Not named in the Poppy announcement. Poppy vs A2A →

PACT (Personal Agent Consent & Trust Protocol)

Decagon's protocol, open-sourced with Instinct on the day Poppy was announced. Built on A2A and OAuth 2.0, it separates an agent's identity from its authority to act on an account.Poppy vs PACT →

UCP (Universal Commerce Protocol)

Google's open protocol for agent shopping, from discovery through checkout and after. Announced January 11, 2026. Poppy vs UCP →

ACP (Agentic Commerce Protocol)

OpenAI and Stripe's checkout protocol, behind Instant Checkout in ChatGPT. Released September 29, 2025. Poppy vs ACP →

TAP (Trusted Agent Protocol)

Visa and Cloudflare's protocol for proving an agent's identity by signing its HTTP requests.Poppy vs TAP →

Web Bot Auth

An IETF draft, led by Cloudflare, for bots and agents to sign HTTP requests using HTTP Message Signatures (RFC 9421). TAP builds on it.

Participants

Customer

The person who decides what access to give their personal agent. They want speed, dependability, and an agent that acts in their interest.

Company

The business that sets parameters for what agents can do, and which routes exist. Companies want to know when a personal agent is acting for a customer.

Agent builder

A company building personal agents. They want a direct, consistent way to work with participating companies.

Announced next, not shipping yet

More detailed permissions

A possible later feature: customers and companies set limits on specific actions.

Push notifications

A possible later feature: the company tells the personal agent when a flight is delayed or an order ships.

Payment extensions

A possible later feature: the agent completes a purchase without sharing credit card information.

See also

Sources

  1. Introducing Personal Agent Protocol · Sierra (Bret Taylor, Clay Bavor), Oct 6, 2026 · primary source
  2. Introducing the Personal Agent Consent & Trust Protocol (PACT) · Decagon, Oct 6, 2026 · primary source
  3. Model Context Protocol · modelcontextprotocol.io · primary source
  4. Agent2Agent (A2A) Protocol · a2a-protocol.org · primary source
  5. Under the Hood: Universal Commerce Protocol (UCP) · Google Developers Blog · primary source
  6. Stripe powers Instant Checkout in ChatGPT and releases Agentic Commerce Protocol codeveloped with OpenAI · Stripe, Sep 29, 2025 · primary source
  7. Getting Started with Visa's Trusted Agent Protocol · Visa Developer · primary source

poppy.md is independent and not affiliated with Sierra, Meta or any Poppy partner. Facts here come from the sources listed on each page.