# What Is Poppy (Personal Agent Protocol)? A Sourced Guide

> Poppy is the Personal Agent Protocol draft from Sierra and Meta. Learn how discovery, OAuth sessions, sign-in, APIs and company agents work in draft 0.1.

Source: https://poppy.md/docs/overview.html

Last checked against sources: Oct 10, 2026

# What is Poppy (Personal Agent Protocol)?

Poppy is the short name for Personal Agent Protocol, an open protocol for how personal agents and companies work together. Sierra and Meta announced it on October 6, 2026, and published draft 0.1 on October 9. It covers discovery, authorization, web browsing, APIs and conversations.

 Draft 0.1 is available. It may change, including in backward-incompatible ways, before a stable release. This guide reflects the draft and links to the official sources. Read the draft →

Poppy is the protocol's published short name. PAP is also used for the older Password Authentication Protocol (PPP), which is unrelated.

## The problem it's aimed at

Today a personal agent uses a company's website the way you would. It loads pages, clicks through forms and, when it gets stuck, calls support or opens a chat window. It's slow, and it breaks whenever the site changes.

The business has its own problem: it can't tell a customer's agent from a scraper. Amazon's reason for blocking Meta's Muse in September was exactly that, an agent that didn't say who it was. Sierra's pitch is that a direct, agreed connection could finish the same task in seconds.

## Who wants what

The announcement frames Poppy around three parties. Each one is after something different, and the protocol is supposed to give all three enough to show up.

### Customers

Speed, and a task done right the first time, by an agent that's working for them.

### Businesses

To know when an agent is acting for a real customer, and to decide what it may do.

### Agent builders

One direct, consistent way in, instead of a different workaround for every site.

## How a visit works

The rule of thumb from Sierra's post: customers decide what access their agent gets, and companies set the parameters for what agents can do. In practice:

- **Discover.** The agent reads the company's `/.well-known/poppy.json` file to find sign-in options, APIs and company agents.
- **Start as a guest** when that's enough, say to check stock or a returns policy.
- **Sign in** through a direct browser flow, a device code, or a company-defined mediated flow.
- **Grant scopes.** The draft defines `poppy:read` and `poppy:write`, with company-defined scopes as an option.
- **Finish on a route** the company offers: its website, its APIs (MCP and OpenAPI are the two named), or its own agent.

The session carries across channels, so a question asked before sign-in and an order change made afterward count as the same visit. [Diagrams and detail →](/docs/architecture)

## What Poppy doesn't do yet

Sierra lists three ideas as possible later steps: finer permissions on specific actions, push notifications (a delayed flight, a shipped order) and payments without sharing card details. None is in the announced first version. If you need agent checkout today, that's ACP, UCP or TAP territory. [How they compare →](/compare)

## Who's behind it

Sierra is the AI customer-service company run by Bret Taylor and Clay Bavor. Taylor was Facebook's CTO, helped create the "log in with Facebook" style of sign-in, and now chairs OpenAI's board. Meta makes Muse, the personal agent that pushed this whole issue into the open.

10 organisations are named across the October 6 launch lists. On October 9, Sierra announced 35 additional design partners, including OpenAI, Cloudflare, Visa and Notion. Genesys, Rocket, Shopify, Stripe and Walmart are on both launch lists. Sierra adds Instinct; Meta adds NiCE and Decagon. Anthropic, Google and Amazon are not named as partners.[Full partner comparison →](/ecosystem/partners)

## Two comparisons the founders use

Taylor compares Poppy to social sign-in, the "log in with Google or Facebook" flow he worked on. Meta's David Singleton, a former Stripe CTO, reaches for email instead: it works because anyone can use the standard to talk to anyone. Both analogies point the same way. Whether Poppy gets there depends on the companies that aren't in the room yet.

### Spec status →

What was promised, what's shipped, and when we last checked.

### FAQ →

Short sourced answers to the questions people keep asking.

## Sources

- [Introducing Personal Agent Protocol](https://sierra.ai/blog/introducing-personal-agent-protocol) · Sierra (Bret Taylor, Clay Bavor), Oct 6, 2026 · primary source
- [Sharing a draft of Personal Agent Protocol](https://sierra.ai/blog/poppy) · Sierra (Bret Taylor, Clay Bavor), Oct 9, 2026 · primary source
- [Personal Agent Protocol overview (Draft 0.1)](https://personalagentprotocol.org/docs/overview) · Personal Agent Protocol, Oct 9, 2026 · primary source
- [Personal Agent Protocol specification (Draft 0.1)](https://personalagentprotocol.org/docs/spec) · Personal Agent Protocol, Oct 9, 2026 · primary source
- [Meta joins with group of companies to tame 'chaos' of doing business with AI bots](https://www.cnbc.com/2026/10/06/meta-joins-companies-to-tame-chaos-of-doing-business-with-ai-bots.html) · CNBC, Oct 6, 2026
- [Genesys, NiCE Join Sierra, Meta on Open Standard for Personal AI Agents](https://www.cmswire.com/contact-center/genesys-joins-sierra-meta-on-open-standard-for-personal-ai-agents-01/) · CMSWire
- [Meta's Personal Agent Protocol Signs Walmart Before It Has a Spec](https://www.beri.net/article/meta-sierra-personal-agent-protocol-oauth-guest-read-write-access-vs-ucp-acp-trusted-agent-protocol-retail-banks) · BERI

poppy.md is independent and not affiliated with Sierra, Meta or any Poppy partner. Facts here come from the sources listed on each page.
