Getting your business ready for personal agents
Poppy draft 0.1 is public under Apache 2.0. It defines discovery, sign-in, sessions, scopes, web browsing, APIs and company-agent conversations. The draft may change before a stable release.Read the specification →
Start with the draft itself and check its open topics before committing to an integration. Treat this checklist as a starting point for your team's review.
1. Find out who's already visiting
Personal agents aren't waiting for a standard. Muse launched on September 8, 2026. By September 20 Amazon was blocking it, saying the agent didn't identify itself. Before you plan for agents, check your logs and support queues for the ones you already have.
2. Decide what a guest agent can see
Sierra's examples for a guest session are product availability and returns policies. Make sure that information is easy to read on your site without signing in. That's useful for agents today, whatever v0.1 says.
3. Sort your account actions into read and write
The draft defines poppy:read and poppy:write, and lets companies define narrower scopes. Map each account action to the scopes it needs, then check the same limits across web browsing, APIs and company-agent actions.
4. Check your sign-in can authorize a third party
Draft 0.1 supports direct, device and mediated sign-in. Review which types fit your security model and whether your OAuth server supports the required metadata and token behavior.
5. Pick your route
| Route | Good fit when | What you'd need |
|---|---|---|
| Website | You don't want to build anything new yet | Pages an agent can actually use: clear forms, stable markup |
| APIs | You already have an API or an MCP server | An MCP server or an OpenAPI description, the two standards Sierra names |
| Your own agent | Tasks need back-and-forth, like a warranty claim | A customer-facing agent that can take requests from other agents |
6. Keep payments out of scope for now
Payments are a future Poppy extension. If agents need to check out today, look at what's already live: ACP with Stripe, UCP from Google, or Visa's TAP.See how they compare →
What not to do yet
- Build from the official draft, and account for backward-incompatible changes before a stable release.
- Don't treat Poppy as the only door. Anthropic, Google and Amazon aren't named as partners, and their agents will keep showing up.
- Don't promise customers anything about agent liability or chargebacks. Nothing announced so far covers it.
Track draft changes
Sierra has announced design workshops and a reference implementation. We'll update this checklist as the specification changes and log each update on the status page.
Sources
- Introducing Personal Agent Protocol · Sierra (Bret Taylor, Clay Bavor), Oct 6, 2026 · primary source
- Meta's Personal Agent Protocol Signs Walmart Before It Has a Spec · BERI
- Meta joins with group of companies to tame 'chaos' of doing business with AI bots · CNBC, Oct 6, 2026
- Model Context Protocol · modelcontextprotocol.io · primary source
poppy.md is independent and not affiliated with Sierra, Meta or any Poppy partner. Facts here come from the sources listed on each page.