# Poppy for Businesses: Implement Draft 0.1

> A practical guide to Poppy draft 0.1 for businesses: publish discovery, choose sign-in methods, scopes and the interfaces personal agents can use.

Source: https://poppy.md/for-businesses.html

Last checked against sources: Oct 10, 2026

# Getting your business ready for personal agents

Poppy draft 0.1 is public under Apache 2.0. It defines discovery, sign-in, sessions, scopes, web browsing, APIs and company-agent conversations. The draft may change before a stable release.[Read the specification →](https://personalagentprotocol.org/docs/spec)

Start with the draft itself and check its open topics before committing to an integration. Treat this checklist as a starting point for your team's review.

## 1. Find out who's already visiting

Personal agents aren't waiting for a standard. Muse launched on September 8, 2026. By September 20 Amazon was blocking it, saying the agent didn't identify itself. Before you plan for agents, check your logs and support queues for the ones you already have.

## 2. Decide what a guest agent can see

Sierra's examples for a guest session are product availability and returns policies. Make sure that information is easy to read on your site without signing in. That's useful for agents today, whatever v0.1 says.

## 3. Sort your account actions into read and write

The draft defines `poppy:read` and `poppy:write`, and lets companies define narrower scopes. Map each account action to the scopes it needs, then check the same limits across web browsing, APIs and company-agent actions.

## 4. Check your sign-in can authorize a third party

Draft 0.1 supports direct, device and mediated sign-in. Review which types fit your security model and whether your OAuth server supports the required metadata and token behavior.

## 5. Pick your route

 Route Good fit when What you'd need Website You don't want to build anything new yet Pages an agent can actually use: clear forms, stable markup APIs You already have an API or an MCP server An MCP server or an OpenAPI description, the two standards Sierra names Your own agent Tasks need back-and-forth, like a warranty claim A customer-facing agent that can take requests from other agents

## 6. Keep payments out of scope for now

Payments are a future Poppy extension. If agents need to check out today, look at what's already live: ACP with Stripe, UCP from Google, or Visa's TAP.[See how they compare →](/compare)

## What not to do yet

- Build from the official draft, and account for backward-incompatible changes before a stable release.
- Don't treat Poppy as the only door. Anthropic, Google and Amazon aren't named as partners, and their agents will keep showing up.
- Don't promise customers anything about agent liability or chargebacks. Nothing announced so far covers it.

## Track draft changes

Sierra has announced design workshops and a reference implementation. We'll update this checklist as the specification changes and log each update on the [status page](/status).

## Sources

- [Introducing Personal Agent Protocol](https://sierra.ai/blog/introducing-personal-agent-protocol) · Sierra (Bret Taylor, Clay Bavor), Oct 6, 2026 · primary source
- [Meta's Personal Agent Protocol Signs Walmart Before It Has a Spec](https://www.beri.net/article/meta-sierra-personal-agent-protocol-oauth-guest-read-write-access-vs-ucp-acp-trusted-agent-protocol-retail-banks) · BERI
- [Meta joins with group of companies to tame 'chaos' of doing business with AI bots](https://www.cnbc.com/2026/10/06/meta-joins-companies-to-tame-chaos-of-doing-business-with-ai-bots.html) · CNBC, Oct 6, 2026
- [Model Context Protocol](https://modelcontextprotocol.io) · modelcontextprotocol.io · primary source

poppy.md is independent and not affiliated with Sierra, Meta or any Poppy partner. Facts here come from the sources listed on each page.
