# Poppy (Personal Agent Protocol): Spec Status & Comparisons

> Independent tracker for the Personal Agent Protocol by Sierra and Meta: what was announced on Oct 6, 2026, spec v0.1 status, partners, and how Poppy compares with MCP, A2A, UCP and ACP.

Source: https://poppy.md/

Draft 0.1 published · checked Oct 10, 2026

# Poppy:
what's announced,
what's still missing.

**Poppy (Personal Agent Protocol)** is an open standard Sierra and Meta announced on October 6, 2026. It sets out how your AI agent signs in to a business and acts for you. You choose what access to grant. The business chooses the route. Draft 0.1 is public and still evolving.

poppy.md is an independent tracker, not affiliated with Sierra, Meta or the partners. We log every partner, date and claim with its source, and we'll annotate v0.1 the day it ships.

 What is Poppy Poppy vs MCP, A2A, UCP…

Announced

Oct 6

Oct 6 launch orgs

10

Auth

OAuth

 How a Poppy session works

R / W

Access

### The customer picks access

Read-only or write. That’s the whole menu for now; finer limits are on the "later" list.

OAuth

Session

### Sessions run on OAuth

Sign in on the company’s own page, or use credentials already set up with the agent. A guest visit is fine for stock checks.

3

Routes

### The business picks the route

Its website, an API such as MCP or OpenAPI, or its own agent when the job needs a conversation.

 Fact sheet

## Poppy in ten lines

Everything here comes from Sierra's post or named coverage. If it isn't sourced, it isn't on the list. Checked Oct 10, 2026.

 How we got here: the timeline

 Name Poppy (Personal Agent Protocol)

 Announced October 6, 2026, at Sierra Summit, San Francisco

 Created by Sierra (Bret Taylor, Clay Bavor) and Meta

 What it covers How a personal AI agent signs in to a business and what it may do there

 Auth OAuth sessions; guest or signed in

 Access levels Read-only or write, chosen by the customer

 Routes Company website, APIs (MCP, OpenAPI), or the company’s own agent

 Spec Draft 0.1 published October 9, 2026 · Apache 2.0

 Not covered yet Payments, push notifications, finer permissions

 Not named as partners Anthropic, Google, Amazon

 Draft 0.1

## How the Personal Agent Protocol works

You, your agent and the company share one visit. The draft now defines discovery, sign-in, sessions and the routes companies can offer.

WEB

### Discover on the site

The agent finds what the company offers and how to reach it. A guest session can check stock or a returns policy.

 GUEST

OAUTH

### You choose access

If the task needs your account, you sign in. You decide read-only or write. The visit stays the same.

 CONSENT

ROUTE

### The company picks a route

Website pages, an API such as MCP or OpenAPI, or the company’s own agent.

 DONE

 </>

#### Draft 0.1 defines the details

Draft 0.1 specifies discovery at `/.well-known/poppy.json`, OAuth sign-in, session tokens and the API and conversation routes. It can still change before a stable release.

 See the architecture

 The protocol pile-up

## Where Poppy fits next to MCP, A2A, UCP, ACP, TAP and PACT

Agents already have a protocol for tools, one for talking to each other, two for shopping and one for proving who they are. Poppy adds the customer's permission. Here's where each one ends.

### Poppy vs MCP

 Low overlap

Model Context Protocol · Anthropic

Tools and data an AI app can call

 Read the comparison

### Poppy vs A2A

 Some overlap

Agent2Agent · Google, now a Linux Foundation project

How two agents talk to each other

 Read the comparison

### Poppy vs UCP

 Some overlap

Universal Commerce Protocol · Google, with Shopify and retailers

The shopping flow: discovery, checkout, after-sale

 Read the comparison

### Poppy vs ACP

 Some overlap

Agentic Commerce Protocol · OpenAI and Stripe

In-agent checkout and payment tokens

 Read the comparison

### Poppy vs TAP

 High overlap

Trusted Agent Protocol · Visa and Cloudflare

Proving an agent’s identity on each request

 Read the comparison

### Poppy vs PACT

 High overlap

Personal Agent Consent & Trust Protocol · Decagon and Instinct

Agent identity and customer authority, agent-to-agent

 Read the comparison

 October 6 launch lists

## Two announcements, two partner lists

Sierra and Meta didn't publish the same names. Seven appear on both. Instinct is only on Sierra's list; NiCE and Decagon are only on Meta's.

 Company Role Sierra post Meta post Sierra Co-creator Meta Co-creator Genesys Launch partner Rocket Companies Launch partner Shopify Launch partner Stripe Launch partner Walmart Launch partner Instinct Launch partner NiCE Partner Decagon Working group

Not named on the October 6 lists: Anthropic, Google, Amazon. Meta's list as reported by CMSWire.

 What each partner actually said

## Questions people keep asking

 Is the Poppy specification published? +

Yes. Draft 0.1 was published on October 9, 2026 under Apache 2.0. It is subject to change before a stable release.

 Are OpenAI, Anthropic, Google or Amazon part of Poppy? +

OpenAI joined as a design partner on October 9, 2026. Anthropic, Google and Amazon are not named in the partner announcements.

 Does Poppy handle payments? +

Not in the announced first version. Payment extensions, letting an agent buy without sharing card details, are listed as a possible later step.

 Does Poppy replace MCP? +

No. The announcement names MCP and OpenAPI as API routes a company can offer inside a Poppy session.

 All 18 answers

 Draft 0.1 published · October 9, 2026

## Building for agents before the spec lands?

Don't code against guessed endpoints. Start with what's actually been announced, and check the tracker. We'll publish an annotated read of v0.1 the day it goes live.

 Checklist for businesses Read Sierra's post

 Spec status RSS updates
