October 10, 2026InfrastructureMCPAgents

Sierra Published Poppy, the Spec for Agents Doing Business With Companies. 37 Partners, Apache 2.0.

Three days after announcing it, Sierra put the draft on the table. Personal Agent Protocol, which everyone involved calls Poppy, is now a readable Draft 0.1 at personalagentprotocol.org, licensed Apache 2.0, with a reference implementation and design workshops promised within a month. The partner list grew from seven to 37 overnight. The original seven were Meta, Genesys, Instinct, Rocket, Shopify, Stripe and Walmart. The 35 new names include Bank of America, Wells Fargo, BBVA, Chime, Mastercard, Visa, PayPal, Venmo, Plaid, Adyen, Synchrony, Cigna, GEICO, Liberty Mutual, United Airlines, Hertz, Target, Nordstrom, Gap, Comcast, DIRECTV, FOX, SiriusXM, Okta, 1Password, Cloudflare, Notion, Zapier, Zendesk, Klaviyo, OneSignal, ElevenLabs, Atomic, Insurify, and OpenAI. Bret Taylor posted it with the line that the response had been "incredible."

Say the problem plainly, because the spec does. Today a company either blocks agents or lets an agent log in as the user and do anything the user could. Companies spend effort detecting agents, agents spend effort evading detection, and nobody wins. Poppy inserts a ladder between those extremes: blocked, search without signing in, view the account after sign-in, make changes with the user's approval, full access. A company picks a rung per action. A user picks what their agent may do. The protocol's job is to make both choices machine-readable.

The mechanics are deliberately boring, which is the right call for a standard. A company publishes a poppy.json at /.well-known/ listing its OAuth issuer, the sign-in types it allows, its APIs as OpenAPI or MCP endpoints, a conversation endpoint for its own agent, and a browser-session endpoint. The agent identifies itself with a client_id that is an HTTPS URL pointing at its own metadata and signing keys. Sessions start signed out and get promoted through one of three sign-in types: direct, where the user signs in on the company's page; device, via a code on any device; or mediated, where the agent submits credentials the company has chosen to accept. Every API call carries a short-lived session token bound to the agent's key with DPoP proof, so a stolen token is useless without the key. Scopes are just poppy:read and poppy:write plus whatever the company defines. One session covers API calls, a conversation with the company agent, and browsing the website, where the agent's browser posts a signed assertion and the company sets a cookie tied to the session. Conversations carry a sender field that says whether a person or an AI is speaking, and the company can request the user join directly.

What is new here is not the cryptography, all of which is OAuth, JWT, DPoP and OpenAPI that already exist. What is new is that a bank, a card network, an airline and an insurer have put their names on a document that says an agent is a first-class client with its own identity, distinct from the user, with scoped permissions the company controls. That is the exact thing Wikimedia asked OpenAI for three weeks ago and the exact thing the Philadelphia police found out the hard way this week was missing. Sierra wrote it, Meta co-signed it, OpenAI is on the list. Anthropic and Google are not. A standard for how agents identify themselves to the companies they act on is the kind of thing that gets decided once. The first draft is 0.1, and the people who need to object have about a month.

Protocol site: https://personalagentprotocol.org/
Spec: https://personalagentprotocol.org/docs/spec
Sierra post: https://sierra.ai/blog/poppy
← Previous
Cloudflare Bought Deno. Ryan Dahl Says the Reason Is Agent Harnesses.
Next β†’
The Pentest Agent Named in the Korean Bank Breaches Went Closed-Source. That Fixes Nothing.
← Back to all articles

Comments

Loading...
>_